Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

48 results about "Key size" patented technology

In cryptography, key size or key length is the number of bits in a key used by a cryptographic algorithm (such as a cipher). Key length defines the upper-bound on an algorithm's security (i.e. a logarithmic measure of the fastest known attack against an algorithm, relative to the key length), since the security of all algorithms can be violated by brute-force attacks. Ideally, key length would coincide with the lower-bound on an algorithm's security. Indeed, most symmetric-key algorithms are designed to have security equal to their key length. However, after design, a new attack might be discovered. For instance, Triple DES was designed to have a 168 bit key, but an attack of complexity 2¹¹² is now known (i.e. Triple DES has 112 bits of security). Nevertheless, as long as the relation between key length and security is sufficient for a particular application, then it doesn't matter if key length and security coincide. This is important for asymmetric-key algorithms, because no such algorithm is known to satisfy this property; elliptic curve cryptography comes the closest with an effective security of roughly half its key length.

A signaling service system and a communication method based on the signaling service system

The embodiment of the application provides a signaling service system and a communication method based on the signaling service system, the method is applied to a first client, a two-way authentication request for a second client is sent to a key management platform, and a session key handle sent by the key management platform after two-way authentication is passed is received, key negotiation is carried out between the key management platform and the second client, and a negotiation key handle and first public key information sent by the key management platform are received; a second key negotiation request is sent to the second client, the second key negotiation request comprises the session key handle, a negotiation key length and the first public key information, a session key sent by the key management platform is received, and communication is carried out with the second client according to the session key. Through the authentication mechanism based on quantum encryption technology, two-way identity authentication and quantum key negotiation are carried out, the security of a signaling channel can be ensured, and the risk of information leakage and malicious attack is reduced.
Owner:CHINA TELECOM QUANTUM TECH CO LTD

Safety method and device based on homomorphic encryption

PendingCN121713437ASecuring communicationKey sizeAlgorithm
The invention provides a security method and device based on homomorphic encryption, and belongs to the technical field of communication, and the method comprises the steps: obtaining a level 2 error learning hypothesis LWE ciphertext; converting the LWE ciphertext into a first ring error learning hypothesis RLWE'ciphertext at a level 1 by executing a public key switching algorithm and a splicing operation; and calculating the first RLWE'ciphertext by executing a scheme switching algorithm to obtain a first RGSW ciphertext at the level 1. It can be seen that one RLWE'ciphertext, such as a first RLWE 'ciphertext, is calculated through a public key switching algorithm, then the first RLWE' ciphertext is expanded into an RGSW ciphertext, such as a first RGSW ciphertext, through a scheme switching algorithm, the key size is smaller, and the overhead is smaller than that of calculation of two RLWE 'ciphertexts, so that the overhead of circuit bootstrap in a hierarchical homomorphic calculation mode can be reduced, and the circuit bootstrap efficiency is improved. The operation efficiency is improved.
Owner:HUAWEI TECH CO LTD +1

Method, apparatus, and computer program for setting encryption key in wireless communication system, and recording medium for same

The present disclosure relates to a method, apparatus, and computer program for setting an encryption key in a wireless communication system; and a recording medium for same. According to one embodiment of the present disclosure, a method for setting an encryption key size in a wireless communication system may comprise: a step in which a first controller of a first device receives a first message containing information on a minimum value of a first encryption key size from a first host of the first device; and a step in which the first controller transmits, to the first host, a second message indicating an encryption change. The second message may contain information on the first encryption key size.
Owner:INTELLECTUAL DISCOVERY CO LTD

Key length discriminator for ransomware attacks

An example computer system for providing countermeasures for a ransomware attack can include: one or more processors; and non-transitory computer-readable storage media encoding instructions which, when executed by the one or more processors, causes the computer system to generate a key by to: create a salt using artificial intelligence; form a data section by the salt and an original key; and form a dummy section to fill out a length of the key.
Owner:WELLS FARGO BANK NA

A method for processing financial data with improved security

This invention discloses a method for improving the confidentiality of financial data processing. In the field of information security technology, the method automatically identifies the source department and data type based on the submitter information of the financial data, determines the confidentiality level of the data using a confidentiality level rating table, and dynamically parses the key length and arrangement rules accordingly. It uses the characterization conversion results of the submitter's account and submission time, along with a random string, to perform multi-source fusion to construct a high-entropy basic key. After being hosted by a hardware security module, this key is intercepted to form the final encryption key, ensuring its unpredictability and security. An encryption algorithm combined with a random initialization vector is used to encrypt the original data text, ensuring the confidentiality and integrity of the data. The encrypted data is segmented according to the key length, generating a random number sequence and binding it to the data block. The number mapping relationship is stored on the blockchain. After being encapsulated with a unique identifier, the data block is randomly shuffled and further divided, and finally distributed and stored in the cloud.
Owner:JINAN JUSHI INFORMATION TECH CO LTD

Apparatus in wireless communication system and method performed thereby

A first device and a method performed by the same are provided. The method comprises the following steps: a first host sends an HCI setting minimum encryption key size command to a first controller through a first host controller interface (HCI), wherein the HCI setting minimum encryption key size command comprises a parameter for specifying a minimum encryption key size; and receiving, by the first host, an HCI encryption change event from the first controller via the first HCI, the HCI encryption change event comprising a first parameter indicating that an encryption change has occurred, where the HCI encryption change event comprising a second parameter specifying a size of a key for encryption, the first controller does not negotiate a key size less than the minimum encryption key size, where the HCI encryption change event further includes a third parameter for an identifier of a connection between the first device and the second device, where the HCI encryption change event occurs on the first device, and where the first controller does not negotiate a key size less than the minimum encryption key size. To inform the first host when a change has occurred for connection encryption present between the first device and the second device.
Owner:INTELLECTUAL DISCOVERY CO LTD

Key use method and device and storage medium

The invention discloses a secret key using method and device and a storage medium. The method comprises the steps that n data processing processes are created and used for conducting concurrent processing on data; obtaining n unused key files with the length of L from the key files with the total length of M according to the data average length L within a past period of time T, and sequentially and correspondingly distributing the n key files to corresponding data processing processes; and distributing the to-be-processed data to the corresponding data processing process for encryption processing. According to the invention, a segment of key is preset in each data processing process, so that the data processing process can immediately execute encryption operation when receiving the to-be-processed data without waiting to request to distribute the key to a key file; particularly, under the condition that the length of the data to be processed is smaller than the length of the preset key, encryption can be completed by directly using the preset key, the encryption preparation time is remarkably shortened, and the real-time performance of data processing is improved.
Owner:MATRICTIME DIGITAL TECH CO LTD

Encryption and decryption method and system, computer equipment and storage medium

The invention relates to the technical field of data security, in particular to an encryption and decryption method and system, computer equipment and a storage medium. The method comprises the following steps: sequentially storing an initial key in a zeroth register, a first register, a second register, a third register, a sixth register and a seventh register; according to the key length of the initial key, performing iteration round key addition operation iteration on the sub-keys stored in the registers to obtain the sub-keys output by each round of iteration operation, and sequentially storing the sub-keys in the corresponding registers according to a generation sequence; if the round key adding operation meets an iteration target, generating a target key after the initial key is expanded based on each round key in each register; and encrypting or decrypting a target file based on the target key. The invention provides an encryption and decryption method which is shorter in path and higher in efficiency.
Owner:芯来智融半导体科技(上海)股份有限公司

Video encryption transmission link optimization method and system based on digital twinning

The invention discloses a video encryption transmission link optimization method and system based on digital twinning. The method comprises the following steps: deploying lightweight probes at a sending end, a receiving end and an intermediate node, acquiring an encryption algorithm, a key length, encryption and decryption time delay, hop-by-hop time delay and a packet loss rate in real time, and sending the information with timestamps into a message queue; after the cloud twin container reads the data, a network topological graph, an encryption state machine and a video quality attenuation model are updated, a future traffic matrix and an attacker model are input into a running diagram neural network, and multiple groups of encryption parameter and routing path combinations are output; the reinforcement learning agent selects an optimal combination, issues encryption parameters to an encryption engine through a network configuration protocol, and issues a new path to a forwarding plane through a segment routing protocol; after the strategy takes effect, the probe continues to collect performance data, a message queue is sent back to correct network weight, closed-loop optimization is formed, encryption delay and end-to-end delay are continuously reduced, and dynamic optimization of a video encryption transmission link is achieved.
Owner:BEIJING FUSION HSBC TECH CO LTD

Encryption authentication method based on hash function and Feistel structure

The invention relates to the technical field of information security, and provides an encryption authentication method based on a hash function and a Feistel structure, the encryption authentication method comprises an encryption authentication algorithm and a decryption verification algorithm, the encryption authentication method is realized by taking the Feistel structure as a password structure, selecting a hash function as a round function of the Feistel structure, and instantiating the round function into a hash function. According to the invention, encryption and decryption and message integrity verification can be carried out. The plaintext length and the secret key length are selectable, and the method is high in universality, good in expansibility, low in error code diffusion and high in safety. The method can be widely applied to wireless communication environments such as satellite internet and internet of things.
Owner:SPACE STAR TECH CO LTD +1

LED algorithm implementation method

The invention discloses an LED algorithm implementation method, and belongs to the technical field of lightweight cryptographic algorithms. In order to solve the problems of high hardware resource occupation and low efficiency in the prior art, a round constant table and a finite field multiplication intermediate value table are generated through pre-calculation, and finite field multiplication operation is simplified into table look-up and XOR operation; a bidirectional shift register and module multiplexing design is adopted, so that hardware logic is shared in encryption and decryption processes; secret key reading overhead is reduced through a secret key cache and secret key register matching mechanism; and a round number label is added to the data, so that pipeline parallel processing of multiple groups of data is realized. The method supports 64-bit, 80-bit and 128-bit key lengths, and significantly reduces hardware resource consumption and improves encryption and decryption throughput efficiency while ensuring algorithm security.
Owner:PENG TI STORAGE TECH (NANJING) CO LTD

An encryption algorithm optimization method and system based on artificial intelligence

The application discloses an encryption algorithm optimization method and system based on artificial intelligence, relates to the technical field of artificial intelligence, and aims to solve the problem that the existing encryption technology is difficult to balance security and efficiency in a dynamic environment due to the adoption of fixed parameters. The method comprises the following steps: collecting multi-source perception data such as network traffic, system resources, user behavior, data sensitivity and threat intelligence in real time; constructing a joint feature vector that fuses semantics and risks; generating an optimal encryption strategy through a deep reinforcement learning model; dynamically configuring the encryption algorithm type, key length and operation strength; and optimizing the model performance based on the execution feedback closed loop. The system comprises a security agent module, a feature fusion unit, a deep Q network decision engine, a hot-pluggable cryptographic engine and a feedback learning module. Through the above scheme, the application can realize dynamic adaptive adjustment of the encryption strategy, significantly improve the resource utilization efficiency while ensuring high security protection.
Owner:HUNAN UNIV OF HUMANITIES SCI & TECH

Digital signature method, signature verification method and digital signature system

The invention discloses a digital signature method, a signature verification method and a digital signature system. The method comprises the following steps: acquiring a public key and a private key; determining a commitment vector based on the public key and the random mask vector; determining a signature challenge value and a response vector based on the commitment vector, the random mask vector, the private key and the to-be-signed message; determining an intermediate verification vector based on the signature challenge value; comparing the intermediate verification vector with a preset range, and determining a prompt vector based on the intermediate verification vector when the intermediate verification vector belongs to the preset range; and determining a target signature corresponding to the signature challenge value, the response vector and the prompt vector. The technical problem that a signature algorithm needs to frequently reject sampling and is low in calculation efficiency due to the fact that a digital signature method adopted in the related technology is difficult to give consideration to public key scale and security is solved.
Owner:BEIJING ACAD OF INFORMATION SCI & TECH

A method and system for adaptive enhancement of a vehicle-mounted TLS configuration

ActiveCN121711190BRevolutionizing the static configuration modelimprove throughputSecuring communicationComplex mathematical operationsCommunications securityKey size
The application provides a kind of vehicle-mounted TLS configuration adaptive enhancement method and system, the method includes real-time acquisition from the multi-source heterogeneous data of different sources of vehicle;State estimation algorithm is used to fuse the multi-source heterogeneous data processing, generate the fusion state vector representing current driving scene;Based on the fusion state vector, multi-dimensional risk assessment is carried out, the comprehensive risk score is calculated and the risk level is judged;Based on the risk level, the configuration parameters of the transport layer security TLS protocol are optimized by using multi-objective optimization algorithm to generate TLS configuration strategy;The configuration parameters at least include encryption suite and key length;The TLS configuration strategy is executed, and the performance index is monitored, and the performance index obtained by monitoring is fed back to the step of generating the fusion state vector, to form a closed loop control, crack the inherent problem that communication security, real-time performance and resource constraints are difficult to be considered in vehicle dynamic environment.
Owner:NANCHANG AUTOMOTIVE INST OF INTELLIGENCE & NEW ENERGY +1

An adaptive real-time digital signal encryption processing system

The application discloses a kind of self-adapting real-time digital signal encryption processing systems, including signal processing module, for collecting multi-source digital signal and time stamp mark and standard signal stream are generated with standardization;Risk assessment module is used to generate security level according to terminal security, firewall and historical attack feature evaluation risk;Parameter control module is used to construct control vector to determine elliptic curve encryption parameter, key length and update cycle;Correlation mapping module is used to generate digest and map control vector in sliding window hash;Encryption processing module is used to generate encrypted signal stream in elliptic curve segmented encryption;Block chain storage module is used to form verifiable storage according to time writing block chain;Security update module is used to output encrypted signal and synchronously update terminal security and firewall strategy.The application realizes digital signal self-adapting encryption, hash check and block chain storage, and improves security, integrity and traceability.
Owner:NANCHANG CAMPUS OF EAST CHINA UNIV OF TECH

Power distributed terminal secure communication method and system based on post-quantum cryptography

PendingCN122293324AKey sizeKey (cryptography)
This invention discloses a secure communication method and system for power distributed terminals based on post-quantum cryptography. With the development of quantum computing technology, traditional secure communication mechanisms based on elliptic curve cryptography face potential vulnerabilities. In existing secure communication systems for power distributed terminals, the terminal device and the secure access gateway typically use the SM2 elliptic curve cryptography algorithm for session key negotiation, which poses security risks in a quantum computing environment. This invention replaces the SM2 algorithm with a lattice-based post-quantum cryptography algorithm for session key negotiation and doubles the key length of the SM4 algorithm used for symmetric encryption services. While maintaining the original power communication system architecture and business processes, this invention achieves a quantum security upgrade for the power distributed terminal communication system, improving the system's long-term security in future quantum computing environments.
Owner:STATE GRID JIANGSU ELECTRIC POWER CO LTD RESEARCH INSTITUTE +1

Key data packaging method and electronic equipment

The invention discloses a key data packaging method and electronic equipment. The key data packaging method comprises the following steps: acquiring initial key data and a key block encryption key; obtaining a key algorithm corresponding to the key, and determining the maximum key length based on the key algorithm; filling the secret key in a mode of adding a random number to the secret key, so that the length of the filled secret key is the same as the maximum secret key length, and the initial secret key data after length filling is obtained; determining a current key length range based on the attribute information of the key block encryption key; determining a current key length according to key related data, the length of the filled key and a current key length range; and adding a random number to the initial key data after length filling to carry out block filling so as to enable the length of the initial key data after block filling to be the same as the current key length. According to the method, the initial key data is subjected to length confusion, so that the key is protected, the key related data is also protected, and the security in the key transmission process is further improved.
Owner:FUJIAN LANDI COMMERCIAL EQUIPMENT CO LTD

Searchable encryption method and device based on sm4 algorithm

The invention discloses a searchable encryption method and device based on an sm4 algorithm, and the method comprises the following steps: a secret key generation step: a data owner generates two secret keys s1 and s2 corresponding to the SM4 algorithm based on preset security parameters, s1 and s2 belong to {0, 1} k, k is the length of the secret key, and s1 and s2 serve as encryption operation basic secret keys of the SM4 algorithm; through innovative fusion of the SM4 algorithm and the searchable encryption technology, the technical breakthrough of efficient retrieval, low resource consumption and strong adaptability is realized on the premise of ensuring the security and privacy of cloud data, the core contradiction that security and efficiency are difficult to consider in the prior art is solved, and the security and privacy of the cloud data are ensured. The method can be widely applied to scenes with high requirements on data security and retrieval efficiency, such as personal cloud storage, enterprise-level document management, medical data sharing and the like, and has extremely high commercial value and application prospect.
Owner:DIGITAL LUZHOU IND INVESTMENT GRP CO LTD

Dynamic encryption authentication method and system based on channel adaptation and multi-modal fingerprint

The application relates to the technical field of data encryption, and relates to a dynamic encryption authentication method and system based on channel self-adaptation and multi-modal fingerprints, which comprises the following steps: firstly, using a receiving end and a spectrum analyzer and other devices to obtain the signal-to-noise ratio, channel state information, error vector amplitude and channel impulse response of a communication channel, and using a current transformer to obtain the current harmonic amplitude ratio of a motor of the device, and calculating the average bit error rate; then, according to the real-time signal-to-noise ratio and the average bit error rate, combining a preset strategy to dynamically select an encryption algorithm and the corresponding key length; then, taking the channel impulse response characteristics, the current harmonic amplitude ratio and the error vector amplitude as multi-modal fingerprints, splicing according to preset weights and generating a temporary session key through a key derivation function; finally, using the selected encryption algorithm and the generated temporary session key to perform dynamic encryption authentication. The application can improve the security of the authentication process and reduce the communication delay.
Owner:JINAN UNIVERSITY

Industrial instrument monitoring data transmission method and system based on data encryption

The invention relates to the technical field of industrial data transmission, and discloses an industrial instrument monitoring data transmission method and system based on data encryption, and the method comprises the steps: carrying out the formatting packaging of a real-time monitoring data flow of an industrial instrument, and obtaining a standard to-be-transmitted data frame; performing structured disassembly on the data frame to obtain timestamp information, instrument identification information and monitoring numerical value information; performing multi-dimensional feature coding on the three types of information to obtain content feature vectors; based on a preset strategy mapping table, performing strategy matching mapping on each dimension of characteristic value of the content characteristic vector to obtain an encryption strategy instruction, and performing semantic analysis to obtain a target encryption mode and a key length; in combination with the encryption program of the target encryption mode and the key length, completing key negotiation to obtain a session key, and then performing secret state conversion on the standard to-be-transmitted data frame to obtain an encrypted data packet; according to the invention, the efficiency of industrial instrument monitoring data transmission based on data encryption can be improved.
Owner:SHANGCHEN IND CONTROL EQUIP (SHANGHAI) CO LTD

A computer network security data transmission system

The application discloses a computer network security data transmission system and relates to the technical field of network security.The application forms a core framework of the computer network security data transmission system through mutual cooperation of multiple sets of algorithm units, calculates a data encryption danger value Esv by quantifying multiple factors such as attack frequency, intensity, fluctuation amplitude and key length, can dynamically adjust an encryption strategy to adapt to different security requirements, provides a self-adaptive and evolvable mathematical framework for the computer network security data transmission system, significantly improves the intelligent level of the system, and calculates a data transmission danger value Dtr by combining multiple influence factors such as data transmission time Dtt and network delay Nd through a transmission danger value algorithm unit, so that the computer network security data transmission system can comprehensively quantitatively evaluate data transmission risks and also provides scientific and reliable data support for adjustment of the encryption strategy in subsequent data transmission.
Owner:SHENZHEN GUNAI TECHNOLOGY CO LTD

Implementation method of anti-quantum hybrid cryptographic optimization algorithm

The invention provides an anti-quantum hybrid cryptographic optimization algorithm implementation method. The method comprises the following steps: acquiring a performance parameter of a sending end, a type of the sending end and a current network state of a transmission network; calling a preset algorithm combination candidate set based on the type of the sending end; according to the performance parameter and the current network state, dynamically adjusting the key length and the iteration round number of the algorithm in the algorithm combination candidate set; splitting a password operation task into sub-tasks, distributing the sub-tasks to a multi-core unit of a processor of the sending end and a thread unit of a graphics processor, and performing parallel processing by utilizing an algorithm of the algorithm combination candidate set to obtain encrypted data and a corresponding authentication tag; and sending the encrypted data and the authentication label to a receiving end. Therefore, the dynamic adaptability, the parallel processing efficiency and the anti-quantum security verification capability of the hybrid password scheme are improved.
Owner:CHINA ELECTRONICS CORP 6TH RES INST +1

Computing unit, terminal device, network, calculation method, and program

PendingJP2026049960ACoding/ciphering apparatusKey sizeHash function
The bit length of the given key is compressed to generate a key of equal size to the key used in the cryptographic algorithm. [Solution] The computing device causes a computer, which includes at least a processor and memory, to perform the following steps: when the bit length of a common key assigned for use in communication between a terminal device and a network is longer than the bit length of an input key used in a predetermined algorithm, a processing step of obtaining a bit sequence different from the bit sequence of the common key by performing different arithmetic operations on the bit sequence of the common key based on predetermined conditions; and a hashing step of inputting the bit sequence obtained in the processing step into a predetermined hash function agreed in advance between the terminal device and the network, thereby obtaining a bit sequence having the same bit length as the bit length of the input key.
Owner:KDDI CORP

Peripheral interface data real-time encryption transmission method and system and storage medium

The invention relates to the technical field of network security and data encryption, and discloses a peripheral interface data real-time encryption transmission method and system and a storage medium. The method comprises the following steps: dynamically evaluating the isomerism, the change rate and the security risk of a data stream by collecting the characteristics of the data stream in real time, and generating a threat evaluation result; and when the interface is marked as a high risk, the system automatically matches the optimal encryption algorithm from the encryption strategy library, generates a matching algorithm set in combination with delay and key length, optimizes transmission parameters, implements dynamic encryption, and realizes real-time updating of the encryption strategy and balance of transmission performance, and the protection capability of network security is improved.
Owner:深圳市彦胜科技有限公司

Optical fiber communication data encryption transmission method based on three-dimensional chaotic mapping and high-frequency key replacement

The invention provides an optical fiber communication data encryption transmission method based on three-dimensional chaotic mapping and high-frequency key replacement. The method comprises the following steps: S1, optical fiber communication data transmission design; s2, optical fiber communication data encryption based on improved Logistic chaotic mapping; s3, encrypting optical fiber communication data based on an improved DES algorithm; and S4, optical fiber communication data encryption transmission is realized. The improved chaotic mapping and DES algorithm are fused, a two-stage encryption mechanism is constructed, the unpredictability of the chaotic system and the stability of the block cipher are combined, and the anti-attack ability of the system is fundamentally improved; the key space of Logistic chaotic mapping is creatively increased, so that the size and complexity of the key space are improved, and the encryption security is enhanced; chaotic mapping is expanded to three dimensions, the total key length is greatly prolonged to 1088 bits, the potential safety hazard that a traditional DES key is too short is thoroughly solved, and the difficulty and cost of brute force cracking are greatly increased.
Owner:POWERCHINA HUADONG ENG CORP LTD

Computing unit, terminal device, network, calculation method and program

The bit length of the given key is compressed to generate a key of equal size to the key used in the cryptographic algorithm. [Solution] The arithmetic unit performs the following steps: an extraction step of extracting a bit sequence having the same bit length as the input key if the bit length of the common key is longer than the bit length of the input key used in a predetermined algorithm; an encryption step of generating ciphertext by performing a predetermined plaintext encryption process agreed upon between the terminal device and the network using the extracted bit sequence as a key; and a key generation step of repeatedly processing the bit sequences of the generated ciphertext until the total bit length of the generated ciphertext is longer than the bit length of the input key if the bit length of the generated ciphertext is shorter than an integer multiple of the bit length of the input key, dividing the resulting bit sequence according to the bit length of the input key, and generating a key having the same bit length as the input key based on the multiple bit sequences obtained by the division.
Owner:KDDI CORP

Efficient Cryptographic Key Management in Resource Constrained Devices

One or more embodiments address the transition to Post Quantum Cryptography (PQC) within secure element hardware environments. The embodiments focus on key management solutions for resource-constrained devices running JAVA CARD or similar platforms. PQC implementations face challenges from large key sizes that strain secure element resources, including RAM, ROM, flash memory, input / output bandwidth, and processing capabilities. The embodiments present methods for handling PQC keys through importation, exportation, generation, storage, utilization, and protection operations. The implementation manifests as an Application Programming Interface (API) that enables applications to leverage key management capabilities efficiently within secure element resource constraints. The API delivers advantages through memory optimization using flexible condensation and derivation mechanisms. Security benefits emerge from integrating key operations within the certified platform environment, enabling hardware acceleration and side-channel attack countermeasures through native code implementation.
Owner:ORACLE INT CORP

Improved method and device for user information encryption in identity authentication

The invention discloses an improved method for user information encryption in identity verification. The method comprises the following steps: S1, collecting user information; s2, judging whether the user information is registered or completely matched with data in a database or not by utilizing a safe intersection solving algorithm, and if an intersection exists, indicating that the user information is correct and the verification is passed; otherwise, verification fails. S3, an improved DES encryption algorithm is adopted to encrypt the intersection data verified in the S2, the plaintext block length of the algorithm is 192 bits, and the key length of the algorithm is expanded to be three times of the length; when the three groups of data are respectively subjected to iterative encryption, pairwise communication is carried out on the three encryption processes, and ciphertexts generated after communication become a whole. The invention further provides an improved system for user information encryption in identity authentication. According to the method, the retrieval method of the database is taken as an entry point, the efficiency of retrieving the data in the database is improved, and meanwhile, the content of a non-intersection part is ensured not to be leaked.
Owner:BEIJING UNIV OF TECH

Data security sharing method and system based on block chain

The invention discloses a data security sharing method and system based on a block chain, relates to the technical field of data security sharing, and is used for solving the problem of reduced security of shared data, calling shared data through a shared database, reading block chain information, obtaining a key length and an encryption duration, and generating a shared encryption coefficient. Screening target data, compressing the target data and extracting content mode features; calling storage node information, detecting disaster recovery switching time through an operation and maintenance log, counting access permission change times in unit time, and calculating node toughness characteristics; constructing a feature vector based on a content mode and node toughness, evaluating an encryption risk level by using K-means clustering, generating an encryption priority coefficient according to sorting, calculating an encryption evaluation value in combination with normalized disaster recovery switching time, executing secondary encryption when a preset threshold value is reached, and obtaining a second encryption result; and the security, the restorability and the protection priority dynamic balance of the shared data in the storage process are realized.
Owner:HUBEI ENG UNIV