Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

276 results about "Key leakage" patented technology

Data security processing method and system based on distributed storage

The invention relates to a data security processing method and system based on distributed storage, and relates to the technical field of computer information processing. The method comprises the following steps: cutting data into encryption fragments with a configurable number by adopting a dynamic fragmentation strategy, and generating a physically isolated dynamic check block in combination with a timestamp to realize tampering prevention; a dynamic threshold value is dynamically calculated based on the data sensitivity index and the node load, and the node is optimized through the reliability score for cooperative decryption; a database table is divided into independent marshalling storage according to main foreign key association, foreign key fields are encrypted by adopting cross keys, and cross-marshalling access needs to meet a multi-key threshold condition; an intelligent threat perception engine is constructed, access logs and threat intelligence are analyzed in real time, and key rotation, fragment replacement and joint defense response mechanisms are dynamically triggered. According to the invention, full life cycle protection of data is realized, and the problems of key leakage risk and cross-table association attack are effectively solved.
Owner:WUHAN ANYU INFORMATION SECURITY TECH CO LTD

Remote power supply operation and maintenance virtual conference cooperation method and system and electronic equipment

The invention discloses a remote power supply operation and maintenance virtual conference cooperation method and system and electronic equipment, and particularly relates to the field of power operation and maintenance scheduling, and the method comprises the following steps: I, accessing various data of a power supply network, constructing a three-dimensional topology energy flow diagram in real time, and dynamically generating a security level matrix in combination with real-time equipment working conditions; iI, establishing a temporary operation authority tunnel, starting a virtual conference space, and automatically matching a most suitable interaction mode according to behaviors and intentions of participants; according to the method, the operation compliance and safety can be improved, key leakage and instruction tampering are effectively prevented, the encryption strength of remote operation is enhanced, permission abuse is prevented, the system toughness is improved, and safe closed-loop management from access to execution is realized; the comprehensiveness and timeliness of state monitoring of the power supply network are effectively improved, more accurate abnormal event identification can be realized, the problem positioning efficiency is improved, and a user is ensured to preferentially acquire the most reliable and most representative abnormal propagation chain.
Owner:DONGYING CITY DONGYING DISTRICT POWER SUPPLY CO STATE GRID SHANDONG ELECTRIC POWER CO

Security inter-core communication method based on derived key negotiation

The invention discloses a safety inter-core communication method based on derived key negotiation. The safety defect of a traditional inter-core communication scheme is overcome through a dynamic key negotiation mechanism. Based on a preset derived base key and a random salt value, a unique temporary session key is negotiated before each communication, and forward security is ensured: even if the derived base key is leaked, historical encrypted data still cannot be decoded; a bidirectional salt value check code verification mechanism is adopted, chip identity legality authentication is achieved in the negotiation stage, and forgery or tampering attacks are blocked; during communication, a data ciphertext check code is generated through a check key, and data integrity and source authenticity are guaranteed; it is ensured that the session key is unpredictable each time through the random salt value, and replay attacks are effectively resisted in combination with a timeliness verification mechanism. In addition, key re-negotiation is triggered according to data sensitivity, a key exposure time window is dynamically reduced, the risk of long-term key leakage is further reduced, and safety and resource efficiency are both considered.
Owner:SHENZHEN ROADROVER TECH

Network data sharing method and system based on dual identity authentication

The invention discloses a network data sharing method and system based on dual identity authentication, and the method comprises the steps: a user A logs in a client A through the dual authentication of a password and a digital certificate, and transmits an encrypted file data packet formed after an original file is encrypted to a server; the user A selects target data at the client A and appoints a shared user B, and the server updates a shared file list of the user A; the user B submits a data downloading request on the client B, and the server verifies the authority of the user B and sends the encrypted file data packet to the client B; the client B decrypts the encrypted file data packet to obtain an original file; the system comprises a client module, a storage module and a server module. According to the method, a dynamic key generation mechanism is adopted, the requirement for real-time change of the authority in a multi-user cooperation scene is met, the leakage risk of a preset key is avoided, and the conflict between user privacy and sharing convenience is effectively solved.
Owner:NANJING UNARY INFORMATION TECH

Information processing apparatus, information processing method, and recording medium

To reduce labor related to an update of an encryption key in response to an encryption request for the AI software specifying the third type key, encryption key leakage or the like.An information processing apparatus according to the present technology includes an encryption key creation part that creates an encryption key on a basis of a first type key stored in advance in an imaging apparatus, a second type key different from the first type key, and a third type key that is different from the first type key and the second type key and is a key multiplied with the second type key to create a combination key stored in the imaging apparatus, or is a key stored in the imaging apparatus together with the second type key, as an encryption key used by the imaging apparatus for encryption of artificial intelligence (AI) software including at least software of an artificial intelligence model, the imaging apparatus performing image recognition processing using the artificial intelligence model on a captured image obtained by capturing an image of a subject, the encryption key creation part creating, in response to specification of a key derived from new information different from original information as the third type key, a new encryption key based on the third type key derived from the new information, the first type key, and the second type key on a basis of the new information.
Owner:SONY SEMICON SOLUTIONS CORP

Information security protection method and system for electric power acquisition terminal equipment

The invention relates to the technical field of information security protection of electric power acquisition terminal equipment, and discloses an information security protection method and system for the electric power acquisition terminal equipment. According to the method, the unique identifier is generated by collecting equipment hardware features, and counterfeiting and tampering are prevented. The feature complexity is improved through high-dimensional transformation, and the anti-thrust capability is enhanced. The dynamic perturbation factor causes the device identifier to change over time, preventing replay attacks. The multi-factor key generation is combined with hardware features, environmental parameters and time sequence factors, so that the security of the key is improved, and cracking is avoided. The hierarchical challenge response mechanism enhances the security through multi-level authentication, and prevents an attacker from easily bypassing verification. High-dimensional abnormal behavior detection can dynamically identify potential security threats. A multi-stage key updating mechanism ensures that the equipment keeps encryption protection for a long time, and risks caused by key leakage are avoided. The whole system works cooperatively, and the safety of equipment authentication, data encryption and communication is effectively improved.
Owner:BEIJING BONA ELECTRIC CO LTD

Method and device for safely accessing industrial control equipment to public test platform

The invention discloses a method and device for safely accessing industrial control equipment to a public test platform, and the method comprises the steps: carrying out the initialization of the public test platform, including the generation of a public and private key pair, the configuration of a digital certificate, the configuration of a Bloom filter, the selection of a hash function set matched with the Bloom filter, and the construction of a controlled resource identifier set; the public test platform receives registration information of the industrial control equipment, grants a corresponding authority to the industrial control equipment according to the registration information, generates a minimum authorized resource set corresponding to the authority, writes the minimum authorized resource set into the Bloom filter, and stores identity information of the industrial control equipment; the public testing platform performs bidirectional authentication of the public testing platform and the industrial control equipment based on an authentication request initiated by the industrial control equipment, and dynamically updates authentication information held by the public testing platform and the industrial control equipment respectively; and after the bidirectional authentication is completed, the public test platform performs access admission judgment on a resource access request initiated by the industrial control equipment by using a bloom filter based on the controlled resource identifier set and corresponding authority granted to the industrial control equipment. The invention aims to solve the problems that the current industrial control equipment in a large-scale access scene is weak in authentication anti-attack capability, a secret key is easy to leak and counterfeit, physical attack protection is insufficient, communication lacks forward and backward security, and a resource authorization mechanism does not have a fine granularity and minimum authorization principle.
Owner:XI AN JIAOTONG UNIV

Block chain-based trusted IoT (Internet of Things) access method and equipment

The embodiment of the invention provides a trusted IoT (Internet of Things) access method and equipment based on a block chain. The method is applied to the technical field of communication, and comprises the following steps: firstly, generating a key for the Internet of Things in a TEE environment of an intelligent gateway, encrypting a resource address of an Internet of Things device, preventing the key from being acquired by malicious software, preventing the key from being counterfeited, and ensuring the security of the Internet of Things device accessing a block chain network, and a block chain stores a key index instead of the key, so that the security of the Internet of Things device accessing a block chain network is ensured. The risk of key leakage is further reduced; by setting a device management contract and a policy authority contract, the authority of a user for accessing the Internet of Things device is inquired and managed, fine control of the access authority is realized, and only the user having the authority can obtain a corresponding secret key from an intelligent gateway to decrypt an encrypted resource address provided in a block chain. According to the arrangement, leakage of the resource address is effectively prevented, and sensitive information is prevented from being leaked.
Owner:NINGBO TELIAN INFORMATION TECH CO LTD

Communication data encryption method and device, equipment and medium

The invention relates to the technical field of data security, can be applied to business scenes such as financial science and technology, medical health and the like, and discloses a communication data encryption method, device, equipment and medium, which comprises the following steps: generating an asymmetric key pair of a client, sending a client public key to a server, receiving a server public key and a digital signature, and after the digital signature of the server-side public key is verified, a shared symmetric encryption key is generated based on the client-side private key and the server-side public key, anti-extraction processing is performed on the shared symmetric encryption key, and the shared symmetric encryption key is stored in a client-side exclusive private directory for encrypting the communication content between the client side and the server side. According to the invention, the anti-extraction processing is carried out on the shared symmetric encryption key to ensure that the key cannot be easily extracted or cracked in the storage and use processes, so that the security of communication data encryption is enhanced, and the risk of key leakage or malicious acquisition is effectively prevented.
Owner:CHINA PING AN LIFE INSURANCE CO LTD

Encryption method and device suitable for large file, computer equipment and storage medium

The invention discloses an encryption method and device suitable for a large file, computer equipment and a medium, and the method comprises the steps: segmenting a to-be-encrypted large file into a plurality of sub-data blocks according to a preset rule, and coding each sub-data block to obtain an index value of each sub-data block; generating a master key, and generating a sub-data key corresponding to each sub-data block based on the index value of each sub-data block and the master key; based on the sub-data key corresponding to each sub-data block, performing encryption processing on each sub-data block to obtain a plurality of encrypted sub-data blocks; obtaining a check chain value of the to-be-encrypted large file based on each encrypted sub-data block; and merging the plurality of encrypted sub-data blocks and the check chain value to obtain a ciphertext of the to-be-encrypted large file. According to the method, association between blocks can be effectively cut off, the key leakage risk can be effectively reduced, the encryption strength is enhanced through the dynamic sub-keys, memory overflow is avoided through block processing, the security, reliability and processing efficiency of large file encryption are improved, and the requirements of large file secure storage and transmission are met.
Owner:ASPIRE TECH (SHENZHEN) LTD

A supply chain data management method based on privacy computing

The present invention discloses a supply chain data management method based on privacy computing, which belongs to the field of data processing technology. By adopting privacy computing technology, it realizes encryption processing and efficient management of supply chain data, ensuring the security, privacy and reliability of data during the circulation process. At the same time, the key is fragmented and decentralized, which can effectively prevent key leakage and loss, and can greatly improve data security. This method is applicable to various supply chain scenarios, helps to improve supply chain collaboration efficiency, and reduce the risk of data leakage.
Owner:GOLDEN NETWORK (BEIJING) E-COMMERCE CO LTD

Satellite internet traffic security protection method and system

The invention relates to the technical field of network security, in particular to a satellite internet traffic security protection method and system, and the method comprises the steps: obtaining an orbit characteristic parameter and an external disturbance parameter, and generating a first chaotic key sequence; the method comprises the following steps: constructing a signal tampering risk coefficient, an identity camouflage risk coefficient, a data integrity risk coefficient, a traffic behavior abnormity risk coefficient and a key leakage risk coefficient based on traffic state information collected by a ground terminal in real time, and further generating a traffic safety score; and adaptively selecting an encryption algorithm based on the traffic security score, and encrypting traffic data of the communication link by using a session key derived from the first chaotic key sequence. According to the invention, the communication traffic can be monitored and encrypted in real time, and the security of the satellite internet traffic data is ensured.
Owner:GOLDEN SHIELD TESTING TECH CO LTD

Data transmission optimization system based on communication network

The invention discloses a data transmission optimization system based on a communication network. According to the invention, the symmetric encryption module adopts an AES algorithm, and the high-speed encryption performance of the symmetric encryption module is used for quickly encrypting a large amount of data, so that the real-time performance of data transmission is ensured. And the asymmetric encryption module carries out security encryption on the symmetric key by using an RSA algorithm, so that the security of the key in the transmission process is ensured, and the risk of key leakage is prevented. The hybrid encryption controller module ingeniously combines the advantages of symmetric encryption and asymmetric encryption, generates a key in real time through the dynamic key generation module, and optimizes encrypted data through the ciphertext processing module, thereby constructing a multi-level and all-around security protection system. According to the design, various network attacks are effectively resisted, the integrity and non-tampering property of data transmission are guaranteed, and a solid security guarantee is provided for data transmission in a communication network.
Owner:HUNAN YOUZONG NETWORK TECHNOLOGY CO LTD

User security authentication method and system based on encryption processing

The invention discloses a user security authentication method and system based on encryption processing. The method comprises an initialization stage, user key processing, secondary encryption, user identity authentication, server identity authentication, secondary security authentication, dynamic update of an expansion mechanism and key management. The invention belongs to the field of data encryption, and particularly relates to a user security authentication method and system based on encryption processing, according to the scheme, Q is generated through a high-entropy pseudo-random number, and the anti-prediction capacity of key generation is greatly improved; introducing a double confusion mechanism to carry out secondary encryption; detecting data errors by checking the basic groups; therefore, the security of encryption authentication is obviously improved; primary identity authentication, direct authentication between a user and a target server and secondary security authentication are performed in combination with biological characteristic data of the user, so that a multi-layer authentication mechanism is constructed, and the confidentiality and integrity of a key are ensured; based on dynamic expansion and hierarchical key management, the risk of single-point key leakage is reduced; and the encryption authentication effect is improved.
Owner:CHINA UNICOM ONLINE INFORMATION TECHNOLOGY CO LTD +1

Video encryption method and system based on dynamic fragmentation and multilayer confusion

The invention discloses a video encryption method and system based on dynamic fragmentation and multilayer confusion. Identifying all sensitive areas in each frame of original image and calculating a frame-level sensitivity score of the original image; setting a fragmentation mechanism, and dynamically dividing and fragmenting the target video according to the fragmentation mechanism; embedding watermark information into the segmented video frame frequency domain, and converting the video frame frequency domain embedded with the watermark information into a spatial domain; encrypting the video frame embedded with the hidden watermark information by adopting a multi-layer encryption technology; and a watermark self-repairing mechanism is set, and a decryption algorithm is automatically matched according to the terminal type. The encryption calculation amount of a non-sensitive area can be reduced, the anti-attack capability is enhanced, and the key leakage probability is reduced; watermarks are embedded according to characteristic differentiation of different regions, it is ensured that copyright identifiers of key content cannot be deleted, and meanwhile robustness and processing efficiency are balanced; the decryption algorithm supports real-time video processing, an authorized user does not need to manually input a key, and the key management cost is reduced.
Owner:ZHENGZHOU THINK FREELY HI TECH

Distributed key protection method and system for multi-trusted hardware collaboration environment

The present invention discloses a distributed key protection method and system for a multi-trusted hardware collaboration environment. The method comprises: when a trusted hardware receives a trusted service application, obtaining a trusted hardware randomly assigned by an upper-layer system as an assisting trusted hardware, the assisting trusted hardware and the access feasible hardware as the executing trusted hardware, each executing trusted hardware generating a dynamic private key shard; the access trusted hardware sending the first part of the ciphertext to all assisting trusted hardware; each executing trusted hardware calculating a decryption intermediate value based on the dynamic private key shard; each assisting trusted hardware sending the decryption intermediate value to the access trusted hardware; the access trusted hardware calculating the plaintext corresponding to the ciphertext based on all the decryption intermediate values; the access trusted hardware executing the service; and the access trusted hardware encrypting the service execution result using the user's public key so that the user client can decrypt it. The present invention can provide homogeneous services, prevent key leakage, prevent conspiracy attacks, and support heterogeneous trusted hardware.
Owner:TSINGHUA UNIVERSITY +1

Quantum key management method and system for satellite internet biological characteristics

The invention relates to a quantum key management method and system for satellite internet biological characteristics, and the method comprises the following steps: carrying out the registration of biological characteristics and the initialization of communication protocol parameters for a user terminal which is accessed for the first time; for the registered user terminal, before initiating communication each time, binding the real-time biological characteristics with the quantum key, and carrying out encrypted transmission of the session key by using the bound quantum key, so as to carry out encrypted transmission of satellite internet transmission data by using the session key; and in the encryption transmission process of the satellite internet transmission data, according to a preset period, performing satellite link security level adjustment and quantum key dynamic updating. According to the invention, identity authentication and terminal authentication in a high-delay and narrow-bandwidth application scene can be realized, the security problems of identity counterfeiting, key leakage and the like are solved, and the method can be applied to satellite internet scenes such as emergency communication, field operation and the like, and has the advantages of strong compatibility, low deployment cost and the like.
Owner:SPACE STAR TECH CO LTD

Client information confidentiality management method and system based on encryption algorithm

The invention relates to the field of information confidentiality management, in particular to a client information confidentiality management method and system based on an encryption algorithm. The whole-process closed-loop management from key distribution to data encryption and decryption and then to service analysis and optimization is realized. Firstly, high-strength key protection and hardware acceleration provided by a hardware security module are utilized, key management and core encryption and decryption operation of sensitive data are executed in a secure environment as much as possible, and the risks of key leakage and data tampering are reduced from the source. And secondly, the system ensures the responsibility division and information transmission orderliness of each module in the processing flow through clear data stream butt joint. Through the architecture, large-scale and diversified data can be encrypted firstly after entering the system, then differential analysis is realized according to different sensitive levels, and finally a comprehensive result is obtained through linkage optimization.
Owner:SHENZHEN QIANHAI MINGYUE XINSI SOFTWARE CO LTD

Cooperative encryption and decryption method and system based on NTRU algorithm

The invention discloses a collaborative encryption and decryption method and system based on an NTRU algorithm, and relates to the field of data security, and the method comprises the steps: a client and a server respectively generate local keys based on the NTRU algorithm, and cooperatively generate a global public key; the secret key comprises a part of private key of the client, a part of public key of the client, a part of private key of the server and a part of public key of the server; encrypting a plaintext message to be encrypted by using the global public key to generate a ciphertext; the server decrypts the ciphertext by using a local part of private keys to obtain a part of plaintext; and the client decrypts the partial plaintext by using the local partial private key to obtain a complete ciphertext. According to the application, the risk of key leakage can be reduced, the data security is improved, and the hardware purchase and maintenance cost can be reduced.
Owner:BEIJING RENXINZHENG TECH CO LTD

ECU secret key safety filling method and system

The invention belongs to the technical field of automobile electronics, and particularly relates to an ECU secret key safety filling method and system. Bidirectional identity authentication is carried out, a secure communication channel between the KLM and the KMS is established by adopting an mTLS protocol, and identity counterfeiting attack is prevented in combination with a certificate bidirectional verification mechanism; secret key encryption transmission: carrying out asymmetric encryption on a secret key plaintext by using an ECU root secret key public key; multiple signature verification is carried out, ECU identity information is signed through a KLM working key private key, a key ciphertext is signed through the KMS working key private key, a KMS working key public key is signed through the KLM working key private key, and the ECU verifies the KLM identity legality and verifies the key integrity twice; the technical problems of identity counterfeiting and secret key leakage and tampering in the traditional secret key filling process are effectively solved, the purposes of secure transmission and secret key storage in the secret key filling process are achieved, and the automobile information security level is remarkably improved.
Owner:SHENZHEN ROADROVER TECH

Smart home security authentication management method and system based on wireless local area network

The invention provides a smart home security authentication management method and system based on a wireless local area network. The method comprises the following steps: constructing a home network security authentication domain; when a new smart home device is accessed, marking the new smart home device as a second smart home device, and obtaining a device authentication state matrix of a home network security authentication domain; generating an authentication challenge vector based on the device authentication state matrix, and sending the authentication challenge vector to the second smart home device and the first smart home device for cooperative verification; and if the authentication challenge vector passes the cooperative verification, updating keys of all smart home devices in the home network security authentication domain according to a preset dynamic key synchronization protocol. Through construction of a home network security authentication domain, intra-domain sharing of security parameters such as a device authentication state and key management is realized, when any key is updated, other devices update synchronously, and associated dependence exists among keys, so that a risk conduction path of a whole network falling situation caused by key leakage of a single device is blocked.
Owner:CVC CERTIFICATION & TESTING CO LTD +1

Certificateless puncturable signcryption method for resisting long-range attack of block chain

The invention belongs to the field of computer and information security, and discloses a blockchain anti-long-range attack certificateless puncturable signcryption method, which comprises seven steps of system initialization and parameter establishment, user part private key extraction, puncture key updating, secret value extraction, public key generation, signcryption and de-signcryption. An authoritative node set in the block chain is adopted to initialize the system and generate a user part private key and a puncture key, so that the defect of key distribution based on a centralized entity is overcome; a puncturable technology is embedded, and the private key of the user is associated with the message, so that the capability of operating specific messages is realized, and long-range attacks caused by key leakage in the block chain are resisted; in addition, the signcryption and de-signcryption operation not only saves the calculation and communication cost, but also ensures the confidentiality and integrity of the block chain message. According to the method, the problems that long-range attacks exist in centralized entities and block chain rights and interests in the prior art, and confidentiality and integrity of messages on a chain cannot be provided at the same time in the prior art are solved.
Owner:HANGZHOU INTERNATIONAL INNOVATION INSTITUTE OF BEIHANG UNIVERSITY +1

Data encryption transmission system and method for wireless WIFI engineering

The invention belongs to the technical field of wireless transmission, and provides a data encryption transmission system and method for wireless WIFI engineering, and the method comprises the following steps: determining a transmitting node for wireless transmission, recognizing preliminary candidate equipment with data frame receiving capability through channel scanning in a coverage range of the transmitting node, and transmitting the preliminary candidate equipment to a server; the receiving capability of the preliminary candidate device is verified, the preliminary candidate device passing verification is used as a potential receiving node of wireless transmission, and a potential receiving node set is constructed; and calculating theoretical transmission time based on the real-time transmission rate of the transmitting node and the size of the data packet to be transmitted. Potential receiving nodes are accurately identified and a node set is dynamically maintained, so that equipment participating in data transmission has stable receiving capability, key updating is triggered in combination with real-time channel flow analysis, key evolution is matched with a channel state, encryption dynamics is enhanced, and the key leakage risk is reduced.
Owner:GUANGXI ZHONGWU INFORMATION TECH GRP CO LTD

On-chain processing method and device based on multi-party terminal, equipment and medium

The embodiment of the invention discloses an on-chain processing method and device based on a multi-party terminal, equipment and a medium. A specific embodiment of the method comprises the following steps: receiving a private key fragment and authorization information transmitted by an authorization terminal through a secure channel; verifying the authorization information to obtain an agency relationship; receiving request information submitted by the proxy terminal; verifying whether the authorization relation information is valid or not, and verifying whether the execution task information is within an authorization range or not; performing signature encryption on the public key information of the proxy terminal to obtain an execution signature; generating an execution record, and storing the execution record in a block chain in a chaining manner; and executing a change operation on the permission modification request initiated by the authorization terminal to obtain a permission change record, and uploading the permission change record to the block chain for storage. The implementation mode can be used for a block chain proxy scene with a high security standard, the risk of private key leakage is eliminated, and fine-grained permission control is realized.
Owner:SHANGHAI QI ZHI INSTITUTE

Block chain-oriented forward security group signature system and method based on lattice cryptography

The invention provides a block chain-oriented forward security group signature system and method based on lattice cryptography, and belongs to the field of group signature. The system comprises an anti-quantum signature module, a dynamic group management module, a key evolution module, a privacy protection module and a supervision and tracing module. A post-quantum signature algorithm based on an ideal lattice is designed, the anti-quantum characteristic is achieved through the calculation complexity of the shortest integer solution (RSIS) problem on a ring, and meanwhile the storage efficiency is optimized through a cyclic matrix structure of the ideal lattice; secondly, constructing a dynamic group signature mechanism supporting complete anonymity, and realizing transaction traceability while protecting user privacy in combination with a Nor-Yung dual encryption and VLR revocation mechanism; finally, an improved bonsai tree key evolution scheme is introduced, forward security guarantee is provided through periodic key updating, and it is ensured that the historical transaction security is not affected even if a current key is leaked; according to the method, the problems of quantum computing threat, insufficient privacy protection and key leakage risk faced by a block chain system can be effectively solved.
Owner:TAIYUAN UNIVERSITY OF TECHNOLOGY

Power distribution ring main unit communication method and system based on quantum random number and identity authentication

The embodiment of the invention provides a distribution ring main unit communication method and system based on quantum random numbers and identity authentication, and relates to the technical field of quantum communication. The communication method comprises the following steps: acquiring an equipment identifier generated by a power distribution ring main unit terminal; bidirectional identity verification is carried out on the power distribution ring main unit terminal and the main center; obtaining an initial session key; generating a segmentation key according to the initial session key, and segmenting the service data; judging whether the time of encrypting the service data of the current segment by the current segment key is greater than a first time threshold and / or whether the message quantity of the service data of the current segment is greater than a first message threshold; and encrypting the service data of the current segment to generate a new segment key when the time threshold value and / or the first message threshold value are / is greater than the first time threshold value and / or the first message threshold value. According to the invention, a segmented key rotation mechanism triggered based on double thresholds of time and the number of messages is adopted, so that the service cycle of the key is shortened, the forward security and backward security capabilities are improved, and systematic risks caused by key leakage are prevented.
Owner:STATE GRID ANHUI ELECTRIC POWER CO LTD

Hadoop tenant-level encryption isolation implementation method and device

The invention discloses a Hadoop tenant-level encryption isolation implementation method, and aims to solve the problems of single key leakage risk, namespace planarization, encryption area unauthorized binding, no tenant dimension auditing and the like existing in an existing Ranger-KMS scheme. The method comprises the following steps: creating an independent master key for each tenant to realize physical isolation; the key alias, the encryption area paths and the strategy resources are forced to carry tenant prefixes, and the consistency is verified; a tenant context is transmitted through a thread local variable; when an encryption area is created, tenant attributes are persisted, and operation consistency is verified; and the key plaintext is only stored in the KMS memory and is safely reset after being used. According to the method, full-dimension isolation of keys, data, strategies and auditing is realized, single-tenant key leakage does not influence the cluster, unauthorized access and information leakage are completely eradicated, compliance auditing requirements are met, single-cluster multi-tenant safe coexistence is supported, and hardware cost is reduced.
Owner:CHINA ELECTRONICS CLOUD DIGITAL INTELLIGENCE TECH CO LTD

Block chain energy data security protection method, system and device based on attribute control and double-layer encryption and medium

The invention relates to the technical field of energy data security protection, and discloses a block chain energy data security protection method, system and device based on attribute control and double-layer encryption, and a medium, and the method comprises the steps: constructing an ABAC triple policy engine based on user attributes, resource attributes and environment attributes, converting the conventional static authority management into dynamic policy verification, and carrying out the dynamic policy verification; a double-layer AES-GCM encryption algorithm is designed, the data anti-cracking capability is improved through two encryption operations, the linear time complexity is kept while the encryption security is guaranteed, and the efficiency requirement of energy data processing is considered; a dynamic key management mechanism is matched, a unique key pair is generated for each piece of data, the key leakage risk is reduced, and the problem of contradiction between safety and efficiency in a traditional encryption algorithm is solved; an on-chain and off-chain collaborative storage architecture is adopted, encrypted energy data are stored through an IPFS distributed storage system, only the hash value is subjected to on-chain verification for integrity, and capacity limitation caused by traditional block chain full-node storage is broken through.
Owner:GUIZHOU POWER GRID CO LTD

Internet of Things equipment encryption method and device and electronic equipment

The invention relates to the technical field of Internet of Things equipment encryption, and discloses an Internet of Things equipment encryption method and device and electronic equipment, and the method comprises the steps of secret key level-to-level management, dynamic secret key updating, hierarchical encryption communication, and secret key revocation and recovery. According to the invention, a three-level architecture of the master key, the regional key and the equipment key is adopted, hierarchical isolation management of the keys is realized, and the key leakage risk is effectively reduced; a dynamic key updating mechanism can automatically identify and update expired or abnormal keys, so that the flexibility of the system is improved; equipment-level, area-level and core-level data isolation protection is realized through a layered encryption communication strategy, and cross-level attacks are prevented; by quickly identifying abnormal equipment and executing key revocation and recovery, safe operation of the system is ensured; a verification mechanism is introduced to guarantee the integrity and reliability of data transmission. The method is suitable for various scenes such as smart cities and industrial Internet of Things, and provides all-around safety guarantee for Internet of Things equipment.
Owner:JINING POLYTECHNIC

Ciphertext quantum key management and relay method and system

PendingCN122316607ACiphertextTrunking
This invention discloses a method and system for ciphertext quantum key management and relay. The method includes sending routing control information to relay nodes to relay quantum key ciphertext received from connected QKD devices to destination nodes according to the routing control information; sending first encryption information corresponding to each relay node on the relay path to the destination node, so that the destination node converts the XOR value of the quantum key ciphertext based on each of the first encryption information to obtain a first key ciphertext; the quantum key ciphertext is obtained by the QKD device encrypting its generated quantum key using a local key encryption key, the first encryption information carrying a first key encryption key that is the same as the key encryption key corresponding to each relay node, and the first key ciphertext being the ciphertext obtained by encrypting the shared key with the local key encryption key of the QKD device connected to the destination node; this invention can reduce the risk of quantum key leakage.
Owner:QUANTUMCTEK CO LTD +1