Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

584 results about "Plaintext" patented technology

In cryptography, plaintext usually means unencrypted information pending input into cryptographic algorithms, usually encryption algorithms. Cleartext usually refers to data that is transmitted or stored unencrypted ('in the clear').

Large model service security verification method and device, medium, equipment and product

A security verification method, apparatus, medium, device and product for a large model service relate to the technical field of computers, receive an encryption service request, acquire a private key of a client from a key management service running in a trusted execution environment through an encryption and decryption service running in the trusted execution environment, decrypt the encryption service request based on the private key, and verify the security of the encryption service request. The method comprises the following steps: decrypting a service request of a user, sending the decrypted service request to a large model service to obtain a reasoning result of the large model service, encrypting the reasoning result through a public key of a client, and returning the encrypted reasoning result to the client, so that the service request of the user can be visible in a plaintext in a trusted execution environment; the security of the user data is greatly ensured, and the problem of user data leakage can be avoided through the public and private key pair of the user dimension. In addition, the key management service and the encryption and decryption service both run in the trusted execution environment, so that attacks from an IaaS layer can be shielded.
Owner:BEIJING VOLCANO ENGINE TECH CO LTD

Data storage security protection method and system based on solid state disk

The invention relates to the field of computer security, and discloses a data storage security protection method and system based on a solid-state hard disk, which comprises the following steps: identifying the inherent physical difference of a flash memory chip in the solid-state hard disk so as to calculate the read-write time sequence micro-deviation of the solid-state hard disk; performing hash operation on the device root key and the unique identifier of the controller corresponding to the solid state disk to obtain a bound master control key; generating a temporary encryption key of the write-in operation to encrypt plaintext data of the host system to obtain ciphertext data; writing the ciphertext data into a flash memory physical page corresponding to the physical page address to obtain a ciphertext physical page address; when the access mode is a hostile attack mode, secretly updating the ciphertext physical page address into a new physical page address, and deleting the ciphertext physical page address; and when the access mode is a secure access mode and the verification key is consistent with the bound master control key, normal loading and data access requests of the solid state disk are allowed. According to the invention, the security and integrity of data storage can be improved.
Owner:深圳市彦胜科技有限公司

Security data isolation and information exchange method and system based on lightweight protocol

The invention relates to a security data isolation and information exchange method and system based on a lightweight protocol, belongs to the technical field of industrial automation control system security, and solves the technical problems of low transmission efficiency, high analysis overhead, high security risk and high resource consumption of an existing method. Comprising the following steps: collecting and preprocessing original plaintext data at an industrial control network side; an external unit identifier, a timestamp and a pre-shared key on the industrial control network side are used as encryption factors, lightweight stream cipher encryption and packaging are carried out on the preprocessed data, and a lightweight protocol data packet is generated; through a special physical isolation device, the light-weight protocol data packet subjected to deep detection is unidirectionally isolated and ferried from an industrial control network side to an internal network side; performing post-processing on the received lightweight protocol data packet at the intranet side to restore original data; and delivering the restored original plaintext data to an intranet service application. And safe and efficient information data exchange is realized.
Owner:BEIJING JINGHANG COMPUTING & COMM RES INST

Quantum security signature method and device, equipment, medium and program product

The invention provides a quantum security signature method which can be applied to the technical field of quantum communication. The quantum security signature method comprises the following steps: in response to a received quantum security signature request for target plaintext data, performing risk assessment on the quantum security signature request according to a preset security policy, and determining a risk level corresponding to the quantum security signature request; determining a target post-quantum signature algorithm and an algorithm parameter set corresponding to the quantum security signature request according to the risk level; according to the algorithm parameter set, performing dynamic function reconstruction on the computing resource for executing the signature operation to obtain the reconstructed computing resource; and performing quantum security signature on the target plaintext data by using the reconstructed computing resources and a target post-quantum signature algorithm to obtain a quantum security signature result. The invention further provides a quantum security signature device and equipment, a storage medium and a program product.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Solid state disk controller circuit and solid state disk

The invention relates to the technical field of electric digital data processing, and discloses a solid state disk controller circuit and a solid state disk. The controller circuit comprises a physical unclonable function unit based on an SRAM (Static Random Access Memory), which is used for dynamically generating a stable hardware trust root key during power-on; the secure boot and firmware decryption engine is used for deriving a firmware decryption authentication key and a data key packaging key by using the key, and carrying out decryption and integrity verification on the encrypted firmware; the runtime firmware execution monitoring unit is used for detecting illegal jump in real time and triggering safe shutdown through a hardware-level control flow diagram; and the dynamic data encryption key management unit recovers the plaintext data key and sends the plaintext data key to the encryption engine only during operation, and power failure disappears. By means of the scheme, end-to-end security protection of firmware and data is achieved, and the risks of static key leakage and firmware tampering are eradicated.
Owner:深圳市彦胜科技有限公司

Precision-controllable lattice-based homomorphic encryption inner product data similarity retrieval method and system

The invention provides a controllable-precision lattice-based homomorphic encryption inner product data similarity retrieval method and system, and relates to the technical field of privacy calculation and security retrieval. The retrieval terminal performs polynomial coding on the retrieval vector to obtain a retrieval plaintext polynomial; performing lattice-based homomorphic encryption on the retrieval plaintext polynomial to obtain a retrieval ciphertext; the server performs homomorphic multiplication on the retrieval ciphertext and the data ciphertext to obtain a discrimination ciphertext; the retrieval terminal decrypts the discrimination ciphertext; determining whether retrieval matching succeeds or not based on the constant term coefficient of the decryption polynomial; the data ciphertext is obtained based on lattice-based homomorphic encryption of a data plaintext polynomial; the data plaintext polynomial is obtained by encoding a polynomial of the data feature vector based on a similarity threshold; the constant term coefficient of the product of the data plaintext polynomial and the retrieval plaintext polynomial is equal to the difference between the inner product of the data feature vector and the retrieval vector and the similarity threshold. The problem that traditional searchable encryption only supports accurate matching and easily leaks query intentions is solved.
Owner:STATE GRID ANHUI ELECTRIC POWER CO LTD +1

Attribute-based encryption system for selective document security

The present disclosure provides a method for selectively encrypting and decrypting portions of a document. The method includes receiving a document containing plaintext, analyzing the document using an artificial intelligence system to identify portions containing sensitive information, assigning predefined security levels or attributes to the identified portions, sending an encrypt file content request to a cryptographic engine, receiving an encrypted file content response, building an encrypted document by replacing portions with masking symbols and storing encrypted portions as metadata, and sending the encrypted document to a client device. The artificial intelligence system uses machine learning models trained on domain-specific data and employs pattern recognition and contextual analysis to identify sensitive content based on semantic understanding and classification rules.
Owner:NTT RESEARCH INC

Random tag linear homomorphic signature electronic voting method and system based on algebraic group model

The invention discloses an electronic voting method which comprises the following steps: selecting a group G meeting a cryptographic security hypothesis, and determining a generator P and a prime order p; splitting the ElGamal encryption private key into an election committee layer private key and a terminal verification layer private key, and generating a layered public key and a layered key legality proof; and generating a signature key pair of a linear homomorphic signature with a randomized tag, generating the randomized tag and an initial signature for each vote plaintext in the legal vote plaintext set S, and forming a common reference string CRS and disclosing the common reference string CRS. Executing pre-verification based on the terminal public key, generating an intermediate ElGamal ciphertext and a pre-verification proof, and superposing the intermediate ElGamal ciphertext and the pre-verification proof with the committee public key to generate a final ciphertext; an initial signature is obtained from the CRS and a valid signature is generated through linear combination. Verifying the pre-verification proof based on the terminal public key, and verifying the signature validity in combination with the committee public key; and re-randomizing the ciphertext and the signature, storing the ciphertext and the signature in a vote box, encrypting a vote counting result, and generating a decryption proof. According to the invention, the security and credibility of the electronic voting system are improved.
Owner:ZHEJIANG UNIV +1

Cooperative encryption and decryption method and system based on NTRU algorithm

The invention discloses a collaborative encryption and decryption method and system based on an NTRU algorithm, and relates to the field of data security, and the method comprises the steps: a client and a server respectively generate local keys based on the NTRU algorithm, and cooperatively generate a global public key; the secret key comprises a part of private key of the client, a part of public key of the client, a part of private key of the server and a part of public key of the server; encrypting a plaintext message to be encrypted by using the global public key to generate a ciphertext; the server decrypts the ciphertext by using a local part of private keys to obtain a part of plaintext; and the client decrypts the partial plaintext by using the local partial private key to obtain a complete ciphertext. According to the application, the risk of key leakage can be reduced, the data security is improved, and the hardware purchase and maintenance cost can be reduced.
Owner:BEIJING RENXINZHENG TECH CO LTD

SQLite database transparent encryption method, system and device based on national cryptographic algorithm and storage medium

The invention relates to the technical field of database security, in particular to an SQLite database transparent encryption method, system and device based on a national cryptographic algorithm and a storage medium, and the method comprises the following steps: S1, when an SQLite database is opened, loading and connecting a hardware cryptographic device to obtain an encryption master key and a corresponding key handle; s2, in response to the write-in operation, calling a national secret symmetric encryption algorithm through a key handle, encrypting a plaintext of a database page to generate a page, and writing the page into a database file; s3, reading the ciphertext page in response to the reading operation, decrypting the ciphertext page through a cryptographic symmetric decryption algorithm adjusted by a key handle after analysis, recovering a plaintext page and returning the plaintext page to the application; and S4, circularly executing encryption writing and decryption reading to process the continuous request, and releasing the key handle and disconnecting the hardware connection until the database connection is closed. According to the method, transparent full disk encryption, meeting the national secret standard, of the SQLite database is achieved, the secret key safety and the operation performance are guaranteed through hardware cryptographic equipment, and good application compatibility is kept.
Owner:SUPCON TECH CO LTD

Wireless communication data storage method and system

The invention belongs to the technical field of wireless communication and data transmission, and relates to a wireless communication data storage method and system, and the method comprises the steps: a transmitting end packages original service data into a structured data frame, generates an implicit integrity fingerprint, carries out the parametric coding of a key field through employing the fingerprint as an index, and carries out the storage of the key field; the coding field and the other plaintext fields are combined into a composite transmission frame, related data in a memory of a sending end are cleaned after sending, and a receiving end analyzes the received frame, reconstructs and verifies the implicit fingerprint and generates a trusted data packet; if the transmission or verification fails, directional decoding and verification are carried out on the retransmission data based on the confirmed fingerprint value, and an updated trusted data packet is generated; according to the method, the problems that the effective load rate is reduced due to the fact that an explicit check field must be added in a traditional scheme, the system stability risk is caused due to the fact that a sending end occupies a limited memory for a long time to support retransmission, and the wireless bandwidth and node power consumption extra burden is caused by a complete frame retransmission mode are solved.
Owner:SHENZHEN NEW TIME COMMUNICATIONS CO LTD

Java JAR packet encryption protection method and device, equipment and medium

The invention discloses a Java JAR packet encryption protection method and device, equipment and a medium, and the Java JAR packet encryption protection method comprises the steps: splitting a JAR packet decryption key into two fragments, and statically storing the two fragments in a starter program and a dynamic link library in a nonlinear confusion structure, thereby avoiding the exposure of a key plaintext. During starting, the starter transmits the first secret key fragment to the dynamic link library through secure inter-process communication, and the first secret key fragment is combined with the second fragment in the memory to restore a complete secret key. And during class loading, the Java agent intercepts a request and transmits an encrypted class byte code to the dynamic link library through the JNI, the encrypted class byte code is decrypted by using the restored key, and a plaintext is returned for loading. According to the method, static decompilation and dynamic memory dump attacks are prevented, and the anti-reverse and anti-leakage capabilities of Java software in a privatized deployment environment are remarkably improved.
Owner:SHENZHEN JIMI SOFTWARE CO LTD

Block chain data encryption query method and device, equipment and medium

The invention relates to the technical field of block chains, and discloses a block chain data encryption query method, device, equipment and medium, the method comprises the following steps: extracting data content information of to-be-chained data, using a homomorphic encryption algorithm to encrypt the data content information to obtain ciphertext content information; taking the ciphertext content information and the corresponding ciphertext hash value as on-chain evidence storage data to be stored in a block chain in a chaining manner; performing association mapping on the on-chain evidence storage data and the ciphertext access rule through the smart contract to generate an authority association rule corresponding to the on-chain evidence storage data; performing permission verification on the access permission in the data query request based on a permission association rule; after the permission verification is passed, querying the on-chain evidence storage data in a homomorphic encryption state according to the data query request to obtain an encrypted query result; and decrypting the encrypted query result to obtain target plaintext query data. The reliability of data encryption query can be improved.
Owner:CHINA MERCHANTS FINANCE HLDG CO LTD

Program code processing method and related equipment

The invention discloses a program code processing method and related equipment. The program code processing method and the related equipment are used for remarkably reducing character string decryption overhead during operation while ensuring the safety of character strings. The method comprises the following steps: traversing a target program code to obtain each constant character string in the target program code; generating a static field corresponding to each constant character string in a static character string container; replacing the reference to the constant character string in the target program code with the reference to the static field corresponding to the constant character string in the static character string container; performing obfuscation processing on the target program code subjected to reference replacement, and encrypting a static field in the target program code; and running the obfuscated target program code, and if the target program code executes the reference to the static field, obtaining a character string plaintext corresponding to the static field through an access instruction to the static field.
Owner:KINGDEE SOFTWARE(CHINA) CO LTD

Low-overhead anti-power analysis AES algorithm mask protection method

The invention discloses a low-overhead anti-power analysis AES (advanced encryption standard) algorithm mask protection method. According to the method, two shares of a plaintext and a secret key are received in a clock period 0, ten rounds of round functions are executed from the clock period 0 to the clock period 30, each round needs three clock periods, and two shares of a ciphertext are output in a clock period 31; in the implementation of a round function and key expansion, the calculation of an S box (not including input linear mapping) needs three clock periods; in the third clock period after S box calculation is completed, a round of residual operation (wherein the residual operation of a round function comprises a multiplication module of the S box, S box output linear mapping, row shifting, column confusion and round key addition, and the residual operation of key expansion comprises key word XOR generation of a next round of round key) and the next round of S box input linear mapping calculation are completed at the same time. According to the mask, the side channel security capability of first-order power consumption analysis resistance can be provided for the AES algorithm, and the requirements on random numbers and chip area are remarkably reduced.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI

Unified password service method and system supporting cross-level sharing

The invention discloses a unified password service method and system supporting cross-level sharing. The method comprises the following steps: generating a root key in a hardware security module HSM cluster; generating a key encryption key KEK in the HSM cluster based on the root key; generating a data encryption key DEK based on the KEK; the API gateway receives an encryption request sent by the service application, and performs identity authentication and authority authentication; the cryptographic operation service instance calls a key management service (KMS); the KMS obtains the stored corresponding encrypted DEK and the associated KEKID from a distributed database according to the target key ID; decrypting the encrypted DEK by using the KEK corresponding to the KEKID through the HSM; the KMS encrypts the plaintext data by using the plaintext DEK to obtain ciphertext data; the superior tenant grants the access permission of the target key to the corresponding subordinate tenant through the key sharing interface, and a sharing relation is recorded in a key permission table; according to the invention, key plaintext storage and exposure risks are fundamentally eliminated.
Owner:SHENZHEN HUASHENG JIUSI TECH CO LTD

Hadoop tenant-level encryption isolation implementation method and device

The invention discloses a Hadoop tenant-level encryption isolation implementation method, and aims to solve the problems of single key leakage risk, namespace planarization, encryption area unauthorized binding, no tenant dimension auditing and the like existing in an existing Ranger-KMS scheme. The method comprises the following steps: creating an independent master key for each tenant to realize physical isolation; the key alias, the encryption area paths and the strategy resources are forced to carry tenant prefixes, and the consistency is verified; a tenant context is transmitted through a thread local variable; when an encryption area is created, tenant attributes are persisted, and operation consistency is verified; and the key plaintext is only stored in the KMS memory and is safely reset after being used. According to the method, full-dimension isolation of keys, data, strategies and auditing is realized, single-tenant key leakage does not influence the cluster, unauthorized access and information leakage are completely eradicated, compliance auditing requirements are met, single-cluster multi-tenant safe coexistence is supported, and hardware cost is reduced.
Owner:CHINA ELECTRONICS CLOUD DIGITAL INTELLIGENCE TECH CO LTD

Bootstrapping of fully homomorphic encrypted ciphertexts based on non-cyclotomic rings

A processor-based method comprising: bootstrapping a first ciphertext that is a fully- homomorphic encryption of a plaintext, the plaintext being representable as a vector of coefficients of a polynomial, the bootstrapping comprising: obtaining, from the first ciphertext, an encryption of data indicative of one or more coefficients of the plaintext; based on a bootstrapping key, performing Torus-fully-homomorphic-encryption (TFHE) bootstrappings on the obtained encryption of data, the bootstrappings resulting in one or more bootstrap outputs; deriving, from the bootstrap outputs, a series of one or more encrypted values, each value of the series being based on a coefficient of a respective term of a polynomial; and creating, from, at least, a key-switching-key and the derived series of encrypted values, data indicative of a ring-based or module-based ciphertext, resulting in a second ciphertext that is an encryption, with reduced noise, of the data indicative of one or more coefficients of the plaintext.
Owner:DWALLET LABS LTD

Method for homomorphic encryption with low noise growth

The present invention relates to a method for homomorphically encrypting general plaintext spaces with controlled noise growth, comprising: a general plaintext space by selecting a polynomial of degree greater than 1, and defining the plaintext space as formula (I), where f(x) and t(x) are polynomials; applying an encoding method on a message and producing a corresponding element in the plaintext space Rt; applying a homomorphic encryption method that takes the encoded message as input and returns a ciphertext that encrypts the message; providing a decryption method that takes the ciphertext as input and returns the decoded plaintext; applying a method to homomorphically process encrypted messages by evaluating an arithmetic circuit representing the function to be evaluated, wherein the noise growth during homomorphic operations is determined by the size of; and applying a method to refresh ciphertexts via bootstrapping, which consists of homomorphically processing the decryption circuit.
Owner:KATHOLIEKE UNIV LEUVEN

Method for protecting parameters of a network model based on multiple keys

The application discloses a network model parameter protection method based on a multi-layer key, relates to the technical field of data protection, and calculates a low-entropy page upper limit at a single moment based on device parameters and a maximum layer scale of a model, and determines a page budget balance in combination with a remaining count of a previous round; in response to a hierarchical decryption request, if the balance is sufficient, a certain amount is deducted and a one-time session key is derived in combination with a device fingerprint; then, the assigned physical page is subjected to no-information-residue verification, after the verification, the parameter ciphertext is decrypted using the session key and written, and the current low-entropy page count is increased in real time; after the page is used up, forced overwriting and clearing verification are performed, after the verification, the page budget balance is backfilled and the low-entropy page count is reduced, and the one-time session key is destroyed; finally, a digital signature is generated and stored as evidence. The application establishes a budget gating and recycling mechanism, realizes dynamic limitation of the amount of plaintext in the runtime memory, and solves the exposure risk problem caused by full-decryption of model parameters of an edge device.
Owner:BEIJING DAOPOWER

Device and method for anti-counterfeiting and full-life-cycle management of filter element

The invention discloses a filter element anti-counterfeiting and full life cycle management device and method, and relates to the technical field of filter element anti-counterfeiting, the filter element anti-counterfeiting and full life cycle management device comprises a production management device, an anti-counterfeiting filter element is manufactured and produced by the production management device, the anti-counterfeiting filter element is installed on a whole water purifier, and the anti-counterfeiting filter element is used for filtering water flow discharged by the whole water purifier; the user module is connected with the whole water purifier, the user module is used for controlling the whole water purifier to quantitatively drain water, the cloud server is connected with the user module, and the cloud server is used for regulating and managing the whole water purifier and the anti-counterfeiting filter element through the user module. According to the filter element anti-counterfeiting and full-life-cycle management device, the two-dimensional code plaintext SN and the chip encryption SN are associated through the cloud end, the product is judged to be a certified product only when the two SN are matched and are not activated, the problem that a static two-dimensional code is easy to copy is solved, chip physical locking accumulated values are only accumulated and do not modify characteristics, and a host encryption instruction is combined, so that the anti-counterfeiting and full-life-cycle management of the filter element is realized. And the usage data are real and cannot be tampered.
Owner:ZHEJIANG QINYUAN WATER TREATMENT S T

A method and system for lightweight secure communication between in-vehicle network ECUs

ActiveCN121077828BIncrease communication delayImplement legality verificationKey distribution for secure communicationPublic key for secure communicationPlaintextCommunications security
The present application relates to the technical field of in-vehicle network communication, and discloses a lightweight and secure communication method and system between ECUs in an in-vehicle network. The communication method comprises an ECU identity authentication phase: each ECU interacts with a CAN gateway, and the CAN gateway performs batch identity authentication to verify the legality of all ECUs; a data classification phase: according to the data sensitivity, the data to be transmitted is classified as confidential data or non-confidential data; a data transmission phase: if the data to be transmitted is confidential data, the sender ECU uses a session key and an ASCON encryption algorithm to encrypt and authenticate the plaintext of the confidential data, generates ciphertext and authentication parameters, and sends a data packet containing the ciphertext and authentication parameters to the receiver ECU; if it is non-confidential data, the sender ECU uses a session key and an ASCON encryption algorithm to only sign but not encrypt the plaintext, generates an authentication tag, and sends a data packet containing the plaintext and the authentication tag to the receiver ECU. The present application takes into account the security and computational overhead of in-vehicle ECU communication.
Owner:HEFEI UNIV OF TECH

Federal learning privacy protection method for dynamic search hybrid encryption and contribution value perception

The invention relates to the technical field of federated learning and privacy protection, and discloses a federated learning privacy protection method for dynamic search hybrid encryption and contribution value perception, which mainly comprises the following steps of: constructing a privacy protection scheme of a local evaluation and hybrid encryption mechanism combined with contribution degree perception to realize differentiated privacy protection of client privacy data; the calculation time overhead and the communication overhead based on a single homomorphic encryption privacy mechanism are effectively reduced; a central storage server access control and dynamic key rotation mechanism driven by a security token is constructed, and key non-replay and historical data non-revealing are realized by combining a searchable relevance trap door index stored by a ciphertext; according to the method, on the basis of a security aggregation algorithm of contribution perception, the contribution value of each local model in a ciphertext state is evaluated by a joint secrecy calculation protocol, aggregation screening of a global model under the condition that the contribution value plaintext is not revealed is ensured, power dispersion of a central storage server is completed, and the overall efficiency and privacy of the system are remarkably improved.
Owner:KUNMING UNIV OF SCI & TECH

Homomorphic encryption device and method for control systems that discloses a portion of non-ptivate outcome

PendingKR1020260123872APlaintextAlgorithm
The present invention relates to a homomorphic encryption device that discloses only specific information of a control system, comprising: a ciphertext generation unit that generates a ciphertext by applying a predetermined encryption technique to an input signal of the control system; a ciphertext modification unit that modifies the ciphertext by adding a random number vector designed such that the random component of the ciphertext becomes zero; and a disclosure unit that calculates a residue signal in an encrypted state from the modified ciphertext and discloses a specific component of the residue signal as plaintext.
Owner:FOUND FOR RES & BUSINESS SEOUL NAT UNIV OF SCI & TECH +1

Smart home equipment and platform connection management method

The invention relates to a smart home device and platform connection management method, and belongs to the field of whole house intelligence, and the method comprises the steps: a platform configures a CTEI string code and an exclusive PIN code for each accessed device; the equipment establishes TCP connection with the platform, and requests to obtain the SM9 public key from the platform; the platform verifies the validity of the application instruction timestamp, the legality of the CTEI string code and the PIN code and the consistency of the HMAC-SM3 signature, and issues an SM9 private key; the device splices the CTEI string code and the device MAC address into a plaintext, encrypts and signs the plaintext, and submits the plaintext to the platform; and the platform verifies and signs the decrypted ciphertext, generates a temporary symmetric key, encrypts the temporary symmetric key and sends the encrypted temporary symmetric key to the equipment, the equipment decrypts the ciphertext to obtain the temporary symmetric key, and the equipment and the platform perform encryption and decryption transmission on the service data by using the temporary symmetric key. According to the method disclosed by the invention, through deep fusion design of the hardware identifier and the national cryptographic algorithm, a high-security-level equipment-platform connection system is constructed, and meanwhile, the management refinement level of the platform on the terminal equipment is improved.
Owner:E-SURFING DIGITAL LIFE TECH CO LTD

Ciphertext conversion system, ciphertext conversion method, and non-transitory computer readable medium

A ciphertext conversion system (100) includes a conversion key generation device (600) and a conversion device (700). The conversion key generation device (600) performs encryption of a public-key encryption scheme using a public key and a first decryption enabling condition, so as to generate a first converted public-key ciphertext and a key corresponding to the first converted public-key ciphertext, performs encryption of a symmetric-key encryption scheme using a second symmetric-key encryption secret key as a plaintext and the key corresponding to the first converted public-key ciphertext as a secret key, so as to generate a first partial conversion key, and calculates, as a second partial conversion key, an exclusive-OR of a result of performing encryption using a first symmetric-key encryption secret key and first auxiliary information and a result of performing encryption using the second symmetric-key encryption secret key and second auxiliary information. The conversion device (700) calculates, as at least part of a converted symmetric-key ciphertext, an exclusive-OR of a symmetric-key ciphertext and the second partial conversion key, where the symmetric-key ciphertext is an exclusive-OR of a plaintext and a result of performing encryption using the first symmetric-key encryption secret key and the first auxiliary information.
Owner:MITSUBISHI ELECTRIC CORP

A method for sending meter reading information and a meter transmission system

This application provides a method for sending meter reading information and a meter transmission system. The method includes: a concentrator initiating a meter reading request to the corresponding meter at predetermined intervals; upon receiving the request, if the mobile device is online, the meter sends a first ciphertext to the mobile device; the mobile device performs a second encryption on the first ciphertext using a second encryption algorithm and returns the resulting second ciphertext to the meter; the first ciphertext is generated by the meter using a temporary public key and the first encryption algorithm to encrypt plaintext meter reading data; the meter decrypts and verifies the second ciphertext using the private key corresponding to the temporary public key, and sends the second ciphertext to the concentrator after successful verification; the concentrator encrypts the second ciphertext to obtain a third ciphertext based on the number of re-reading attempts and the time the request was initiated, and sends the third ciphertext to the server. This method ensures the security of meter reading data transmission.
Owner:NANJING NENGRUI AUTOMATION EQUIP

Federated learning-based information big data privacy protection collection method and system

The present application relates to the technical field of federated learning, in particular to a federated learning-based information big data privacy protection collection method and system, comprising the following steps: calculating a privacy sensitivity coefficient according to data attributes, perturbing and recombining a privacy gradient according to the coefficient, calculating gradient bias variance to construct a node contribution table, performing secure weighted aggregation based on the contribution table and the privacy gradient, calculating an encryption parameter to generate a global ciphertext parameter set, updating a global model and constructing a privacy feedback table.In the present application, the sensitive coefficient is used to replace the original feature field operation by regulating the perturbation limit in the training stage, the underlying sample hidden distribution is maintained to completely block the security collapse caused by the aggregation of plaintext, the evaluation system is constructed by calculating the cross-period bias variance to perform weighted aggregation, the weight of the heterogeneous terminal is balanced to correct the evolution direction deviation, the dynamic encryption parameter is injected into the global sequence to establish a ciphertext lossless defense line to resist flow disassembly interception and monitoring.
Owner:JINING UNIV

Controllable image steganography method and system based on steganography diffusion model

The invention relates to the technical field of image information security, and discloses a controllable image steganography method and system based on a steganography diffusion model. Comprising the following steps: acquiring a hash value of a color plaintext image, and obtaining a plurality of random sequences according to the hash value and three-dimensional memristor chaotic mapping; decomposing the color plaintext image into three channel matrixes, and performing scrambling and diffusion operation on the channel matrixes based on a random sequence to generate a color ciphertext image; adding noise to the carrier image to obtain a preprocessed carrier image; obtaining a plurality of wavelet coefficient matrixes according to the preprocessed carrier image; generating a ciphertext-containing wavelet coefficient matrix according to the color ciphertext image and the wavelet coefficient matrix; performing inverse discrete wavelet transform on the confidential wavelet coefficient matrix to obtain a noisy and confidential carrier image; and de-noising the noisy and confidential carrier image by using the steganography diffusion model to generate a final confidential carrier image. According to the method, the visual quality of the carrier image can be ensured, steganography analysis is effectively resisted, and the image steganography safety is improved.
Owner:GUANGDONG OCEAN UNIVERSITY +1