Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

467 results about "Master key" patented technology

A master key operates a set of several locks. Usually, there is nothing special about the key itself, but rather the locks into which it will fit. These master-keyed locks are configured to operate with two, or more, different keys: one specific to each lock (the change key), which cannot operate any of the others in the set, and the master key, which operates all the locks in the set. Locks that have master keys have a second set of the mechanism used to operate them that is identical to all of the others in the set of locks. For example, master keyed pin tumbler locks often have two shear points at each pin position, one for the change key and one for the master key. A far more secure (and more expensive) system has two cylinders in each lock, one for the change key and one for the master key.

Container mirror image security management method and system

The invention relates to the technical field of data access security, and discloses a container mirror image security management method and system, and the method comprises the steps: constructing a container mirror image, generating a differential encryption key through a strategy center, carrying out the encryption strategy of a kernel dependence layer, a runtime environment layer, an application code layer and a sensitive configuration layer, and forming a hierarchical protection basis. If an access request is triggered, firstly collecting equipment fingerprints and geofence information and evaluating an environmental risk score, verifying access authority and an access scene matching degree through attribute-based encryption, analyzing operation track characteristics in real time, identifying an abnormal mode, and if the three-layer verification is passed, generating a temporary access token; according to the method, access request authority is verified, a temporary access token is matched, key fragments are synthesized, a master key is only temporarily generated in a memory and encrypted and stored, and through combination of a double-layer encryption channel and inner-layer and outer-layer defense, the anti-attack ability of container mirror image transmission is improved, and man-in-the-middle attack and data tampering are effectively coped with.
Owner:NANJING TORTOISE & HARE RACE SOFTWARE RES INST CO LTD

Decentralized artificial intelligence based system and method for processing tasks based on prompts

A system includes a plurality of nodes. Each of the plurality of nodes includes memory; a network interface; and a hardware processor coupled with the memory and the network interface. The system further includes a computing device. The computing device includes memory storing a master key, security keys encrypted using the master key, and associations between the security keys and the nodes. The computing device further includes a network interface and a hardware processor coupled with the memory and the network interface. The processor is configured to receive, from a node of the one or more nodes, a request for a security key of the one or more security keys, identify an association between the node and the security key within the associations, decrypt the security key using the master key to generate a decrypted security key, and communicate the decrypted security key to the node.
Owner:INFINITYONE LLC

Health data encryption storage method and device, equipment and storage medium

The invention relates to a health data encryption storage method and device, equipment and a storage medium, and the method comprises the steps: obtaining to-be-processed health data, carrying out the sensitivity analysis and grade division of the health data, and obtaining health data sub-blocks; performing encryption preprocessing on the health data sub-blocks, and performing group data protection according to a preset differential privacy algorithm to obtain encrypted data blocks; generating an initial master key through a hardware security module, and performing derived hierarchical encryption on the encrypted data block to obtain a data encryption key; performing fragmentation processing and regular distributed storage on the data encryption key to obtain a dynamic security key; and performing metadata separation storage on the encrypted data according to the dynamic security key, and performing data permission determination according to a preset role-based access control mechanism to obtain an encrypted isolation database. According to the invention, efficient security protection can be maintained under different application scenes and access permissions, and the risk of data leakage is reduced.
Owner:SHENZHEN MATERNITY & CHILD HEALTHCARE HOSPITAL +1

Revocable attribute-based encryption method with strategy hiding

The invention discloses a revocable attribute-based encryption method with strategy hiding, which is based on ciphertext strategy attribute encryption, solves the problem that user privacy is leaked due to disclosure of an access strategy, realizes revocation of fine-grained user attribute access authority, and is proved to be completely safe. In a system establishment stage, system parameters are disclosed, a public key and a master key are generated, an authoritative authority authorizes a data user, distributes a private key and generates an AGK tree and an attribute group key, a data owner generates a ciphertext according to the public key, an access structure set by the data owner and a selected secret value, and the ciphertext is transmitted to the data owner. And then hiding the mapping function by using a cuckoo filter, positioning the attribute by a data user through the cuckoo filter, updating a private key by using an attribute group key, and finally decrypting the ciphertext to obtain the wanted information.
Owner:HUAIYIN INSTITUTE OF TECHNOLOGY

Data security authentication method and system for smart medical treatment

The invention discloses a data security authentication method and system for smart medical treatment, and relates to the field of data security, and the method comprises the steps: obtaining the identity authentication information of a user, and generating an anti-quantum root key; obtaining operation data and an operation log; according to the operation type, dynamically deriving a temporary sub-key based on the master key, and decomposing the temporary sub-key to obtain m temporary sub-key fragments and n temporary sub-key fragments; transmitting the m temporary sub-key fragments to the client terminal; generating a second signature fragment based on the n temporary sub-key fragments, receiving the first signature fragment, and combining the first signature fragment and the second signature fragment to obtain an operation signature; calculating a hash value of the operation data, and embedding the hash value into the operation signature; and encrypting the operation log based on the embedded operation signature to generate a tamper-resistant log, and marking the temporary sub-key as a failure state. The security of the medical data can be effectively improved.
Owner:TONGJI HOSPITAL ATTACHED TO TONGJI MEDICAL COLLEGE HUAZHONG SCI TECH

Method and apparatus for distributing encrypted device unique credentials

A system and method for providing credentials device unique credentials to a chip is disclosed. In one embodiment, the method comprises receiving the credentials in credential provisioning server (CPS), the credentials having information encrypted according to a secure server key (SSK) securely stored in a hardware security module (HSM) communicatively coupled to the CPS, the hardware security module also securely storing a master key; receiving a credential request in the CPS, the credential request comprising a chip identifier that identifies the chip; securely decrypting the encrypted information in the HSM according to the SSK; securely computing a chip-unique key in the HSM, according to the chip identifier and the master key; re-encrypting the decrypted information according to the computed chip-unique key; and providing the credentials having the re-encrypted information to the device.
Owner:ARRIS ENTERPRISES LLC

Attribute-based encrypted medical data sharing method based on dynamic NFT

The invention discloses a dynamic NFT-based attribute-based encrypted medical data sharing method, which comprises the following steps that: firstly, a user submits identity authentication information to a trusted digital identity platform, and applies for an attribute certificate from an institution to which the user belongs; secondly, the key management system completes system initialization and generates a master key and a public key, the medical data owner generates an attribute-based encrypted ciphertext according to the access strategy and casts a dynamic NFT according to the smart contract, and when the medical data demander conforms to the access strategy, the medical data owner issues a sub-NFT of the dynamic NFT to the medical data demander through the smart contract; and then the medical data demander applies for a master key from the key management system and decrypts the ciphertext. And finally, the medical data owner changes the access strategy and re-judges whether the medical data demander conforms to the access strategy. According to the invention, the data access control does not depend on a fixed strategy any more, and the controllability and security of the data access control are enhanced.
Owner:HANGZHOU DIANZI UNIV

Stable transmission method for server data encryption and rapid authentication

The invention discloses a stable transmission method for server data encryption and rapid authentication, and belongs to the technical field of data security. The method comprises the following steps: dividing data into three levels of core sensitive data, important data and common data by utilizing a semantic analysis model; performing encryption protection on different levels of data by adopting a hierarchical encryption strategy; a master key is generated based on a chaotic system, a session key is generated in combination with a timestamp and a device fingerprint and is regularly alternated, and secure distribution is performed through a trusted execution environment and a block chain; multi-modal features are fused, the identity is verified through zero-knowledge proof, and the authentication strength is adjusted through dynamic risk assessment. The method is suitable for cloud computing, the Internet of Things and a distributed storage system, through deep fusion of a multi-level hybrid encryption algorithm, a dynamic key management mechanism and a self-adaptive authentication strategy, data security encryption, rapid authentication and stable transmission are achieved, and security, efficiency and adaptability are improved.
Owner:SHANGHAI GUIHENG TECHNOLOGY CO LTD

Multi-level access control and authority synchronization method for secure mobile storage

The invention discloses a multi-level access control and authority synchronization method for secure mobile storage, and belongs to the field of mobile storage security. Aiming at the problems of data leakage, poor authority management and the like of the mobile storage device, a multi-level access control framework, a decentralized authority synchronization mechanism and a dynamic token and zero-knowledge proof system are constructed. Generating a plurality of layers of sub-keys from a master key by using a PBKDF2 algorithm through hierarchical key generation, and associating different encryption areas and authority strategies; incremental synchronization is carried out based on a Merkle tree, and data consistency is guaranteed through a consistency verification protocol; a temporary token is generated by using a Schnorr protocol, and the permission is verified in combination with zero-knowledge proof, so that the privacy security is ensured. In scene application of a power grid and the like, a master key is activated through biological recognition, permission is loaded according to a strategy, and permission change is efficiently synchronized. According to the method, the mobile storage security and the management efficiency are improved, and accurate authority control and reliable synchronization are realized.
Owner:GUANGXI POWER GRID CORP

Method for applying anti-quantum certificate to TLS1.2 handshake process

The invention discloses a method for applying an anti-quantum certificate to a TLS1.2 handshake process, which realizes the application of an MLDSA anti-quantum signature algorithm and an MLKEM anti-quantum key encapsulation mechanism in the handshake process by expanding a cipher suite and a signature algorithm field of a TLS1.2 protocol. The method specifically comprises the following steps: defining a cipher suite supporting MLKEM and an MLDSA signature algorithm enumeration value; the client declares algorithm support in ClientHello, and the server responds and returns a certificate chain containing the double-antibody quantum certificate; after the client verifies the certificate, the pre-master key is encapsulated by using MLKEM, and the server de-encapsulates the derived session key; and the two parties send Finished messages to each other to complete handshake. According to the scheme, on the premise that a TLS1.2 basic framework is not changed, the communication security is enhanced through double-resistance quantum algorithm integration, international and national cryptographic algorithms are supported, quantum computing attacks can be resisted, meanwhile, adaptation of the international and national cryptographic algorithms is supported, compatibility with an existing system is ensured, the security risk of a traditional cryptographic algorithm in a quantum environment is solved, and the security risk of the traditional cryptographic algorithm in the quantum environment is reduced. And a standardized solution is provided for anti-quantum upgrade of the TLS1.2 protocol.
Owner:BEIJING SKYFAITH TECH CO LTD

Distributed key management and encryption communication method oriented to big data environment

The invention relates to the technical field of network security, in particular to a distributed key management and encryption communication method oriented to a big data environment. The method comprises the following steps: establishing a system architecture and configuring safety parameters; generating a master key and a session key through the random number; segmenting the master key into a plurality of segments and storing the segments to different nodes; encrypting the session key by using the public key of the receiver, distributing the session key through the secure channel, and decrypting the session key by the receiver to obtain the session key; constructing a Merkle tree through an AES-GCM function, and introducing a network adaptation factor into an encryption process by considering that security requirements and network conditions of data encryption in different environments are different; and regularly updating a secret key, implementing an access control strategy, and recording a log to perform system audit so as to guarantee long-term security. According to the invention, the efficient AES-GCM encryption algorithm is used, so that the speed and security of data encryption are improved. By implementing the access control strategy, only the authorized user can access and operate the key, and the security of the system is improved.
Owner:ZHENGZHOU DAXUAN ELECTRONICS TECH CO LTD

Forward security strategy hidden attribute-based keyword search method

The invention relates to the technical field of information security, in particular to a forward security policy hidden attribute-based keyword search method, which is used for access control and search of sensitive information and comprises the following steps: acquiring a public parameter and a master key; attribute processing is performed on an attribute set submitted by a data user, a user private key is constructed, and a puncture key is output; the method comprises the following steps: randomly selecting a symmetric key, performing symmetric encryption on a plaintext through the symmetric key to obtain an initial ciphertext, sequentially performing strategy hidden encryption, keyword encryption and label binding on the plaintext to obtain a corresponding output representation, and integrating the initial ciphertext and the output representation to obtain a complete ciphertext; when the constraint condition is met, the puncture key is updated; establishing a keyword set according to the data user demand content, generating a trap door, and initiating a search request; matching the trap door with the complete ciphertext according to the search request to obtain a matching result, and decrypting the initial ciphertext by integrating the updated puncture key and the user private key to obtain a corresponding plaintext; and the forward safety is effectively improved.
Owner:NANJING UNIV OF POSTS & TELECOMM

Dynamic double-layer hidden watermark and encryption binding file protection method and system based on deep learning

The invention relates to a dynamic double-layer hidden watermark and encryption binding file protection method and system based on deep learning, and belongs to the technical field of digital content security. The problems of attack resistance, traceability obstruction and key-watermark unhooking in document cross-platform circulation are solved. According to the scheme, the method comprises the following steps of: extracting semantic fingerprints by using a sentence vector model Sentence-BERT; the fuzzy extractor generates a master key and derives a time key chain; the authentication encryption algorithm AEAD encrypts and binds the source and the timestamp load; container layer structure rearrangement and document layer zero-width character double embedding are carried out; the generative adversarial network or diffusion model adversarial training improves the optical character recognition and transcoding resistance; version binding and tracing are achieved through the watermark hash chain. The technical effects cover anti-counterfeiting migration, cross-layer fault-tolerant guarantee recoverability, rearrangement attack resistance, full-period accurate traceability and post-quantum security enhancement.
Owner:SOUTHWEST UNIV

Method and system for safely sharing operation data of low-altitude unmanned aerial vehicle

The invention provides a low-altitude unmanned aerial vehicle operation data security sharing method and system, and the method comprises the steps: initializing a low-altitude unmanned aerial vehicle operation data security sharing system through a low-altitude traffic management platform, and generating a public parameter, a master key and an identity private key of a user; wherein the master key comprises a master public key and a master private key; the unmanned aerial vehicle encrypts the operation data of the unmanned aerial vehicle based on the identity information of the agent side to obtain an initial ciphertext, and uploads the initial ciphertext to the cloud platform; the agent side decrypts the initial ciphertext based on an identity private key of the agent side to obtain operation data of the unmanned aerial vehicle, generates a re-encryption key and uploads the re-encryption key to the cloud platform; the cloud platform re-encrypts the initial ciphertext based on the re-encryption key to generate a re-encrypted ciphertext; and the multi-body sharer end decrypts the re-encrypted ciphertext based on the identity private key of the multi-body sharer end to obtain the operation data of the unmanned aerial vehicle. According to the invention, the sharing security of the operation data of the unmanned aerial vehicle in a dynamic open network environment can be efficiently guaranteed.
Owner:HANGZHOU INNOVATION RES INST OF BEIJING UNIV OF AERONAUTICS & ASTRONAUTICS

Data storage security protection method and system based on solid state disk

The invention relates to the field of computer security, and discloses a data storage security protection method and system based on a solid-state hard disk, which comprises the following steps: identifying the inherent physical difference of a flash memory chip in the solid-state hard disk so as to calculate the read-write time sequence micro-deviation of the solid-state hard disk; performing hash operation on the device root key and the unique identifier of the controller corresponding to the solid state disk to obtain a bound master control key; generating a temporary encryption key of the write-in operation to encrypt plaintext data of the host system to obtain ciphertext data; writing the ciphertext data into a flash memory physical page corresponding to the physical page address to obtain a ciphertext physical page address; when the access mode is a hostile attack mode, secretly updating the ciphertext physical page address into a new physical page address, and deleting the ciphertext physical page address; and when the access mode is a secure access mode and the verification key is consistent with the bound master control key, normal loading and data access requests of the solid state disk are allowed. According to the invention, the security and integrity of data storage can be improved.
Owner:深圳市彦胜科技有限公司

Symmetric encryption for private smart contracts among multiple parties in a private peer-to-peer network

Features for providing a secure method of symmetric encryption for private smart contacts among multiple parties in a private peer-to-peer network. The features include a master key representing a unique blockchain ledger. The master key may be shared among multiple participants in a private peer-to-peer network. Sharing of the master key may include communicating the master key in an encrypted message (e.g., email) using public key infrastructure (PKI). In some implementations, more complex distribution features may be includes such as quantum entanglement. The features support instantiation of a smart contract using a specific master key. The request may be submitted as an entry to the ledger with appropriate metadata and / or payload information for identifying and processing the request.
Owner:EXPERIAN INFORMATION SOLUTIONS INC

Urban inspection data sharing method and device based on unmanned aerial vehicle

The invention discloses a city inspection data sharing method and device based on an unmanned aerial vehicle, and the method comprises the steps: firstly determining an inspection time period when the inspection data needs to be shared, and collecting the position, speed, signal and meteorological data set of the unmanned aerial vehicle in the time period according to a preset sampling frequency; after all the data sets are aligned through timestamps, features are extracted respectively to form multi-dimensional feature vectors; converting the multi-dimensional feature vector into a one-dimensional array, and generating a hash feature value through a hash algorithm in combination with a timestamp and a random number; extracting a master key and an authentication key from the hash feature value, generating an initialization vector based on the master key, binding the master key, the authentication key and a timestamp, and then distributing the three to a receiver; inspection data is divided into blocks, a number and a timestamp are added to each block, encryption is performed by using a master key and an initialization vector, an authentication tag is generated in combination with an authentication key, and a data packet is packaged and then transmitted. According to the invention, the problem of low security during routing inspection data sharing of the unmanned aerial vehicle in the prior art is solved.
Owner:YIKONG UAV TECHNOLOGY (JIANGXI) CO LTD

Rail transit-oriented soft information codeword reconstruction security key extraction method and system

The invention discloses a rail transit-oriented soft information codeword reconstruction security key extraction method and system, and relates to the field of digital information transmission, in the method, a sending end and a legal receiving end alternately send pilot frequencies to each other through a preset channel, and calculate a channel feature sequence of the preset channel; the sending end generates a master key from a preset random source, and encodes the master key to obtain a code word sequence; the sending end generates an information interaction sequence according to the first feature sequence and the code word sequence, and sends the information interaction sequence to a legal receiving end; after the legal receiving end receives the information interaction sequence, the legal receiving end reconstructs the second feature sequence according to the information interaction sequence to obtain a code word structure sequence; and the legal receiving end decodes the code word structure sequence to obtain a final key. The method and the device are used for improving the consistency rate of the secret keys among the legal users, so that the secret key generation and extraction efficiency is improved, and the safety of a rail transit system is improved.
Owner:卡斯柯信号(西安)有限公司 +1

Quantum cipher migration resisting method and system, electronic equipment and storage medium

The invention relates to an anti-quantum password migration method and system, electronic equipment and a storage medium, and belongs to the technical field of anti-quantum data transmission. The method comprises the following steps: carrying out adaptive expansion on a transport layer security protocol; the encryption end and the decryption end perform secure transmission of the application data based on the expanded transport layer security protocol, and the secure transmission process of the application data comprises the following steps: generating a master key, a multi-level sub-key and a path key chain according to a chain type post-quantum key generation mechanism based on the expanded cipher suite; the encryption end generates an encryption key through a part of the sub-keys, encrypts application data in a symmetric encryption mode to generate a ciphertext, and sends the ciphertext and a path node key at the tail end of the path key chain to a decryption end; and the decryption end verifies the path node key, generates a decryption key by using part of the sub-keys after the verification of the path node key is passed, and decrypts the ciphertext. According to the invention, the security and high efficiency of data transmission in the anti-quantum cryptography migration process are realized.
Owner:RELATED (BEIJING) TECHNOLOGY CO LTD

Anti-quantum identification signature method based on lattice SIS problem

The invention provides an anti-quantum identification signature method based on an on-lattice SIS problem. The method comprises the following steps: selecting system safety parameters and other related system parameters; generating a system public parameter and a master key by using the system security parameter and other related system parameters; generating a corresponding public and private key pair by using the user identity ID; the user generates a signature of the message by using the private key; and the verifier verifies the validity of the signature by using the system parameters and the user public key. According to the method, a lattice-based digital signature scheme is constructed by utilizing an SIS difficulty problem on a middle lattice, and quantum attack resistance security is provided for an information system for deploying the algorithm scheme; personal identity information of the user is used for registering and generating public and private keys, the key escrow problem participated by a third party is relieved, and the privacy security of the user is improved.
Owner:GUIZHOU UNIV +1

Optical network mutual backup video data encryption method and system based on distributed system

The invention discloses an optical network mutual backup video data encryption method and system based on a distributed system, and belongs to the field of data encryption. The method comprises the following steps: generating a node trust evaluation value by acquiring optical network topology data including link state parameters and edge node dynamic load parameters; and adopting a distributed consensus protocol to screen edge nodes meeting the dynamic load fluctuation range and the trust evaluation value threshold as encrypted cooperative nodes. And generating a master key segmentation factor based on the node trust value, splitting the master key into sub-key fragments, partitioning optical network mutual backup video data, and binding and encrypting the partitioned optical network mutual backup video data with the sub-keys to form mutual backup encrypted data blocks, thereby realizing redundant storage of heterogeneous nodes across physical locations. According to the method, the initial encryption path is constructed according to the link state parameters, the transmission priority is dynamically disturbed by using the chaotic mapping sequence, the target encryption path adaptive to the storage requirement is generated, and finally the encrypted data blocks are distributed to the heterogeneous nodes through the path, so that the encryption efficiency and the data redundancy storage reliability can be improved.
Owner:BEIJING ZHAOKE HENGXING SCI & TECH CO LTD

Privacy number-based traceable secure communication method, device and equipment

The invention relates to a traceable security communication method, device and equipment based on a privacy number, and belongs to the technical field of communication processing, and the method realizes credible storage of communication data by obtaining a communication record and generating a distributed unique identifier, adopting an SM2 algorithm for signature and writing evidence data into a block chain. Meanwhile, the preset master key is subjected to fragmentation processing, a plurality of sub-key fragments are generated, the storage position is determined, and the session key is generated by adopting an SM4 algorithm to perform end-to-end encryption on the communication content, so that the communication security is guaranteed. Besides, a zero-knowledge proof protocol is introduced for identity verification, dynamic risk assessment and an authority fusing mechanism are combined, high-risk communication is effectively prevented, multiple cryptography technologies and safety mechanisms are comprehensively applied, and safety, credibility and auditing performance of the communication process are comprehensively improved.
Owner:HANGZHOU RONGXUAN INFORMATION TECH CO LTD

Rekeyable lock cylinder

A rekeyable lock cylinder with a cylinder body, an inner sleeve, and a plug assembly is provided. The plug assembly includes a plurality of key followers and a corresponding plurality of first racks and second racks disposed in carriers. The first racks correspond to operation of a user key and the second racks correspond to operation of a master key. As such, the lock cylinder is usable in a user / master key system. Disengaging either of the first or second racks from the key followers allows rekeying of the lock cylinder for the user key or the master key.
Owner:ASSA ABLOY AMERICAS RESIDENTIAL INC

Internet of Things puncturable attribute-based encryption method based on block chain and Bloom filter

The invention discloses an Internet of Things puncturable attribute-based encryption method based on a block chain and a Bloom filter, and is used for solving the problems of low dynamic permission revocation efficiency and difficult operation auditing in an Internet of Things environment. The method realizes a core function through the following steps: an authorization mechanism initializes system parameters and segments a master key; a data owner defines an access strategy and initializes the Bloom filter during encryption; when the permission is revoked, a puncture tuple containing a label binding component, a strategy binding component and a cross validation component is generated, and the ciphertext is updated after verification of a block chain smart contract; and during decryption, the cloud server firstly screens the validity of the user tag through a Bloom filter, and then decrypts the data in combination with an attribute strategy. The method has the advantages that the complexity of puncture verification is reduced by the Bloom filter, and the resource consumption is remarkably reduced; two-factor binding and cross validation ensure that puncture operation cannot be forged; and the block chain completely records key generation, puncture and decryption operations, so that operation transparency and auditing performance are realized.
Owner:GUILIN UNIV OF ELECTRONIC TECH

Identity authentication method and system based on national secret algorithm

The invention discloses an identity authentication method and system based on a national secret algorithm, and the method comprises the steps: building a hierarchical key management system based on a national secret IBE framework, generating a system master key pair through employing an SM2 algorithm, and achieving a decentralized key distribution mechanism; constructing a domain perception differential privacy protection module, defining a privacy budget allocation strategy according to the security level, and adding calibrated Laplace noise to the user identity feature vector; designing a distributed batch matrix multiplication protocol, and decomposing the distributed batch matrix multiplication protocol to a plurality of computing nodes for parallel processing through a secret sharing technology; a zero-knowledge proof verification mechanism is implemented, and identity verification is completed through a commitment scheme based on an SM3 hash algorithm; deploying a self-adaptive key updating strategy, and analyzing threat level change through a threat situation evaluation function; and establishing a secure communication channel based on SM4 symmetric encryption, and performing encryption processing by using the temporary session key. The security and expandability of the system are improved, the privacy of the user is effectively protected, and the system adapts to a dynamically changing network threat environment.
Owner:GUIZHOU BLUESKY INNOVATIVE SCI & TECH CO LTD

Auditable master secrets and key vault

Systems and techniques are provided for generating cryptographic keys. For instance, a process may include generating a plurality of master keys based on a plurality of generated random numbers, a second number, and a nonce number; storing a master key, of the plurality of master keys, along with a generated random number of the plurality of generated random numbers, the second number, and the nonce number used to generate the master key in a one-time programmable memory; generating public key-private key pairs for the plurality of master keys; transmitting public keys of the plurality of public key-private key pairs for audit; destroying an audited master key, along with the generated random number, second number, and the nonce number used to generate the audited master key, based on the audit; and storing a non-audited public key-private key pair corresponding to the master key that were not destroyed based on the audit.
Owner:QUALCOMM INC

System and method for providing secure can communication

The present disclosure provides systems and methods for providing secure CAN communications. Exemplary embodiments of the present disclosure provide secure CAN communication between vehicle components. According to an embodiment, a method for providing may include: generating, by at least one processing unit of a transmitter, a one-time password (OTP); acquiring, by at least one processing unit of the transmitter, a master key provided in advance to the transmitter and the receiver; deriving, by at least one processing unit of the transmitter, a shared key based on the OTP and the master key; generating, by at least one processing unit of the transmitter, a message authentication code (MAC) based on the derived shared key; attaching, by at least one processing unit of the transmitter, the MAC to the message; and transmitting the attached message to the receiver via the CAN bus by at least one processing unit of the transmitter.
Owner:TOYOTA JIDOSHA KK

Encryption and decryption method and system fusing quantum key and secret sharing, and medium

The invention relates to the technical field of information security, and discloses an encryption and decryption method and system fusing a quantum key and secret sharing, and a medium. According to the encryption and decryption method, a QKD method is adopted to generate a master key and a data encryption key, the master key is divided into a plurality of encryption fragments under the condition of encryption operation, storage nodes of the plurality of encryption fragments are determined by a dynamic method, enough encryption fragments are obtained under the condition of decryption operation, the master key and the data encryption key are recovered, and the encryption and decryption efficiency is improved. Therefore, the decryption of the data is realized. According to the encryption and decryption method, the master key and the data encryption key are generated based on the QKD device, hierarchical protection is formed, a secret sharing algorithm is set to be combined with a Hash dynamic method, storage nodes of encryption fragments are automatically migrated, targeted attacks are resisted, the data security of a database is guaranteed, the master key is obtained through a Lagrange interpolation method, the decryption efficiency is high, and the encryption and decryption efficiency is high. And the recovery time is controllable.
Owner:STATE GRID ANHUI ELECTRIC POWER CO LTD +1

Data secrecy method, device, equipment, medium and program product

The invention provides a data secrecy method which can be applied to the technical field of information security. The data secrecy method comprises the following steps: acquiring an internal master key plaintext, a first external key plaintext and a second external key plaintext from a local table; based on the internal master key plaintext, the first external key plaintext and the second external key plaintext, an internal encryption key ciphertext is decrypted to obtain an internal encryption key plaintext, and the first external key and the second external key are generated by an external device; and encrypting disk data based on the internal encryption key plaintext to obtain storage data. The invention further provides a data secrecy device and equipment, a storage medium and a program product.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Encryption method and device suitable for large file, computer equipment and storage medium

The invention discloses an encryption method and device suitable for a large file, computer equipment and a medium, and the method comprises the steps: segmenting a to-be-encrypted large file into a plurality of sub-data blocks according to a preset rule, and coding each sub-data block to obtain an index value of each sub-data block; generating a master key, and generating a sub-data key corresponding to each sub-data block based on the index value of each sub-data block and the master key; based on the sub-data key corresponding to each sub-data block, performing encryption processing on each sub-data block to obtain a plurality of encrypted sub-data blocks; obtaining a check chain value of the to-be-encrypted large file based on each encrypted sub-data block; and merging the plurality of encrypted sub-data blocks and the check chain value to obtain a ciphertext of the to-be-encrypted large file. According to the method, association between blocks can be effectively cut off, the key leakage risk can be effectively reduced, the encryption strength is enhanced through the dynamic sub-keys, memory overflow is avoided through block processing, the security, reliability and processing efficiency of large file encryption are improved, and the requirements of large file secure storage and transmission are met.
Owner:ASPIRE TECH (SHENZHEN) LTD