Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

871 results about "Key management" patented technology

Key management refers to management of cryptographic keys in a cryptosystem. This includes dealing with the generation, exchange, storage, use, crypto-shredding (destruction) and replacement of keys. It includes cryptographic protocol design, key servers, user procedures, and other relevant protocols.

Method and system for encrypting and isolating storage data of credential mobile terminal

The invention relates to a method and system for encrypting and isolating storage data of a credential mobile terminal, and belongs to the technical field of information. The method comprises the following steps: encrypting and partitioning the whole storage area, and setting an access strategy according to user permission; when a user requests to access, executing multi-factor authentication containing a password and an external hardware certificate, and adding biological characteristic authentication; after the authentication is passed, an encryption key is taken from the domestic security chip; and encrypting and decrypting data by using the secret key, and opening corresponding partition access according to authority. The system comprises a storage partition module, an identity authentication module, a key management module, an encryption and decryption module and an authority control module and is used for executing the method. The method also comprises the steps of equipment startup trusted boot and firmware upgrade verification, is based on a custom curing system, and is compatible with Android 10 +. The problems of poor hardware controllability and positioning security risk of the creative mobile terminal are solved, and full-link data security protection is realized.
Owner:JINAN UNIV IND TECH RES INST CO LTD +1

Large model service security verification method and device, medium, equipment and product

A security verification method, apparatus, medium, device and product for a large model service relate to the technical field of computers, receive an encryption service request, acquire a private key of a client from a key management service running in a trusted execution environment through an encryption and decryption service running in the trusted execution environment, decrypt the encryption service request based on the private key, and verify the security of the encryption service request. The method comprises the following steps: decrypting a service request of a user, sending the decrypted service request to a large model service to obtain a reasoning result of the large model service, encrypting the reasoning result through a public key of a client, and returning the encrypted reasoning result to the client, so that the service request of the user can be visible in a plaintext in a trusted execution environment; the security of the user data is greatly ensured, and the problem of user data leakage can be avoided through the public and private key pair of the user dimension. In addition, the key management service and the encryption and decryption service both run in the trusted execution environment, so that attacks from an IaaS layer can be shielded.
Owner:BEIJING VOLCANO ENGINE TECH CO LTD

Mobile solid state disk data encryption storage method based on trusted computing module

The invention relates to the technical field of data security, in particular to a mobile solid state disk data encryption storage method based on a trusted computing module. According to the method, integrity measurement is carried out on an operating environment through a trusted computing module, and a trusted measurement value is generated; generating a session-level encryption key based on the trusted magnitude; encrypting data using the key and storing key metadata; during data reading, correlation verification is carried out to determine whether decryption is authorized or not; and baseline adjustment can be triggered according to the measurement deviation. According to the invention, the data security of the mobile storage device is improved, and an environment-aware dynamic key management mechanism is realized.
Owner:BEIJING XINXUN XINAN TECH CO LTD

Data transmission methods, devices, computer equipment and communication systems

This application discloses a data transmission method, apparatus, computer device, and communication system, relating to the field of communications. The method includes: generating an authentication key based on security credentials distributed by an authentication center; authenticating devices with an authentication code generated from the authentication key; and transmitting encrypted data processed by an encryption key. Thus, authentication is based on the generated authentication key, eliminating the need for devices to transmit the authentication key itself, preventing its acquisition, improving authentication key security, and reducing network attacks. The authentication center does not need to manage authentication keys and security credentials, decentralizing the authentication mechanism and reducing the complexity of key management. Furthermore, the authentication key has a small data size, meeting the storage requirements of resource-constrained IoT devices, thereby achieving secure authentication for resource-constrained IoT devices, reducing network attacks on the IoT, and improving IoT network security.
Owner:HUAWEI TECH CO LTD

Cluster self-discovery method suitable for cloud server cipher machine

The invention relates to the technical field of information security, in particular to a cluster self-discovery method suitable for a cloud server cipher machine, which comprises the following steps: when physical equipment of the cloud server cipher machine leaves a factory, a certificate management module generates an equipment certificate and a root CA certificate in combination with an enterprise CA system, and stores the equipment certificate and the root CA certificate; after the virtual cipher machine is created and started, the key management service module combines with the certificate management module to generate a virtual machine certificate, and stores the virtual machine certificate, the storage device certificate and the root CA certificate together; the cluster management service module enables the master node of the virtual cipher machine to discover the slave node of the virtual cipher machine in the same network domain through UDP broadcast, and executes three-level verification on the slave node of the virtual cipher machine from three aspects of an equipment certificate, a virtual machine certificate and an authentication signature; and the virtual cipher machine master node synchronizes the cluster master key to the virtual cipher machine slave node passing verification. According to the invention, hierarchical identity isolation and verification of the cloud server cipher machine host and the virtual cipher machine can be realized, and the security of cluster self-discovery and authentication stages is ensured.
Owner:山东三未信安信息科技有限公司

Domestic cloud platform security optimization method based on trusted execution environment

The invention discloses a localized cloud platform security optimization method based on a trusted execution environment, which is suitable for a multi-tenant computing and key business data security protection scene of a localized cloud platform. Comprising the following steps of executing security startup and measurement verification on a domestic chip, constructing a hardware root trust chain, loading a trusted execution environment, performing sensitivity evaluation and grading on tenant tasks, and dynamically scheduling the tasks related to privacy or key data to a TEE (Trusted Execution Environment) for execution; and performing task data encryption and decryption and dynamic key management, and performing multi-level permission verification on the access request. According to the method, hardware-level security isolation and data protection during operation of the localized cloud platform in a multi-tenant operation environment are realized, and the credibility and protection capability of the platform in the links of task scheduling, encryption calculation and remote verification are remarkably improved.
Owner:STATE GRID LIAONING ELECTRIC POWER CO LTD

Solid state disk data encryption method and solid state disk

The invention relates to the technical field of electric digital data processing security, and discloses a solid state disk data encryption method and a solid state disk. According to the method, a national cryptographic algorithm hardware encryption and decryption co-processing module is serially arranged on a data bus between a main control chip and a flash memory particle array, so that transparent encryption of write-in data and transparent decryption of read-out data are realized; the module performs encryption and decryption based on an SM4 algorithm and an XTS advanced encryption standard mode in combination with a logic address as an adjustment value, and securely injects a root key through an out-of-band interface to derive a data key. The system comprises a main control chip, a flash memory array and the co-processing module, wherein the co-processing module is integrated with a hardware encryption and decryption engine, a key management unit and data flow control logic. On the premise that a general main control chip is not changed, high-performance, high-compatibility and high-security national cryptographic hardware-level full-disk encryption is realized.
Owner:深圳市彦胜科技有限公司

API invoker authentication method and apparatus, communication device, and storage medium

A method for authenticating an application program interface (API) invoker enhances secure communication between API invokers and a Common Application Program Interface Framework (CAPIF). The method involves sending authentication information from the API invoker to the CAPIF function, which authenticates the invoker's identity. The process includes obtaining enrollment information to establish a secure transport layer security (TLS) connection with the CAPIF function. Advanced authentication mechanisms leverage an authentication and key management for applications (AKMA) anchor key, enabling secure derivation and verification of application function keys (KAF). Additionally, the CAPIF function uses received authentication data to retrieve API invoker configuration information, onboard signing keys, and certificates. These elements facilitate secure API access and interaction while ensuring compliance with authentication protocols.
Owner:BEIJING XIAOMI MOBILE SOFTWARE CO LTD

Secure key injection method and system

The invention discloses a secure key injection method and system, which are applied to electronic equipment with a rich execution environment and a secure virtual machine environment, and the method comprises the following steps: receiving a key injection request in the rich execution environment, and loading and starting the secure virtual machine environment; forwarding the key injection request to a secure virtual machine environment; generating a key pair in the secure virtual machine environment, and sending a public key certificate and an identity certificate of the key pair to a key management background through a rich execution environment; the key management background returns response data after verification is passed, and the response data is forwarded to the secure virtual machine environment through the rich execution environment; verifying the response data in the secure virtual machine environment; and after the verification is passed, storing the to-be-injected key material in the response data in the secure virtual machine environment. According to the invention, end-to-end security protection of the key material is realized through dual-environment cooperation, and the anti-attack capability and the data confidentiality of the injection process are effectively improved.
Owner:FUJIAN WISBO DIGITAL TECHNOLOGY CO LTD

Identity authentication method and system based on national secret algorithm

The invention discloses an identity authentication method and system based on a national secret algorithm, and the method comprises the steps: building a hierarchical key management system based on a national secret IBE framework, generating a system master key pair through employing an SM2 algorithm, and achieving a decentralized key distribution mechanism; constructing a domain perception differential privacy protection module, defining a privacy budget allocation strategy according to the security level, and adding calibrated Laplace noise to the user identity feature vector; designing a distributed batch matrix multiplication protocol, and decomposing the distributed batch matrix multiplication protocol to a plurality of computing nodes for parallel processing through a secret sharing technology; a zero-knowledge proof verification mechanism is implemented, and identity verification is completed through a commitment scheme based on an SM3 hash algorithm; deploying a self-adaptive key updating strategy, and analyzing threat level change through a threat situation evaluation function; and establishing a secure communication channel based on SM4 symmetric encryption, and performing encryption processing by using the temporary session key. The security and expandability of the system are improved, the privacy of the user is effectively protected, and the system adapts to a dynamically changing network threat environment.
Owner:GUIZHOU BLUESKY INNOVATIVE SCI & TECH CO LTD

Encrypted data storage and key management protection method based on blue-ray disc

The invention provides an encrypted data storage and key management protection method for a blue-ray disc, which relates to the technical field of data storage security and comprises the following steps of: performing multi-frequency data block division by extracting access time sequence characteristics of original data, calculating a multi-dimensional entropy value to determine an encryption algorithm parameter and a key; and extracting physical characteristic signals of the blue-ray disc to obtain sector defect distribution and evaluate reliability, thereby realizing optimal mapping storage of encrypted data and a multi-dimensional reliability sector group. According to the invention, the data storage security is effectively improved, the key management mechanism is optimized, and the physical characteristics of the blue-ray disc are fully utilized to enhance the data protection capability.
Owner:BEIJING XINXUN XINAN TECH CO LTD

Cross-security domain computing power resource federation and privacy protection system

The invention provides a cross-security domain computing power resource federation and privacy protection system. The system comprises a scheduling management node, a communication gateway, a plurality of computing nodes, a verification node and a key management node. The scheduling management node decomposes the calculation general task into a plurality of subtasks and plans different node execution paths; the communication gateway encapsulates the subtask data into an encrypted data packet containing a position identification segment and an encrypted data segment which can be independently decrypted; the computing node is integrated with the trusted execution environment to provide hardware-level security isolation; the summarizing node is used for receiving sub-task results which are processed by the computing nodes and comprise encrypted data segments; the verification node realizes calculation integrity verification; and the key management node confirms a task completion state by collecting the position identification segment, and coordinates and starts a data segment aggregation decryption process. According to the method, the data and code privacy of the computing task is ensured while the computing power island is broken, and a cross-domain computing power resource sharing mechanism with balanced safety and performance is established.
Owner:HANHOU (BEIJING) TECH CO LTD

Quantum encryption method and system based on lightweight end equipment, and medium

The invention discloses a quantum encryption method and system based on a lightweight end device and a medium, and relates to the technical field of quantum encryption, and the method comprises the steps: obtaining the real-time state of a receiving-transmitting end lightweight device, carrying out the self-adaptive analysis, and determining a key generation strategy; starting a quantum key distribution device to generate an initial key, distributing the initial key through an authentication channel, and performing post-processing; classified storage is carried out through a key management server, key identifiers are generated, and a sender requests a quantum key according to the identifiers before sending data; and encrypting data by using the key and a lightweight symmetric encryption algorithm, generating a ciphertext, and sending the ciphertext to a receiving end for decryption. The technical problems of resource limitation and low key generation and distribution efficiency of lightweight end equipment in quantum key distribution and encryption application are solved, the real-time state of the equipment is matched by dynamically adjusting the key generation rate and length through a self-adaptive key generation strategy, the calculation overhead is reduced, and the key generation efficiency is improved. And the encryption efficiency and the resource adaptability are improved.
Owner:ANHUI XINJIE INTELLIGENT TECH CO LTD

Solid state disk controller circuit and solid state disk

The invention relates to the technical field of electric digital data processing, and discloses a solid state disk controller circuit and a solid state disk. The controller circuit comprises a physical unclonable function unit based on an SRAM (Static Random Access Memory), which is used for dynamically generating a stable hardware trust root key during power-on; the secure boot and firmware decryption engine is used for deriving a firmware decryption authentication key and a data key packaging key by using the key, and carrying out decryption and integrity verification on the encrypted firmware; the runtime firmware execution monitoring unit is used for detecting illegal jump in real time and triggering safe shutdown through a hardware-level control flow diagram; and the dynamic data encryption key management unit recovers the plaintext data key and sends the plaintext data key to the encryption engine only during operation, and power failure disappears. By means of the scheme, end-to-end security protection of firmware and data is achieved, and the risks of static key leakage and firmware tampering are eradicated.
Owner:深圳市彦胜科技有限公司

Vehicle information safety protection system based on combination of national secret algorithm and PUF (Physical Unclonable Function)

The invention discloses a vehicle information safety protection system based on combination of a national cryptographic algorithm and a PUF (Physical Unclonable Function), which belongs to the field of vehicle information safety and encrypted communication, and comprises a response generation module used for generating a PUF response in a safety chip of a vehicle; the key derivation module is used for generating an encrypted master key through a key derivation function based on the PUF response, the vehicle owner identity and the random number nonce; the encryption and signature module is used for generating a ciphertext and carrying out digital signature on the ciphertext; the state monitoring module is used for monitoring the running state of the vehicle hardware; the key management module is used for triggering a failure operation of the encrypted master key when the state monitoring module detects that the hardware state is abnormal; and the decryption verification module is used for regenerating the PUF response and verifying the consistency of the generated key so as to execute data decryption. According to the method, hardware-level encryption protection of the vehicle data is realized through combination of the PUF and the national cryptographic algorithm, so that the safety of the vehicle owner data is protected in the whole life cycle of the vehicle.
Owner:HUBEI UNIV

Safe acquisition method and device of BMC information, equipment and medium

The invention relates to the technical field of BMC security, and provides a security acquisition method and device of BMC information, equipment and a medium, and the method comprises the steps: generating a one-time public key and a one-time private key for a single communication session according to a self MAC address and real-time time; performing hash operation on the one-time public key to obtain a one-time public key hash value; sending the one-time public key hash value to a key management server, so that the key management server signs the one-time public key hash value by using a preset private key, and receiving a returned signature result; packaging the one-time public key and the signature result into a request message, and broadcasting the request message to a local area network to enable the BMC to generate and return an encrypted response message after signature verification; and monitoring and receiving an encrypted response message returned by the BMC, decrypting the encrypted response message by using the one-time private key, and extracting and displaying BMC information. According to the technical scheme, confidentiality, safety and integrity of the response information in the transmission process are guaranteed.
Owner:NINGCHANG INFORMATION TECH (HANGZHOU) CO LTD

Intelligent communication device and communication method based on tunnel encryption

The invention discloses intelligent communication equipment and a communication method based on tunnel encryption, and relates to the field of communication technology and information security. According to the method, the tunnel encryption technology is adapted and optimized through hardware performance and network environment detection of intelligent communication equipment; managing a session key based on multi-factor identity authentication and a distributed key; encrypting transmission data, packaging the encrypted transmission data into an encryption tunnel for transmission, and synchronously carrying out integrity verification; monitoring network flow in real time, identifying abnormal behaviors through a machine learning model, and triggering safety early warning; encryption parameters are dynamically adjusted to balance security and device performance. The corresponding intelligent communication equipment comprises a hardware unit and a software unit. According to the method, the problems that traditional tunnel encryption is poor in adaptability on intelligent equipment, high in key management risk and difficult to balance performance and safety are solved, safe, efficient and self-adaptive intelligent communication is achieved, and the method is suitable for encryption communication scenes of various intelligent terminals.
Owner:CHINA ERACOM CONTRACTING & ENG

Smart power grid data privacy protection system and method based on homomorphic encryption technology

The invention relates to the technical field of power grid data privacy protection, in particular to a smart power grid data privacy protection system and method based on a homomorphic encryption technology. The system protects data privacy of an intelligent power grid based on a homomorphic encryption technology, and comprises eight modules: a data acquisition module is connected with an intelligent electric meter in a multi-protocol manner in a 15-minute period to adopt electric data; the data filtering and preprocessing module optimizes data quality; the homomorphic encryption module generates a ciphertext capable of being added and multiplied by using an FHE algorithm; the multi-level key management module manages multiple types of keys in the whole life cycle; the secure transmission module transmits the ciphertext by means of a hybrid protocol; the data analysis module decrypts and analyzes the ciphertext in the data center; the decryption module decrypts after authorization; and the auditing and monitoring module records operation and monitors abnormity. According to the invention, it is ensured that the power use data is kept in an encrypted state in the whole life cycle of collection, transmission and analysis, the data is available and invisible, and the data privacy protection level and quantum attack resistance of the smart grid are improved.
Owner:INFORMATION & COMM COMPANY OF QINGHAI ELECTRIC POWER

Wireless network security management method and system

The invention discloses a wireless network security management method and system. In the method, a system initialization module completes initialization, calls a key management module to generate signatures of a platform end and wireless equipment and encrypts asymmetric key pairs, and a wireless equipment management module records basic information of storage equipment. Before wireless equipment accesses, an authentication request containing first encryption information and first signature information is initiated through a request gateway module, after a platform end decrypts and verifies the signature to complete equipment authentication, second encryption information and second signature information are returned, and an equipment end decrypts and verifies the signature to complete bidirectional authentication. And network access is allowed in combination with the white list and the equipment registration state, and an administrator completes identity authentication and authority verification through the user authority management module and the request gateway module. After the equipment accesses the network, heartbeat communication and bidirectional authentication are carried out at regular intervals, equipment communication is controlled through a network communication strategy, and operation monitoring, situation analysis and log auditing are synchronously carried out. According to the invention, the problems of high access and operation and maintenance management security risk and the like in the prior art are solved.
Owner:JIANGSU NEW QUALITY INFORMATION TECH CO LTD +1

Quantum key management method and system for satellite internet biological characteristics

The invention relates to a quantum key management method and system for satellite internet biological characteristics, and the method comprises the following steps: carrying out the registration of biological characteristics and the initialization of communication protocol parameters for a user terminal which is accessed for the first time; for the registered user terminal, before initiating communication each time, binding the real-time biological characteristics with the quantum key, and carrying out encrypted transmission of the session key by using the bound quantum key, so as to carry out encrypted transmission of satellite internet transmission data by using the session key; and in the encryption transmission process of the satellite internet transmission data, according to a preset period, performing satellite link security level adjustment and quantum key dynamic updating. According to the invention, identity authentication and terminal authentication in a high-delay and narrow-bandwidth application scene can be realized, the security problems of identity counterfeiting, key leakage and the like are solved, and the method can be applied to satellite internet scenes such as emergency communication, field operation and the like, and has the advantages of strong compatibility, low deployment cost and the like.
Owner:SPACE STAR TECH CO LTD

Secure data transmission system based on dynamic encryption authentication

According to the secure data transmission system based on dynamic encryption authentication provided by the invention, a trust root which cannot be tampered is established for the whole system through the hardware password module, and continuous derivation and rotation of a session key are realized by the dynamic key management module on the basis, so that the security risk caused by long-term use of a static key is effectively solved. And the secure communication gateway module executes bidirectional authentication and anti-hijacking challenge response by using a dynamic key, so that the real-time credibility and session continuity of the communication process are ensured. And the strategy control engine uniformly coordinates the behaviors of key management and the communication gateway by receiving and compiling the declarative strategy, so that flexible deployment and centralized management and control of the security strategy are realized. According to the system, a cryptographic basis, a dynamic strategy, real-time monitoring and automatic response are deeply fused, a self-adaptive and automatic deep defense system with the capability of continuously resisting advanced threats is constructed, and the overall safety level and the operation efficiency of data transmission are remarkably improved.
Owner:HUANENG INFORMATION TECH CO LTD

Unified key management method and device for distributed cryptographic service component

PendingCN121770743AKey distribution for secure communicationDistributed key generationSecure communication
The invention discloses a unified key management method and device for a distributed password service component, and aims to solve the problems of single-point failure, consistency deficiency and insufficient life cycle management and control of existing key management. According to the method, based on a distributed key generation protocol, Shamir secret sharing, PBFT consensus and Lagrange interpolation, key generation, distributed storage, safe distribution and dynamic rotation whole-process management and control are achieved. The device is composed of n nodes including a processor, a memory and a communication and key processing module, and supports encrypted storage, secure communication and consensus collaboration. Security is guaranteed through a threshold mechanism, hash verification and a hash chain technology, availability is improved through SDN optimization and failover, and nodes and parameters can be flexibly adapted and expanded. The method is applied to scenes such as a power grid, gives consideration to safety, availability and compliance, and is suitable for unified key management of distributed system password services.
Owner:GUANGXI POWER GRID CORP

Unified key management

Methods, systems, and devices for data management are described. A data management system (DMS) may create a first key family including a first key to encrypt and decrypt first data encryption keys associated with first data management jobs. The DMS may create a second key family after encrypting the first data encryption keys using the first key. A first key of the second key family may be used to encrypt and decrypt second data encryption keys that are associated with second data management jobs. The DMS may create a second key of both the first and second key families. The second key of the first key family may be used to decrypt the first data encryption keys. The second key of the second key family may be used to encrypt third data encryption keys and to decrypt the second data encryption keys and the third data encryption keys.
Owner:RUBRIK INC

Secure interaction method and system for data space sandbox and data source

The invention discloses a secure interaction method and system for a data space sandbox and a data source, and the method comprises the steps: initializing and authenticating a sandbox environment, and generating a unique environment identifier EnvID; based on the threshold signature scheme, negotiating among the plurality of key management nodes, the sandbox and the data source to generate a session key; the method comprises the following steps: sending a data request to a data source through a sandbox, requesting data added with an environment identifier EnvID based on a sandbox private key signature, after the data source receives the data request and verifies the signature, encrypting outer-layer data based on a session key, encrypting inner-layer data based on an attribute-based encryption algorithm, and generating Merkle root hash of response data; and decrypting outer-layer data based on the session key in a memory through a sandbox, decrypting and processing inner-layer data based on an attribute-based encryption private key, generating a zero-knowledge proof zkProof, and submitting Merkle root hash and the zero-knowledge proof zkProof to a block chain for evidence storage and auditing.
Owner:AISINO CORPORATION

Communication method and apparatus

A communication method, performed by a first communication apparatus or a chip in the first communication apparatus, includes sending a first request to a first discovery key management network element. The first request is used to request a security parameter. The first request includes an identifier of a proximity-based service. The proximity-based service is a proximity-based service provided by a second communication apparatus for the first communication apparatus. The communication method also includes receiving the security parameter and an identifier of the security parameter from the first discovery key management network element. The communication method further includes receiving a discovery message from the second communication apparatus. The discovery message carries the identifier of the proximity-based service and the identifier of the security parameter. The communication method additionally includes processing the discovery message based on the security parameter corresponding to the identifier of the security parameter.
Owner:HUAWEI TECH CO LTD

Semantic communication security enhancement system based on SIM (Subscriber Identity Module) card quantum key presetting

The invention relates to the technical field of mobile communication, and particularly provides a semantic communication security enhancement system based on SIM card quantum key presetting, comprising an SIM card security base module configured to generate physical unclonable function characteristics and preset quantum security keys by using SIM card hardware characteristics; the lightweight authentication protocol module is in communication connection with the SIM card security base module and is configured to realize dynamic identity authentication based on physical unclonable function characteristics and a quantum security key; the semantic security enhancement module is configured to perform privacy protection processing on the semantic communication data; the trusted execution environment optimization module is in communication connection with the SIM card safety base module and the lightweight authentication protocol module and is configured to construct a hardware-software collaborative trusted execution environment; the quantum security enhancement module is integrated on the SIM card security base module and is configured to provide quantum attack resistance and dynamic key management; according to the invention, the real-time performance and anti-quantum computing capability of key distribution are significantly improved.
Owner:CHINA MOBILE INTERNET CO LTD +1

Sensor data acquisition security authentication system based on block chain

The invention relates to the technical field of data security and block chains, and particularly discloses a sensor data acquisition security authentication system based on a block chain. The system comprises a sensor node module, a dynamic key management module, a ciphertext processing engine, a block chain consensus module and an authentication decision module, a key is dynamically generated through a physical unclonable function and environmental noise, and decryption-free integrity authentication of ciphertext data is realized in combination with stream cipher encryption and block chain distributed verification. According to the method, the security and the system throughput in the data acquisition process are improved, and meanwhile, the calculation overhead is reduced.
Owner:SHENZHEN LOLAAGE TECH CO LTD

Vehicle communication data processing method, vehicle and storage medium

The embodiment of the invention provides a vehicle communication data processing method, a vehicle and a storage medium, and the method comprises the steps: obtaining target feature data and real-time state data of a target vehicle, the target feature data being used for representing multi-dimensional physical features associated with the target vehicle, and the real-time state data being used for representing real-time state data of the target vehicle; the real-time state data is used for representing an engine running state and an ignition state of the target vehicle; generating key seed data based on the target feature data and the real-time state data; a vehicle session key is generated according to the key seed data, and the vehicle session key is used for encrypting and decrypting the session data packet; and performing data communication of the target vehicle by using the vehicle session key. According to the method and the device, the technical problems of low security of a fixed key management scheme and great influence of an encryption authentication mechanism on real-time performance in related technologies are solved.
Owner:CHERY AUTOMOBILE CO LTD

Key management method and device based on quantum security chip carrier

The invention relates to a key management method and device based on a quantum security chip carrier, and relates to the technical field of quantum computing, a unique UID is generated through a quantum random number generator in combination with a PUF technology, a mapping relation is established, sub-keys are derived in a layered mode and stored in a partitioned mode, and the key management efficiency is improved. A ternary binding mechanism of a chip unique identity, a quantum random entropy source and a storage environment fingerprint is constructed, through integrity verification, bidirectional identity authentication and a quantum secure transmission channel, key full-life-cycle security control is realized, quantum attacks and security threats are effectively resisted, and the security, credibility, traceability and suitability of key management are improved.
Owner:FANERJIA INTELLIGENT ELECTRIC CO LTD

Security virtual machine sensitive data full life cycle protection method and system and medium

The invention provides a safe virtual machine sensitive data full life cycle protection method and system and a medium, and the method comprises the steps that a collaborative architecture of a safe virtual machine module and a trusted execution environment module is constructed, the safe virtual machine module runs in a common world Android system and comprises a protected virtual machine, and the trusted execution environment module runs in the protected virtual machine; an encryption and decryption demand is triggered through a callback function in the load; and the trusted execution environment module runs in the secure world, and key management and encryption and decryption operations are executed by a trusted application. The two modules are connected through a data interaction module. When the protected virtual machine is closed or dormant, the sensitive data is transmitted to the trusted execution environment module through the client application to be encrypted and then stored in the nonvolatile storage; and when the protected virtual machine is started or awakened, the encrypted data is read, decrypted by the trusted execution environment module and then returned to the protected virtual machine, so that full-flow hardware-level protection of the data from operation to storage is realized. The invention aims to realize the hardware-level security protection of the sensitive data in the full life cycle of the virtual machine.
Owner:KYLIN CORP