Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

120 results about "Key generation center" patented technology

Identity privacy protection system and method for safe sharing of power data

PendingCN121561950AData processing applicationsDigital data protectionChosen-plaintext attackAttack
The invention discloses an identity privacy protection system and method oriented to power data security sharing, which combine single-factor combination authentication and identity traceability and utilize the transparency and tamper resistance of a block chain. Comprising an electric power key generation center, an electric power cloud service provider, an electric power data owner, an electric power data user and a block chain, user identity privacy is ensured, safe identity verification is supported, identity traceability is achieved under necessary conditions, and meanwhile safe distribution of keys is achieved. In addition, services and resources are isolated by using groups, so that the flexibility and the expandability of the services and the resources are enhanced. Security analysis and experimental evaluation prove that the method can effectively resist selected plaintext attacks, and meanwhile, high efficiency and practicability are kept.
Owner:STATE GRID HENAN INFORMATION & TELECOMM CO

SM9-based identity-based searchable public key encryption method and system

The invention provides an SM9-based identity-based searchable public key encryption method and an SM9-based identity-based searchable public key encryption system. The system comprises a key generation center, a cloud storage server and a file sending and receiving party. A secret key generation center generates system public and private keys by using an SM9 algorithm, and generates a private key for a user in combination with identity information of the user. The file sender uses the user identity of the receiver and the file keyword to generate a keyword index and uploads the keyword index to the cloud server; when a receiver retrieves the file, the auxiliary parameters in the index are firstly obtained from the cloud server, then a keyword trap door is generated through a private key of the receiver, and the keyword trap door is uploaded to the cloud server; and the server compares the index with the trap door through a matching algorithm, and returns a corresponding ciphertext file to a receiver for decryption if matching succeeds. The secret key generation method is consistent with an SM9 algorithm, the application field of SM9 is expanded, and the safe and efficient searchable public key encryption method which does not need certificate management and can effectively resist internal keyword guessing attacks is achieved.
Owner:NANJING UNIV OF POSTS & TELECOMM

Internet of vehicles heterogeneous signcryption communication system and method based on double-layer block chain

The invention discloses an Internet of Vehicles heterogeneous signcryption communication system and method based on a double-layer block chain, relates to the technical field of Internet of Vehicles, and solves the technical problems that the Internet of Vehicles technology is insufficient in expansibility and poor in compatibility, safety and efficiency are difficult to consider, and use requirements are difficult to meet. The system comprises a private key generation center PKG, a secret key generation center KGC, an on-board unit OBU, a roadside unit RSU and a double-layer block chain device. The private key generation center PKG is used for generating and distributing a public key and private key pair of the identity signcryption IBC; the key generation center KGC is used for key updating and management of the certificateless signcryption CLC; the OBU is used for performing communication between the vehicle and other vehicles or the road side unit; the roadside unit RSU is used for communication support and data forwarding; and the double-layer block chain equipment is used for carrying out data storage and security verification in the communication system. According to the invention, the calculation overhead and communication cost of the system are obviously reduced, and safe, efficient and extensible authentication and data transmission in a high-dynamic and large-scale V2X environment is realized.
Owner:SHENZHEN SEG SCI NAVIGATIONS CO LTD

Unmanned aerial vehicle cluster dynamic cross-domain group key management method and system based on CRT

The invention discloses an unmanned aerial vehicle cluster dynamic cross-domain key management method and system based on the Chinese remainder theorem (CRT), a key generation center generates system public and private keys and public parameters, and a ground station and an unmanned aerial vehicle perform hierarchical registration and verify respective keys; the unmanned aerial vehicles respectively generate signature messages and send the signature messages to a specified ground station for identity verification, and the ground station constructs a group key based on CRT and publishes the group key to the block chain; when a new unmanned aerial vehicle applies for joining, a signature message is sent to the ground station, and the ground station updates and publishes the group key; when the unmanned aerial vehicle applies for leaving, a leaving message is sent to the ground station, and the ground station updates and publishes the group key. According to the method, complex operations such as bilinear pairing operation and large integer modular exponentiation operation are avoided by optimizing the group key derivation process based on the CRT, and the calculation complexity is remarkably reduced. Meanwhile, efficient cross-domain authentication and batch verification are realized through Pedersen commitment and a zero-knowledge proof technology, and communication and calculation overhead is reduced.
Owner:SOUTHEAST UNIV

Lightweight hierarchical trust access authentication method and system based on identification

The invention discloses an identification-based lightweight hierarchical trust access authentication method and system, and mainly relates to the technical field of network security. Comprising the following steps: in an offline stage, an electric power registration center generates a private key root bound with an identity for a terminal through identity-based cryptography, a key generation center derives a lightweight work key voucher and pre-calculates verification points of all terminals, and a unified main multi-dimensional Bloom filter is constructed and distributed to a main station; in the online stage, a terminal updates a key and generates a signature only through hash operation, a master station reconstructs candidate verification points after receiving a message, and non-interactive verification is completed by locally querying a master multi-dimensional bloom filter. The method has the advantages that unification of strong identity credibility and extreme light weight of the terminal is achieved, the terminal side only needs efficient Hash operation, the server supports high-concurrency and low-delay authentication through the pre-calculation and Bloom filter technology, and the problem of safe access of massive distributed terminals in the electric power Internet of Things is effectively solved.
Owner:STATE GRID SHANDONG ELECTRIC POWER COMPANY WEIFANG POWER SUPPLY +1

Cleanable certificateless signcryption method, device, equipment and system

The invention provides a cleanable certificateless signcryption method, a cleanable certificateless signcryption device, cleanable certificateless signcryption equipment and a cleanable certificateless signcryption system. Receiving a signcryption ciphertext which is sent by the data sending end and contains signature information and ciphertext information; verifying the signcryption ciphertext according to the public parameter and the key information; and after the verification is passed, re-randomizing signature information and ciphertext information in the signcryption ciphertext in an undecrypted state to obtain a purified signcryption ciphertext, and sending the purified signcryption ciphertext to a data receiving end to trigger the data receiving end to verify and decrypt the purified signcryption ciphertext to obtain plaintext information corresponding to the ciphertext information. According to the method and the device, the signcryption ciphertext can be re-random on the premise that the ciphertext is not unlocked, and meanwhile, the re-random signcryption ciphertext is ensured to still meet confidentiality and integrity and can be verified by a receiving end, so that leakage attack behaviors of a malicious data sender are effectively prevented.
Owner:BEIHANG UNIV +1

Internet of vehicles data sharing method based on cloud

The invention discloses a cloud-based Internet of Vehicles data sharing method, which comprises the following steps that: under a certificateless framework, a secret key generation center distributes part of private keys, and a user combines local secret key values into a complete private key; a data owner encrypts and uploads traffic data based on bilinear mapping, and then constructs a re-encryption key through polynomial interpolation, so that a cloud server can decrypt all receivers in an authorization set through one-time re-encryption, and meanwhile, the identities of the receivers are hidden. Timestamp embedding achieves temporary entrustment, and the cloud does not make contact with plaintexts and private keys in the whole process. According to the scheme, key escrow is eliminated, terminal communication calculation overhead is reduced, and anonymous, fine-grained and time-efficient data sharing requirements of the Internet of Vehicles are met.
Owner:JIANGSU UNIV OF TECH

Image publishing privacy protection method based on attribute encryption

The invention discloses an image release privacy protection method based on attribute encryption, which solves the problems that in the prior art, access control expansibility is poor, an image processing mode damages visibility and a sensitive area is not self-defined, realizes safe image access control, ensures that only an authorized user can decrypt and recover an original image, and improves user experience. Meanwhile, the sensitive area is protected from unauthorized access; the method comprises the following steps: initializing an attribute-based encryption system through a key generation center, and distributing a public key and a user private key to realize fine-grained access control. And an image owner scrambles image color blocks by using DCT (Discrete Cosine Transform), and steganoscopes control parameters in the image to be published. And after the authorized visitor extracts the encryption parameter, the private key is used for decryption to obtain the original key, and the auxiliary information is combined to perform inverse operation on the image sensitive area to accurately recover the original image. In the whole process, flexible access control is achieved, and meanwhile protection and availability of image content are effectively balanced.
Owner:XIDIAN UNIV

A commercial cryptographic digital certificate generation method supporting quantum-resistant cryptography

The application relates to the technical field of information security, in particular to a commercial cipher digital certificate generation method supporting quantum-resistant cipher, which comprises the following steps: a certificate authority generates a hybrid signature self-signed certificate with quantum-resistant cipher signature and traditional public key cipher signature; a user generates a hybrid signature certificate request file and sends the file to the certificate authority; the certificate authority generates a hybrid signature user signature certificate; a key generation center generates a user traditional public key cipher encryption key pair and a user quantum-resistant cipher encryption key pair; the certificate authority generates a hybrid signature user encryption certificate; the certificate authority generates a hybrid encryption public key, a private key encryption ciphertext and a hybrid ciphertext; and the user extracts the hybrid signature signature certificate, the encryption certificate, the quantum-resistant cipher encryption private key and the traditional public key cipher encryption private key, and verifies the signature certificate and the encryption certificate. The application can resist quantum attacks and is compatible with existing digital certificates.
Owner:SHANDONG DUOFANG SEMICON CO LTD +1

A cloud auditing method and system for anonymous data

The application relates to a cloud auditing method and system for anonymous data. The method comprises the following steps: a group administrator sets an initial group state, a key generation center (PKG) generates a master key, a partial key and public parameters; the group administrator allocates a unique identifier to each group user; the group administrator generates a first key pair and distributes the first key pair to the corresponding group user; the group user generates a file label, calculates a corresponding verifier for each block of the file, and a cloud server verifies the correctness of the file label and the verifier; a third-party auditor (TPA) generates an auditing challenge; the cloud server creates a corresponding proof; and the TPA verifies the correctness of the proof. The technical scheme provided by the application introduces a new anonymous strategy in the auditing model, an anonymous strategy based on group element equivalence class replacement realizes anonymity and traceability only with constant level consumption, and can simultaneously support the functions of anonymity, user revocation and traceability.
Owner:TIANJIN UNIV

Multi-group data security sharing method and system supporting traceability and revocation

The invention discloses a multi-group data security sharing method and system supporting traceability and revocation. A trusted key generation center generates parameters required by system operation; generating an attribute private key and a puncturable private key; the data owner uses a pre-formulated access control strategy to encrypt data to be shared by adopting puncturable attribute-based encryption; the group administrator formulates a new access control strategy, and generates a re-encryption key based on an attribute private key of the group administrator; the cloud server performs re-encryption on the original ciphertext according to the proxy re-encryption key; and the group administrator decrypts the original ciphertext according to the attribute private key and the puncturable private key, and the user in the group decrypts the re-encrypted ciphertext according to the attribute private key, the puncturable private key and the authorized private key to obtain the plaintext of the data to be shared. According to the method, the user decryption key is divided into the attribute private key, the puncturable private key and the authorized private key, the group user identity can be uniquely determined through combination of the three types of keys, and refined tracing is achieved.
Owner:WUHAN UNIV

Public key legality verification method and device based on asymmetric encryption algorithm, equipment and medium

The invention discloses a public key legality verification method and device based on an asymmetric encryption algorithm, equipment and a medium, and relates to the technical field of key management, a user public key is generated based on random numbers and elliptic curve parameters of the asymmetric encryption algorithm, and the user public key and a user unique identifier are sent to a key generation center; the key generation center calculates a user declaration public key and a key generation center private key by using the user public key and the user unique identifier; obtaining a user declaration public key and a key generation center private key sent by the key generation center, and calculating a user private key based on the key generation center private key; generating a signature public-private key pair of the user by using the user declaration public key and the user private key, performing matching verification on the signature public-private key pair, and determining the legality of the user declaration public key, thereby avoiding the limitation that the life cycle of the key completely depends on a key generation center, reducing the demand for computing resources and the computing complexity, effectively adapting to resource-limited equipment, and improving the user experience. And the safety, the flexibility and the expandability of the system are improved.
Owner:CETC CYBERSPACE SECURITY TECH CO LTD

An SM9 encryption method supporting single private key decryption of multiple ciphertexts

The application discloses an SM9 encryption method supporting single private key decryption of multiple ciphertexts, a key generation center generates a main public and private key pair, discloses the generated main public key to users in a system, and secretly saves the main private key; the key generation center generates a private key of a user by using the main public and private key pair and all identities ID of the user, and sends the private key to the user through a secure channel; an encrypter generates ciphertext corresponding to a message by using the main public key of the key generation center based on a selected encryption ID and the encrypted message; and a decryption algorithm decrypts the ciphertext to obtain plaintext based on the ciphertext corresponding to the message, the main public key of the key generation center and the private key of the decrypter. The private key can decrypt different ciphertexts encrypted by different public keys, greatly reduces the storage cost of the private key of the user and reduces the management of the private key, and is helpful to promote the application of the SM9 encryption algorithm.
Owner:SOUTHEAST UNIV

A method and system for intelligent collaborative defense against identity spoofing attacks

The application provides a method and system for intelligent collaborative defense against identity spoofing attacks, aiming to improve identity security and resource scheduling efficiency in cross-domain communication. The method includes: when a user registers, an authentication center generates a key pair, encryption parameters and an identity certificate and stores them in a slave chain; a key generation center (KGC) preloads factors containing private keys to a roadside unit (RSU); when a user initiates a pseudonym generation request, the RSU forwards it to a dynamically designated edge computing unit, and simultaneously sends a parallel request to a base station; an intelligent collaborative platform uses an AI model to predict the computing power of the base station group and the resource status of the edge unit in real time, dynamically schedules remote data transmission and cloud sharing, and assigns the edge unit to calculate pseudonym generation parameters; the user generates a pseudonym and a key pair based on the parameters, and signs and encrypts a message; when the recipient verifies the message, the edge unit verifies the legality of the pseudonym, and cooperatively queries the identity certificate through the master-slave chain, and finally verifies the validity of the signature. The application significantly improves the defense capability against spoofing attacks and the system response efficiency through an AI-driven multi-level resource collaboration and dynamic scheduling mechanism.
Owner:北京国瑞数智技术有限公司

A lattice-based puncturable key-policy attribute-based searchable encryption method and system

The present application relates to the technical field of attribute searchable encryption, in particular to a lattice-based puncturable key-policy attribute searchable encryption method and system, which realizes fine-grained and dynamic management of search authority of data receivers through initialization of a key generation center and a key puncture mechanism, and can precisely revoke search capability of a specific keyword without updating all keys; ciphertext generated by a data owner combines attribute encryption and signature technology, which ensures data confidentiality and integrity and resists quantum attacks; a trapdoor generated by a puncture key of a data receiver protects search privacy and realizes efficient ciphertext retrieval; and a test algorithm executed by a cloud server can accurately verify matching of the trapdoor and the ciphertext and return a result under an honest but curious security model. The whole scheme effectively solves the deficiencies of existing schemes in fine-grained dynamic revocation, quantum attack resistance and multi-receiver access control under the support of lattice cryptography theory.
Owner:BEIJING ELECTRONICS SCI & TECH INST

Identity-based digital signature encryption method and system in Internet of Things environment

The invention discloses an identity-based digital signature encryption method and system in an Internet of Things environment, and belongs to the technical field of Internet of Things security. The method comprises the following steps that: a key generation center KGC generates system parameters which comprise a bilinear mapping parameter, a hash function and a master key, and publishes a public parameter; receiving registration information submitted by a user or equipment to the KGC by using own identity information, and calculating and distributing a corresponding private key by the KGC according to the identity information; the sender encrypts the message by using the identity information of the receiver and signs the message by using a private key of the sender; and the receiver verifies the validity of the signature by using the identity information of the sender, and decrypts the message by using a private key of the receiver. According to the invention, the identity-based digital signature encryption is introduced into the communication of the Internet of Things, and through the design of the identity, namely the public key, the lightweight, efficient and flexible communication security guarantee of the Internet of Things is realized, the key and identity management is simplified, the efficient equipment authentication and dynamic access are realized, and the security and mutual trust of cross-scene communication are ensured.
Owner:BEIJING SANSEC TECH DEV

A data encryption sharing method and an efficient data anonymous indexing and retrieval method based on inner product function encryption

The application discloses a data encryption sharing method and an efficient data anonymous tracking retrieval method based on inner product function encryption, and comprises the following steps: a data owner extracts the features of personal data and generates corresponding personal data feature vectors; the data owner sends the personal data feature vectors to a key generation center; the key generation center executes a key generation algorithm to generate corresponding private keys for the personal data feature vectors of the data owner; a retrieval execution party collects personal data of a data retrieval party; the retrieval execution party obtains public parameters from the key generation center, encrypts the personal data of the data retrieval party based on the public parameters, and forms vector ciphertext; and the retrieval execution party executes a decryption algorithm on the vector ciphertext based on the private key and the public parameters, and performs retrieval from the private key of the data owner.
Owner:ZHONGHE TECHNOLOGY (XIONGAN) CO LTD

Certificateless signcryption method, system and device for resisting quantum attack in Internet of Vehicles

The invention discloses an anti-quantum attack certificateless signcryption method, system and device in the Internet of Vehicles, and relates to the technical field of Internet of Vehicles information security, and the method comprises the steps: generating a system public parameter, a main public key and a main private key through a system parameter and a security parameter preset by a vehicle Internet of Vehicles system by a key generation center; obtaining a partial private key based on the identity identifier of the sender, and combining the partial private key with a locally generated random vector to obtain a complete private key of the sender; the sender vehicle performs signcryption operation on the plaintext message by using the complete private key of the sender vehicle and the public key of the receiver, and generates a signcryption text containing a ciphertext and a link label; the receiver carries out decryption and signature verification on the received signcryption text by using a private key of the receiver; according to the method, the lattice cryptographic algorithm based on the error learning and short integer solution problem is introduced, so that the capability of resisting quantum attacks is realized, and the security requirement of the Internet of Vehicles for resisting quantum computing threats in the future is met.
Owner:CHANGZHOU SMART CLOUD NETWORK INFORMATION TECHNOLOGY CO LTD

Two-factor identity authentication method and system for power system

The invention provides a two-factor identity authentication method and system for a power system, and the method comprises the steps: carrying out the registration and login of power equipment through employing an SM2 algorithm; acquiring biological characteristics and identity information of an operator on the authenticated and logged-in power equipment, and generating an identifier ID for the operator; an operator registration request is initiated to a key generation center, an SM9 private key is obtained, and operator registration is completed; verifying the identity of the operator, and logging in the operator; performing operation authentication; the operation authentication comprises the following steps: generating a one-time random number r2; signing the operation details containing the r2 by using an SM9 private key to generate a signature S1; performing joint signature on the signatures S1 and r2 by using an SM2 private key to generate a signature S2; and the r2, the signature S1, the signature S2 and the operation information are sent to a server for verification and are stored in a database to form an audit record. In this way, identity verification of operators and non-repudiation tracing of operation behaviors are achieved.
Owner:NANJING GUODIAN NANZI POWER GRID AUTOMATION CO LTD

Public key authenticated encryption method and system for searchable similar data

The application discloses a public key authentication encryption method and system capable of searching similar data. The public key authentication encryption method comprises the following steps: a key generation center generates public and private keys for a data sender and a data user; the data sender encrypts a file and an abstract of the file by using the public and private keys and a public key of the data user, and sends the ciphertext to a cloud server; the data user encrypts the abstract received from the data sender previously by using a private key and a public key of the data sender, and sends the trapdoor to the cloud server; the cloud server performs similar matching on the ciphertext and the trapdoor, and if the matching is less than or equal to n times and a threshold value is reached, the matching is successful, and the cloud server sends the parsed ciphertext to the data sender; the data sender returns updated ciphertext to the data user after processing, and updates a user query frequency list; and the data user decrypts to obtain the file. The application can realize the similar data search function under the premise of guaranteeing resistance to internal and external keyword guessing attacks.
Owner:HUAIYIN INSTITUTE OF TECHNOLOGY

Cross-KDC key management method and device, electronic equipment and readable storage medium

The invention provides a cross-KDC key management method and device, electronic equipment and a readable storage medium, and relates to the technical field of information security, and the method comprises the steps: selecting any key distribution center as a key generation center for generating a key; in response to a key acquisition request initiated by an application program of a to-be-acquired key, matching a key sending rule based on an attribute judgment result of whether a key distribution center connected with the application program of the to-be-acquired key is a key generation center or not, and sending the key to the application program of the to-be-acquired key according to the matched key sending rule; sending the latest key generated by the key generation center to the same application program of the to-be-acquired key located in different key distribution centers; and after determining that each application program of the to-be-acquired key successfully acquires the latest key, executing key starting instruction broadcasting, so that the same application program in each key distribution center synchronously starts the latest key. The purpose of key distribution and starting consistency control in the multi-KDC environment is achieved.
Owner:CHINA CONSTRUCTION BANK +1

Privacy-enhanced trusted data transaction method and system based on alliance chain

The application relates to data transaction technology and discloses a privacy-enhanced trusted data transaction method based on a consortium chain, which comprises the following steps: a key generation center generates a system parameter list; a data owner calculates a shared key according to the system parameter list, calculates encrypted ciphertext, and uploads the encrypted ciphertext to a decentralized storage network; the decentralized storage network receives the encrypted ciphertext, generates a unique content identifier, and divides the encrypted ciphertext into multiple ciphertext fragments; a root node hash value is calculated, and the root node hash value and the unique content identifier are recorded in the consortium chain; a data buyer encrypts data demand, publishes the data demand through the consortium chain, and the consortium chain matches transaction data according to corresponding demand attributes in the data demand and performs decryption operation to obtain required transaction data. The application further provides a system of the privacy-enhanced trusted data transaction method based on the consortium chain, which can realize safe transaction of data and improve controllability of data in a transaction process.
Owner:CHONGQING UNIV

A data security processing method, electronic equipment and storage medium

PendingCN122339696ACiphertextEngineering
Embodiments of the present application disclose a data security processing method, an electronic device and a storage medium. The method comprises: sending an encryption request to a key generation center, so that the key generation center generates a master public key according to target attribute information in the encryption request; receiving the master public key from the key generation center, and encrypting to-be-encrypted data by using an access strategy and the master public key to obtain ciphertext data; uploading the ciphertext data to a distributed network node for storage, and uploading a data digest corresponding to the to-be-encrypted data and the access strategy to a blockchain for on-chain storage. The method realizes reasonable distribution of the rights and interests of data owned by a data owner from the perspective of the data owner.
Owner:HANGZHOU CHIPSEA SEMICON TECH CO LTD

Identity authentication method of alliance chain under identity-based strong permission control mode

The application discloses an identity authentication mode of a consortium chain in a strong permission control mode based on identification, calculates a user public key from a user identification and a set of public mathematical parameters by using an elliptic curve bilinear pair theory, the user public key comprises a user identification and a version number of the user on the consortium chain, wherein the user identification is used for identity authentication, and the version number is used for key update; and a user private key corresponding to the user public key is calculated from the user identification, the set of public mathematical parameters and a secret value in a domain range, and is uniformly generated by a key generation center and downloaded to the user. The application adopts the above identity authentication mode, does not need the participation of a trusted third party, effectively resists attacks of intermediaries, does not need to bind identity information and a public key by using a digital certificate, reduces the bandwidth occupied by the transmission of a certificate in an identity authentication process, improves identity authentication efficiency, and solves the problem of IBC key update.
Owner:BEIHANG UNIV

Lightweight data sharing method and system

The invention discloses a lightweight data sharing method and system. The method comprises the following steps: a key generation center generates a system main public key and a main private key, and generates a corresponding private key for each participant; the data owner encrypts the original data by using the system main public key and the identity label of the data user to generate a ciphertext, and calculates the hash of the ciphertext; storing the ciphertext in an under-chain storage system and acquiring a content identifier; performing uplink storage on the content identifier and the ciphertext hash; the data user initiates a data access request through an intelligent contract, and the data owner sends an access authorization token and a content identifier to the data user through an under-chain channel after offline verification of validity; the data user obtains the ciphertext, decrypts the ciphertext to obtain plaintext data, and generates a zero-knowledge proof based on a zero-knowledge proof generation algorithm; and the smart contract verifies the zero-knowledge proof on the chain and records a verification result. According to the method, complete data storage is avoided, and on-chain resources are greatly saved.
Owner:LINGSHU TECH CO LTD

Unmanned seal system and unmanned seal method based on unmanned seal system

The invention discloses an unmanned seal using system, an unmanned seal using method based on the unmanned seal using system, and the field of information security and Internet of Things cross technology, and the method comprises the steps: a management platform carries out the verification of a seal using application, obtains a quantum session key from a key generation center if the verification is passed, generates first encrypted data, and carries out the verification of the seal using application; sending the first encrypted data and the quantum session key identifier to an access control; the entrance guard verifies the identity of the user, verifies the first encrypted data if the verification is passed, generates second encrypted data if the verification is passed, and sends the second encrypted data and the quantum session key identifier to the seal container; the seal container verifies the second encrypted data, if the verification is passed, third encrypted data is generated, and the third encrypted data and the quantum session key identifier are sent to the seal device; and the seal equipment verifies the third encrypted data, and if the verification is passed, seal using operation is executed. According to the method, the intelligence and the safety in the unmanned seal using process are improved.
Owner:中电信量子信息科技集团有限公司

Certificateless key negotiation method and system supporting public key check and application

The invention relates to the field of electric power information network and data security, in particular to a certificateless key negotiation method and system supporting public key check and application, and the method comprises the steps: initializing a key generation center, outputting public parameters, constructing a revocation system based on an accumulator, and outputting revocation state parameters; the user sequentially generates a user private key and a user public key based on the public parameter, and sends the user public key to the key generation center, so that the key generation center returns part of the private key and part of the public key, accumulates the user to an accumulator, and updates the revocation state parameter; according to the invention, the revocation state of the user can be checked, the user generates the user key in the key generation process, and the key generation center only generates a part of keys, so that the problem of key escrow is solved, and the security of the user is improved. And the safety and light weight of the system are ensured.
Owner:STATE GRID HENAN INFORMATION & TELECOMM CO +4

A method for automatic key negotiation and management of a link-layer transparent encryption device based on an identifier algorithm

This invention discloses a method for automatic key negotiation and management of link-layer transparent encryption devices based on the SM9 identifier cryptography algorithm. Addressing the problem of extremely high certificate management costs in existing link-layer transparent encryption devices that use a PKI system for key negotiation, this invention proposes a certificateless key negotiation scheme based on the SM9 identifier cryptography algorithm. This method uses a Key Generation Center (KGC) to pre-configure a private key generated from the node's identity identifier. When the sending node detects raw data packets flowing to the target intranet, it directly extracts the receiving node's identity identifier (such as the device serial number) as the public key to initiate SM9 negotiation. This invention eliminates the cumbersome certificate exchange, revocation list maintenance, and verification steps of traditional PKI systems, significantly reducing certificate management costs and negotiation message overhead while achieving implicit authentication.
Owner:BEIJING GUOLING TECH CO LTD

Mixed attribute base searchable signcryption method

The invention provides a mixed attribute base searchable signcryption method, and relates to the technical field of cryptography. The method comprises the steps that a decryptor encrypts a retrieval keyword according to a classic decryption key to generate a search token and sends the search token to a cloud server; wherein the classic decryption key is information obtained by encrypting a decryption attribute set of a decryptor by the key generation center; the cloud server adopts a cloud private key, searches a target hybrid ciphertext matched with the keyword from the keyword components of the plurality of hybrid ciphertexts according to the search token, and sends the target hybrid ciphertext to a decipherer; each hybrid ciphertext is information obtained after the signcryption person encrypts the message to be signcrypted and the keyword information of the message to be signcrypted according to the post-quantum public key; and the decryptor decrypts the target hybrid ciphertext by using the post-quantum private key and determines the message to be signcrypted, and the post-quantum public key and the post-quantum private key are keys pre-generated by the key generation center. According to the invention, fusion of an anti-quantum key encapsulation mechanism and an attribute-based searchable encryption technology can be realized.
Owner:中电信量子信息科技集团有限公司

A privacy-preserving computer-aided diagnostic method based on inner product function encryption

ActiveCN117786735BImplement proxy authorizationImplement ciphertext access controlDigital data protectionMedical automated diagnosisComputer aided diagnosticsAlgorithm
This invention discloses a privacy-preserving computer-aided diagnostic method based on inner product function encryption. The steps include: 1) A key generation center calls a group generation algorithm to generate a master key msk and public parameters pp; 2) Calculates and returns a key to the data owner based on msk, the data owner's identifier ID, and the input vector; 3) The model owner calculates D = e(h1, h2) based on pp, ID, and the input vector. r And then send the ciphertext to the computer-aided diagnostic device; 4) The data owner obtains the inner product operation result based on the ciphertext and the key, and then calculates the prediction result.
Owner:PEKING UNIV