Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

1441 results about "Key management" patented technology

Key management refers to management of cryptographic keys in a cryptosystem. This includes dealing with the generation, exchange, storage, use, crypto-shredding (destruction) and replacement of keys. It includes cryptographic protocol design, key servers, user procedures, and other relevant protocols.

Computer network data secure transmission system and method

The invention discloses a computer network data secure transmission system and method, and particularly relates to the technical field of network data secure transmission, and the system comprises a dynamic key management module which generates a key seed through a quantum random number generator, generates a dynamic key bound with a data packet in combination with a timestamp, and transmits the dynamic key to a server; after being encrypted by a receiving end public key, the data are transmitted through an independent verification channel; the dual-path transmission control module is used for establishing dual channels of a main path and a shadow path, a data packet of the main path is embedded into a random camouflage protocol header to simulate a non-sensitive protocol, and a blank data packet is filled in the shadow path to maintain traffic characteristics; according to the real-time verification engine, a receiving end constructs an encrypted hash tree to achieve fragment-level integrity verification, and meanwhile, requests key state three-state verification from the key management module. Through key dynamic generation and separation transmission, dual-path adaptive fragmentation distribution, fragmentation hash tree reconstruction and key linkage verification, and abnormal triggering fragmentation level retransmission, the problems of long-term effectiveness of a static key, predictable transmission path and verification lag are solved.
Owner:陈俊奕

Financial data encryption transmission and storage method based on cloud computing

The invention relates to the technical field of cloud computing financial security, and provides a financial data encryption transmission and storage method. The method is characterized by comprising the following steps of: executing sensitivity-driven data grading fragmentation on a user terminal; dynamic elliptic curve encryption is carried out on transmission data through a two-channel encryption engine, and fully homomorphic encryption is carried out on storage data; dynamically distributing the fragments to heterogeneous cloud nodes by the multi-cloud routing based on reinforcement learning; a distributed key management matrix is constructed, key fragments are dispersed and stored in a block chain and a hardware security module, and reconstruction is activated through biological characteristics. The method has the advantages that full-link ciphertext operation is realized, and the plaintext exposure risk is eliminated; ciphertext state financial calculation is supported; single point failure is resisted; the APT attack is defended dynamically; and the quantum security evolution capability is realized. The method is suitable for mobile banks, cross-border payment and other scenes.
Owner:BEIJING CREDIT MANAGEMENT CO LTD

Network data encryption and privacy protection system in cloud environment

The invention relates to the technical field of cloud computing, in particular to a network data encryption and privacy protection system in a cloud environment, which comprises a key management unit driven by a wolf pack algorithm, an encryption algorithm optimization unit, a privacy protection strategy dynamic adjustment unit and a safety monitoring and abnormity response unit. The invention discloses a cloud environment network data encryption and privacy protection system constructed based on a wolf pack algorithm. High-security keys are dynamically generated and distributed through a key management unit, security performance and resource consumption are balanced through an encryption algorithm optimization unit, multi-target dynamic gaming and compliance guarantee are achieved through a privacy protection strategy unit, distributed attack detection and cooperative defense are completed through a security monitoring unit, and the security performance is improved through a cooperative feedback mechanism between the units. Intelligent encryption protection, dynamic strategy adjustment and efficient attack response of the full life cycle of the data in the cloud environment are realized, and the system security, the resource utilization rate and the compliance capability are remarkably improved.
Owner:HUNAN WUXIANG ELECTRIC POWER TECH CO LTD

Multi-factor dynamic authentication internet of things network security access platform

The invention relates to the technical field of Internet of Things, and discloses a multi-factor dynamic authentication Internet of Things network security access platform, which adopts a multi-factor authentication mechanism, combines biological characteristics, behavior characteristics and environment characteristics of equipment, performs identity verification through biological recognition, equipment fingerprints and behavior analysis, and utilizes a dynamic authentication strategy. Detecting an abnormal IP behavior and triggering a security policy by adopting a dynamic IP binding technology, combining with equipment fingerprint identification and learning and analyzing an equipment network behavior mode; a dynamic key management mechanism is adopted, and keys are automatically generated, distributed and updated according to different devices, application scenes and communication requirements; machine learning and artificial intelligence technologies are utilized to comprehensively analyze historical access data, abnormal behavior modes, environment security states and the like of equipment, and the security risk of equipment access is automatically evaluated if suspicious equipment is detected. The method has the advantage of improving the security of the Internet of Things.
Owner:卞玉捷

Secure communication method for edge node and terminal equipment based on dynamic key negotiation

The invention relates to a secure communication method for an edge node and terminal equipment based on dynamic key negotiation. The method comprises the following steps: the terminal equipment sends an initial signal when initiating a communication request; the edge node generates a scenarized first key negotiation parameter and feeds back the scenarized first key negotiation parameter after passing dual identity and state verification; after the terminal device decrypts the parameter, a dynamic entropy value is collected by combining a network adaptive sensor, and a second key negotiation parameter associated with the first parameter feature is generated; the two parties calculate session keys based on an ECDH algorithm, and the consistency of the keys is ensured through dynamic entropy verification and Hash comparison; and after the key negotiation succeeds, entering a hierarchical encrypted data transmission stage, and dynamically updating a session key based on a multi-dimensional trigger mechanism. According to the method, through hardware credibility verification, a scenarized key strategy, dynamic entropy enhancement and national secret algorithm adaptation, dynamic management of keys and adaptive matching of terminal resources are achieved, attacks such as equipment counterfeiting and parameter tampering are effectively resisted, and the high-security and compliance requirements in the fields of industrial control and the like are met.
Owner:BEIJING HUAKUN ZHENYU INTELLIGENT TECH CO LTD

Industrial Internet of Things equipment data encryption transmission method based on edge computing

The invention discloses an edge computing-based industrial Internet of Things equipment data encryption transmission method, which comprises the following steps of: constructing an edge node alliance comprising at least two cross-regional edge gateways, completing bidirectional identity authentication through an alliance root certificate, and establishing an encrypted communication link; industrial equipment collects original data and then transmits the original data to an edge gateway which the industrial equipment belongs to, and the gateway extracts data features and divides the data features into a core control level, a process parameter level, a common monitoring level and a security level; differential encryption strategies are adopted for different levels of data; each edge gateway uploads the encrypted data to a distributed key management node, and obtains and synchronizes a periodically updated key chain; during cross-region transmission, performing secondary packaging and encryption to generate a data packet containing identifications such as a security level and the like; and the receiving end verifies the legality of the node, decrypts and verifies the integrity of the data, distributes the data if the decryption is passed, and blocks the alarm if the decryption The method is suitable for scenes such as single-area monitoring and multi-area manufacturing, data security and transmission efficiency balance are achieved, and all-weather stable transmission is guaranteed.
Owner:HEFEI UNIV OF ECONOMICS

Data encryption method, encryption equipment and storage medium

The invention relates to the technical field of data encryption, and discloses a data encryption method, encryption equipment and a storage medium. In the method, an encryption device obtains to-be-encrypted data uploaded by a terminal, and extracts a plurality of data features from the to-be-encrypted data, the data features including a data sensitive feature, a business risk feature and a user behavior feature; performing quantitative scoring on the plurality of data features to obtain a plurality of feature scores, and calculating a total data score according to the plurality of feature scores; inputting the total data score into a preset trained decision tree model to determine the security level of the to-be-encrypted data; according to the security level, determining a target encryption algorithm from a preset corresponding relationship between the security level and the encryption algorithm; and encrypting the to-be-encrypted data according to the target encryption algorithm and the dynamically generated encryption key. By means of the method, the problems that differential protection is difficult to achieve according to data characteristics in a related encryption method, and security risks are caused by key management staticization are solved.
Owner:SHANGHAI TELECOMM ENG

Data auditing and approving method and device

The invention relates to the technical field of data security, and particularly provides a data auditing and approving method and device, which is applied to a scene that multi-role collaborative decryption is required for multi-level approval, and comprises the following steps: S1, data fragmentation and hybrid encryption; s2, performing dynamic key management; s3, attribute base access control; and S4, block chain evidence storage and auditing. Compared with the prior art, dynamic key generation, hierarchical encryption storage, fine-grained permission control and real-time permission revocation can be realized through a credible key management mechanism, and data whole-process security processing under data privatization data auditing is met.
Owner:SHANDONG INSPUR CLOUD GOVERNMENT INFORMATION TECHNOLOGY CO LTD

Stable transmission method for server data encryption and rapid authentication

The invention discloses a stable transmission method for server data encryption and rapid authentication, and belongs to the technical field of data security. The method comprises the following steps: dividing data into three levels of core sensitive data, important data and common data by utilizing a semantic analysis model; performing encryption protection on different levels of data by adopting a hierarchical encryption strategy; a master key is generated based on a chaotic system, a session key is generated in combination with a timestamp and a device fingerprint and is regularly alternated, and secure distribution is performed through a trusted execution environment and a block chain; multi-modal features are fused, the identity is verified through zero-knowledge proof, and the authentication strength is adjusted through dynamic risk assessment. The method is suitable for cloud computing, the Internet of Things and a distributed storage system, through deep fusion of a multi-level hybrid encryption algorithm, a dynamic key management mechanism and a self-adaptive authentication strategy, data security encryption, rapid authentication and stable transmission are achieved, and security, efficiency and adaptability are improved.
Owner:SHANGHAI GUIHENG TECHNOLOGY CO LTD

Privacy protection method, system and device for block chain network node auditing management

The invention discloses a privacy protection method, system and device for block chain network node audit management, and the method specifically comprises the steps: generating a node anonymous voucher for a candidate node, carrying out the privacy authentication, mapping the sensitive information of the authenticated candidate node into an irreversible cryptographic hash value, and storing the irreversible cryptographic hash value in a distributed key management node; constructing a dynamic credible auditing group, selecting verification nodes from the candidate nodes, and performing uplink evidence storage after BLS aggregation signature; performing privacy aggregation calculation on the node behavior data of the verification node to generate an audit score ciphertext; fine-grained access control is realized through attribute-based encryption, and a node reputation level is dynamically bound through an auditing strategy; adaptive noise is added to an audit result by adopting a differential privacy mechanism, and the epsilon-differential privacy constraint condition is met by dynamically adjusting the noise amount; in the reward and punishment execution stage, a ring signature and a stealth address technology are combined, so that reward and punishment records are unhooked from real identities of nodes, and meanwhile, the trade traceability is ensured.
Owner:HANGZHOU YUNXIANG NETWORK TECH

Method and system for encrypting and isolating storage data of credential mobile terminal

The invention relates to a method and system for encrypting and isolating storage data of a credential mobile terminal, and belongs to the technical field of information. The method comprises the following steps: encrypting and partitioning the whole storage area, and setting an access strategy according to user permission; when a user requests to access, executing multi-factor authentication containing a password and an external hardware certificate, and adding biological characteristic authentication; after the authentication is passed, an encryption key is taken from the domestic security chip; and encrypting and decrypting data by using the secret key, and opening corresponding partition access according to authority. The system comprises a storage partition module, an identity authentication module, a key management module, an encryption and decryption module and an authority control module and is used for executing the method. The method also comprises the steps of equipment startup trusted boot and firmware upgrade verification, is based on a custom curing system, and is compatible with Android 10 +. The problems of poor hardware controllability and positioning security risk of the creative mobile terminal are solved, and full-link data security protection is realized.
Owner:JINAN UNIV IND TECH RES INST CO LTD +1

Large model service security verification method and device, medium, equipment and product

A security verification method, apparatus, medium, device and product for a large model service relate to the technical field of computers, receive an encryption service request, acquire a private key of a client from a key management service running in a trusted execution environment through an encryption and decryption service running in the trusted execution environment, decrypt the encryption service request based on the private key, and verify the security of the encryption service request. The method comprises the following steps: decrypting a service request of a user, sending the decrypted service request to a large model service to obtain a reasoning result of the large model service, encrypting the reasoning result through a public key of a client, and returning the encrypted reasoning result to the client, so that the service request of the user can be visible in a plaintext in a trusted execution environment; the security of the user data is greatly ensured, and the problem of user data leakage can be avoided through the public and private key pair of the user dimension. In addition, the key management service and the encryption and decryption service both run in the trusted execution environment, so that attacks from an IaaS layer can be shielded.
Owner:BEIJING VOLCANO ENGINE TECH CO LTD

Methods and systems for identifying AUSF and accessing related keys in 5G prose

Methods and systems for identifying AUSF and accessing related keys in 5G ProSe. The AUSF corresponding to a remote UE is identified by an AMF based on routing indicator or SKI. The AUSF is capable of key management of ProSe UE-to-Network relay communication. The AUSF authorizes the remote UE to access a 5G core network through one or more UE-to-network relays. The authorization of the remote UE is performed based on a SUPI corresponding to the remote UE. The SUPI is obtained from a UDM. Once the remote UE is authorized, the AUSF can derive keys that enable the remote UE to access the 5G core network through the one or more UE-to-network relays. The keys derived by the AUSF 803 can be referred to as authentication keys. The derived keys include REAR key, KNR_ProSe, KD, and KNRP.
Owner:SAMSUNG ELECTRONICS CO LTD

Internet of Things secure access method based on cloud edge collaboration

The invention discloses an Internet of Things secure access method based on cloud edge collaboration, which comprises the following steps: firstly, an Internet of Things device and an edge server respectively register in a CSC (Content Service Controller), and obtain an intelligent card or related data to complete information updating and storage; the equipment is inserted into an intelligent card to log in, and data are sent to the edge server after identity password verification; the edge server verifies the timestamp and then forwards the data to the CSC; the CSC verifies the timestamp and the identity, generates a session key parameter and sends the session key parameter to the edge server; the edge server verifies the identity of the CSC and then generates session key encrypted data to be transmitted back, and after the verification of the device is passed, secure communication is established. According to the method, mutual verification and encryption protection are adopted in identity verification; a timestamp, a random value and strict verification are used for message transmission to prevent replay and man-in-the-middle attack; secret key management guarantees safety through dynamic change of secret values, attacks such as physical capture are resisted in combination with PUF, and communication safety is comprehensively guaranteed.
Owner:SICHUAN BAICHENG INFORMATION TECHNOLOGY CO LTD

Distributed photovoltaic data acquisition method and device based on adaptive encryption communication and multi-link redundancy

The invention provides a distributed photovoltaic data acquisition method and device based on adaptive encryption communication and multi-link redundancy, and the method comprises the steps: collecting real-time power generation data, equipment state data and environment parameters of a photovoltaic system through a multi-source sensor, and forming original data; an MQTT over TLS adaptive encryption communication protocol is adopted to perform end-to-end encryption on original data, and dynamic key management is combined to ensure transmission security; based on a dynamic link selection algorithm, encrypted data is transmitted to a power master station through 4G and LoRaWAN double-link redundancy, so that the transmission reliability is improved; and the master station side decrypts the data and then integrates the data to a database to support power grid dispatching and predictive analysis. According to the invention, the problems of safety and reliability in distributed photovoltaic data acquisition are solved, and the method is suitable for a smart power grid monitoring scene with high reliability and high real-time performance requirements.
Owner:HUBEI CENT CHINA TECH DEV OF ELECTRIC POWER

Communication method and device, storage medium and computer program product

The invention provides a communication method and device, a storage medium and a computer program product, relates to the technical field of communication, and is used for improving the reliability of AKMA service. The method comprises the steps that under the condition that parameters of a terminal are updated, a UDM network element obtains authentication and key management AKMA service data of an application and a parameter updating reason of the terminal; and under the condition that the AKMA service data indicates that the terminal subscribes to the AKMA service and the parameter updating reason of the terminal is route identifier updating, initial registration request information of the terminal is sent to an access and mobility management function AMF network element, and the initial registration request information is used for requesting the terminal to execute initial registration.
Owner:ZTE CORP

Security coprocessor hybrid encryption method and system based on SM2 / 3 / 4 domestic cryptographic algorithm

According to the safety coprocessor hybrid encryption method based on the SM2 / 3 / 4 domestic cryptographic algorithm, a novel hybrid encryption system based on the SM2 / 3 / 4 and considering encryption safety, efficiency and key management convenience is constructed on the basis of the characteristics of the SM2 algorithm, the SM3 algorithm and the SM4 algorithm, and the encryption / decryption and signature / verification process is achieved. And aiming at the efficiency problem of a domestic SM algorithm, an encryption / decryption and signature / verification scheme is designed and realized through pure software analysis and software and hardware (SW / HW) collaboration, so that optimal division of software and hardware is realized, and the algorithm efficiency is greatly improved.
Owner:ANHUI NORMAL UNIV

Mobile solid state disk data encryption storage method based on trusted computing module

The invention relates to the technical field of data security, in particular to a mobile solid state disk data encryption storage method based on a trusted computing module. According to the method, integrity measurement is carried out on an operating environment through a trusted computing module, and a trusted measurement value is generated; generating a session-level encryption key based on the trusted magnitude; encrypting data using the key and storing key metadata; during data reading, correlation verification is carried out to determine whether decryption is authorized or not; and baseline adjustment can be triggered according to the measurement deviation. According to the invention, the data security of the mobile storage device is improved, and an environment-aware dynamic key management mechanism is realized.
Owner:BEIJING XINXUN XINAN TECH CO LTD

Secure node exchange attribute-based keys (SNEAK)

The arrangements disclosed herein relate to systems, apparatus, methods, and non-transitory computer readable media for Secure Node Exchange Attribute-based Keys (SNEAK) including secure exchange of sensitive message elements between sequential message nodes using attribute-based key management. Each message node can access none, one, some, or all encrypted message elements based on assigned attributes of that message node. A key management node provides key exchange for each Content Encryption Key (CEK) used to protect the message elements based on attributes of the message nodes.
Owner:WELLS FARGO BANK NA

Method and system for managing a computing infrastructure

A computer-implemented method for managing a computing infrastructure with at least one self-encrypting disk connected to a customer network, involves accessing instructions that orchestrate compute resources and include modules for server management, key management, file transfer, and IPMI. The server management module receives requests from the orchestrator to start nodes and reconfigure hosts, boots hosts over provisioning networks, downloads images, and unlocks self-encrypting disks using passwords stored in the key management system. The method also includes soft rebooting hosts and removing their configuration to switch them back to customer networks.
Owner:OVH

Data transmission methods, devices, computer equipment and communication systems

This application discloses a data transmission method, apparatus, computer device, and communication system, relating to the field of communications. The method includes: generating an authentication key based on security credentials distributed by an authentication center; authenticating devices with an authentication code generated from the authentication key; and transmitting encrypted data processed by an encryption key. Thus, authentication is based on the generated authentication key, eliminating the need for devices to transmit the authentication key itself, preventing its acquisition, improving authentication key security, and reducing network attacks. The authentication center does not need to manage authentication keys and security credentials, decentralizing the authentication mechanism and reducing the complexity of key management. Furthermore, the authentication key has a small data size, meeting the storage requirements of resource-constrained IoT devices, thereby achieving secure authentication for resource-constrained IoT devices, reducing network attacks on the IoT, and improving IoT network security.
Owner:HUAWEI TECH CO LTD

Private key management method and device and computer equipment

The invention discloses a private key management method and apparatus, and a computer device. The private key management method comprises the steps of obtaining instance binding information sent by a virtualization platform; verifying the instance binding information according to a preset key strategy, and generating a token when the verification is passed; splitting the logic private key based on the birth token to generate a first private key share and a derived parameter used for deriving a second private key share, and performing encryption packaging on the derived parameter by taking the instance binding information as additional authentication data to form a key capsule containing the instance binding information; returning the key capsule to the corresponding instance, so that the instance unpacks the key capsule in the own operating environment and derives a second private key share; and when a signature request sent by the instance based on the second private key share is received, cooperatively generating a signature result based on the first private key share and the second private key share. The security and controllability of private key management can be effectively improved on the premise of not depending on a special hardware module.
Owner:ASPIRE TECH (SHENZHEN) LTD

Cluster self-discovery method suitable for cloud server cipher machine

The invention relates to the technical field of information security, in particular to a cluster self-discovery method suitable for a cloud server cipher machine, which comprises the following steps: when physical equipment of the cloud server cipher machine leaves a factory, a certificate management module generates an equipment certificate and a root CA certificate in combination with an enterprise CA system, and stores the equipment certificate and the root CA certificate; after the virtual cipher machine is created and started, the key management service module combines with the certificate management module to generate a virtual machine certificate, and stores the virtual machine certificate, the storage device certificate and the root CA certificate together; the cluster management service module enables the master node of the virtual cipher machine to discover the slave node of the virtual cipher machine in the same network domain through UDP broadcast, and executes three-level verification on the slave node of the virtual cipher machine from three aspects of an equipment certificate, a virtual machine certificate and an authentication signature; and the virtual cipher machine master node synchronizes the cluster master key to the virtual cipher machine slave node passing verification. According to the invention, hierarchical identity isolation and verification of the cloud server cipher machine host and the virtual cipher machine can be realized, and the security of cluster self-discovery and authentication stages is ensured.
Owner:山东三未信安信息科技有限公司

Domestic cloud platform security optimization method based on trusted execution environment

The invention discloses a localized cloud platform security optimization method based on a trusted execution environment, which is suitable for a multi-tenant computing and key business data security protection scene of a localized cloud platform. Comprising the following steps of executing security startup and measurement verification on a domestic chip, constructing a hardware root trust chain, loading a trusted execution environment, performing sensitivity evaluation and grading on tenant tasks, and dynamically scheduling the tasks related to privacy or key data to a TEE (Trusted Execution Environment) for execution; and performing task data encryption and decryption and dynamic key management, and performing multi-level permission verification on the access request. According to the method, hardware-level security isolation and data protection during operation of the localized cloud platform in a multi-tenant operation environment are realized, and the credibility and protection capability of the platform in the links of task scheduling, encryption calculation and remote verification are remarkably improved.
Owner:STATE GRID LIAONING ELECTRIC POWER CO LTD

Anti-quantum key management method for vehicle-mounted domain centralized electronic and electrical architecture

The invention discloses an anti-quantum key management method for a vehicle-mounted domain centralized electronic and electrical architecture. Firstly, the invention provides a self-adaptive security policy generation method based on an analytic hierarchy process. Key factors influencing vehicle-mounted service safety are sorted through a system, a three-layer AHP hierarchical structure model with the purpose of selecting an optimal encryption mechanism is constructed, and therefore vehicle-mounted service safety modeling is achieved. According to the method, the most suitable security policy can be automatically matched according to the characteristics of different services, the self-adaptive security policy generation of the service granularity is realized, and the optimization of the system resource use efficiency is realized while the communication security is ensured. Secondly, the invention provides a fine-grained anti-quantum key management scheme based on the Chinese remainder theorem, and the fine-grained anti-quantum key management scheme is specially designed for adapting to a one-to-many communication scene widely existing in a vehicle-mounted network. The method supports efficient distribution and dynamic updating of group keys of service granularity, and has good quantum attack resistance.
Owner:XIDIAN UNIV +2

Supply chain data protection method fusing block chain and attribute-based proxy re-encryption

The invention discloses a supply chain data protection method fusing a block chain and attribute-based proxy re-encryption, and the method comprises the steps: building an industry-based attribute through credible initialization, and achieving the parameter distribution through a block chain smart contract; dynamic key management is adopted to generate an attribute binding key for each participant, and automatic revocation and update are supported; an access strategy is accessed through conditional proxy re-encryption, and it is ensured that data only decrypts a requester meeting service conditions; a hierarchical encryption storage mechanism is designed, key data are stored on a chain, and large-capacity production logs are efficiently processed outside the chain through IPFS; and meanwhile, a compliance penetration interface is provided for a supervision mechanism, and legal data access under an emergency event is supported. It is ensured that the parameter generation process meets the verifiability requirement of a trusted computing platform, compliance verification and security isolation of data access are achieved, and attribute-level dynamic authorization and cross-enterprise security sharing of supply chain data are ensured.
Owner:JIANGXI UNIV OF SCI & TECH

Techniques for a key management service in an overlay network

Techniques are disclosed for implementing a key management service in a reduced footprint data center. A cryptographic service can execute at a computing device of the reduced footprint data center. The cryptographic service can generate a master encryption key and encrypt the master encryption key using a secure component of the computing device to produce an encrypted master encryption key. The encrypted master encryption key can be stored in a block storage volume communicatively connected to the computing device. The cryptographic service can transmit the master encryption key to a host region data center and receive a wrapped master encryption key. The cryptographic service can store the wrapped master encryption key in a database of the reduced footprint data center.
Owner:ORACLE INT CORP

Block chain data security storage method based on verifiable secret sharing

The invention discloses a blockchain data security storage method based on verifiable secret sharing. The method comprises the following steps executed by computer hardware: receiving to-be-stored data, performing encryption processing on the to-be-stored data to obtain a ciphertext, storing the ciphertext to a distributed file system, obtaining a storage address, and calculating a hash value of the ciphertext; dividing the encryption key into a plurality of sub-key fragments according to set parameters, and calculating a hash value of each sub-key fragment; packaging the sub-key fragment, the sub-key fragment hash value and the ciphertext hash value into a transaction unit, and writing the transaction unit into the block chain; receiving a decryption request, and reconstructing an encryption key when the number of submitted effective sub-key fragments reaches a threshold value; and acquiring the ciphertext from the distributed file system, verifying the hash value of the ciphertext, and decrypting by using the reconstructed encryption key to obtain the plaintext. According to the invention, the security management and control of the full life cycle of the data are realized, the integrity, confidentiality and authenticability of the data and the secret key are ensured, and the security of the data in the processes of storage, transmission, secret key management and the like is ensured.
Owner:GUIZHOU UNIV

Solid state disk data encryption method and solid state disk

The invention relates to the technical field of electric digital data processing security, and discloses a solid state disk data encryption method and a solid state disk. According to the method, a national cryptographic algorithm hardware encryption and decryption co-processing module is serially arranged on a data bus between a main control chip and a flash memory particle array, so that transparent encryption of write-in data and transparent decryption of read-out data are realized; the module performs encryption and decryption based on an SM4 algorithm and an XTS advanced encryption standard mode in combination with a logic address as an adjustment value, and securely injects a root key through an out-of-band interface to derive a data key. The system comprises a main control chip, a flash memory array and the co-processing module, wherein the co-processing module is integrated with a hardware encryption and decryption engine, a key management unit and data flow control logic. On the premise that a general main control chip is not changed, high-performance, high-compatibility and high-security national cryptographic hardware-level full-disk encryption is realized.
Owner:深圳市彦胜科技有限公司

API invoker authentication method and apparatus, communication device, and storage medium

A method for authenticating an application program interface (API) invoker enhances secure communication between API invokers and a Common Application Program Interface Framework (CAPIF). The method involves sending authentication information from the API invoker to the CAPIF function, which authenticates the invoker's identity. The process includes obtaining enrollment information to establish a secure transport layer security (TLS) connection with the CAPIF function. Advanced authentication mechanisms leverage an authentication and key management for applications (AKMA) anchor key, enabling secure derivation and verification of application function keys (KAF). Additionally, the CAPIF function uses received authentication data to retrieve API invoker configuration information, onboard signing keys, and certificates. These elements facilitate secure API access and interaction while ensuring compliance with authentication protocols.
Owner:BEIJING XIAOMI MOBILE SOFTWARE CO LTD