Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

15 results about "Key tree" patented technology

Vehicle-mounted dynamic key management and verification method, device, equipment and medium

The invention discloses a vehicle-mounted dynamic key management and verification method and device, equipment and a medium, and relates to the technical field of computer networks. In response to an encryption request for target firmware in a target vehicle, acquiring firmware information of the target firmware issued by the cloud; the firmware information comprises an identification code of a target vehicle and a firmware version number of the target firmware; performing slicing processing on the target firmware to obtain at least one firmware slice in the target firmware; generating a firmware key tree corresponding to the target firmware based on the firmware information and the original entropy; the firmware key tree comprises a root key of the target firmware and a slice key of each firmware slice. By adopting the technical scheme, the key can be dynamically managed based on firmware information such as the firmware version number, the binding of the key with the vehicle-mounted equipment and the firmware is realized, the risk that the existing static key is easy to leak is solved, and the safety of the vehicle function is improved.
Owner:CHINA FAW CO LTD

A multi-agent communication key management method and system adaptive to dynamic topology

This invention discloses a multi-agent communication key management method and system adapted to dynamic topologies, relating to the field of multi-agent communication security technology. It addresses the problems of low scalability and high failure risk in the existing centralized key generation and distribution processes of agent keys. The invention includes: the role of the GC can be elected and rotated among multiple agents, avoiding physical single points of failure; and it establishes a multi-agent group key system based on a logical key tree. When an agent joins or leaves, only logarithmic-level key updates are required, reducing the communication overhead of key distribution from O(N) to O(logN), significantly improving the system's efficiency and scalability when handling large-scale, highly dynamic groups.
Owner:BEIJING XINLIAN SHUAN TECHNOLOGY CO LTD +1

Data processing method and device

The invention provides a data processing method and device.The method comprises the steps that in response to a data reading operation, a stored encrypted data block is read based on a current reading address; generating a first session key by using the current read address and a first leaf node key corresponding to the current read address in a key tree; wherein the first leaf node key is generated based on a historical read address, a historical leaf node key and a historical authentication tag; verifying the legality of the first session key by using a pre-stored first authentication tag corresponding to the current read address; under the condition that the validity verification of the first session key is passed, carrying out reverse splicing on the encrypted data block by utilizing the first authentication tag to obtain ciphertext data; and decrypting the ciphertext data by using the first session key to obtain plaintext data.
Owner:CHENGDU KAIYUAN COMPUTING ECOLOGICAL TECHNOLOGY CO LTD

Hierarchical broadcast key management method and system

The invention relates to the technical field of network communication security, in particular to a hierarchical broadcast key management method and system applied to the Internet of Things, an intelligent sensor network and a distributed system. Comprising a root node, an intermediate node and a leaf node, the system collects network state parameters such as network density and node average energy, calculates a tree balance factor and dynamically adjusts a key tree structure, the network is divided into a plurality of security domains, each domain has an independent key system and comprises a broadcast key, a forward key and a communication key, a domain key is decomposed into a plurality of key components, and the key components are distributed in the security domains. According to the method, a subtree key is generated in a sectional type combined key derivation mode, a node state is monitored in cooperation with a self-repairing mechanism, key fragment reconstruction is triggered when a failure or key leakage occurs, the expandability of the system is remarkably improved, the network capacity is increased in an exponential level, and the network communication safety performance is effectively improved.
Owner:COSONIC INTELLIGENT TECH CO LTD

Stateless anti-quantum signature method based on hash function

The invention discloses a stateless anti-quantum signature method based on a hash function, and the method comprises the steps: obtaining a to-be-signed message M and a preset key tree which corresponds to a private key set {sk1, sk2,..., sk2h}; performing hash operation on the message M to be signed to obtain a message hash value m = H (M); calculating a key index value i based on the message hash value m and the height value h of the key tree; and in a private key set corresponding to the key tree, calling a leaf node private key ski corresponding to the key index value i to sign the message to obtain a signature result. A hash value of a to-be-signed message is calculated, a key index value is calculated in combination with a key tree height, and a private key of a corresponding leaf node is called to complete signature, so that stateless operation is realized, and private key leakage caused by non-updated state or repeated use is avoided; and the calculation logic is simple, the key state does not need to be managed, and the implementation complexity and resource occupation are reduced.
Owner:ASPIRE TECH (SHENZHEN) LTD +1

A student intelligent mental monitoring and protection system

The application discloses a kind of student intelligence mental monitoring and protection system, it is related to data transmission field.The system, including psychological monitoring data collection module, key distribution module, key distribution optimization module, key configuration management module, key configuration management optimization module and secondary encryption module: the student psychological monitoring data collected is pre-stored to key configuration attribution, is configured with the student psychological monitoring data pre-stored in key configuration attribution, after configuration is completed, student psychological monitoring data is transmitted to cloud storage server and is stored.The application is by the distribution of key according to key distribution quantization value to carry out real-time optimization, the relevant parameter of key tree is dynamically adjusted by the configuration management quantization value of key, and the student psychological monitoring data of secondary encryption protection is carried out to easy leak, and then the effect of improving the privacy protection of student psychological monitoring data is realized, solve the problem of insufficient privacy protection of student psychological monitoring data in prior art.
Owner:HUNAN ANZHI NETWORK TECH CO LTD

Safe communication authentication method for electric energy meter

The invention discloses a secure communication authentication method for an electric energy meter, and aims to solve the problems that only link encryption is carried out in a multi-level network from an electric meter to a collector to a master station, the collector is visible and changeable, and packets are easy to lose in small-frame fragmentation. According to the method, the entity proof token and the mixed public key are packaged and bound in a hard manner, the key tree is constructed from the object level to the fragment level, the Merkel fragment commitment is used for generating the fragment level initialization parameter and the authentication related data, and the authentication encryption algorithm with the synthesis initialization vector characteristic is used for encryption and integrity protection. And meanwhile, a trusted execution environment monotonic counter is used for preventing rollback, and a system type forward error correction enhancement recovery capability is introduced, so that the technical effects of real end-to-end authentication and encryption, fragment-level insertion modification prevention, rearrangement prevention, truncation prevention, whole message consistency verification and adaptation to out-of-order and packet loss scenes are realized.
Owner:LIYANG HUAPENG ELECTRIC POWER METER

A non-repudiation storage method and system with multiple snapshot security

The application discloses a non-repudiation storage method and system with multi-snapshot security, and the method comprises the following steps: generating system public parameters according to security parameters; inputting a password of a security deletion system to initialize a first master key; inputting a password of a hidden storage system to initialize a second master key; storing a disk state of a PPRF through a tree structure to generate a first key tree; encrypting and storing encryption keys of all files to generate a first file key table; constructing a storage space of the non-repudiation storage system; writing, updating and deleting common files; and writing, updating and deleting hidden data. The application has multi-snapshot security during normal file changes; the hidden space and the common space can be freely switched; compared with the existing non-repudiation storage system with multi-snapshot security, the capacity can be increased by 50 times at most; and the hidden space is entirely encrypted by using the master key in the TPM module, thereby providing strong guarantee for the security of the hidden space.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

An ECDH-based group encryption method

The application relates to an ECDH-based group encryption method and belongs to the technical field of information security, which comprises the following steps: 1, a communication party generates a respective key pair based on an ECC algorithm, and exchanges the generated public key; 2, a message sender generates a temporary key pair, combines the temporary private key with the public keys of all other communication parties through an ECDH algorithm, and generates a shared public key tree according to a binary tree structure; 3, the encrypted message is sent to other communication parties together with the shared public key tree; 4, after obtaining the shared public key tree, other communication parties find the position of the communication party in the shared public key tree, and perform ECDH calculation from the child node to the parent node according to the tree structure to obtain a final shared key. The application realizes a group encryption method capable of being used for instant communication through the shared tree mode, and the updating complexity of the key is significantly reduced by slightly increasing the algorithm resource of the message sender.
Owner:CHENGDU FEIBAT TECH CO LTD

A cross-modal retrieval method supporting authorized access

The application relates to a cross-modal retrieval method supporting authorized access, and relates to the field of cloud computing security. A vector inner product encryption scheme FBIPE realizes the privacy of data and query requests, and an authorized key tree guarantees low-interactive authorized access. First, text / images in a database / query request are converted into text / image vectors by using a cross-modal hashing technology, and all the vectors are encrypted by using the FBIPE. Then, an independent key is generated for each vector in the database by using the authorized key tree, and the corresponding text / image vector ciphertext is re-encrypted by using the key. Finally, in the cross-modal retrieval process, authorized access is completed because the authorized key corresponding to unauthorized access data cannot be restored. The whole authorized cross-modal retrieval method is based on lightweight cryptography primitives, and the designed authorized key tree can realize low-interactive authorization, and the overall operation efficiency is high.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Intelligent psychological monitoring and protecting system for students

The invention discloses an intelligent psychological monitoring and protecting system for students, and relates to the field of data transmission. The system comprises a psychological monitoring data collection module, a secret key distribution module, a secret key distribution optimization module, a secret key configuration management module, a secret key configuration management optimization module and a secondary encryption module. And performing configuration processing on student psychological monitoring data pre-stored in the secret key configuration attribution, and transmitting the student psychological monitoring data to a cloud storage server for storage after configuration is completed. According to the invention, the distribution of the secret key is optimized in real time according to the secret key distribution quantized value, the configuration management quantized value of the secret key dynamically adjusts the related parameters of the secret key tree, and the student psychological monitoring data easy to leak is subjected to secondary encryption protection, so that the effect of improving the privacy protection of the student psychological monitoring data is realized; the problem of insufficient privacy protection of student psychological monitoring data in the prior art is solved.
Owner:HUNAN ANZHI NETWORK TECH CO LTD

Large-scale node dynamic security networking method and system for satellite-ground convergence network

The invention discloses a dynamic security networking method and system for large-scale nodes of a satellite-ground convergence network. The invention provides a rapid and safe networking authentication method between large-scale adjacent nodes, cross-layer nodes and cross-domain nodes for the large-scale heterogeneous node safe networking requirement in a 6G heterogeneous fusion network scene. By fusing a key management system based on a key tree and a hash chain, a trusted identity label and a block chain technology, efficient identity authentication and session key negotiation among large-scale satellite nodes can be realized, the communication overhead and the calculation overhead of multi-round interaction are reduced, the requirements of the 6G network for flexibility and dynamics can be met, and in addition, the service life of the 6G network is prolonged. Direct trust establishment among heterogeneous nodes can be promoted, and the expansibility and interoperability of the network are improved.
Owner:XIDIAN UNIV

Multi-dimensional dynamic encryption and tracing method and system for collaborative document

The invention belongs to the technical field of information security, and particularly discloses a multi-dimensional dynamic encryption and tracing method and system for a collaborative document, and the method comprises the steps: dividing the document into content units, generating a main encryption key and a unit key, and constructing a key tree; generating an authorization voucher in response to the authorization request, and performing cryptographic conversion on a unit key to obtain a re-encrypted authorization voucher; after the verification of the server, decrypting the complete view of the assembled document and embedding the watermark embedded with the encrypted information; when a leaked copy is found, watermark decryption identity and context information are extracted, and a leaked collaborator and an access session are traced; through organic combination of technical links such as multi-dimensional encryption, proxy re-encryption authorization, dynamic watermark rendering by a client, leakage traceability and the like, full-life-cycle closed-loop management from encrypted storage, permission distribution, safe use to leakage responsibility investigation of collaborative documents is realized, and the problem of a security window of permission change delay in a traditional key management scheme is solved.
Owner:SHENZHEN HUAXINYUAN SEMICONDUCTOR CO LTD

A migration method for virtual trusted roots under a dual-architecture approach

This invention discloses a method for migrating a virtual root of trust (vTPCM) under a dual-architecture system, comprising three parts: S1: vTPCM key tree establishment; S2: vTPCM instance management; and S3: vTPCM migration. In a dual-architecture trusted computing environment, multiple virtual roots of trust (vTPCMs) can be virtualized based on the hardware root of trust (TPCM). The virtualization components of the TPCM are installed on the protection component. This invention establishes a vTPCM key tree based on the TCM key system, facilitating the management of vTPCM keys and enabling secure migration of vTPCM instances. The virtual root of trust migration method described in this invention includes core vTPCM components, including a vTPCM migration module, a remote authentication module, and a vTPCM instance management module, all deployed on the protection component. This effectively prevents external attacks, providing security, practicality, and facilitating the migration of vTPCM instances.
Owner:BEIJING UNIV OF TECH

Cross-modal retrieval method supporting authorized access

The invention discloses a cross-modal retrieval method supporting authorized access, and relates to the field of cloud computing security. The vector inner product encryption scheme FBIPE realizes the privacy of data and query requests, and the authorization key tree ensures low-interaction authorization access. The method comprises the following steps: firstly, converting a text / image in a database / query request into text / image vectors by utilizing a cross-modal hash technology, and encrypting all the vectors by utilizing FBIPE; then, generating an independent key for each vector in the database by using the authorization key tree, and re-encrypting the corresponding text / image vector ciphertext by using the key; finally, in the cross-modal retrieval process, due to the fact that the authorization key corresponding to the unauthorized access data cannot be recovered, authorized access is completed. The whole authorization cross-modal retrieval method is based on lightweight cryptographic primitives, and the designed authorization key tree can realize low-interaction authorization and is high in overall operation efficiency.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA