Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

1989 results about "Key generation" patented technology

Key generation is the process of generating keys in cryptography. A key is used to encrypt and decrypt whatever data is being encrypted/decrypted. A device or program used to generate keys is called a key generator or keygen.

Methods and Systems for Privacy-Preserving Location Verification

A computer-implemented method and system for privacy-preserving location verification in distributed networks comprises initializing a multi-modal biometric authentication system on a user device, generating cryptographic keys using a distributed key generation protocol, binding the cryptographic keys to biometric templates using a fuzzy vault scheme, constructing and broadcasting encrypted location beacons, and generating zero-knowledge proofs of location claims. The system includes user devices equipped with biometric sensors and verifier devices configured to validate location claims and maintain consensus in a blockchain network. The method implements real-time liveness detection for multiple biometric input types, executes fault-tolerant consensus algorithms with privacy preservation, and maintains a dual-scoring mechanism comprising device trust scores and user reputation scores. The system enables secure location verification while preserving user privacy through cryptographic protocols and biometric authentication in decentralized environments.
Owner:ABDELSAMIE MAHER A

Sensing data chip-level dynamic key negotiation method

The invention relates to the technical field of sensing data security, and discloses a sensing data chip-level dynamic key negotiation method, which comprises the following steps of: acquiring a unique hardware identifier and key parameters of a sensor node, and generating a dynamic key seed matrix; after acquisition is completed, randomly intercepting data segments, performing median filtering and normalization preprocessing, extracting local statistical features and global features to generate a data feature sequence, and splicing the data feature sequence to a seed matrix to obtain a dynamic key generation matrix; a dynamic negotiation key is generated through standardization and SM3 Hash algorithm encryption, and is stored in a cloud and node security unit; during verification, dual verification is realized through hash comparison and plaintext bit-by-bit matching; and setting an environment parameter exception triggering mechanism, and updating the key if accumulative exception exceeds the limit. According to the method, hardware and dynamic data features are fused, and the key security and adaptability are improved.
Owner:ZHONGYING QINGCHUANG TECH CO LTD

Federal learning system based on multi-key homomorphic encryption and adaptive differential privacy

The invention relates to a federated learning system based on multi-key homomorphic encryption and adaptive differential privacy, and belongs to the technical field of privacy computing. According to the system, on the premise that no trusted third party exists, a multi-client collaborative key generation and threshold decryption mechanism is achieved, it is ensured that model parameters are always in an encrypted state in the aggregation process, and leakage of a single node is prevented. By introducing a parameter sensitivity analysis and selective encryption strategy, the system only encrypts high-risk parameters, and the encryption burden is effectively reduced. Meanwhile, in combination with an adaptive privacy budget allocation mechanism, the system dynamically adjusts noise intensity according to a model training state, and model performance and convergence speed are maintained while privacy protection capability is improved. According to the method, high robustness and collusion resistance are realized, stable operation under the condition that part of clients are offline is supported, and the method is suitable for application scenes such as medical treatment and finance with high data sensitivity and strict performance requirements.
Owner:FUZHOU UNIV

Adaptive encryption system based on AI intelligent safety management

The invention discloses a self-adaptive encryption system based on AI intelligent security management, which relates to the technical field of information security, and comprises a data acquisition module, a risk assessment module, an encryption algorithm selection module, a key generation and management module, an encryption execution module and an encryption effect feedback module, the data collection module is used for collecting various data in a system operation environment, including but not limited to network flow data, equipment state data and user behavior data; and the risk assessment module analyzes the collected data based on an AI algorithm and assesses the security risk level faced by the current system. The operation environment data is comprehensively collected through the data acquisition module, the security risk level is evaluated in real time through the risk evaluation module based on the AI algorithm, the adaptive encryption algorithm can be dynamically selected according to the risk, the defect that a traditional encryption system is fixed in strategy is overcome, and encryption pertinence and effectiveness are improved.
Owner:HEBI CRYPTOADVANCED TECH RES INST

Industrial internet data security communication method based on hybrid anti-quantum cryptography

The invention discloses an industrial internet data security communication method based on hybrid anti-quantum cryptography, which relates to the technical field of data communication, and comprises the following steps: acquiring a key pair and an anti-quantum security certificate; sending a connection request to data receiver equipment to complete certificate credibility authentication, and sending an anti-quantum security certificate of the equipment; receiving a shared key seed sent by the data receiver equipment; decrypting the encapsulated ciphertext to obtain a shared key seed, and generating a corresponding shared key according to the same shared key generation algorithm as the data receiver equipment; the method comprises the following steps of: signing original data by using a signature private key, splicing a signature and the original data to obtain spliced data, encrypting the spliced data by using a shared key based on an AES-256-GCM algorithm to obtain an encrypted ciphertext and an ML-DSA signature, and sending the encrypted ciphertext to data receiver equipment. According to the method, the key distribution step is simplified, the signature verification calculation overhead is optimized, and the data communication efficiency is improved.
Owner:SICHUAN UNIV +1

Method and system for realizing USB flash disk equipment interaction based on flash memory encryption technology

The invention relates to the technical field of cores, and discloses a method and a system for realizing USB flash disk equipment interaction based on a flash memory encryption technology, which comprises the following steps of: dividing an encryptable data block of a flash memory controller, and determining a dynamic entropy weight of the encryptable data block by utilizing an equipment interaction instruction and a random noise characteristic signal; generating a self-adaptive key generation sequence capable of encrypting data blocks through an address allocation mode and a dynamic entropy weight of a flash memory controller; calculating a side channel leakage risk index of the flash memory controller, and setting a security level label of an encryptable data block in combination with a self-adaptive key generation sequence; the method comprises the following steps: setting a differentiated security protection mechanism of an encipherable data block by constructing an access control matrix of the encipherable data block and an encryption risk area of a flash memory controller; and generating a secure interaction scheme of the USB flash disk equipment based on the self-adaptive key generation sequence in combination with the differential security protection mechanism and the access control matrix. According to the invention, the interaction safety and reliability of the USB flash disk equipment can be improved.
Owner:SHENZHEN LINGCHUANG IND CO LTD

Cloud data secure transmission system and method based on quantum encryption technology

The invention relates to the technical field of network security, in particular to a cloud data secure transmission system and method based on a quantum encryption technology. Comprising a quantum key generation and management unit used for generating a physical layer security key, realizing key true random generation through a quantum state unclonable principle, and optimizing key negotiation efficiency by adopting an improved adaptive basis vector matching algorithm; a data transmission encryption unit; a physical layer safety monitoring unit; and a channel fusion switching unit. According to the method, the physical layer security key is generated based on the quantum state unclonable principle, the dependency limitation of a traditional encryption algorithm on mathematics is broken through, and the cracking risk of quantum computing on bottom layer encryption logic can be reduced; according to the invention, photon polarization state parameters are collected in real time through the physical layer security monitoring unit, the eavesdropping behavior is detected based on the preset error rate threshold, real-time perception of the eavesdropping behavior in a transmission link is realized, and the defect that the security state of the physical layer cannot be perceived in real time in a traditional scheme is overcome.
Owner:JIUYILI DIGITAL TECH (SHENZHEN) CO LTD

Image encryption system and method in smart power grid environment

The invention discloses an image encryption system and method in an intelligent power grid environment, and aims to solve the problem that an encryption strategy is static and lacks self-adaptive capability in the prior art. The image encryption system comprises terminal equipment, edge equipment and central equipment, and a dynamic key generation unit on the terminal equipment generates a dynamic key by cooperatively utilizing a physical unclonable feature (PUF) of the equipment and a real-time load of a power grid; the hierarchical encryption unit performs encryption of different intensities based on image content complexity. A topology sensing transmission module of the system analyzes power grid topology by using a graph neural network (GNN) and dynamically optimizes transmission. In addition, the image encryption system further integrates low-density parity check code encoding and decoding and a self-adaptive decryption strategy so as to enhance the anti-interference capability. According to the invention, by constructing a sensing, decision-making and execution integrated adaptive security system, the security, high efficiency and robustness of smart grid image data transmission are significantly improved.
Owner:EASTERN GANSU UNIVERSITY

Identity authentication unloading method and system based on intelligent network card

The invention relates to the field of network security, and discloses an identity authentication unloading method and system based on an intelligent network card. The method comprises the following steps: presetting a master key in an intelligent network card; presetting a master key in the intelligent network card; receiving client request data forwarded by the application layer and extracting a service identifier; generating a private key of the corresponding service through the service identifier and the master key; acquiring a local authentication message, signing the local authentication message by using the private key, generating a server signature value, and sending the server signature value to the client through the application layer to trigger a client authentication process; receiving client certificate data forwarded by the application layer and extracting a certificate signature value; and verifying the certificate signature value by using a preset certificate issuing mechanism public key and generating a verification result, and outputting feedback information based on the verification result. According to the method, a hardware-level unloading function in an identity authentication process is realized through the intelligent network card, and the problems of high calculation overhead and poor expansibility of traditional TLS bidirectional authentication are solved.
Owner:JIHUA LAB

Anonymous Internet of Things identity authentication method and device based on anti-quantum computing password

The invention provides an anonymous Internet of Things identity authentication method and device based on an anti-quantum computing password. A key generation device sends a public key to a message sending end and a message receiving end, and sends a private key to an authentication server; the authentication server generates a blind parameter based on the private key, and sends the blind parameter to the message sending end; the message sending end performs blind operation based on the blind parameter, the public key and the to-be-transmitted message to obtain a blind message, and sends the blind message to the authentication server; the authentication server performs post-quantum signature on the blind message based on the private key to obtain a to-be-solved blind signature, and sends the to-be-solved blind signature to the message sending end; the message sending end carries out blind resolution operation on the to-be-resolved blind signature to obtain a target signature; the message sending end sends the to-be-transmitted message and the target signature to a message receiving end; and the message receiving end performs post-quantum verification on the target signature based on the public key, and if verification succeeds, processing is performed based on the to-be-transmitted message. Through the scheme of the invention, the user data security can be improved.
Owner:HANGZHOU HIKVISION DIGITAL TECHNOLOGY CO LTD

Configurable number-theory transformation parallel computing acceleration method and device for post quantum cryptography algorithm

The invention discloses a configurable number-theory transformation parallel computing acceleration method and device for a post quantum cryptographic algorithm, and relates to the technical field of cryptographic algorithms. The number theory transformation is a calculation bottleneck in lattice-based post-quantum cryptography and PQC; a hardware accelerator specially designed for number theory transformation (NTT) is an effective solution for improving the execution speed. At present, a mainstream design neglects the influence of the scale of a calculation array, so that the design of an NTT calculation circuit is poor in flexibility and low in memory utilization rate, and a two-dimensional reconfigurable number theory transformation acceleration circuit is provided; the method is applied to a key generation stage, an encryption stage and a decryption stage of the post-quantum cryptographic algorithm. The NTT reconfigurable computing circuit provided by the invention can keep the utilization rate of hardware resources, and is suitable for mobile terminal equipment with limited resources; the NTT circuit adopts a low-complexity memory mapping scheme, so that the address control logic is greatly simplified, and the hardware overhead is reduced.
Owner:BEIJING INST OF TECH +1

Data packet optimization processing method and device, equipment and medium

The invention relates to the technical field of data processing, can be applied to business scenes such as financial science and technology and medical health, and discloses a data grouping optimization processing method, device and equipment and a medium. The method comprises the steps that input data are collected, cleaning and format unification are completed, and cleaned data are generated; generating a grouping mark from a condition constraint library based on the data attribute field; dividing the data into a plurality of subsets according to a segmentation strategy and distributing the subsets to a plurality of processing nodes; generating a grouping key in each processing node according to the grouping mark and the data attribute field; grouping identifiers are distributed for the records based on the grouping keys, and a local grouping result table is formed; and finally, collecting all local results, verifying the consistency, and generating a global grouping result table. According to the method, sorting and key generation are performed in combination with the data attribute fields and the grouping marks, high-precision grouping identification is realized, and the accuracy of a global grouping result is guaranteed through an inter-node consistency verification mechanism.
Owner:CHINA PING AN LIFE INSURANCE CO LTD

Data auditing and approving method and device

The invention relates to the technical field of data security, and particularly provides a data auditing and approving method and device, which is applied to a scene that multi-role collaborative decryption is required for multi-level approval, and comprises the following steps: S1, data fragmentation and hybrid encryption; s2, performing dynamic key management; s3, attribute base access control; and S4, block chain evidence storage and auditing. Compared with the prior art, dynamic key generation, hierarchical encryption storage, fine-grained permission control and real-time permission revocation can be realized through a credible key management mechanism, and data whole-process security processing under data privatization data auditing is met.
Owner:SHANDONG INSPUR CLOUD GOVERNMENT INFORMATION TECHNOLOGY CO LTD

Multi-level access control and authority synchronization method for secure mobile storage

The invention discloses a multi-level access control and authority synchronization method for secure mobile storage, and belongs to the field of mobile storage security. Aiming at the problems of data leakage, poor authority management and the like of the mobile storage device, a multi-level access control framework, a decentralized authority synchronization mechanism and a dynamic token and zero-knowledge proof system are constructed. Generating a plurality of layers of sub-keys from a master key by using a PBKDF2 algorithm through hierarchical key generation, and associating different encryption areas and authority strategies; incremental synchronization is carried out based on a Merkle tree, and data consistency is guaranteed through a consistency verification protocol; a temporary token is generated by using a Schnorr protocol, and the permission is verified in combination with zero-knowledge proof, so that the privacy security is ensured. In scene application of a power grid and the like, a master key is activated through biological recognition, permission is loaded according to a strategy, and permission change is efficiently synchronized. According to the method, the mobile storage security and the management efficiency are improved, and accurate authority control and reliable synchronization are realized.
Owner:GUANGXI POWER GRID CORP

Secure communication method and system based on QRNG and Beidou positioning terminal

The invention provides a secure communication method and system based on a QRNG and a Beidou positioning terminal. A sending end and a receiving end of communication preset a pre-shared initial key, and a space-time reference parameter group is obtained through Beidou positioning; a secret key packaging secret key is generated by using a national secret SM4 algorithm; monitoring time-space parameter deviation in a communication process in real time, and triggering a key updating protocol when the time-space parameter deviation exceeds a threshold value; and after the receiving end verifies the Hash verification value, decrypting to obtain the primary encryption key, and restoring the plaintext data. According to the system, the generated true random number sequence is used as an encryption key, so that the unpredictability and randomness of the key are fundamentally enhanced, and quantum computing attack and man-in-the-middle attack are effectively resisted. The use of the pre-shared key mechanism and the key packaging key improves the response speed and efficiency of the communication system. And meanwhile, the position parameter and the timestamp are deeply fused to the key generation process, so that the spatio-temporal information is more difficult to counterfeit, and the defense capability of the system is further improved.
Owner:YIXUNTONG TECH CO LTD

Network information data transmission security method based on advanced encryption standard (AES)

The invention relates to network information security and cryptography, and provides an AES-based network information data transmission security method, which comprises the following steps of: generating an information key, namely generating a round key through loop iteration; the encryption process of information data transmission comprises the following steps: encrypting a plaintext after preprocessing, and generating an intermediate ciphertext and an integrity verification label; in the information data decryption process, the plaintext is recovered through reverse operation after the label is verified; the data security constraint of the information is carried out, and a multi-level defense system is constructed; aP I mapping for information transmission, and calling an interface to realize encryption, decryption and authentication verification; information data encryption complexity is controlled, complexity is optimized, and big data are encrypted in a blocking mode; the information data security is guaranteed, and the transmission security is ensured. The method significantly enhances data security, improves transmission efficiency, constructs multi-level security defense, provides flexibility and adaptability, simplifies implementation and management, conforms to the future security trend, and provides an efficient, reliable and easy-to-use solution for network information security.
Owner:GUANGDONG UNIV OF SCI & TECH

Security authentication method and device, computer equipment, readable storage medium and program product

The invention relates to a security authentication method and device, computer equipment, a computer readable storage medium and a computer program product. The method comprises the following steps: receiving a key generation request sent by target equipment; if it is determined that the key generation request is legal, generating a trust identifier and a security certificate of the target device, obtaining an identifier verification request through the trust identifier, and sending the identifier verification request to an authentication server, so that the authentication server verifies the trust identifier to obtain an access token corresponding to the target device; receiving a message returned by the authentication server, and processing an access token carried by the message to obtain a trust identifier; and writing the security certificate into the target protection area, and sending the trust identifier and the security certificate to the target equipment, so that the target equipment is registered in the authentication server. By adopting the method, the identity verification of the equipment and the control of an encryption communication mechanism are realized, and the safety protection performance in a communication system is further improved.
Owner:CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1

Dynamic key generation system and method based on multi-source QRNG and QKD

The invention relates to the technical field of quantum cryptography, in particular to a dynamic key generation system and method based on multi-source QRNG and QKD, and the system comprises an interface registration method, a calling method, related equipment and a storage medium, is used for generating a high-security quantum key, and is a quantum key service system with a layered architecture. By abstracting, integrating and managing bottom-layer multi-source QRNG and QKD equipment and fully utilizing the flexible scheduling of quantum equipment, the security of key generation is ensured, so that the key service has higher performance, usability and security, and unified, dynamic and high-security quantum key generation and supply services are provided for various applications of the upper layer. The method is widely applied to the industries and fields of government, finance, energy, traffic, electric power and the like, meets the requirements of quantum key acquisition of various business applications in cloud computing and non-cloud environments, and ensures information security and business continuity.
Owner:CHINA SOUTHERN POWER GRID DIGITAL GRID GROUP (GUIZHOU) CO LTD

Network security protection system and method based on electric power emergency communication environment

The invention belongs to the technical field of network security, and particularly relates to a network security protection system and method based on an electric power emergency communication environment, and the system comprises a quantum-classical hybrid encryption system which is used for generating a dynamic key in real time; the biological characteristic driven dynamic trust ring is used for equipment identity authentication; the unmanned aerial vehicle relay network protocol is used for data transmission; the secret key after-reading burn-down protocol is used for information secret key after-reading burn-down; a key output by the quantum-classical hybrid encryption system is used for authentication encryption of a biological characteristic driven dynamic trust ring, an unmanned aerial vehicle relay network protocol transmits data encrypted by the quantum key, and a key burn-down protocol is used for reading encrypted data to trigger a key burn-down mechanism. According to the method, the key security is improved, the network attack difficulty is increased, the communication delay in a disaster is reduced, man-in-the-middle capture and attack can be immunized, and the problem of contradiction between the encryption strength and the real-time performance is solved.
Owner:CHINA SOUTHERN POWER GRID COMPANY

Security inter-core communication method based on derived key negotiation

The invention discloses a safety inter-core communication method based on derived key negotiation. The safety defect of a traditional inter-core communication scheme is overcome through a dynamic key negotiation mechanism. Based on a preset derived base key and a random salt value, a unique temporary session key is negotiated before each communication, and forward security is ensured: even if the derived base key is leaked, historical encrypted data still cannot be decoded; a bidirectional salt value check code verification mechanism is adopted, chip identity legality authentication is achieved in the negotiation stage, and forgery or tampering attacks are blocked; during communication, a data ciphertext check code is generated through a check key, and data integrity and source authenticity are guaranteed; it is ensured that the session key is unpredictable each time through the random salt value, and replay attacks are effectively resisted in combination with a timeliness verification mechanism. In addition, key re-negotiation is triggered according to data sensitivity, a key exposure time window is dynamically reduced, the risk of long-term key leakage is further reduced, and safety and resource efficiency are both considered.
Owner:SHENZHEN ROADROVER TECH

Secure data transmission method for wireless communication system

The invention discloses a secure data transmission method for a wireless communication system, which relates to the technical field of secure data transmission and comprises three steps of key generation and synchronization, physical layer subcarrier encryption and key enhancement and authentication. The method comprises the following steps: firstly, extracting multi-dimensional features through channel detection to generate a dynamic initial key, and setting a trigger condition to realize key synchronization; then, a permutation matrix is generated by using a secret key to perform scrambling encryption on a data subcarrier position, and a receiving end performs descrambling and then performs feedback through CRC verification so as to guarantee data integrity; and finally, quantum noise is introduced to enhance the randomness of the secret key, and zero-knowledge authentication is adopted to verify the identity, so that the security and the anti-attack capability of wireless communication data transmission are effectively improved.
Owner:SHENZHEN XIAOPAN TECHNOLOGY CO LTD

Network data sharing method and system based on dual identity authentication

The invention discloses a network data sharing method and system based on dual identity authentication, and the method comprises the steps: a user A logs in a client A through the dual authentication of a password and a digital certificate, and transmits an encrypted file data packet formed after an original file is encrypted to a server; the user A selects target data at the client A and appoints a shared user B, and the server updates a shared file list of the user A; the user B submits a data downloading request on the client B, and the server verifies the authority of the user B and sends the encrypted file data packet to the client B; the client B decrypts the encrypted file data packet to obtain an original file; the system comprises a client module, a storage module and a server module. According to the method, a dynamic key generation mechanism is adopted, the requirement for real-time change of the authority in a multi-user cooperation scene is met, the leakage risk of a preset key is avoided, and the conflict between user privacy and sharing convenience is effectively solved.
Owner:NANJING UNARY INFORMATION TECH

Power real-time data dynamic encryption transmission method and system based on national secret algorithm

The invention discloses an electric power real-time data dynamic encryption transmission method and system based on a national secret algorithm. According to the method, the real-time updating of the session key is realized by fusing the SM3 Hash algorithm and the multi-dimensional dynamic factor, and the anti-attack capability of data transmission of the power system is improved. A timestamp and data counter double-trigger mechanism is introduced in the key generation process, so that the key is automatically alternated under a fixed time interval or a data volume threshold value, a key exposure window is shortened, and the security risk caused by using the same key for a long time is reduced. Key synchronization is carried out in combination with an SM2 bidirectional authentication channel, the confidentiality of key distribution is ensured, access of unauthorized equipment is avoided through an identity authentication mechanism, full-closed-loop security protection from key generation to transmission is formed, the high-security requirement of the power industry for key data transmission is met, and the security of key data transmission is improved. Through deep combination of a cryptographic algorithm system and a dynamic adaptation mechanism, the high efficiency and compliance of power real-time data transmission are considered while the security is ensured.
Owner:GUIZHOU WUJIANG HYDROPOWER DEV

Session key generation method and related apparatus

The application discloses a session key generation method and related device, and relates to the technical field of quantum encryption; when a first SIM card needs to interact information with a second SIM card, a private key team and a public key team can be generated; since the first SIM card is pre-configured with a hybrid key encapsulation algorithm, the public key team includes a public key that can resist quantum attacks, so after the public key team is sent to the second SIM card, the second SIM card can generate key generation information by using an encapsulation algorithm in the hybrid key encapsulation algorithm, encrypt the key generation information by using the public key team, obtain ciphertext information, and send the ciphertext information to the first SIM card; in this way, the first SIM card can decrypt the ciphertext information by using the private key team, obtain the key generation information, and thus obtain a session key.
Owner:ORIGIN QUANTUM COMPUTING TECH (HEFEI) CO LTD

Security operation and maintenance management method for power production management system based on national secret algorithm

The invention discloses an electric power production management system safety operation and maintenance management method based on a national secret algorithm. According to the method, the key and the real-time running state of the equipment are deeply bound through a dynamic key derivation mechanism, so that the key is dynamically adjusted along with parameters such as the load rate, the temperature and the bit error rate, state change, namely key updating, is realized, and the anti-cracking capability of the key is greatly improved; the SM2, SM3, SM4 and other national cryptographic standards are adopted from root key generation, identity authentication, data transmission encryption and log tampering prevention of the full-link application of the national cryptographic algorithm system, it is ensured that the encryption strength meets the national password management requirement, and the overall encryption protection level of the system is improved. Closed-loop protection is formed through deep linkage among multiple steps, fragmentation of a safety mechanism is avoided, meanwhile, the traceability and the fault recovery efficiency of system operation are further improved through the whole-process encryption archiving and emergency response rapid recovery process of audit logs, and transmission and storage safety of power production core data is guaranteed.
Owner:GUIZHOU WUJIANG HYDROPOWER DEV

Industrial internet data secure transmission method based on quantum key distribution

The invention relates to the technical field of industrial internet data secure transmission, and discloses an industrial internet data secure transmission method based on quantum key distribution, and the method comprises the steps: obtaining a data transmission request, and determining the channel feature parameters of a data unit; calculating a quantum key generation index, and generating a key input set; loading a quantum key distribution model, and determining dynamic key parameters; marking parameters to generate a secure transmission map; and performing data integrity detection, and performing encrypted transmission based on a detection result. When parameter conflicts are detected, fusing parameters according to path priorities; parameter differences are monitored in real time after transmission, and the secret key is corrected when the parameters are abnormal. The pre-configured quantum key distribution model is constructed through historical data training. And when the secure transmission map is generated, the dynamic key parameters are superposed to a three-dimensional channel map layer containing transmission path topology, quantum state preparation parameters and bit error rate conditions for visualization. Dynamic and secure transmission of industrial internet data is realized, and the security and reliability of transmission are improved.
Owner:国义招标股份有限公司

Data storage security protection method and system based on solid state disk

The invention relates to the field of computer security, and discloses a data storage security protection method and system based on a solid-state hard disk, which comprises the following steps: identifying the inherent physical difference of a flash memory chip in the solid-state hard disk so as to calculate the read-write time sequence micro-deviation of the solid-state hard disk; performing hash operation on the device root key and the unique identifier of the controller corresponding to the solid state disk to obtain a bound master control key; generating a temporary encryption key of the write-in operation to encrypt plaintext data of the host system to obtain ciphertext data; writing the ciphertext data into a flash memory physical page corresponding to the physical page address to obtain a ciphertext physical page address; when the access mode is a hostile attack mode, secretly updating the ciphertext physical page address into a new physical page address, and deleting the ciphertext physical page address; and when the access mode is a secure access mode and the verification key is consistent with the bound master control key, normal loading and data access requests of the solid state disk are allowed. According to the invention, the security and integrity of data storage can be improved.
Owner:深圳市彦胜科技有限公司

Identity authentication method and system for resisting identity forgery attack

The invention provides an identity authentication method and system for resisting an identity forgery attack, which are used for guaranteeing the safety of cross-domain communication. The method comprises the following steps: firstly, initializing a system, and generating a key pair for an entity based on an elliptic curve; when the user registers in the domain, the authentication center generates a key pair, encryption parameters and an identity certificate and stores the key pair, the encryption parameters and the identity certificate in the slave chain. A key generation center (KGC) pre-generates a factor including a private key and pre-loads the factor to a roadside unit (RSU). When a user initiates a pseudonym generation request, the RSU verifies the request and forwards the request to a nearby base station; and the base station predicts a resource use state by using an AI model, and dynamically assigns a service base station to calculate pseudonym generation parameters in real time. A user generates own pseudonym, verification parameters and a key pair after obtaining the parameters, and generates a unique signature by using the pseudonym key to encrypt a message and send the encrypted message. After the receiver verifies the validity of the message, a verification request is forwarded to the base station through the RSU, the service base station is dynamically assigned to verify the legality of the pseudonym based on the AI strategy, and a user identity certificate is inquired and verified through carrying address information cross-chain (slave chain / main chain cooperation). According to the method, malicious vehicles with fake kana can be effectively identified, dynamic scheduling of resources is realized by using AI, and the low-delay requirement is met.
Owner:北京国瑞数智技术有限公司

Distributed quantum security encryption method, system and device

The invention provides a distributed quantum security encryption method, system and device. The method comprises the following steps: monitoring the quality of a quantum key distribution link in real time, and dynamically selecting a quantum key, a post-quantum session key or a fusion key of the quantum key and the post-quantum session key as a working key; and when the node cannot be directly reached, the trusted relay node generates an end-to-end key seed by using a quantum key and a post-quantum cryptography shared key which are respectively established with the two ends, the end-to-end key seed is encrypted and distributed by a public key and then a session key is independently derived by the two communication parties, and the relay node cannot decrypt. The system adopts a distributed Mesh network architecture supporting a terminal / relay dual mode. The device integrates a quantum random number generator, a post quantum cryptography coprocessor and a mixed key engine. The method integrates the advantages of quantum physical security and post quantum cryptography, has high security and availability, and is suitable for constructing a key infrastructure security communication network resisting quantum computing attack.
Owner:INFORMATION & COMMNUNICATION BRANCH STATE GRID JIANGXI ELECTRIC POWER CO

Gateway data security guarantee method based on star flash technology

The invention belongs to the technical field of data security, and particularly relates to a gateway data security guarantee method based on a satellite flash technology. The method comprises the following steps: constructing a star flash multi-channel dynamic scrambling communication structure, establishing a dual-channel architecture, and completing initial key generation and authentication channel synchronization through a dual-channel scrambling code negotiation mechanism; extracting features of the access equipment, constructing and updating an identity feature vector; performing atlas processing on the historical data, and constructing a node behavior atlas database; generating a comprehensive safety confidence score according to the identity feature vector and the behavior map matching degree and the like; and if the score is lower than a threshold, blocking communication. According to the invention, the anti-monitoring and anti-attack capabilities are improved, dynamic key negotiation, identity credible modeling and abnormal behavior identification are realized, and the security of gateway data interaction is ensured.
Owner:JINAN BOSAI NETWORK TECH CO LTD +1