Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

218 results about "Key leakage" patented technology

Data security processing method and system based on distributed storage

The invention relates to a data security processing method and system based on distributed storage, and relates to the technical field of computer information processing. The method comprises the following steps: cutting data into encryption fragments with a configurable number by adopting a dynamic fragmentation strategy, and generating a physically isolated dynamic check block in combination with a timestamp to realize tampering prevention; a dynamic threshold value is dynamically calculated based on the data sensitivity index and the node load, and the node is optimized through the reliability score for cooperative decryption; a database table is divided into independent marshalling storage according to main foreign key association, foreign key fields are encrypted by adopting cross keys, and cross-marshalling access needs to meet a multi-key threshold condition; an intelligent threat perception engine is constructed, access logs and threat intelligence are analyzed in real time, and key rotation, fragment replacement and joint defense response mechanisms are dynamically triggered. According to the invention, full life cycle protection of data is realized, and the problems of key leakage risk and cross-table association attack are effectively solved.
Owner:WUHAN ANYU INFORMATION SECURITY TECH CO LTD

Remote power supply operation and maintenance virtual conference cooperation method and system and electronic equipment

The invention discloses a remote power supply operation and maintenance virtual conference cooperation method and system and electronic equipment, and particularly relates to the field of power operation and maintenance scheduling, and the method comprises the following steps: I, accessing various data of a power supply network, constructing a three-dimensional topology energy flow diagram in real time, and dynamically generating a security level matrix in combination with real-time equipment working conditions; iI, establishing a temporary operation authority tunnel, starting a virtual conference space, and automatically matching a most suitable interaction mode according to behaviors and intentions of participants; according to the method, the operation compliance and safety can be improved, key leakage and instruction tampering are effectively prevented, the encryption strength of remote operation is enhanced, permission abuse is prevented, the system toughness is improved, and safe closed-loop management from access to execution is realized; the comprehensiveness and timeliness of state monitoring of the power supply network are effectively improved, more accurate abnormal event identification can be realized, the problem positioning efficiency is improved, and a user is ensured to preferentially acquire the most reliable and most representative abnormal propagation chain.
Owner:DONGYING CITY DONGYING DISTRICT POWER SUPPLY CO STATE GRID SHANDONG ELECTRIC POWER CO

Security inter-core communication method based on derived key negotiation

The invention discloses a safety inter-core communication method based on derived key negotiation. The safety defect of a traditional inter-core communication scheme is overcome through a dynamic key negotiation mechanism. Based on a preset derived base key and a random salt value, a unique temporary session key is negotiated before each communication, and forward security is ensured: even if the derived base key is leaked, historical encrypted data still cannot be decoded; a bidirectional salt value check code verification mechanism is adopted, chip identity legality authentication is achieved in the negotiation stage, and forgery or tampering attacks are blocked; during communication, a data ciphertext check code is generated through a check key, and data integrity and source authenticity are guaranteed; it is ensured that the session key is unpredictable each time through the random salt value, and replay attacks are effectively resisted in combination with a timeliness verification mechanism. In addition, key re-negotiation is triggered according to data sensitivity, a key exposure time window is dynamically reduced, the risk of long-term key leakage is further reduced, and safety and resource efficiency are both considered.
Owner:SHENZHEN ROADROVER TECH

Information processing apparatus, information processing method, and recording medium

To reduce labor related to an update of an encryption key in response to an encryption request for the AI software specifying the third type key, encryption key leakage or the like.An information processing apparatus according to the present technology includes an encryption key creation part that creates an encryption key on a basis of a first type key stored in advance in an imaging apparatus, a second type key different from the first type key, and a third type key that is different from the first type key and the second type key and is a key multiplied with the second type key to create a combination key stored in the imaging apparatus, or is a key stored in the imaging apparatus together with the second type key, as an encryption key used by the imaging apparatus for encryption of artificial intelligence (AI) software including at least software of an artificial intelligence model, the imaging apparatus performing image recognition processing using the artificial intelligence model on a captured image obtained by capturing an image of a subject, the encryption key creation part creating, in response to specification of a key derived from new information different from original information as the third type key, a new encryption key based on the third type key derived from the new information, the first type key, and the second type key on a basis of the new information.
Owner:SONY SEMICON SOLUTIONS CORP

Method and device for safely accessing industrial control equipment to public test platform

The invention discloses a method and device for safely accessing industrial control equipment to a public test platform, and the method comprises the steps: carrying out the initialization of the public test platform, including the generation of a public and private key pair, the configuration of a digital certificate, the configuration of a Bloom filter, the selection of a hash function set matched with the Bloom filter, and the construction of a controlled resource identifier set; the public test platform receives registration information of the industrial control equipment, grants a corresponding authority to the industrial control equipment according to the registration information, generates a minimum authorized resource set corresponding to the authority, writes the minimum authorized resource set into the Bloom filter, and stores identity information of the industrial control equipment; the public testing platform performs bidirectional authentication of the public testing platform and the industrial control equipment based on an authentication request initiated by the industrial control equipment, and dynamically updates authentication information held by the public testing platform and the industrial control equipment respectively; and after the bidirectional authentication is completed, the public test platform performs access admission judgment on a resource access request initiated by the industrial control equipment by using a bloom filter based on the controlled resource identifier set and corresponding authority granted to the industrial control equipment. The invention aims to solve the problems that the current industrial control equipment in a large-scale access scene is weak in authentication anti-attack capability, a secret key is easy to leak and counterfeit, physical attack protection is insufficient, communication lacks forward and backward security, and a resource authorization mechanism does not have a fine granularity and minimum authorization principle.
Owner:XI AN JIAOTONG UNIV

Block chain-based trusted IoT (Internet of Things) access method and equipment

The embodiment of the invention provides a trusted IoT (Internet of Things) access method and equipment based on a block chain. The method is applied to the technical field of communication, and comprises the following steps: firstly, generating a key for the Internet of Things in a TEE environment of an intelligent gateway, encrypting a resource address of an Internet of Things device, preventing the key from being acquired by malicious software, preventing the key from being counterfeited, and ensuring the security of the Internet of Things device accessing a block chain network, and a block chain stores a key index instead of the key, so that the security of the Internet of Things device accessing a block chain network is ensured. The risk of key leakage is further reduced; by setting a device management contract and a policy authority contract, the authority of a user for accessing the Internet of Things device is inquired and managed, fine control of the access authority is realized, and only the user having the authority can obtain a corresponding secret key from an intelligent gateway to decrypt an encrypted resource address provided in a block chain. According to the arrangement, leakage of the resource address is effectively prevented, and sensitive information is prevented from being leaked.
Owner:NINGBO TELIAN INFORMATION TECH CO LTD

A supply chain data management method based on privacy computing

The present invention discloses a supply chain data management method based on privacy computing, which belongs to the field of data processing technology. By adopting privacy computing technology, it realizes encryption processing and efficient management of supply chain data, ensuring the security, privacy and reliability of data during the circulation process. At the same time, the key is fragmented and decentralized, which can effectively prevent key leakage and loss, and can greatly improve data security. This method is applicable to various supply chain scenarios, helps to improve supply chain collaboration efficiency, and reduce the risk of data leakage.
Owner:GOLDEN NETWORK (BEIJING) E-COMMERCE CO LTD

User security authentication method and system based on encryption processing

The invention discloses a user security authentication method and system based on encryption processing. The method comprises an initialization stage, user key processing, secondary encryption, user identity authentication, server identity authentication, secondary security authentication, dynamic update of an expansion mechanism and key management. The invention belongs to the field of data encryption, and particularly relates to a user security authentication method and system based on encryption processing, according to the scheme, Q is generated through a high-entropy pseudo-random number, and the anti-prediction capacity of key generation is greatly improved; introducing a double confusion mechanism to carry out secondary encryption; detecting data errors by checking the basic groups; therefore, the security of encryption authentication is obviously improved; primary identity authentication, direct authentication between a user and a target server and secondary security authentication are performed in combination with biological characteristic data of the user, so that a multi-layer authentication mechanism is constructed, and the confidentiality and integrity of a key are ensured; based on dynamic expansion and hierarchical key management, the risk of single-point key leakage is reduced; and the encryption authentication effect is improved.
Owner:CHINA UNICOM ONLINE INFORMATION TECHNOLOGY CO LTD +1

Video encryption method and system based on dynamic fragmentation and multilayer confusion

The invention discloses a video encryption method and system based on dynamic fragmentation and multilayer confusion. Identifying all sensitive areas in each frame of original image and calculating a frame-level sensitivity score of the original image; setting a fragmentation mechanism, and dynamically dividing and fragmenting the target video according to the fragmentation mechanism; embedding watermark information into the segmented video frame frequency domain, and converting the video frame frequency domain embedded with the watermark information into a spatial domain; encrypting the video frame embedded with the hidden watermark information by adopting a multi-layer encryption technology; and a watermark self-repairing mechanism is set, and a decryption algorithm is automatically matched according to the terminal type. The encryption calculation amount of a non-sensitive area can be reduced, the anti-attack capability is enhanced, and the key leakage probability is reduced; watermarks are embedded according to characteristic differentiation of different regions, it is ensured that copyright identifiers of key content cannot be deleted, and meanwhile robustness and processing efficiency are balanced; the decryption algorithm supports real-time video processing, an authorized user does not need to manually input a key, and the key management cost is reduced.
Owner:ZHENGZHOU THINK FREELY HI TECH

Distributed key protection method and system for multi-trusted hardware collaboration environment

The present invention discloses a distributed key protection method and system for a multi-trusted hardware collaboration environment. The method comprises: when a trusted hardware receives a trusted service application, obtaining a trusted hardware randomly assigned by an upper-layer system as an assisting trusted hardware, the assisting trusted hardware and the access feasible hardware as the executing trusted hardware, each executing trusted hardware generating a dynamic private key shard; the access trusted hardware sending the first part of the ciphertext to all assisting trusted hardware; each executing trusted hardware calculating a decryption intermediate value based on the dynamic private key shard; each assisting trusted hardware sending the decryption intermediate value to the access trusted hardware; the access trusted hardware calculating the plaintext corresponding to the ciphertext based on all the decryption intermediate values; the access trusted hardware executing the service; and the access trusted hardware encrypting the service execution result using the user's public key so that the user client can decrypt it. The present invention can provide homogeneous services, prevent key leakage, prevent conspiracy attacks, and support heterogeneous trusted hardware.
Owner:TSINGHUA UNIVERSITY +1

Quantum key management method and system for satellite internet biological characteristics

The invention relates to a quantum key management method and system for satellite internet biological characteristics, and the method comprises the following steps: carrying out the registration of biological characteristics and the initialization of communication protocol parameters for a user terminal which is accessed for the first time; for the registered user terminal, before initiating communication each time, binding the real-time biological characteristics with the quantum key, and carrying out encrypted transmission of the session key by using the bound quantum key, so as to carry out encrypted transmission of satellite internet transmission data by using the session key; and in the encryption transmission process of the satellite internet transmission data, according to a preset period, performing satellite link security level adjustment and quantum key dynamic updating. According to the invention, identity authentication and terminal authentication in a high-delay and narrow-bandwidth application scene can be realized, the security problems of identity counterfeiting, key leakage and the like are solved, and the method can be applied to satellite internet scenes such as emergency communication, field operation and the like, and has the advantages of strong compatibility, low deployment cost and the like.
Owner:SPACE STAR TECH CO LTD

Cooperative encryption and decryption method and system based on NTRU algorithm

The invention discloses a collaborative encryption and decryption method and system based on an NTRU algorithm, and relates to the field of data security, and the method comprises the steps: a client and a server respectively generate local keys based on the NTRU algorithm, and cooperatively generate a global public key; the secret key comprises a part of private key of the client, a part of public key of the client, a part of private key of the server and a part of public key of the server; encrypting a plaintext message to be encrypted by using the global public key to generate a ciphertext; the server decrypts the ciphertext by using a local part of private keys to obtain a part of plaintext; and the client decrypts the partial plaintext by using the local partial private key to obtain a complete ciphertext. According to the application, the risk of key leakage can be reduced, the data security is improved, and the hardware purchase and maintenance cost can be reduced.
Owner:BEIJING RENXINZHENG TECH CO LTD

Smart home security authentication management method and system based on wireless local area network

The invention provides a smart home security authentication management method and system based on a wireless local area network. The method comprises the following steps: constructing a home network security authentication domain; when a new smart home device is accessed, marking the new smart home device as a second smart home device, and obtaining a device authentication state matrix of a home network security authentication domain; generating an authentication challenge vector based on the device authentication state matrix, and sending the authentication challenge vector to the second smart home device and the first smart home device for cooperative verification; and if the authentication challenge vector passes the cooperative verification, updating keys of all smart home devices in the home network security authentication domain according to a preset dynamic key synchronization protocol. Through construction of a home network security authentication domain, intra-domain sharing of security parameters such as a device authentication state and key management is realized, when any key is updated, other devices update synchronously, and associated dependence exists among keys, so that a risk conduction path of a whole network falling situation caused by key leakage of a single device is blocked.
Owner:CVC CERTIFICATION & TESTING CO LTD +1

Data encryption transmission system and method for wireless WIFI engineering

The invention belongs to the technical field of wireless transmission, and provides a data encryption transmission system and method for wireless WIFI engineering, and the method comprises the following steps: determining a transmitting node for wireless transmission, recognizing preliminary candidate equipment with data frame receiving capability through channel scanning in a coverage range of the transmitting node, and transmitting the preliminary candidate equipment to a server; the receiving capability of the preliminary candidate device is verified, the preliminary candidate device passing verification is used as a potential receiving node of wireless transmission, and a potential receiving node set is constructed; and calculating theoretical transmission time based on the real-time transmission rate of the transmitting node and the size of the data packet to be transmitted. Potential receiving nodes are accurately identified and a node set is dynamically maintained, so that equipment participating in data transmission has stable receiving capability, key updating is triggered in combination with real-time channel flow analysis, key evolution is matched with a channel state, encryption dynamics is enhanced, and the key leakage risk is reduced.
Owner:GUANGXI ZHONGWU INFORMATION TECH GRP CO LTD

Power distribution ring main unit communication method and system based on quantum random number and identity authentication

The embodiment of the invention provides a distribution ring main unit communication method and system based on quantum random numbers and identity authentication, and relates to the technical field of quantum communication. The communication method comprises the following steps: acquiring an equipment identifier generated by a power distribution ring main unit terminal; bidirectional identity verification is carried out on the power distribution ring main unit terminal and the main center; obtaining an initial session key; generating a segmentation key according to the initial session key, and segmenting the service data; judging whether the time of encrypting the service data of the current segment by the current segment key is greater than a first time threshold and / or whether the message quantity of the service data of the current segment is greater than a first message threshold; and encrypting the service data of the current segment to generate a new segment key when the time threshold value and / or the first message threshold value are / is greater than the first time threshold value and / or the first message threshold value. According to the invention, a segmented key rotation mechanism triggered based on double thresholds of time and the number of messages is adopted, so that the service cycle of the key is shortened, the forward security and backward security capabilities are improved, and systematic risks caused by key leakage are prevented.
Owner:STATE GRID ANHUI ELECTRIC POWER CO LTD

Hadoop tenant-level encryption isolation implementation method and device

The invention discloses a Hadoop tenant-level encryption isolation implementation method, and aims to solve the problems of single key leakage risk, namespace planarization, encryption area unauthorized binding, no tenant dimension auditing and the like existing in an existing Ranger-KMS scheme. The method comprises the following steps: creating an independent master key for each tenant to realize physical isolation; the key alias, the encryption area paths and the strategy resources are forced to carry tenant prefixes, and the consistency is verified; a tenant context is transmitted through a thread local variable; when an encryption area is created, tenant attributes are persisted, and operation consistency is verified; and the key plaintext is only stored in the KMS memory and is safely reset after being used. According to the method, full-dimension isolation of keys, data, strategies and auditing is realized, single-tenant key leakage does not influence the cluster, unauthorized access and information leakage are completely eradicated, compliance auditing requirements are met, single-cluster multi-tenant safe coexistence is supported, and hardware cost is reduced.
Owner:CHINA ELECTRONICS CLOUD DIGITAL INTELLIGENCE TECH CO LTD

Block chain energy data security protection method, system and device based on attribute control and double-layer encryption and medium

The invention relates to the technical field of energy data security protection, and discloses a block chain energy data security protection method, system and device based on attribute control and double-layer encryption, and a medium, and the method comprises the steps: constructing an ABAC triple policy engine based on user attributes, resource attributes and environment attributes, converting the conventional static authority management into dynamic policy verification, and carrying out the dynamic policy verification; a double-layer AES-GCM encryption algorithm is designed, the data anti-cracking capability is improved through two encryption operations, the linear time complexity is kept while the encryption security is guaranteed, and the efficiency requirement of energy data processing is considered; a dynamic key management mechanism is matched, a unique key pair is generated for each piece of data, the key leakage risk is reduced, and the problem of contradiction between safety and efficiency in a traditional encryption algorithm is solved; an on-chain and off-chain collaborative storage architecture is adopted, encrypted energy data are stored through an IPFS distributed storage system, only the hash value is subjected to on-chain verification for integrity, and capacity limitation caused by traditional block chain full-node storage is broken through.
Owner:GUIZHOU POWER GRID CO LTD

Ciphertext quantum key management and relay method and system

PendingCN122316607ACiphertextTrunking
This invention discloses a method and system for ciphertext quantum key management and relay. The method includes sending routing control information to relay nodes to relay quantum key ciphertext received from connected QKD devices to destination nodes according to the routing control information; sending first encryption information corresponding to each relay node on the relay path to the destination node, so that the destination node converts the XOR value of the quantum key ciphertext based on each of the first encryption information to obtain a first key ciphertext; the quantum key ciphertext is obtained by the QKD device encrypting its generated quantum key using a local key encryption key, the first encryption information carrying a first key encryption key that is the same as the key encryption key corresponding to each relay node, and the first key ciphertext being the ciphertext obtained by encrypting the shared key with the local key encryption key of the QKD device connected to the destination node; this invention can reduce the risk of quantum key leakage.
Owner:QUANTUMCTEK CO LTD +1

Key security management method of cold wallet and cold wallet server end

A key security management method of a cold wallet and a cold wallet server, a user provides a mnemonic word to generate a key and a wallet address, and then the system stores the key fragments in different storage addresses of volatile memory, such as memory. Even if the cold wallet server is invaded and the memory data is leaked, the entire key information will not be leaked, that is, the invasion can only obtain part of the key fragments, and cannot piece together the complete key to manipulate the cold wallet assets, greatly reducing the overall key leakage risk caused by local security problems. Moreover, if the cold wallet server detects illegal intrusion, it will start system restart or power-off protection measures. Once the system restarts or powers off, the key fragment data stored in the memory will also disappear, further improving the security and reliability of key protection.
Owner:HONG KONG MOUBICHENG CO LTD

Key distribution method of quantum security infrastructure, facility, equipment and medium

The invention provides a key distribution method of a quantum security infrastructure, a facility, equipment and a medium, and relates to the technical field of quantum secure communication, and the method comprises the following steps: in the encryption communication process of a terminal, based on a key set pre-shared in pairs between key management systems, reducing the risk of key leakage in the key relay process, and improving the security of the terminal. And the security of quantum key distribution in the key relay process is improved.
Owner:中电信量子信息科技集团有限公司

A semantic-aware cross-modal encrypted retrieval method

This invention relates to a semantically aware cross-modal encrypted retrieval method, belonging to the fields of information retrieval and data encryption. By introducing deep learning, it enhances the semantic feature mining capability for multimodal data, replacing the traditional keyword retrieval mode with semantic feature retrieval. A low-overhead multimodal data encrypted retrieval method is introduced, designing a parallel retrieval tree structure based on the block-based approach to achieve low-overhead, privacy-preserving, and fast semantic similarity retrieval. The rationality of the scheme is analyzed from aspects such as precision, search time, and storage overhead. This invention obtains multimodal features by extracting features from query requests; it uses a similarity-hiding encrypted retrieval algorithm to generate encrypted query trapdoors for multimodal query features; and it enables secure multimodal data retrieval in the medical IoT, combining the powerful edge computing capabilities and fast response of traditional scenarios, overcoming the problems of insufficient end-user computing resources and key leakage.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Anti-quantum method and system based on stateless signature and execution isomorphism

This invention discloses a quantum-resistant method and system based on stateless signatures and execution isomorphism, belonging to the field of quantum-resistant cryptography. First, the sender generates an mKEM broadcast payload based on a modulus error rounding algorithm and signs it using a stateless hash signature algorithm. The receiver performs microsecond-level verification of the signature at the network card driver layer; if verification fails, the signature is silently discarded. After successful verification, a dedicated PQC hardware engine decapsulates the signature, implicitly outputting a pseudo-random scrap key if verification fails. The operating system executes an I / O-aware microarchitecture with isomorphic execution, forcing subsequent processes to maintain physical isomorphism in system calls, memory accesses, and peripheral bus activities, regardless of whether the key is real or scrap. This invention eliminates the risk of private key leakage caused by cloud-based state management through stateless signatures and completely eliminates distinguishable side-channel fingerprints across the entire link through physical-level execution isomorphism, achieving system-level quantum-resistant security in high-concurrency scenarios.
Owner:BEIJING LANGKONG QUANTUM TECHNOLOGY CO LTD

Storage device error analysis equipment and method based on PCIe link state perception

The invention relates to the technical field of data storage, in particular to storage device error analysis equipment and method based on PCIe link state perception. Compared with the prior art, link training failure, electrical problems and the like can be positioned through PCIe link state data, the positioning time is shortened by 60%, the fault positioning is accurate, and two different states of complete failure of the master control of the storage device and abnormal but master control operation of the PCIe link are distinguished; when the PCIe link part is available, a high-speed channel is preferentially utilized, the backup efficiency is improved, and the data acquisition efficiency is improved by 40% through a dual-channel interface; the encryption key is generated according to the PCIe link state, the data confidentiality is enhanced by a dynamic key encryption mechanism, and the key leakage risk is reduced by 90%.
Owner:CHIPMOS TECHNOLOGIES (SHANGHAI) LTD

Encryption sending method and device, equipment, storage medium and product

The invention discloses an encryption sending method and device, equipment, a storage medium and a product, and the method comprises the steps that a sending place node employs a first symmetric key and a second public key of a target trusted execution environment unit to encrypt to-be-transmitted target data, obtains encrypted data, and sends the encrypted data to a destination node, the target trusted execution environment unit is selected from a trusted execution environment unit set in the destination node, so that the destination node decrypts the encrypted data by adopting the second private key and the first symmetric key to obtain the target data, and the target trusted execution environment unit is selected from the trusted execution environment unit set in the destination node. According to the method, the second public key is combined for secondary encryption, so that only the target trusted execution environment unit can decrypt the data, and key leakage and man-in-the-middle attack are effectively prevented. Besides, the target trusted execution environment unit can be flexibly and temporarily determined from the trusted execution environment unit set, so that other equipment can be prevented from acquiring the second public key in advance, and the security of data encryption is further improved.
Owner:SHENZHEN POWER SUPPLY PLANNING DESIGN INST

Data processing method and device, computer device, readable storage medium and product

Embodiments of the present application disclose a data processing method and device, computer equipment, readable storage medium and product. The device vendor firmware data of a device vendor side is acquired, and a key identifier matched with a device to be managed is acquired. The device vendor firmware data is signed based on a target customer key matched with the key identifier, to obtain signed firmware data containing signature information. The signed firmware data is sent to the device vendor side, so that the device vendor side publishes the signed firmware data to obtain published firmware data. If the published firmware data acquired from the device vendor side is verified based on the signature information, the published firmware data is sent to the device to be managed, so that the device to be managed performs firmware management based on the published firmware data. The device vendor side does not contact the target customer key required for signing the device vendor firmware data, and can avoid security problems caused by key leakage, thereby ensuring the security of the device to be managed.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

A security detection rule upgrading system

The application discloses a kind of security detection rule upgrade systems, comprising: running agent AGENT, agent management end and result display end SERVER and the rule server of receiving SERVER's rule inquiry and rule download, AGENT with each component or system runs in same platform, for receiving SERVER side rule and executing specific baseline detection item, result is fed back to SERVER side, SERVER is responsible for updating rule from rule server, and is issued to specified AGNET side by strategy configuration, receives AGENT execution result and shows, its beneficial effect is: by adopting asymmetric encryption and symmetric encryption dynamic key mode, provide rule confidentiality and integrity protection, by rule business upgrade logic built-in rule package, abstract rule unified upper layer, rule business logic adjustment does not need to modify AGNET side, by encrypting key segmentation storage, improve the difficulty of key leakage.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Authentication method, apparatus and device based on pre-shared key

The embodiment of the application provides a kind of based on pre-shared key authentication method, device and equipment, in the above-mentioned pre-shared key authentication method, device sends key acquisition request to first server, then receives the ciphertext of pre-shared key sent by first server, then the ciphertext of pre-shared key is decrypted, the plaintext of pre-shared key is obtained, and then according to the plaintext of pre-shared key, identity authentication or encryption and decryption service is carried out with second server, so that it can be realized by one first server with security authentication and authentication mechanism to store the ciphertext of pre-shared key encrypted by the key of equipment side, so that the security of pre-shared key is greatly improved, and in the above-mentioned method, key and ciphertext are separated, and first server does not have decryption capability (because first server does not have decryption key), so that the risk of pre-shared key leakage in first server end can be avoided.
Owner:HUAWEI TECH CO LTD

Key distribution method, facility, device and medium for quantum secure infrastructure

The application provides a key distribution method, facility, equipment and medium of quantum security infrastructure, and relates to the technical field of quantum security communication, and the method comprises the following steps: in the process of encrypted communication of a terminal, based on a set of pre-shared keys between two key management systems, the risk of key leakage in the key relay process is reduced, and the security of quantum key distribution in the key relay process is improved.
Owner:中电信量子信息科技集团有限公司

Intelligent roadside terminal security processing method and system based on multimode communication cooperation and dynamic key chain

The invention provides an intelligent roadside terminal security processing method and system based on multimode communication collaboration and a dynamic key chain, and relates to the technical field of intelligent traffic and network space security crossover, and the method comprises the steps: obtaining a master key based on a trusted mechanism, and carrying out the registration of a roadside terminal through the master key, distributing a unique identification roadside terminal ID and an initial key for each roadside terminal; a secure link is established through an initial key, a roadside terminal collects 3D spatial position information of the roadside terminal and an accessed vehicle and forms a 3D point set to determine the spatial association priority of the vehicle and each roadside terminal, and meanwhile, the channel quality of a communication mode is evaluated in real time to obtain an evaluation result. The key message delay is less than or equal to 30ms, the cross-terminal authentication time is less than or equal to 10ms, the key leakage risk is reduced, and the vehicle-road collaborative real-time performance and security enhancement requirements are met.
Owner:XIAMEN JINLONG CAR ACCESSORIES CO LTD

An identity authentication method and device based on a commercial cipher algorithm

PendingCN122640127AAlgorithmSession key
The application discloses an identity authentication method and device based on commercial cryptographic algorithms, which is applied to a bastion host operation and maintenance scene, and relies on SM2, SM3 and SM4 commercial cryptographic algorithms, and realizes high-security and high-performance two-way identity authentication. The method strictly follows the core process of GB / T 15843.3-2023 standard, and the standard is optimized and enhanced in multiple dimensions through commercial cryptographic algorithms, including true random number hardware generation, SM2 signature verification enhancement, SM3 session key derivation, SM4 transmission encryption and other steps, to make up for the lack of standard original protection and complete two-way identity authentication. The application strengthens the commercial cryptographic algorithm set of hardware devices, and is deeply integrated with the optimized standard, effectively solves the problems of private key leakage, performance bottleneck and standard protection short board of the existing scheme, meets the compliance requirements of equal protection and secret evaluation, and provides a reliable identity access solution for remote operation and maintenance of the bastion host.
Owner:TOEC ANCHEN INFORMATION TECH