Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

184 results about "Key generation center" patented technology

Multi-chain collaborative central node switching method for ensuring authentication efficiency and data reliability

The invention discloses a multi-chain collaborative center node switching method for ensuring authentication efficiency and data reliability, which is applied to a system comprising an identity chain, an authentication chain, an edge computing center, a key generation center, a plurality of unmanned aerial vehicle clusters and at least two aerial directors, and is characterized in that the identity chain is used for identity management of all the unmanned aerial vehicle clusters; the authentication chain is jointly maintained by all the unmanned aerial vehicle clusters and all the air directors. According to the multi-chain collaborative central node switching method for ensuring the authentication efficiency and the data reliability provided by the invention, the secure communication between the clusters can be quickly established in the authentication process of the unmanned aerial vehicle clusters, and the switching of the central nodes can be quickly carried out when the central nodes are threatened and attacked in a multi-chain manner; the new central node continues to execute the flight task, and the forward and backward security is ensured in the switching process, so that the problems of low authentication efficiency of the unmanned aerial vehicle cluster, strong dependency of the central node and insufficient security in the switching process of the central node are solved.
Owner:XIAN TECH UNIV

Identity authentication method and system for resisting identity forgery attack

The invention provides an identity authentication method and system for resisting an identity forgery attack, which are used for guaranteeing the safety of cross-domain communication. The method comprises the following steps: firstly, initializing a system, and generating a key pair for an entity based on an elliptic curve; when the user registers in the domain, the authentication center generates a key pair, encryption parameters and an identity certificate and stores the key pair, the encryption parameters and the identity certificate in the slave chain. A key generation center (KGC) pre-generates a factor including a private key and pre-loads the factor to a roadside unit (RSU). When a user initiates a pseudonym generation request, the RSU verifies the request and forwards the request to a nearby base station; and the base station predicts a resource use state by using an AI model, and dynamically assigns a service base station to calculate pseudonym generation parameters in real time. A user generates own pseudonym, verification parameters and a key pair after obtaining the parameters, and generates a unique signature by using the pseudonym key to encrypt a message and send the encrypted message. After the receiver verifies the validity of the message, a verification request is forwarded to the base station through the RSU, the service base station is dynamically assigned to verify the legality of the pseudonym based on the AI strategy, and a user identity certificate is inquired and verified through carrying address information cross-chain (slave chain / main chain cooperation). According to the method, malicious vehicles with fake kana can be effectively identified, dynamic scheduling of resources is realized by using AI, and the low-delay requirement is met.
Owner:北京国瑞数智技术有限公司

Anti-frequency analysis searchable encryption method and system

According to the anti-frequency analysis searchable encryption method and system, a certificateless encryption system is introduced, for a scene with limited computing resources, the scheme is ensured to be safe and suitable for the scene with the limited computing resources, meanwhile, a trap door algorithm is designed based on a probability trap door generation algorithm, and the security of the scheme is improved. The method improves the resistance of a system to frequency analysis attacks, solves the problem of secret key trusteeship due to the fact that identity information and secret key distribution are concentrated in a private key generation center in a traditional encryption scheme, and improves the encryption efficiency. The technical problem that malicious users are easy to obtain the privacy information of the target keyword by performing frequency analysis on trap doors and initiating keyword guessing attacks is solved.
Owner:GUIZHOU UNIV

Identity privacy protection system and method for safe sharing of power data

PendingCN121561950AData processing applicationsDigital data protectionChosen-plaintext attackAttack
The invention discloses an identity privacy protection system and method oriented to power data security sharing, which combine single-factor combination authentication and identity traceability and utilize the transparency and tamper resistance of a block chain. Comprising an electric power key generation center, an electric power cloud service provider, an electric power data owner, an electric power data user and a block chain, user identity privacy is ensured, safe identity verification is supported, identity traceability is achieved under necessary conditions, and meanwhile safe distribution of keys is achieved. In addition, services and resources are isolated by using groups, so that the flexibility and the expandability of the services and the resources are enhanced. Security analysis and experimental evaluation prove that the method can effectively resist selected plaintext attacks, and meanwhile, high efficiency and practicability are kept.
Owner:STATE GRID HENAN INFORMATION & TELECOMM CO

SM9-based identity-based searchable public key encryption method and system

The invention provides an SM9-based identity-based searchable public key encryption method and an SM9-based identity-based searchable public key encryption system. The system comprises a key generation center, a cloud storage server and a file sending and receiving party. A secret key generation center generates system public and private keys by using an SM9 algorithm, and generates a private key for a user in combination with identity information of the user. The file sender uses the user identity of the receiver and the file keyword to generate a keyword index and uploads the keyword index to the cloud server; when a receiver retrieves the file, the auxiliary parameters in the index are firstly obtained from the cloud server, then a keyword trap door is generated through a private key of the receiver, and the keyword trap door is uploaded to the cloud server; and the server compares the index with the trap door through a matching algorithm, and returns a corresponding ciphertext file to a receiver for decryption if matching succeeds. The secret key generation method is consistent with an SM9 algorithm, the application field of SM9 is expanded, and the safe and efficient searchable public key encryption method which does not need certificate management and can effectively resist internal keyword guessing attacks is achieved.
Owner:NANJING UNIV OF POSTS & TELECOMM

Lightweight certificateless signcryption method capable of proving security in Internet of Vehicles

The invention belongs to the field of secure communication in the Internet of Vehicles, and particularly relates to a lightweight certificateless signcryption method capable of proving security in the Internet of Vehicles, which comprises the following steps: constructing an Internet of Vehicles system consisting of a key generation center KGC, a roadside unit, a vehicle and a block chain, and initializing system parameters; the vehicle-mounted unit in the vehicle and the roadside unit outside the vehicle respectively register in the key generation center, and system parameters and pseudonyms are returned after KGC verification is passed; the KGC generates a part of keys for the pseudonym and returns the keys to the vehicle, and the vehicle calculates and generates a key and a public key according to the returned part of keys and the pseudonym, and uploads the public key and the pseudonym to the block chain; the vehicle signcrypts the message according to the key, obtains the public key of the receiver from the block chain according to the pseudonym of the opposite side, and then sends the signcryption message to the receiver; and the target vehicle or the roadside unit receives the message and performs message de-signcryption, and uploads a transaction record to the block chain for storage. According to the invention, while anonymous and secure communication of each entity in the Internet of Vehicles system is ensured, the communication efficiency is improved by reducing the vehicle calculation pressure and the communication overhead.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Cloud data integrity auditing method, system and device based on certificateless signature, medium and product

The invention discloses a cloud data integrity auditing method, system, device, medium and product based on certificateless signature, and relates to the technical field of network security, the method comprises the following steps: a key generation center obtains a data owner anonymous identity label based on a system master secret key and a data owner real identity label, and sends the data owner anonymous identity label to a server; obtaining a part of private keys of the data owner based on the anonymous identity identifier; the data owner verifies part of the private keys according to the anonymous identity identification, secretly selects the random number as the other part of the private keys if the verification is passed, and obtains a public key according to the other part of the private keys; the data owner obtains the label of each data block based on the two parts of private keys; the third-party auditor initiates an integrity challenge to the cloud service provider; the cloud service provider calculates audit evidence; and the third-party auditor verifies whether the to-be-audited file stored in the cloud is complete or not. According to the application, the TPA can be prevented from exploring privacy, certificate management is simplified, efficient and rapid identity authentication is realized, and real information of a user is hidden.
Owner:BEIJING INSTITUTE OF GRAPHIC COMMUNICATION

Unmanned aerial vehicle mobile edge computing security authentication method and system based on identity-based encryption and physical unclonable function

The invention discloses an unmanned aerial vehicle mobile edge computing security authentication method and system based on identity-based encryption and a physical unclonable function, and belongs to the field of mobile edge computing and unmanned aerial vehicle communication security. A physical response is generated in combination with PUF hardware of the unmanned aerial vehicle node, the physical response and the ID are bound as a credible voucher, and meanwhile, a derived private key for IBE is generated for the unmanned aerial vehicle node based on the ID; after the unmanned aerial vehicle is networked, the KGC periodically initiates challenge response verification, the unmanned aerial vehicle generates a current response by using PUF hardware and returns the current response, the KGC performs comparison, and if an abnormality occurs, the KGC broadcasts to a full text to isolate an abnormal node; iBE is directly carried out on the basis of the ID of the receiver in communication between the unmanned aerial vehicles, and certificate exchange overhead is avoided. According to the method, lightweight identity authentication, physical attack resistance and efficient key management under dynamic topology are realized, and the method is suitable for unmanned aerial vehicle edge computing scenes with limited resources.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

Data controlled sharing method and system based on attribute-based encryption

The invention discloses a data controlled sharing method and system based on attribute-based encryption, and the system is characterized in that a key generation center generates a system public key PK, a main private key MK and a user private key SK, a server gateway configures an access strategy, carries out the encryption processing of a data plaintext and the access strategy, generates a ciphertext, and uploads the ciphertext to a storage device for storage. Wherein the access strategy is converted into a mode that an LSSS matrix is embedded into a ciphertext; the one or more data controlled sharing gateways verify whether the attribute set of the data decryption party meets the access strategy according to the ciphertext and the user private key; if yes, the data plaintext is recovered and obtained by calculating the reconstruction coefficient of the LSSS matrix. According to the invention, the algorithm is simplified, and the system operation efficiency and stability are improved; the system does not need to adopt block chain storage, so that the system architecture design is simplified, the deployment is convenient, the cost is low, and the data security is high.
Owner:BEIJING ZHONG XING TONG CHUANG TECH CO LTD

Quantum security aggregation signature method and device suitable for embedded system

The invention discloses a quantum security aggregation signature method suitable for an embedded system, and the method comprises the steps: initializing system parameters through a trusted key generation center, and generating a pair of public and private keys for each signature user; the signature user signs the message by adopting a signature algorithm and a private key of the signature user, and sends a generated signature result, the message and a digital certificate of the message to the aggregation server; the aggregation server executes an aggregation algorithm according to the received information, multiple signatures are combined into an aggregation signature, and the aggregation signature and related information are sent to a verification server; and the verification server verifies the aggregation signature by using system parameters provided by the trusted key generation center and a public key of the aggregation server so as to ensure the integrity and correctness of the signature, thereby verifying the source of the message and the availability of the message. The method is suitable for various embedded systems with numerous edge nodes and limited computing resources, such as application scenes of unmanned aerial vehicle cluster safety communication, medical wireless sensor safety communication, intelligent network connection automobile and even satellite safety communication and the like.
Owner:SHANGHAI QUANTUM SCI RES CENT +1

Privacy enhanced trusted data transaction method and system based on alliance chain

The invention relates to a data transaction technology, and discloses a privacy enhanced trusted data transaction method based on an alliance chain, which comprises the following steps: a key generation center generates a system parameter list; the data owner calculates a shared key according to the system parameter list, calculates an encrypted ciphertext and uploads the encrypted ciphertext to a decentralized storage network; the decentralized storage network receives the encrypted ciphertext, generates a unique content identifier and divides the encrypted ciphertext into a plurality of ciphertext fragments; calculating a root node hash value, and recording the root node hash value and the unique content identifier into an alliance chain; and the data purchaser encrypts the data demand and issues the data demand through the alliance chain, and the alliance chain matches the transaction data according to the corresponding demand attribute in the data demand and performs decryption operation to obtain the required transaction data. The invention further provides a system of the privacy enhanced trusted data transaction method based on the alliance chain, the secure transaction of the data can be realized, and the controllability of the data in the transaction process is improved.
Owner:CHONGQING UNIV

Internet of vehicles heterogeneous signcryption communication system and method based on double-layer block chain

The invention discloses an Internet of Vehicles heterogeneous signcryption communication system and method based on a double-layer block chain, relates to the technical field of Internet of Vehicles, and solves the technical problems that the Internet of Vehicles technology is insufficient in expansibility and poor in compatibility, safety and efficiency are difficult to consider, and use requirements are difficult to meet. The system comprises a private key generation center PKG, a secret key generation center KGC, an on-board unit OBU, a roadside unit RSU and a double-layer block chain device. The private key generation center PKG is used for generating and distributing a public key and private key pair of the identity signcryption IBC; the key generation center KGC is used for key updating and management of the certificateless signcryption CLC; the OBU is used for performing communication between the vehicle and other vehicles or the road side unit; the roadside unit RSU is used for communication support and data forwarding; and the double-layer block chain equipment is used for carrying out data storage and security verification in the communication system. According to the invention, the calculation overhead and communication cost of the system are obviously reduced, and safe, efficient and extensible authentication and data transmission in a high-dynamic and large-scale V2X environment is realized.
Owner:SHENZHEN SEG SCI NAVIGATIONS CO LTD

Unmanned aerial vehicle cluster dynamic cross-domain group key management method and system based on CRT

The invention discloses an unmanned aerial vehicle cluster dynamic cross-domain key management method and system based on the Chinese remainder theorem (CRT), a key generation center generates system public and private keys and public parameters, and a ground station and an unmanned aerial vehicle perform hierarchical registration and verify respective keys; the unmanned aerial vehicles respectively generate signature messages and send the signature messages to a specified ground station for identity verification, and the ground station constructs a group key based on CRT and publishes the group key to the block chain; when a new unmanned aerial vehicle applies for joining, a signature message is sent to the ground station, and the ground station updates and publishes the group key; when the unmanned aerial vehicle applies for leaving, a leaving message is sent to the ground station, and the ground station updates and publishes the group key. According to the method, complex operations such as bilinear pairing operation and large integer modular exponentiation operation are avoided by optimizing the group key derivation process based on the CRT, and the calculation complexity is remarkably reduced. Meanwhile, efficient cross-domain authentication and batch verification are realized through Pedersen commitment and a zero-knowledge proof technology, and communication and calculation overhead is reduced.
Owner:SOUTHEAST UNIV

Lightweight hierarchical trust access authentication method and system based on identification

The invention discloses an identification-based lightweight hierarchical trust access authentication method and system, and mainly relates to the technical field of network security. Comprising the following steps: in an offline stage, an electric power registration center generates a private key root bound with an identity for a terminal through identity-based cryptography, a key generation center derives a lightweight work key voucher and pre-calculates verification points of all terminals, and a unified main multi-dimensional Bloom filter is constructed and distributed to a main station; in the online stage, a terminal updates a key and generates a signature only through hash operation, a master station reconstructs candidate verification points after receiving a message, and non-interactive verification is completed by locally querying a master multi-dimensional bloom filter. The method has the advantages that unification of strong identity credibility and extreme light weight of the terminal is achieved, the terminal side only needs efficient Hash operation, the server supports high-concurrency and low-delay authentication through the pre-calculation and Bloom filter technology, and the problem of safe access of massive distributed terminals in the electric power Internet of Things is effectively solved.
Owner:STATE GRID SHANDONG ELECTRIC POWER COMPANY WEIFANG POWER SUPPLY +1

Cleanable certificateless signcryption method, device, equipment and system

The invention provides a cleanable certificateless signcryption method, a cleanable certificateless signcryption device, cleanable certificateless signcryption equipment and a cleanable certificateless signcryption system. Receiving a signcryption ciphertext which is sent by the data sending end and contains signature information and ciphertext information; verifying the signcryption ciphertext according to the public parameter and the key information; and after the verification is passed, re-randomizing signature information and ciphertext information in the signcryption ciphertext in an undecrypted state to obtain a purified signcryption ciphertext, and sending the purified signcryption ciphertext to a data receiving end to trigger the data receiving end to verify and decrypt the purified signcryption ciphertext to obtain plaintext information corresponding to the ciphertext information. According to the method and the device, the signcryption ciphertext can be re-random on the premise that the ciphertext is not unlocked, and meanwhile, the re-random signcryption ciphertext is ensured to still meet confidentiality and integrity and can be verified by a receiving end, so that leakage attack behaviors of a malicious data sender are effectively prevented.
Owner:BEIHANG UNIV +1

Internet of vehicles data sharing method based on cloud

The invention discloses a cloud-based Internet of Vehicles data sharing method, which comprises the following steps that: under a certificateless framework, a secret key generation center distributes part of private keys, and a user combines local secret key values into a complete private key; a data owner encrypts and uploads traffic data based on bilinear mapping, and then constructs a re-encryption key through polynomial interpolation, so that a cloud server can decrypt all receivers in an authorization set through one-time re-encryption, and meanwhile, the identities of the receivers are hidden. Timestamp embedding achieves temporary entrustment, and the cloud does not make contact with plaintexts and private keys in the whole process. According to the scheme, key escrow is eliminated, terminal communication calculation overhead is reduced, and anonymous, fine-grained and time-efficient data sharing requirements of the Internet of Vehicles are met.
Owner:JIANGSU UNIV OF TECH

Anonymous authentication method and system for intelligent electric meter

The invention provides an anonymous method and system for a smart electric meter, and the method comprises the steps: building a key generation center, and enabling the smart electric meter and an aggregator to carry out the registration of the key generation center when the smart electric meter and the aggregator join a smart power grid for the first time; the intelligent electric meter encrypts an identity label and a timestamp of the intelligent electric meter by using an intelligent electric meter public key, generates an authentication request message according to the encrypted identity label and timestamp of the intelligent electric meter, and sends the authentication request message to the aggregator; the aggregator verifies the authentication request message after receiving the authentication request message, and generates an authentication response message and sends the authentication response message to the intelligent electric meter under the condition that the verification result is successful; and after receiving the authentication response message, the intelligent electric meter verifies the authentication response message, and under the condition that the verification result is successful, the two parties establish a shared session key to complete the authentication process. According to the method, the problems of low calculation efficiency, insufficient privacy protection, complex authentication process and the like in the prior art are effectively solved.
Owner:STATE GRID LIAONING ELECTRIC POWER CO LTD +3

Privacy protection and traceable anonymous bidirectional authentication method for heterogeneous Internet of Vehicles

The invention discloses a privacy protection and traceable anonymous bidirectional authentication method for heterogeneous Internet of Vehicles, which comprises the following steps: generating public and private keys based on a key generation center, a private key generator and a trusted registration mechanism, and constructing a heterogeneous password system; the vehicle completes key registration by fusing the certificateless public key system, and the roadside unit completes key registration based on the identity public key system; the vehicle registers and uses the pseudonym to communicate with the roadside unit; and the vehicle and roadside unit bidirectional authentication verifies the legality of the opposite side through a hash function and a temporary value, and finally generates a session key. According to the invention, by providing traceable pseudonym and anonymous authentication communication for each vehicle, the privacy of the vehicle can be effectively protected, and an attacker can be prevented from tracking the identity information of the vehicle. Based on various security hypotheses, the method meets various security attributes including anonymity, unlinkability, perfect forward security, security of known temporary information specific to sessions and the like, and the security of data transmission of the Internet of Vehicles can be improved.
Owner:BEIJING UNIV OF TECH

Image publishing privacy protection method based on attribute encryption

The invention discloses an image release privacy protection method based on attribute encryption, which solves the problems that in the prior art, access control expansibility is poor, an image processing mode damages visibility and a sensitive area is not self-defined, realizes safe image access control, ensures that only an authorized user can decrypt and recover an original image, and improves user experience. Meanwhile, the sensitive area is protected from unauthorized access; the method comprises the following steps: initializing an attribute-based encryption system through a key generation center, and distributing a public key and a user private key to realize fine-grained access control. And an image owner scrambles image color blocks by using DCT (Discrete Cosine Transform), and steganoscopes control parameters in the image to be published. And after the authorized visitor extracts the encryption parameter, the private key is used for decryption to obtain the original key, and the auxiliary information is combined to perform inverse operation on the image sensitive area to accurately recover the original image. In the whole process, flexible access control is achieved, and meanwhile protection and availability of image content are effectively balanced.
Owner:XIDIAN UNIV

A commercial cryptographic digital certificate generation method supporting quantum-resistant cryptography

The application relates to the technical field of information security, in particular to a commercial cipher digital certificate generation method supporting quantum-resistant cipher, which comprises the following steps: a certificate authority generates a hybrid signature self-signed certificate with quantum-resistant cipher signature and traditional public key cipher signature; a user generates a hybrid signature certificate request file and sends the file to the certificate authority; the certificate authority generates a hybrid signature user signature certificate; a key generation center generates a user traditional public key cipher encryption key pair and a user quantum-resistant cipher encryption key pair; the certificate authority generates a hybrid signature user encryption certificate; the certificate authority generates a hybrid encryption public key, a private key encryption ciphertext and a hybrid ciphertext; and the user extracts the hybrid signature signature certificate, the encryption certificate, the quantum-resistant cipher encryption private key and the traditional public key cipher encryption private key, and verifies the signature certificate and the encryption certificate. The application can resist quantum attacks and is compatible with existing digital certificates.
Owner:SHANDONG DUOFANG SEMICON CO LTD +1

A cloud auditing method and system for anonymous data

The application relates to a cloud auditing method and system for anonymous data. The method comprises the following steps: a group administrator sets an initial group state, a key generation center (PKG) generates a master key, a partial key and public parameters; the group administrator allocates a unique identifier to each group user; the group administrator generates a first key pair and distributes the first key pair to the corresponding group user; the group user generates a file label, calculates a corresponding verifier for each block of the file, and a cloud server verifies the correctness of the file label and the verifier; a third-party auditor (TPA) generates an auditing challenge; the cloud server creates a corresponding proof; and the TPA verifies the correctness of the proof. The technical scheme provided by the application introduces a new anonymous strategy in the auditing model, an anonymous strategy based on group element equivalence class replacement realizes anonymity and traceability only with constant level consumption, and can simultaneously support the functions of anonymity, user revocation and traceability.
Owner:TIANJIN UNIV

A backward secure certificateless authentication and key agreement method

The present invention relates to a backward-secure certificateless authentication and key negotiation method, which belongs to the technical field of cryptography and solves the problem in the prior art that certificateless authentication and key negotiation schemes cannot achieve backward security for the communication parties. The method comprises the following steps: a key generation center outputs system parameters and secretly stores a master key based on input security parameters, wherein the system parameters include a hash function for generating a random state value of a fixed bit length, and the system parameters are system parameters of a communication system composed of several user terminals; the key generation center and each user terminal generate a public-private key pair for each user terminal based on the system parameters, the user identity of the user terminal, and the master key; and user terminals to be in a conversation perform authentication based on their respective public-private key pairs, system parameters, and identity information of both parties, generate a session key between the user terminals, and update the common state value between the user terminals based on the session key and the common state value between the user terminals.
Owner:XINGTANG TELECOMM TECH CO LTD +2

Multi-group data security sharing method and system supporting traceability and revocation

The invention discloses a multi-group data security sharing method and system supporting traceability and revocation. A trusted key generation center generates parameters required by system operation; generating an attribute private key and a puncturable private key; the data owner uses a pre-formulated access control strategy to encrypt data to be shared by adopting puncturable attribute-based encryption; the group administrator formulates a new access control strategy, and generates a re-encryption key based on an attribute private key of the group administrator; the cloud server performs re-encryption on the original ciphertext according to the proxy re-encryption key; and the group administrator decrypts the original ciphertext according to the attribute private key and the puncturable private key, and the user in the group decrypts the re-encrypted ciphertext according to the attribute private key, the puncturable private key and the authorized private key to obtain the plaintext of the data to be shared. According to the method, the user decryption key is divided into the attribute private key, the puncturable private key and the authorized private key, the group user identity can be uniquely determined through combination of the three types of keys, and refined tracing is achieved.
Owner:WUHAN UNIV

A privacy-preserving cloud data integrity audit method, device, and medium

The present invention relates to the field of information security, and discloses a privacy protection cloud data integrity audit method, device and medium. The method includes: the data holder sets ID∈{0,1} * The signature public key is sent to the key generation center KGC; the key generation center KGC generates a private key s based on the public key ID =H1(ID) α ; where α is a random number and H1 is a hash function; the data holder verifies the private key s to the cloud ID =H1(ID) α The legitimacy of the data is ensured; for legitimate data, a third-party auditor TPA performs an integrity audit on the cloud; the present invention ensures the integrity and privacy of cloud data during the cloud data integrity audit phase, and solves the technical problems that the existing technology can purify signatures without restriction, which easily causes security risks, and is easily attacked by TPA data recovery, and has the risk of privacy leakage.
Owner:SOUTH CENTRAL UNIVERSITY FOR NATIONALITIES

Public key legality verification method and device based on asymmetric encryption algorithm, equipment and medium

The invention discloses a public key legality verification method and device based on an asymmetric encryption algorithm, equipment and a medium, and relates to the technical field of key management, a user public key is generated based on random numbers and elliptic curve parameters of the asymmetric encryption algorithm, and the user public key and a user unique identifier are sent to a key generation center; the key generation center calculates a user declaration public key and a key generation center private key by using the user public key and the user unique identifier; obtaining a user declaration public key and a key generation center private key sent by the key generation center, and calculating a user private key based on the key generation center private key; generating a signature public-private key pair of the user by using the user declaration public key and the user private key, performing matching verification on the signature public-private key pair, and determining the legality of the user declaration public key, thereby avoiding the limitation that the life cycle of the key completely depends on a key generation center, reducing the demand for computing resources and the computing complexity, effectively adapting to resource-limited equipment, and improving the user experience. And the safety, the flexibility and the expandability of the system are improved.
Owner:CETC CYBERSPACE SECURITY TECH CO LTD

An SM9 encryption method supporting single private key decryption of multiple ciphertexts

The application discloses an SM9 encryption method supporting single private key decryption of multiple ciphertexts, a key generation center generates a main public and private key pair, discloses the generated main public key to users in a system, and secretly saves the main private key; the key generation center generates a private key of a user by using the main public and private key pair and all identities ID of the user, and sends the private key to the user through a secure channel; an encrypter generates ciphertext corresponding to a message by using the main public key of the key generation center based on a selected encryption ID and the encrypted message; and a decryption algorithm decrypts the ciphertext to obtain plaintext based on the ciphertext corresponding to the message, the main public key of the key generation center and the private key of the decrypter. The private key can decrypt different ciphertexts encrypted by different public keys, greatly reduces the storage cost of the private key of the user and reduces the management of the private key, and is helpful to promote the application of the SM9 encryption algorithm.
Owner:SOUTHEAST UNIV

A security encryption method for network transmission applicable to urban rail transit systems

The present disclosure belongs to the field of security encryption technologies, and more particularly relates to a security encryption method applicable to network transmission in an urban rail transit system, including: a key generation center selects system parameters and generates a public-private key pair; on-vehicle communication devices generate part of the public-private key pair; the key generation center of the on-vehicle communication devices generates another part of the public-private key pair of the on-vehicle communication devices to form a complete public-private key pair, and the on-vehicle communication devices verify the complete public key and the complete private key; a message signature is generated based on the message to be transmitted by the device; the message sender device encrypts the message to be transmitted using the message receiver's key to form encrypted data and transmits it; the message receiver decrypts the encrypted data using the device's private key. Through the above settings, the real-time performance is improved.
Owner:BEIHANG UNIV

A method and system for intelligent collaborative defense against identity spoofing attacks

The application provides a method and system for intelligent collaborative defense against identity spoofing attacks, aiming to improve identity security and resource scheduling efficiency in cross-domain communication. The method includes: when a user registers, an authentication center generates a key pair, encryption parameters and an identity certificate and stores them in a slave chain; a key generation center (KGC) preloads factors containing private keys to a roadside unit (RSU); when a user initiates a pseudonym generation request, the RSU forwards it to a dynamically designated edge computing unit, and simultaneously sends a parallel request to a base station; an intelligent collaborative platform uses an AI model to predict the computing power of the base station group and the resource status of the edge unit in real time, dynamically schedules remote data transmission and cloud sharing, and assigns the edge unit to calculate pseudonym generation parameters; the user generates a pseudonym and a key pair based on the parameters, and signs and encrypts a message; when the recipient verifies the message, the edge unit verifies the legality of the pseudonym, and cooperatively queries the identity certificate through the master-slave chain, and finally verifies the validity of the signature. The application significantly improves the defense capability against spoofing attacks and the system response efficiency through an AI-driven multi-level resource collaboration and dynamic scheduling mechanism.
Owner:北京国瑞数智技术有限公司

A cross-domain authentication method and system in a vehicle-mounted ad hoc network

The present invention relates to the field of network security and communication technologies, specifically disclosing a cross-domain authentication method and system for a vehicle-mounted ad hoc network. The method is implemented based on a cross-domain authentication system for the vehicle-mounted ad hoc network, which includes a key generation center, a trusted authority within at least one domain corresponding to each area, and several roadside units and vehicles within each area. The method includes the following steps: system initialization, vehicle initialization, roadside unit initialization, construction of a threshold group signature, identity update, intra-domain identity authentication, inter-domain identity authentication, identification of illegal users, and deregistration of illegal users. The present invention provides a cross-domain authentication method that effectively addresses issues such as privacy protection, cross-domain device collaboration, and malicious entity tracking in vehicle networks, promoting the rapid development of smart transportation.
Owner:XIAN UNIV OF POSTS & TELECOMM

A lattice-based puncturable key-policy attribute-based searchable encryption method and system

The present application relates to the technical field of attribute searchable encryption, in particular to a lattice-based puncturable key-policy attribute searchable encryption method and system, which realizes fine-grained and dynamic management of search authority of data receivers through initialization of a key generation center and a key puncture mechanism, and can precisely revoke search capability of a specific keyword without updating all keys; ciphertext generated by a data owner combines attribute encryption and signature technology, which ensures data confidentiality and integrity and resists quantum attacks; a trapdoor generated by a puncture key of a data receiver protects search privacy and realizes efficient ciphertext retrieval; and a test algorithm executed by a cloud server can accurately verify matching of the trapdoor and the ciphertext and return a result under an honest but curious security model. The whole scheme effectively solves the deficiencies of existing schemes in fine-grained dynamic revocation, quantum attack resistance and multi-receiver access control under the support of lattice cryptography theory.
Owner:BEIJING ELECTRONICS SCI & TECH INST