Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

73 results about "Key size" patented technology

In cryptography, key size or key length is the number of bits in a key used by a cryptographic algorithm (such as a cipher). Key length defines the upper-bound on an algorithm's security (i.e. a logarithmic measure of the fastest known attack against an algorithm, relative to the key length), since the security of all algorithms can be violated by brute-force attacks. Ideally, key length would coincide with the lower-bound on an algorithm's security. Indeed, most symmetric-key algorithms are designed to have security equal to their key length. However, after design, a new attack might be discovered. For instance, Triple DES was designed to have a 168 bit key, but an attack of complexity 2¹¹² is now known (i.e. Triple DES has 112 bits of security). Nevertheless, as long as the relation between key length and security is sufficient for a particular application, then it doesn't matter if key length and security coincide. This is important for asymmetric-key algorithms, because no such algorithm is known to satisfy this property; elliptic curve cryptography comes the closest with an effective security of roughly half its key length.

Industrial control system security auditing method and system

The invention relates to the technical field of security auditing, in particular to a security auditing method and system for an industrial control system, and the method comprises the following steps: aiming at a key control task, a communication task and a security task of a real-time operating system, collecting a period, a starting timestamp, a finishing timestamp, a central processing unit occupied time slice and peak memory usage amount data. According to the method, the period, timestamp, central processing unit occupation and memory usage data of a key task of a real-time operating system are collected, a task execution time boundary and a resource consumption envelope are set, and then an expected relation rule set of a task time sequence and resource consumption is constructed by applying historical data statistics and logic rule deduction; and meanwhile, the key length of symmetric and asymmetric encryption, initialization vector generation, hash algorithm selection, key derivation parameters and encryption operation context are stipulated, so that a comprehensive and specific ICS behavior specification baseline is established.
Owner:CHONGQING HUATAI ACCOUNTING FIRM (GENERAL PARTNERSHIP)

Internet of vehicles security authentication and data encryption transmission system integrated with IPv6 technology

The invention discloses an Internet of Vehicles security certification and data encryption transmission system integrated with an IPv6 (Internet Protocol Version 6) technology. According to the invention, the key strategy can be automatically optimized according to the dynamic environment in the actual operation of the Internet of Vehicles, and the dynamic balance between the security protection and the communication efficiency is realized. The system can intelligently judge the cracking risk faced by a current key by combining real-time data such as a vehicle driving state and network environment characteristics, so as to flexibly adjust the key length and the updating frequency: when the network environment is safe and the vehicle is in a low-risk area, the key service cycle is properly prolonged, and the basic key length is maintained to reduce the communication overhead; when a potential threat is detected or a vehicle enters a complex road section, the secret key security level is automatically improved, and the rotation period is shortened to enhance the protection capability. The system burden cannot be increased due to excessive encryption, potential safety hazards cannot be left due to insufficient protection, and key management better meets the actual requirements of high-speed movement of vehicles and rapid change of scenes in the Internet of Vehicles.
Owner:XIANGTAN TECHNICIAN COLLEGE

Information encryption management method and system

The invention belongs to the technical field of data security and passwords, and provides an information encryption management method and system. After the system receives the access request, calling user historical behaviors, and calculating behavior baseline stability; obtaining a time deviation degree based on the difference between the current access time and the historical time distribution, obtaining a geographic deviation degree based on the difference between the source address and the geographic attribution, combining the time deviation degree and the geographic deviation degree into a comprehensive deviation degree, and modulating according to the behavior baseline stability to obtain a context disturbance factor. Fusing the context disturbance factor with the static risk index of the target data to obtain a session risk calibration value; and mapping the key length to the step set according to the session risk calibration value to obtain a final key length, and performing encryption. According to the method, the encryption strength can be adaptively improved when abnormal access occurs, the performance is kept under normal access, and the method has real-time performance, context sensing and good generalization ability.
Owner:NINGBO NINGFAN INFORMATION TECH CO LTD +1

Identity-based signature method supporting multi-message aggregation

The invention discloses an identity-based signature method supporting multi-message aggregation. The identity-based signature method comprises the steps of system initialization and key generation, user signature key generation, message signature construction, single signature verification, signature aggregation and aggregation signature verification. Due to the fact that the linear homomorphic signature technology is adopted, the identity-based aggregation signature method is provided, and the technical problems of signature after aggregation, key size expansion and the like in the existing aggregation signature technology are solved. Through the method, a verifier can safely and efficiently merge a plurality of signatures into a signature with a compact size, efficient data source authentication can be realized while the data integrity is guaranteed, and the verification efficiency is remarkably improved. The method has the advantages of high security, low communication cost, small calculation overhead and the like, can be applied to the technical fields of large-scale data authentication, distributed system security, lightweight cryptographic protocols and the like, and is particularly suitable for mobile terminals or Internet of Things equipment scenes with limited calculation resources.
Owner:SHAANXI NORMAL UNIV

Business data management method and system based on data analysis

The invention relates to the field of business management, in particular to a business data management method and system based on data analysis. The method comprises the following steps: collecting business data in a business database, and dividing each field in a customer data table of each customer; calculating an information chaos coefficient, and calculating a uniqueness ratio; obtaining a sensitivity original score; constructing a field sensitivity score based on the sensitivity original score, calculating a field correlation factor, and obtaining a field coupling coefficient; dividing the encryption strength grade of each field of each user on the basis of the field coupling coefficient, obtaining the key length and the update round number of each field of each customer in the encryption process by combining the field coupling coefficient, encrypting the service data of each field on the basis of the key length and the update round number, and managing the service data; and the refinement, intelligence and security level of business data management is improved.
Owner:HANGZHOU LIUDU ENTERPRISE MANAGEMENT CONSULTING CO LTD

A signaling service system and a communication method based on the signaling service system

The embodiment of the application provides a signaling service system and a communication method based on the signaling service system, the method is applied to a first client, a two-way authentication request for a second client is sent to a key management platform, and a session key handle sent by the key management platform after two-way authentication is passed is received, key negotiation is carried out between the key management platform and the second client, and a negotiation key handle and first public key information sent by the key management platform are received; a second key negotiation request is sent to the second client, the second key negotiation request comprises the session key handle, a negotiation key length and the first public key information, a session key sent by the key management platform is received, and communication is carried out with the second client according to the session key. Through the authentication mechanism based on quantum encryption technology, two-way identity authentication and quantum key negotiation are carried out, the security of a signaling channel can be ensured, and the risk of information leakage and malicious attack is reduced.
Owner:CHINA TELECOM QUANTUM TECH CO LTD

Safety method and device based on homomorphic encryption

The invention provides a security method and device based on homomorphic encryption, and belongs to the technical field of communication, and the method comprises the steps: obtaining a level 2 error learning hypothesis LWE ciphertext; converting the LWE ciphertext into a first ring error learning hypothesis RLWE'ciphertext at a level 1 by executing a public key switching algorithm and a splicing operation; and calculating the first RLWE'ciphertext by executing a scheme switching algorithm to obtain a first RGSW ciphertext at the level 1. It can be seen that one RLWE'ciphertext, such as a first RLWE 'ciphertext, is calculated through a public key switching algorithm, then the first RLWE' ciphertext is expanded into an RGSW ciphertext, such as a first RGSW ciphertext, through a scheme switching algorithm, the key size is smaller, and the overhead is smaller than that of calculation of two RLWE 'ciphertexts, so that the overhead of circuit bootstrap in a hierarchical homomorphic calculation mode can be reduced, and the circuit bootstrap efficiency is improved. The operation efficiency is improved.
Owner:HUAWEI TECH CO LTD +1

Method, apparatus, and computer program for setting encryption key in wireless communication system, and recording medium for same

The present disclosure relates to a method, apparatus, and computer program for setting an encryption key in a wireless communication system; and a recording medium for same. According to one embodiment of the present disclosure, a method for setting an encryption key size in a wireless communication system may comprise: a step in which a first controller of a first device receives a first message containing information on a minimum value of a first encryption key size from a first host of the first device; and a step in which the first controller transmits, to the first host, a second message indicating an encryption change. The second message may contain information on the first encryption key size.
Owner:INTELLECTUAL DISCOVERY CO LTD

Key length discriminator for ransomware attacks

An example computer system for providing countermeasures for a ransomware attack can include: one or more processors; and non-transitory computer-readable storage media encoding instructions which, when executed by the one or more processors, causes the computer system to generate a key by to: create a salt using artificial intelligence; form a data section by the salt and an original key; and form a dummy section to fill out a length of the key.
Owner:WELLS FARGO BANK NA

Data security encryption method for distributed storage of mass data

The invention relates to the technical field of data encryption processing, in particular to a data security encryption method facing mass data distributed storage. Acquiring data importance according to the daily load condition of the storage node in the historical analysis period and the variation trend of the read-write quantity of the disk; determining an ideal key length required by the encryption process of the storage node according to the number of users served by the storage node in the historical analysis period and the data importance; according to the distribution uniformity of data fragments stored by a storage node during real-time data storage, the key complexity of each data fragment on the storage node is obtained, the key complexity is matched with the key length supported by an encryption algorithm, the ideal key length is adjusted, the optimal key length of the data fragments on the storage node is determined, and the optimal key length of the data fragments on the storage node is obtained. And encrypting the data fragments on the storage nodes. According to the method, differential encryption is dynamically performed on each data fragment on different storage nodes through a two-stage adaptive adjustment mechanism, so that the security of distributed storage data encryption is improved.
Owner:SHAANXI SCI TECH UNIV

A method and system for secure access of an internet of things terminal

The application discloses an Internet of Things terminal security access method and system, and relates to the technical field of information security, comprising the following steps: when performing a key generation operation on an Internet of Things terminal, first, the generation environment is monitored in real time to capture data information in the key generation process. The application quantifies the key strength by real-time monitoring of the generation environment and obtaining data information, combining data preprocessing and feature extraction, and the system can timely identify and adjust the key that does not meet the security requirements. When the evaluation result shows that the key strength is insufficient, the system automatically triggers the key regeneration and extends the key length to ensure that the security standard is met. The scheme enables the Internet of Things terminal key generation to respond to environmental changes in real time, effectively improves the key security, breaks through the limitations of the traditional static generation mechanism, enhances the system protection capability and reduces the security risk.
Owner:HUANGHE S & T COLLEGE

A method for processing financial data with improved security

This invention discloses a method for improving the confidentiality of financial data processing. In the field of information security technology, the method automatically identifies the source department and data type based on the submitter information of the financial data, determines the confidentiality level of the data using a confidentiality level rating table, and dynamically parses the key length and arrangement rules accordingly. It uses the characterization conversion results of the submitter's account and submission time, along with a random string, to perform multi-source fusion to construct a high-entropy basic key. After being hosted by a hardware security module, this key is intercepted to form the final encryption key, ensuring its unpredictability and security. An encryption algorithm combined with a random initialization vector is used to encrypt the original data text, ensuring the confidentiality and integrity of the data. The encrypted data is segmented according to the key length, generating a random number sequence and binding it to the data block. The number mapping relationship is stored on the blockchain. After being encapsulated with a unique identifier, the data block is randomly shuffled and further divided, and finally distributed and stored in the cloud.
Owner:JINAN JUSHI INFORMATION TECH CO LTD

Apparatus in wireless communication system and method performed thereby

A first device and a method performed by the same are provided. The method comprises the following steps: a first host sends an HCI setting minimum encryption key size command to a first controller through a first host controller interface (HCI), wherein the HCI setting minimum encryption key size command comprises a parameter for specifying a minimum encryption key size; and receiving, by the first host, an HCI encryption change event from the first controller via the first HCI, the HCI encryption change event comprising a first parameter indicating that an encryption change has occurred, where the HCI encryption change event comprising a second parameter specifying a size of a key for encryption, the first controller does not negotiate a key size less than the minimum encryption key size, where the HCI encryption change event further includes a third parameter for an identifier of a connection between the first device and the second device, where the HCI encryption change event occurs on the first device, and where the first controller does not negotiate a key size less than the minimum encryption key size. To inform the first host when a change has occurred for connection encryption present between the first device and the second device.
Owner:INTELLECTUAL DISCOVERY CO LTD

Key use method and device and storage medium

The invention discloses a secret key using method and device and a storage medium. The method comprises the steps that n data processing processes are created and used for conducting concurrent processing on data; obtaining n unused key files with the length of L from the key files with the total length of M according to the data average length L within a past period of time T, and sequentially and correspondingly distributing the n key files to corresponding data processing processes; and distributing the to-be-processed data to the corresponding data processing process for encryption processing. According to the invention, a segment of key is preset in each data processing process, so that the data processing process can immediately execute encryption operation when receiving the to-be-processed data without waiting to request to distribute the key to a key file; particularly, under the condition that the length of the data to be processed is smaller than the length of the preset key, encryption can be completed by directly using the preset key, the encryption preparation time is remarkably shortened, and the real-time performance of data processing is improved.
Owner:MATRICTIME DIGITAL TECH CO LTD

Encryption and decryption method and system, computer equipment and storage medium

The invention relates to the technical field of data security, in particular to an encryption and decryption method and system, computer equipment and a storage medium. The method comprises the following steps: sequentially storing an initial key in a zeroth register, a first register, a second register, a third register, a sixth register and a seventh register; according to the key length of the initial key, performing iteration round key addition operation iteration on the sub-keys stored in the registers to obtain the sub-keys output by each round of iteration operation, and sequentially storing the sub-keys in the corresponding registers according to a generation sequence; if the round key adding operation meets an iteration target, generating a target key after the initial key is expanded based on each round key in each register; and encrypting or decrypting a target file based on the target key. The invention provides an encryption and decryption method which is shorter in path and higher in efficiency.
Owner:芯来智融半导体科技(上海)股份有限公司

Video encryption transmission link optimization method and system based on digital twinning

The invention discloses a video encryption transmission link optimization method and system based on digital twinning. The method comprises the following steps: deploying lightweight probes at a sending end, a receiving end and an intermediate node, acquiring an encryption algorithm, a key length, encryption and decryption time delay, hop-by-hop time delay and a packet loss rate in real time, and sending the information with timestamps into a message queue; after the cloud twin container reads the data, a network topological graph, an encryption state machine and a video quality attenuation model are updated, a future traffic matrix and an attacker model are input into a running diagram neural network, and multiple groups of encryption parameter and routing path combinations are output; the reinforcement learning agent selects an optimal combination, issues encryption parameters to an encryption engine through a network configuration protocol, and issues a new path to a forwarding plane through a segment routing protocol; after the strategy takes effect, the probe continues to collect performance data, a message queue is sent back to correct network weight, closed-loop optimization is formed, encryption delay and end-to-end delay are continuously reduced, and dynamic optimization of a video encryption transmission link is achieved.
Owner:BEIJING FUSION HSBC TECH CO LTD

Security algorithm management in communication network environment

Techniques are disclosed for security algorithm management. For example, a method includes receiving, at the data transmitting entity associated with a communication network, one or more data packets for transmission to a data receiving entity associated with the communication network, selecting, at the data transmitting entity, one or more security algorithms to be applied to the one or more data packets, wherein the selection is made between one or more first security algorithms configured with a first key length and one or more second security algorithms configured with a second key length, applying, at the data transmitting entity, the selected one or more security algorithms to the one or more data packets, and transmitting, from the data transmitting entity, the one or more data packets to the data receiving entity, in response to the application of the selected one or more security algorithms to the one or more data packets.
Owner:NOKIA TECHNOLOGIES OY

A fast method for balanced general key expansion

This invention discloses a fast, universal key expansion method with good balance, belonging to the field of cryptography. For a 256-bit encryption key, this invention expands the encryption key using only XOR, shift, and S-box operations. Besides possessing excellent balance and other randomness properties, this key expansion method also satisfies the property of lower correlation between round keys, resulting in faster key expansion speed. Depending on the needs of the encryption algorithm, this key expansion method can generate round keys of arbitrarily long lengths. Therefore, this invention is a universal key expansion method applicable to encryption keys of 256 bits and round keys of 128 bits.
Owner:10TH RES INST OF CETC

Encryption authentication method based on hash function and Feistel structure

The invention relates to the technical field of information security, and provides an encryption authentication method based on a hash function and a Feistel structure, the encryption authentication method comprises an encryption authentication algorithm and a decryption verification algorithm, the encryption authentication method is realized by taking the Feistel structure as a password structure, selecting a hash function as a round function of the Feistel structure, and instantiating the round function into a hash function. According to the invention, encryption and decryption and message integrity verification can be carried out. The plaintext length and the secret key length are selectable, and the method is high in universality, good in expansibility, low in error code diffusion and high in safety. The method can be widely applied to wireless communication environments such as satellite internet and internet of things.
Owner:SPACE STAR TECH CO LTD +1

LED algorithm implementation method

The invention discloses an LED algorithm implementation method, and belongs to the technical field of lightweight cryptographic algorithms. In order to solve the problems of high hardware resource occupation and low efficiency in the prior art, a round constant table and a finite field multiplication intermediate value table are generated through pre-calculation, and finite field multiplication operation is simplified into table look-up and XOR operation; a bidirectional shift register and module multiplexing design is adopted, so that hardware logic is shared in encryption and decryption processes; secret key reading overhead is reduced through a secret key cache and secret key register matching mechanism; and a round number label is added to the data, so that pipeline parallel processing of multiple groups of data is realized. The method supports 64-bit, 80-bit and 128-bit key lengths, and significantly reduces hardware resource consumption and improves encryption and decryption throughput efficiency while ensuring algorithm security.
Owner:PENG TI STORAGE TECH (NANJING) CO LTD

Digital asset circulation method and system based on cryptography

The present application relates to the technical field of cryptography, and in particular to a digital asset circulation method and system based on cryptography. The digital asset circulation method comprises: in response to a confirmation end receiving a target asset circulation request of an initiator, obtaining historical circulation information of a receiver and the initiator; calculating a real-time security demand on the basis of the historical circulation information and an asset circulation amount of the target asset circulation request, and allocating a key length of the target asset circulation request on the basis of real-time security demands of all asset circulation requests of a current moment; generating a temporary public key and a temporary private key on the basis of the key length, and using the temporary public key to generate a digital signature of the target asset circulation request; and using the temporary private key to perform signature verification on the digital signature, and if the signature verification is successful, the confirmation end adjusting digital assets in accounts of the initiator and the receiver on the basis of the asset circulation amount. The technical solution of the present application can ensure the circulation efficiency and the circulation safety of digital assets.
Owner:TIANYI CAIJIN TECHNOLOGY SERVICES (WUHAN) CO LTD

An encryption algorithm optimization method and system based on artificial intelligence

The application discloses an encryption algorithm optimization method and system based on artificial intelligence, relates to the technical field of artificial intelligence, and aims to solve the problem that the existing encryption technology is difficult to balance security and efficiency in a dynamic environment due to the adoption of fixed parameters. The method comprises the following steps: collecting multi-source perception data such as network traffic, system resources, user behavior, data sensitivity and threat intelligence in real time; constructing a joint feature vector that fuses semantics and risks; generating an optimal encryption strategy through a deep reinforcement learning model; dynamically configuring the encryption algorithm type, key length and operation strength; and optimizing the model performance based on the execution feedback closed loop. The system comprises a security agent module, a feature fusion unit, a deep Q network decision engine, a hot-pluggable cryptographic engine and a feedback learning module. Through the above scheme, the application can realize dynamic adaptive adjustment of the encryption strategy, significantly improve the resource utilization efficiency while ensuring high security protection.
Owner:HUNAN UNIV OF HUMANITIES SCI & TECH

Digital signature method, signature verification method and digital signature system

The invention discloses a digital signature method, a signature verification method and a digital signature system. The method comprises the following steps: acquiring a public key and a private key; determining a commitment vector based on the public key and the random mask vector; determining a signature challenge value and a response vector based on the commitment vector, the random mask vector, the private key and the to-be-signed message; determining an intermediate verification vector based on the signature challenge value; comparing the intermediate verification vector with a preset range, and determining a prompt vector based on the intermediate verification vector when the intermediate verification vector belongs to the preset range; and determining a target signature corresponding to the signature challenge value, the response vector and the prompt vector. The technical problem that a signature algorithm needs to frequently reject sampling and is low in calculation efficiency due to the fact that a digital signature method adopted in the related technology is difficult to give consideration to public key scale and security is solved.
Owner:BEIJING ACAD OF INFORMATION SCI & TECH

A method and system for adaptive enhancement of a vehicle-mounted TLS configuration

The application provides a kind of vehicle-mounted TLS configuration adaptive enhancement method and system, the method includes real-time acquisition from the multi-source heterogeneous data of different sources of vehicle;State estimation algorithm is used to fuse the multi-source heterogeneous data processing, generate the fusion state vector representing current driving scene;Based on the fusion state vector, multi-dimensional risk assessment is carried out, the comprehensive risk score is calculated and the risk level is judged;Based on the risk level, the configuration parameters of the transport layer security TLS protocol are optimized by using multi-objective optimization algorithm to generate TLS configuration strategy;The configuration parameters at least include encryption suite and key length;The TLS configuration strategy is executed, and the performance index is monitored, and the performance index obtained by monitoring is fed back to the step of generating the fusion state vector, to form a closed loop control, crack the inherent problem that communication security, real-time performance and resource constraints are difficult to be considered in vehicle dynamic environment.
Owner:NANCHANG AUTOMOTIVE INST OF INTELLIGENCE & NEW ENERGY +1

An adaptive real-time digital signal encryption processing system

The application discloses a kind of self-adapting real-time digital signal encryption processing systems, including signal processing module, for collecting multi-source digital signal and time stamp mark and standard signal stream are generated with standardization;Risk assessment module is used to generate security level according to terminal security, firewall and historical attack feature evaluation risk;Parameter control module is used to construct control vector to determine elliptic curve encryption parameter, key length and update cycle;Correlation mapping module is used to generate digest and map control vector in sliding window hash;Encryption processing module is used to generate encrypted signal stream in elliptic curve segmented encryption;Block chain storage module is used to form verifiable storage according to time writing block chain;Security update module is used to output encrypted signal and synchronously update terminal security and firewall strategy.The application realizes digital signal self-adapting encryption, hash check and block chain storage, and improves security, integrity and traceability.
Owner:NANCHANG CAMPUS OF EAST CHINA UNIV OF TECH

Routing path generation method and apparatus, and electronic device and storage medium

A routing path generation method and apparatus, and an electronic device and a storage medium. The method comprises: determining a key length and a receiving node of a quantum key to be sent; acquiring an adjacency relationship of a QKD node in a QKD network, generation time information of an available QKD key on a link, and a corresponding key length; on the basis of the generation time information and the corresponding key length, selecting an alternative link from among links of the QKD network, wherein a key length of an available QKD key, which is generated on the alternative link after a preset time point, is not less than the key length of the quantum key to be sent; and on the basis of the adjacency relationship and the alternative link, generating a target routing path for sending to the receiving node the quantum key to be sent.
Owner:CHINA TELECOM CORP LTD +1

Power distributed terminal secure communication method and system based on post-quantum cryptography

PendingCN122293324AKey sizeKey (cryptography)
This invention discloses a secure communication method and system for power distributed terminals based on post-quantum cryptography. With the development of quantum computing technology, traditional secure communication mechanisms based on elliptic curve cryptography face potential vulnerabilities. In existing secure communication systems for power distributed terminals, the terminal device and the secure access gateway typically use the SM2 elliptic curve cryptography algorithm for session key negotiation, which poses security risks in a quantum computing environment. This invention replaces the SM2 algorithm with a lattice-based post-quantum cryptography algorithm for session key negotiation and doubles the key length of the SM4 algorithm used for symmetric encryption services. While maintaining the original power communication system architecture and business processes, this invention achieves a quantum security upgrade for the power distributed terminal communication system, improving the system's long-term security in future quantum computing environments.
Owner:STATE GRID JIANGSU ELECTRIC POWER CO LTD RESEARCH INSTITUTE +1

Key data packaging method and electronic equipment

The invention discloses a key data packaging method and electronic equipment. The key data packaging method comprises the following steps: acquiring initial key data and a key block encryption key; obtaining a key algorithm corresponding to the key, and determining the maximum key length based on the key algorithm; filling the secret key in a mode of adding a random number to the secret key, so that the length of the filled secret key is the same as the maximum secret key length, and the initial secret key data after length filling is obtained; determining a current key length range based on the attribute information of the key block encryption key; determining a current key length according to key related data, the length of the filled key and a current key length range; and adding a random number to the initial key data after length filling to carry out block filling so as to enable the length of the initial key data after block filling to be the same as the current key length. According to the method, the initial key data is subjected to length confusion, so that the key is protected, the key related data is also protected, and the security in the key transmission process is further improved.
Owner:FUJIAN LANDI COMMERCIAL EQUIPMENT CO LTD