Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

141 results about "Key leakage" patented technology

Quantum key management method and system for satellite internet biological characteristics

The invention relates to a quantum key management method and system for satellite internet biological characteristics, and the method comprises the following steps: carrying out the registration of biological characteristics and the initialization of communication protocol parameters for a user terminal which is accessed for the first time; for the registered user terminal, before initiating communication each time, binding the real-time biological characteristics with the quantum key, and carrying out encrypted transmission of the session key by using the bound quantum key, so as to carry out encrypted transmission of satellite internet transmission data by using the session key; and in the encryption transmission process of the satellite internet transmission data, according to a preset period, performing satellite link security level adjustment and quantum key dynamic updating. According to the invention, identity authentication and terminal authentication in a high-delay and narrow-bandwidth application scene can be realized, the security problems of identity counterfeiting, key leakage and the like are solved, and the method can be applied to satellite internet scenes such as emergency communication, field operation and the like, and has the advantages of strong compatibility, low deployment cost and the like.
Owner:SPACE STAR TECH CO LTD

Hadoop tenant-level encryption isolation implementation method and device

The invention discloses a Hadoop tenant-level encryption isolation implementation method, and aims to solve the problems of single key leakage risk, namespace planarization, encryption area unauthorized binding, no tenant dimension auditing and the like existing in an existing Ranger-KMS scheme. The method comprises the following steps: creating an independent master key for each tenant to realize physical isolation; the key alias, the encryption area paths and the strategy resources are forced to carry tenant prefixes, and the consistency is verified; a tenant context is transmitted through a thread local variable; when an encryption area is created, tenant attributes are persisted, and operation consistency is verified; and the key plaintext is only stored in the KMS memory and is safely reset after being used. According to the method, full-dimension isolation of keys, data, strategies and auditing is realized, single-tenant key leakage does not influence the cluster, unauthorized access and information leakage are completely eradicated, compliance auditing requirements are met, single-cluster multi-tenant safe coexistence is supported, and hardware cost is reduced.
Owner:CHINA ELECTRONICS CLOUD DIGITAL INTELLIGENCE TECH CO LTD

Block chain energy data security protection method, system and device based on attribute control and double-layer encryption and medium

The invention relates to the technical field of energy data security protection, and discloses a block chain energy data security protection method, system and device based on attribute control and double-layer encryption, and a medium, and the method comprises the steps: constructing an ABAC triple policy engine based on user attributes, resource attributes and environment attributes, converting the conventional static authority management into dynamic policy verification, and carrying out the dynamic policy verification; a double-layer AES-GCM encryption algorithm is designed, the data anti-cracking capability is improved through two encryption operations, the linear time complexity is kept while the encryption security is guaranteed, and the efficiency requirement of energy data processing is considered; a dynamic key management mechanism is matched, a unique key pair is generated for each piece of data, the key leakage risk is reduced, and the problem of contradiction between safety and efficiency in a traditional encryption algorithm is solved; an on-chain and off-chain collaborative storage architecture is adopted, encrypted energy data are stored through an IPFS distributed storage system, only the hash value is subjected to on-chain verification for integrity, and capacity limitation caused by traditional block chain full-node storage is broken through.
Owner:GUIZHOU POWER GRID CO LTD

Ciphertext quantum key management and relay method and system

PendingCN122316607ACiphertextTrunking
This invention discloses a method and system for ciphertext quantum key management and relay. The method includes sending routing control information to relay nodes to relay quantum key ciphertext received from connected QKD devices to destination nodes according to the routing control information; sending first encryption information corresponding to each relay node on the relay path to the destination node, so that the destination node converts the XOR value of the quantum key ciphertext based on each of the first encryption information to obtain a first key ciphertext; the quantum key ciphertext is obtained by the QKD device encrypting its generated quantum key using a local key encryption key, the first encryption information carrying a first key encryption key that is the same as the key encryption key corresponding to each relay node, and the first key ciphertext being the ciphertext obtained by encrypting the shared key with the local key encryption key of the QKD device connected to the destination node; this invention can reduce the risk of quantum key leakage.
Owner:QUANTUMCTEK CO LTD +1

Anti-quantum method and system based on stateless signature and execution isomorphism

This invention discloses a quantum-resistant method and system based on stateless signatures and execution isomorphism, belonging to the field of quantum-resistant cryptography. First, the sender generates an mKEM broadcast payload based on a modulus error rounding algorithm and signs it using a stateless hash signature algorithm. The receiver performs microsecond-level verification of the signature at the network card driver layer; if verification fails, the signature is silently discarded. After successful verification, a dedicated PQC hardware engine decapsulates the signature, implicitly outputting a pseudo-random scrap key if verification fails. The operating system executes an I / O-aware microarchitecture with isomorphic execution, forcing subsequent processes to maintain physical isomorphism in system calls, memory accesses, and peripheral bus activities, regardless of whether the key is real or scrap. This invention eliminates the risk of private key leakage caused by cloud-based state management through stateless signatures and completely eliminates distinguishable side-channel fingerprints across the entire link through physical-level execution isomorphism, achieving system-level quantum-resistant security in high-concurrency scenarios.
Owner:BEIJING LANGKONG QUANTUM TECHNOLOGY CO LTD

Storage device error analysis equipment and method based on PCIe link state perception

The invention relates to the technical field of data storage, in particular to storage device error analysis equipment and method based on PCIe link state perception. Compared with the prior art, link training failure, electrical problems and the like can be positioned through PCIe link state data, the positioning time is shortened by 60%, the fault positioning is accurate, and two different states of complete failure of the master control of the storage device and abnormal but master control operation of the PCIe link are distinguished; when the PCIe link part is available, a high-speed channel is preferentially utilized, the backup efficiency is improved, and the data acquisition efficiency is improved by 40% through a dual-channel interface; the encryption key is generated according to the PCIe link state, the data confidentiality is enhanced by a dynamic key encryption mechanism, and the key leakage risk is reduced by 90%.
Owner:CHIPMOS TECHNOLOGIES (SHANGHAI) LTD

Encryption sending method and device, equipment, storage medium and product

The invention discloses an encryption sending method and device, equipment, a storage medium and a product, and the method comprises the steps that a sending place node employs a first symmetric key and a second public key of a target trusted execution environment unit to encrypt to-be-transmitted target data, obtains encrypted data, and sends the encrypted data to a destination node, the target trusted execution environment unit is selected from a trusted execution environment unit set in the destination node, so that the destination node decrypts the encrypted data by adopting the second private key and the first symmetric key to obtain the target data, and the target trusted execution environment unit is selected from the trusted execution environment unit set in the destination node. According to the method, the second public key is combined for secondary encryption, so that only the target trusted execution environment unit can decrypt the data, and key leakage and man-in-the-middle attack are effectively prevented. Besides, the target trusted execution environment unit can be flexibly and temporarily determined from the trusted execution environment unit set, so that other equipment can be prevented from acquiring the second public key in advance, and the security of data encryption is further improved.
Owner:SHENZHEN POWER SUPPLY PLANNING DESIGN INST

Data processing method and device, computer device, readable storage medium and product

Embodiments of the present application disclose a data processing method and device, computer equipment, readable storage medium and product. The device vendor firmware data of a device vendor side is acquired, and a key identifier matched with a device to be managed is acquired. The device vendor firmware data is signed based on a target customer key matched with the key identifier, to obtain signed firmware data containing signature information. The signed firmware data is sent to the device vendor side, so that the device vendor side publishes the signed firmware data to obtain published firmware data. If the published firmware data acquired from the device vendor side is verified based on the signature information, the published firmware data is sent to the device to be managed, so that the device to be managed performs firmware management based on the published firmware data. The device vendor side does not contact the target customer key required for signing the device vendor firmware data, and can avoid security problems caused by key leakage, thereby ensuring the security of the device to be managed.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

A security detection rule upgrading system

The application discloses a kind of security detection rule upgrade systems, comprising: running agent AGENT, agent management end and result display end SERVER and the rule server of receiving SERVER's rule inquiry and rule download, AGENT with each component or system runs in same platform, for receiving SERVER side rule and executing specific baseline detection item, result is fed back to SERVER side, SERVER is responsible for updating rule from rule server, and is issued to specified AGNET side by strategy configuration, receives AGENT execution result and shows, its beneficial effect is: by adopting asymmetric encryption and symmetric encryption dynamic key mode, provide rule confidentiality and integrity protection, by rule business upgrade logic built-in rule package, abstract rule unified upper layer, rule business logic adjustment does not need to modify AGNET side, by encrypting key segmentation storage, improve the difficulty of key leakage.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Authentication method, apparatus and device based on pre-shared key

The embodiment of the application provides a kind of based on pre-shared key authentication method, device and equipment, in the above-mentioned pre-shared key authentication method, device sends key acquisition request to first server, then receives the ciphertext of pre-shared key sent by first server, then the ciphertext of pre-shared key is decrypted, the plaintext of pre-shared key is obtained, and then according to the plaintext of pre-shared key, identity authentication or encryption and decryption service is carried out with second server, so that it can be realized by one first server with security authentication and authentication mechanism to store the ciphertext of pre-shared key encrypted by the key of equipment side, so that the security of pre-shared key is greatly improved, and in the above-mentioned method, key and ciphertext are separated, and first server does not have decryption capability (because first server does not have decryption key), so that the risk of pre-shared key leakage in first server end can be avoided.
Owner:HUAWEI TECH CO LTD

Key distribution method, facility, device and medium for quantum secure infrastructure

The application provides a key distribution method, facility, equipment and medium of quantum security infrastructure, and relates to the technical field of quantum security communication, and the method comprises the following steps: in the process of encrypted communication of a terminal, based on a set of pre-shared keys between two key management systems, the risk of key leakage in the key relay process is reduced, and the security of quantum key distribution in the key relay process is improved.
Owner:中电信量子信息科技集团有限公司

Intelligent roadside terminal security processing method and system based on multimode communication cooperation and dynamic key chain

The invention provides an intelligent roadside terminal security processing method and system based on multimode communication collaboration and a dynamic key chain, and relates to the technical field of intelligent traffic and network space security crossover, and the method comprises the steps: obtaining a master key based on a trusted mechanism, and carrying out the registration of a roadside terminal through the master key, distributing a unique identification roadside terminal ID and an initial key for each roadside terminal; a secure link is established through an initial key, a roadside terminal collects 3D spatial position information of the roadside terminal and an accessed vehicle and forms a 3D point set to determine the spatial association priority of the vehicle and each roadside terminal, and meanwhile, the channel quality of a communication mode is evaluated in real time to obtain an evaluation result. The key message delay is less than or equal to 30ms, the cross-terminal authentication time is less than or equal to 10ms, the key leakage risk is reduced, and the vehicle-road collaborative real-time performance and security enhancement requirements are met.
Owner:XIAMEN JINLONG CAR ACCESSORIES CO LTD

An identity authentication method and device based on a commercial cipher algorithm

PendingCN122640127AAlgorithmSession key
The application discloses an identity authentication method and device based on commercial cryptographic algorithms, which is applied to a bastion host operation and maintenance scene, and relies on SM2, SM3 and SM4 commercial cryptographic algorithms, and realizes high-security and high-performance two-way identity authentication. The method strictly follows the core process of GB / T 15843.3-2023 standard, and the standard is optimized and enhanced in multiple dimensions through commercial cryptographic algorithms, including true random number hardware generation, SM2 signature verification enhancement, SM3 session key derivation, SM4 transmission encryption and other steps, to make up for the lack of standard original protection and complete two-way identity authentication. The application strengthens the commercial cryptographic algorithm set of hardware devices, and is deeply integrated with the optimized standard, effectively solves the problems of private key leakage, performance bottleneck and standard protection short board of the existing scheme, meets the compliance requirements of equal protection and secret evaluation, and provides a reliable identity access solution for remote operation and maintenance of the bastion host.
Owner:TOEC ANCHEN INFORMATION TECH

A dynamic encryption method and system for secure transmission

This invention relates to the field of data encryption transmission technology, specifically disclosing a dynamic encryption method and system for secure transmission. The method includes: first, acquiring input parameters of the data to be transmitted and generating an initial encryption key; processing the data to be transmitted in blocks and determining the importance level of each data block; performing layered initial encryption transmission on each data block according to its importance level; collecting dynamic status parameters of the transmission link to generate key update parameters, adjusting the current encryption key to obtain an updated encryption key; detecting whether there are security risks in the transmission link, and if so, using an upgraded encryption algorithm and an updated encryption key to re-encrypt the incomplete data blocks and continue transmission through a backup encryption link; finally, decrypting the encrypted data blocks to obtain the original data blocks and performing integrity verification. This invention effectively solves the problems of easy key leakage, insufficient security, and low encryption efficiency in traditional static encryption methods.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

Code scanning authentication method, system and related device

The application relates to a code scanning authentication method, a system and related equipment. The method adopts scanning a two-dimensional code displayed by a client to obtain a trusted timestamp and a dynamic address; based on the trusted timestamp, a first signature is generated by using a first signature private key of a mobile terminal, the first signature is sent to a co-signing server to trigger the co-signing server to use a second signature private key stored by the co-signing server to perform secondary signing on the first signature; according to the dynamic address, a final signature, a signature certificate of the mobile terminal and the trusted timestamp are submitted to a corresponding authentication server; after authentication succeeds, in response to a login state query request, the client obtains user identity information and automatically completes login, the problems that in the prior art, mobile terminal key single-point storage risk is high, and after a private key is leaked, the private key is easily abused to cause authentication credentials to be impersonated are solved, the technical effect that authentication credentials impersonation risk caused by single-end private key leakage is avoided, and the security and reliability of code scanning authentication are improved.
Owner:BEIJING EETRUST TECH CO LTD

SecOC vehicle-mounted safety communication method based on dynamic key management enhancement

The invention discloses a SecOC vehicle-mounted safety communication method based on dynamic key management enhancement, which realizes on-demand distribution, dynamic updating and full life cycle management of SecOC keys by introducing a key distribution center. The ECU negotiates a unique preset key through the KDC client and the KDC server; the KDC client requests a service bill from the KDC server based on the service identifier of the application; the SecOC key is dynamically distributed by the KDC, and automatic rotation based on a time strategy and emergency update based on a security event are supported. The SecOC message adopts a gPTP timestamp as a freshness value, and after the data unit and the freshness value are spliced, a message authentication code is calculated. According to the invention, the secret key is not statically preset any more, but is dynamically distributed by the KDC and supports online updating, and through combination of bidirectional certificate authentication and timestamp double-factor authentication, full-life-cycle safety management of the vehicle service secret key is realized, and the risk of secret key leakage is effectively coped with.
Owner:AUTOCORE INTELLIGENT TECH (NANJING) CO LTD

Segmented software authorization method based on pre-distributed service serial number

The invention relates to the field of software activation, in particular to a segmented software authorization method based on a pre-distributed service serial number, which comprises the following steps: generating a service serial number and a complete activation key for each piece of software to be authorized, and splitting the complete activation key into a first key segment and a second key segment; pre-writing the service serial number and the first key segment into a specified path of a target computer operating system; an activation client on the target computer operating system reads the locally stored service serial number and the first key segment; obtaining a second key segment in response to user input; the activation client restores a complete activation key based on the combination of the first key segment and the second key segment; and performing verification based on the complete activation key and the service serial number. Through the scheme, the beforehand refined management of software authorization is realized, the key leakage risk is reduced, and convenient activation experience is provided on the premise of ensuring the security.
Owner:KYLIN CORP

Key generation and updating method and system based on RISC-V security area

PendingCN121864304AImplement deep bindingAchieve unified management and control throughout the entire life cycleKey distribution for secure communicationEncryption apparatus with shift registers/memoriesKey (cryptography)Secure transmission
The invention discloses a key generation and updating method and system based on an RISC-V security area, and belongs to the technical field of information security and cryptography, and the method comprises the following steps: S1, hardware security basic data generation and security transmission; s2, key full life cycle management and control and service data generation; and S3, scene adaptation and compliance key handle output are carried out. According to the secret key generation and updating method and system based on the RISC-V safe area, through RISC-V hardware isolation and software and hardware deep binding, the risks of secret key leakage and tampering are completely eradicated; the adaptive dynamic scene is dynamically managed and controlled through the full life cycle, forward security is guaranteed, low-cost adaptive resource-constrained equipment is achieved, and compliance and compatibility are both considered.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

Method for realizing secure roaming of private key of electronic signer based on SM2 collaborative decryption algorithm

The invention relates to the technical field of information security, and discloses a method for realizing secure roaming of a private key of an electronic signer based on an SM2 collaborative decryption algorithm, which comprises the following steps: S1, a user registers identity information to a server, and the server generates a user signature key pair and a certificate and encrypts and stores the private key; s2, the user and the server cooperatively generate a cooperative key pair, and the server synthesizes a public key and securely transmits a user certificate to the client; and S3, when the user needs to sign, the server securely transmits the private key to the mobile phone APP through a collaborative decryption technology, and the mobile phone APP uses the private key to sign and then destroys the private key. According to the invention, the root private key of the user is always stored in the server in the form of the ciphertext, and the decryption key is derived from the password of the user, so that the risk that the server holds a plaintext private key at a single point is avoided; and the private key only instantaneously exists in the memory of the client during signature, so that the risk of private key leakage caused by equipment loss, APP unloading or malicious software attack is greatly reduced.
Owner:BEIJING SKYFAITH TECH CO LTD

A cluster data encryption and decryption method, device and system based on double trusted binding and decryption deadline control

The application discloses a cluster data encryption and decryption method, device and system based on double trusted binding and decryption deadline control, relates to the technical field of information security, and comprises the following steps: collecting hardware characteristic information of a cluster terminal node, extracting a certain length of bytes as original machine code after processing; obtaining a dynamic key factor, extracting a specified length of bytes as a data key after processing; splicing the original machine code and certificate validity period information, generating certificate machine code after processing; splicing the original machine code and certificate validity period information, generating a machine envelope key after processing, performing symmetric encryption on the data key to obtain a machine key; generating a key certificate; and encrypting plaintext data by using the data key to obtain data ciphertext. The application introduces a multi-hardware characteristic fusion and multi-level key encryption system, and solves the problems of device identity impersonation, key leakage and uncontrollable data life cycle in a cluster environment.
Owner:JIANGSU SHIDA DIMEI DATA PROCESSING CO LTD

Data security encryption method and system based on energy big data

The invention discloses a data security encryption method and system based on energy big data. Comprising the steps that a transmission device receives a first reference key and a second reference key, and the first reference key and the second reference key are obtained through an intelligent contract; generating a main ciphertext and a constraint ciphertext corresponding to the plaintext to be encrypted according to the first reference key and the second reference key; and sending the main ciphertext and the constraint ciphertext to a receiving device together, so that the receiving device obtains a plaintext according to the main ciphertext and the constraint ciphertext in combination with the first reference key and the second reference key. The first reference key and the second reference key are generated through the smart contract, and encryption and decryption are performed based on the first reference key and the second reference key; the plaintext is finally obtained, complex operation is not needed, the encryption transmission process is rapidly achieved, and due to the fact that generation of the first reference key has randomness, key leakage can be avoided, and the safety of data transmission is guaranteed.
Owner:STATE GRID JIANGSU ELECTRIC POWER CO LTD MARKETING SERVICE CENT

A security authentication method, system and electronic device

The present application relates to the technical field of communication security, and in particular to a security authentication method, system and electronic device, comprising: sending an algorithm support list, a hybrid key exchange parameter and a first random number, a first certificate request to a second terminal, so that the second terminal generates a second handshake key and a ciphertext; determining a first handshake key and verifying a target first certificate chain sent by the second terminal using the first handshake key to obtain an authentication result, the present application performs authentication based on the hybrid key exchange parameter, so that the terminal has security against quantum attacks, reduces the leakage of plaintext parameters in the initial handshake message in the whole identity authentication process, uses different encryption processing for subsequent messages, reduces the risk of identity authentication key leakage, and improves the security of identity authentication. Meanwhile, the algorithm selection list is sent in the form of a combination algorithm, which can effectively reduce the algorithm selection matching time of the second terminal and improve the identity authentication efficiency.
Owner:ORIGIN QUANTUM COMPUTING TECH (HEFEI) CO LTD

Full offline accessory key full life cycle management system and method

PendingCN122293323AFull life cycleNetwork data
This invention discloses a fully offline accessory key lifecycle management system and method, belonging to the field of smart terminal accessory security management technology. This invention constructs a six-stage, closed-loop management system covering key generation and programming, factory pre-binding, initial activation verification, continuous usage control, offline key revocation, and physical destruction upon disposal. This invention utilizes a PUF (Physically Unclonable Function) circuit to generate unique key pairs for each device. The private key is permanently embedded within the chip, unreadable and unexportable. A physical unidirectional programming link eliminates the risk of internal key leakage, enabling offline pre-binding between the terminal and accessories, offline key revocation, and hardware-level physical key destruction capabilities. This invention operates entirely offline in a closed loop on the local terminal, without requiring cloud-based network data interaction. It effectively solves the security flaws of traditional accessory key systems, such as easy key leakage, easy mass forgery, lack of offline revocation capabilities, and the possibility of reused discarded keys. This provides a full-process, hardware-level, and highly reliable security management solution for the fully offline bionic interactive terminal accessory ecosystem.
Owner:李俪安

Secure digital signature method and system, electronic equipment and storage medium

The invention provides a secure digital signature method and system, electronic equipment and a storage medium, and the method comprises the steps: obtaining a registration request, and registering a password service provider capable of intercepting a signature request and routing the signature request to a secure environment according to the registration request; when a digital signature needs to be generated in the SSL / TLS handshake process, intercepting a signature request through the password service provider, and determining to-be-signed data meeting the requirements of the secure environment interface according to the signature request; and sending the to-be-signed data to the secure environment, and triggering the secure environment to operate the to-be-signed data by using a pre-stored private key so as to generate a digital signature. According to the method, the private key does not appear in a main processor memory or a file system in a plaintext form under any condition, so that the key leakage risk caused by malicious software, memory extraction or operating system vulnerabilities is fundamentally avoided, and the security assurance level of the private key is improved.
Owner:GUANGZHOU LANGO ELECTRONICS TECH CO LTD

A financial-grade database multidimensional security management and control system and method

The application discloses a financial-grade database multidimensional security management and control system and method, relates to the technical field of financial data security management and control, and deploys a quantum encryption network and a backup key pool; initializes a data hierarchical management mechanism and a key management hub; transforms a database engine and builds a trusted audit hub, and deploys a security agent on a database node. Through the cooperation of the quantum encryption network and the post-quantum backup key pool, the high security of quantum encryption is utilized to resist traditional and quantum computing threats, and the encryption service is ensured not to be interrupted when the quantum network is abnormal, thereby meeting the continuity requirement of financial transactions; fine-grained data grading is combined with a differentiated security strategy, encryption algorithms, access permissions and retention periods are configured for high-sensitive, medium-sensitive and low-sensitive data respectively, precise protection is realized, and operation efficiency is taken into account; and a multi-role key cooperation mechanism avoids single-point key leakage, and the original key is destroyed after the key is generated, so that the key security is further improved.
Owner:SICHUAN RONGKE ZHILIAN TECH CO LTD

Secret key distributed storage and safe calling method and device in optical fiber communication system

The invention relates to the technical field of key management, and discloses a key distributed storage and safe calling method and device in an optical fiber communication system, and the method comprises the steps: segmenting a composite key into a plurality of fragments through a threshold secret sharing algorithm, encrypting the fragments through a hardware feature code, storing the index information of the fragments in a block chain alliance chain, and carrying out the encryption through a hardware feature code; storing the encrypted fragments in an IPFS network, and establishing an association relationship between an index and a content addressing identifier; and during calling, identity authentication and permission verification are performed through the smart contract, the encrypted fragments are retrieved from the IPFS network, threshold recombination is performed to restore the key, and integrity is verified through hash comparison. Through a double-layer distributed architecture and a double-protection system, the problems of high single-point fault risk and high key leakage risk of centralized key storage are solved.
Owner:南昌理工学院 +1

Power grid data security sharing method based on dynamic fragmentation and cross-domain cooperation

The invention relates to the technical field related to automatic control, in particular to a power grid data security sharing method based on dynamic fragmentation and cross-domain cooperation. The method comprises the following steps: S1, collecting power grid data through a sensor, and carrying out preprocessing operation on the collected power grid data; s2, slicing the preprocessed power grid data through a dynamic fragmentation technology, and sending the sliced data to different scheduling mechanisms; s3, a plurality of participants cooperatively complete an encryption calculation task of the slice data after passing permission verification, and finally, the initiator safely obtains and verifies a calculation result; and S4, realizing lightweight auditing and fault recovery through log fragment uplink, intelligent fault detection and an automatic recovery mechanism. In the method, through a threshold Paillier private key decryption mechanism, a single node is prevented from mastering a complete private key, the decryption security and credibility are improved, and the risks of key leakage and abuse existing in centralized decryption are solved.
Owner:STATE GRID SHANDONG ELECTRIC POWER CO

A general two-party oblivious signature method and system

This invention discloses a general two-party unintentional signature method and system, belonging to the field of cryptographic protocol technology. The method includes: participants P1 and P2 jointly generating a signature public key; participants P1 and P2 jointly calculating a signature of the message, wherein the signature is known only to participant P1, and participant P1 uses the signature public key to verify the signature. This invention can both distribute key storage to avoid the risk of key leakage and prevent additional participants from obtaining the final signature content.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI

Short message signature intelligent filing verification system

The invention discloses a short message signature intelligent filing verification system, and belongs to the technical field of Internet security services. According to the method, the problem that security defects exist in the face of key leakage, permission abuse and content fraud due to the fact that the prior art depends on a static key and a fixed strategy and lacks a behavior analysis and security mechanism is solved, and the authenticity and legality of a filing subject are ensured by introducing multi-factor authentication and combining a behavior portrait technology; based on dynamic trust evaluation and permission policy adjustment, intelligent access permission management is realized, normal business requirements can be met, abnormal behaviors can be timely handled, and system security is guaranteed; through Hash operation and dynamic instruction binding, the uniqueness and non-tampering performance of each short message request are ensured; and based on a response mechanism driven by a multi-layer check and decision tree model, efficient, safe and reliable operation of short message communication is further guaranteed.
Owner:深圳众投互联信息技术有限公司

Certificate-based drone data auditing methods, devices, equipment, and media

This application relates to a certificate-based method, apparatus, device, and medium for auditing drone data. The method includes: generating system parameters and a master key pair for a preset certificate center; obtaining user key pairs and identity information for at least one target drone, and receiving a valid digital certificate from the certificate center in conjunction with the system parameters and the master public key; collecting corresponding drone data from the target drone, and generating a homomorphic verifiable tag for the drone data when the valid digital certificate meets preset certificate verification conditions; and auditing the drone data corresponding to one or more target drones through a preset challenge-response interactive auditing mechanism when the drone data and the homomorphic verifiable tag meet preset validity verification conditions to obtain the data audit result. This solves the problems of high key leakage risk, difficulty in homomorphically aggregating verifiable tags from different users, and high audit overhead in existing data auditing schemes.
Owner:HANGZHOU INNOVATION RES INST OF BEIJING UNIV OF AERONAUTICS & ASTRONAUTICS +1