Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

24 results about "Public-key cryptography" patented technology

Public-key cryptography, or asymmetric cryptography, is a cryptographic system that uses pairs of keys: public keys which may be disseminated widely, and private keys which are known only to the owner. The generation of such keys depends on cryptographic algorithms based on mathematical problems to produce one-way functions. Effective security only requires keeping the private key private; the public key can be openly distributed without compromising security.

Remote signature system and tamper resistant device

The present invention realizes a remote signature system in which identity verification is performed for each signing request by combining the remote signature system with public key cryptography. A terminal device (2) comprises a means for generating a key pair for authentication to perform the public key cryptography. A generated secret key is stored in the terminal device (2), and a generated public key is transmitted to the tamper resistant device (5) and is stored in relation with the corresponding signature key. The tamper resistant device comprises a signature key storage means (12) for storing the signature key, a decryption key and signature key identification information as pairs for each user. When requesting a digital signing, a signing request including the signature key identification information, plaintext verification information, and a crypto token including the encrypted verification information and the encrypted signature object data is created and is transmitted to the tamper resistant device (5). The tamper resistant device accesses to the signature key storage means (12) and searches both the decryption key and the signature key. The tamper resistant device decrypts the crypto token using the searched decryption key, and verifies consistency between the decrypted verification information and the plaintext verification information. If they do not match each other, the signing request is excluded from the digital signing.
Owner:KEY TECHNO CO LTD

Digital certificate request file generation and verification method supporting anti-quantum algorithm

The invention discloses a digital certificate request file generation and verification method supporting an anti-quantum algorithm. The method comprises the following steps that T1, a user generates a traditional public key password signature key pair, an anti-quantum password signature key pair and an anti-quantum password encryption temporary key pair; t2, the user calculates a hybrid public key, performs hybrid signature on the hybrid public key, generates a hybrid signature certificate request file, and sends the hybrid signature certificate request file to the certificate issuing system; t3, the user calculates a temporary key request message, performs hybrid signature on the temporary key request message, generates an anti-quantum encryption temporary key request file of the hybrid signature, and sends the anti-quantum encryption temporary key request file to the certificate issuing system; t4, the certificate issuing system verifies the mixed signature certificate request file; and T5, the certificate issuing system verifies the anti-quantum encryption temporary key request file of the mixed signature. The method not only has the capability of resisting the quantum computing attack, but also can ensure the compatibility with the existing traditional PKI facility, and meanwhile, the security of the certificate request process is remarkably improved.
Owner:HEBEI PRIME NUMBER INFORMATION SECURITY CO LTD

Certificateless signature generation method and system based on SM9

ActiveCN115580408BKey (cryptography)Cryptosystem
The application is suitable for the field of information security technology, and provides a certificateless signature generation method and system based on SM9, which comprises the following steps: step S100, system initialization, selecting a master private key from the system, and calculating a master public key according to the master private key; step S200, extracting a partial private key, extracting the partial private key as a partial private key of a signer through the master private key; step S300, setting a secret value, selecting a signer secret value; and step S400, setting a public key. The application is based on the SM9 signature structure, then the certificateless cryptography, and an improved certificateless signature of SM9 is proposed. Compared with the traditional public key cryptography system, the application effectively guarantees the integrity and authenticity of data in the transmission process, fills the gap of the domestic identity cryptography system, and lays a solid underlying cryptography foundation for the application level security.
Owner:SHANGHAI MATRIXELEMENTS TECH CO LTD +1

A power plant data security processing method

PendingCN122457232AKey (cryptography)Ciphertext
The application provides a power plant data security processing method, and belongs to the technical field of power Internet of Things security and privacy computing, which can at least partially solve the problems of complex certificate management of power plant monitoring system, large data aggregation calculation overhead and privacy leakage risk of cloud analysis in the prior art. The application comprises: generating a double-factor private key based on a certificateless public key cryptography system; serializing and encoding multi-dimensional operation data into a single integer using the Chinese remainder theorem; performing homomorphic encryption and signature on the encoded data using the double-factor private key, verifying the signature in batches on the edge side and aggregating in the ciphertext state; loading a neural network model adapted to homomorphic encryption on the cloud to perform ciphertext domain reasoning on the aggregated ciphertext; and decrypting the operation state analysis result on the authorized side. The application realizes ciphertext availability of power plant core data while ensuring data transmission integrity and confidentiality, and reduces communication and calculation overhead.
Owner:XIAN THERMAL POWER RES INST CO LTD

A remote user trusted authentication system, method and medium in an internet of things environment

The application belongs to the technical field of trusted authentication, and discloses a remote user trusted authentication system, method and medium in an Internet of Things environment. The system comprises a registration center (RC), which is a trusted server and is used for safely registering or initializing other entities; an intelligent device, which is arranged in an environment and is used for collecting and transmitting data; a gateway, which supports interconnection between different protocol networks and has computing and storage capabilities; a user, who accesses remote intelligent devices through a login device; and the login device, which is used for user trustworthiness verification. The login device includes but is not limited to a mobile device, an intelligent card and a PC. Through the system and method, the trusted authentication of remote users can be realized, and safe communication between the user and the intelligent device is established. Meanwhile, the application can also solve the problems of public key cryptography complexity, user authentication vulnerability and symmetric cryptography limitations.
Owner:ZHONGNAN UNIVERSITY OF ECONOMICS AND LAW

Systems and methods of digital asset wrapping using a public key cryptography (PKC) framework

Systems, methods, and computer-readable storage media of wrapping digital assets. One method includes receiving, from a central provider system, a digital asset signed by a central private key associated with a digital asset on a central ledger, and verifying the digital asset based on a central public key. The method further includes updating the digital asset including an assignee field, and receiving an attribute for a second assignee of the digital asset. The method further includes wrapping utilizing the private key of the public and private key pair, the digital asset with the attribute and receiving environmental data. The method further includes determining the at least one condition of the attribute is satisfied, and updating the assignee field.
Owner:WELLS FARGO BANK NA

Systems and methods of exchanging digital assets using a public key cryptography (PKC) framework

Systems, methods, and computer-readable storage media of exchanging digital assets using a public key cryptography framework. One method includes encrypting at least one digital asset on an internal ledger and storing the encrypted at least one digital asset on an internal ledger. The method further includes receiving a signed exchange request signed by a first key corresponding with an encrypted digital asset on the internal ledger and providing, to an inter-provider ledger, a second key based on interfacing with the inter-provider ledger based on establishing a first data feed. The method further includes determining the signed exchange request was verified. The method further includes updating a central ledger by interfacing with of the central ledger via an application programming interface (API) based on establishing a second data feed and wherein at least one of a plurality of fields of the encrypted digital asset is a universal field.
Owner:WELLS FARGO BANK NA

A method and system for email data security based on identifier public key cryptography

This invention relates to a method and system for email data security based on identifier public-key cryptography, belonging to the field of information security technology. The method includes: the sender encrypting email attachments using a symmetric key to obtain ciphertext for the attachments; obtaining the recipient's identifier public key based on the recipient's email address; encrypting the email body using the symmetric key to obtain ciphertext for the body; generating email ciphertext structure data by creating a digital envelope based on the sender's identifier private key's signature of the body, the ciphertext, and key factors of the symmetric key encapsulated in the recipient's identifier public key, and sending this data to the recipient; the recipient obtaining the signature, ciphertext, and digital envelope based on the ciphertext structure data, and decrypting the digital envelope using the recipient's identifier private key to obtain the symmetric key; decrypting the ciphertext using the symmetric key to obtain the email body and verifying the signature using the sender's identifier public key; and decrypting the ciphertext for the attachments to obtain the email attachments. This invention achieves end-to-end security for email data, solving server-side performance bottlenecks and key management security issues.
Owner:BEIJING ZHONGHONG LIDA TECH DEV CO LTD +1

Cold storage cryptographic authentication apparatus and system

A cryptographic cold storage apparatus and system. Embodiments of the present disclosure provide for a cold storage apparatus configured to generate a private key, compute an associated PK / PKY and display the latter on a visual display screen. An associated interface apparatus is configured to retrieve the PK / PKH optically and store it in memory. The interface apparatus is configured to produce an associated message and render it at a visual display. The cold storage apparatus may retrieve the message optically, and cryptographically sign the message utilizing one or more public key cryptography methods. The cold storage apparatus produces a graphical output comprising the signed message and renders it at the visual display. The interface apparatus retrieves the signed message and verifies that the cold storage apparatus signed the message, utilizing the public key cryptography methods.
Owner:IPASSETS TECHNOLOGY HOLDINGS INC

Mail data security method and system based on identification public key password

ActiveCN121547309ASecuring communicationComputer networkEnd to end security
The invention relates to a mail data security method and system based on an identification public key password, and belongs to the technical field of information security. The method comprises the following steps: a sender encrypts a mail attachment by using a symmetric key to obtain an attachment ciphertext; obtaining a receiver identification public key based on the receiver email address; encrypting the mail text based on the symmetric key to obtain a text ciphertext; based on the signature of the sender identification private key to the text, the text ciphertext and the digital envelope obtained by encapsulating the key factor of the symmetric key by the receiver identification public key, generating mail ciphertext structure data, and sending the mail ciphertext structure data to the receiver; the receiver obtains the signature, the body ciphertext and the digital envelope based on the mail ciphertext structure data, and decrypts the digital envelope based on the receiver identification private key to obtain the symmetric key; decrypting the body ciphertext based on the symmetric key to obtain the mail body, and verifying the signature through the sender identification public key; and decrypting the attachment ciphertext to obtain the mail attachment. According to the invention, the end-to-end security of the mail data is realized, and the problems of server performance bottleneck and key management security are solved.
Owner:BEIJING ZHONGHONG LIDA TECH DEV CO LTD +1

Public key password management method, system and device, electronic equipment and storage medium

The invention relates to the field of network security, and provides a public key password management method, system and device, electronic equipment and a storage medium, the method is applied to a password module, and the password module is arranged on a user side and integrated in an SIM card or a terminal; the method comprises the following steps: receiving a key parameter sent by an application; based on the key parameter and a locally stored root key seed, recovering to obtain a private key, and performing cryptographic operation by using the private key; the root key seed is a pre-generated fixed random number used for generating a key pair; and returning an operation result to the application and deleting the private key corresponding to the key parameter under the condition that the password operation is completed. According to the public key password management method provided by the invention, the password module does not need to store the key, the cost of the password module is reduced, and the key management efficiency of a digital identity scene is improved.
Owner:CHINA MOBILE COMM LTD RES INST +1

Systems and methods of exchanging digital assets using a public key cryptography (PKC) framework

Systems, methods, and computer-readable storage media of exchanging digital assets using a public key cryptography framework. One method includes encrypting at least one digital asset on an internal ledger and storing the encrypted at least one digital asset on an internal ledger. The method further includes receiving a signed exchange request signed by a first key corresponding with an encrypted digital asset on the internal ledger and providing, to an inter-provider ledger, a second key based on interfacing with the inter-provider ledger based on establishing a first data feed. The method further includes determining the signed exchange request was verified. The method further includes updating a central ledger by interfacing with of the central ledger via an application programming interface (API) based on establishing a second data feed and wherein at least one of a plurality of fields of the encrypted digital asset is a universal field.
Owner:WELLS FARGO BANK NA

Vehicle and roadside unit mutual authentication and key agreement method and device

ActiveCN120378875BKey (cryptography)Password
The application discloses a vehicle and roadside unit mutual trust authentication and key negotiation method, relates to vehicle networking communication entity identity authentication, and belongs to the field of vehicle networking information security. The method pre-sets a trusted center key, and embeds an unclonable device into a communication entity. After receiving a registration response, the communication entity stores a three-tuple in a memory thereof. An authentication message is constructed based on the identity identification of the communication entity, a password, a time stamp and an elliptic curve public key cryptography algorithm. The mutual trust authentication of the identity of the communication entity and the session key negotiation are realized through the interaction of the authentication message and the verification of the to-be-verified parameters. After the mutual trust authentication of the identity is passed, the received key message is verified by the receiving communication entity. The trusted center can track the identity of a false message sender. The communication entity adds the pseudo identity identification of the false message sender to an incremental pseudo identity identification revocation list, and completes the revocation of the false message sender, thereby improving the authentication efficiency of the vehicle and the roadside unit.
Owner:CHANGZHOU INST OF TECH

Two-way authentication methods and related equipment

The application provides a bidirectional authentication method and related equipment, and relates to the fields of network technology and security technology.The method comprises the following steps: a first communication device sends a first time-varying parameter and a first device identifier to an authentication center; receives first authentication data; and verifies the first authentication data based on a first physically unclonable function chip, generates second authentication data in the case that the first authentication data is verified, sends the second authentication data to a second communication device, receives third authentication data, verifies the third authentication data, and the bidirectional authentication of the first communication device and the second communication device is successful in the case that the third authentication data is verified.The application can realize the bidirectional authentication of the two communication parties without sharing the key in advance, can cope with the quantum computing threat faced by the public key cryptography, solves the problem of traditional symmetric key management by using the physically unclonable function, and can prevent the communication device from being imitated, so that the security of the authentication is improved.
Owner:CHINA TELECOM CORP LTD +1

Blockchain-based digital equity resource signature verification method and system

The application provides a kind of digital rights resources signature verification method and system based on block chain, it is related to the field of block chain technology.The method collects the signature of each specific permission node and the signature of each double permission node by signature verifier, if the number of specific permission node signature is equal to, then the verifier collects the signature of each ordinary permission node;If the sum of the number of signatures of double permission node and ordinary permission node is greater than or equal to t, then signature verification is carried out based on the preset elliptic curve public key cryptography algorithm, the allocation purpose of specific permission node is realized, the participants are signed with specific permission and ordinary permission qualification respectively, signature verification is carried out when the demand condition of specific permission is met, which greatly increases the signature verification efficiency of specific permission in the process of digital rights resources transaction, reduces the possibility of collusion and other destruction of consensus existence, thereby ensuring the validity of digital rights resources transaction in block chain signature verification.
Owner:ZHONGJINKE INFORMATION TECH CO LTD +1

Vector space data encryption method based on public key cryptosystem

The invention discloses a vector space data encryption method based on a public key cryptosystem. The method comprises the following steps: firstly, asymmetrically encrypting an integer part of a coordinate point of vector space data through an RSA principle; and secondly, scrambling and encrypting the asymmetrically encrypted vector space data through a chaotic sequence generated by a chaotic system to obtain final encrypted data. According to the method, the RSA and the chaotic system are combined for the first time, non-paired encryption and lossless decryption of the vector space data are achieved, and compared with a traditional vector space data encryption method, the method is wider in application range and higher in safety. Moreover, the method is not only suitable for vector space data, but also suitable for CAD data, three-dimensional point cloud, oblique photography three-dimensional models and other data.
Owner:LANZHOU JIAOTONG UNIV

A terminal device dual authentication method and system

The application relates to the technical field of cryptography, and particularly provides a terminal device double authentication method and system, which has the following steps: S1, a factory stage; S2, an initialization stage; S3, an authentication stage; and S4, an ending stage. Compared with the prior art, the zero-knowledge nature of the zero-knowledge proof is used to make the terminal device calculate a corresponding symmetric key, and the resource-restricted device end only needs to verify the proof to judge whether the authentication is successful, thereby avoiding a large amount of public key cryptography operation when the resource-restricted device performs identity authentication.
Owner:SHANDONG INSPUR SCI RES INST CO LTD

Low-code development platform management system and method

The invention discloses a low-code development platform management system and method, and the system comprises a management system body which comprises a safety management unit, an after-sales service unit, a customer resource management unit, a human resource management unit, an administrative collaborative office unit, and a project management unit. The after-sales service unit, the customer resource management unit, the human resource management unit, the administrative collaborative office unit and the project management unit are all connected with the safety management unit, and the safety management unit comprises a digital signature management module and a public key password management module. The digital signature management module and the public key password management module decrypt and check'no code 'to improve the use safety of the management system body, and the management system body can cover the application requirements of most enterprise management through an enterprise daily application system established through a low-code development platform. And a reasonable and high-safety management platform can be quickly built.
Owner:ZHIYUAN SHENGKE (BEIJING) TECH CO LTD

High integrity communications utilising public key cryptography signatures

PCT designated stageWO2026176175A1Computer networkKey (cryptography)
A method for verifying messages sent over a shared network, comprising generating at least one key pair comprising a private key and a public key and assigning the key pair to a first element connected to a shared media. The public key is distributed to at least a second element on the shared media. A message is transmitted from the first element to the second element. The message comprises an identifier, a data set, a message digest, and an encrypted message digest, generated by encrypting the message digest with the private key. The second element verifies the message received at the second element by decrypting the encrypted message digest using the public key corresponding to the identifier and comparing the decrypted message digest with a calculated message digest.
Owner:BAE SYSTEMS PLC

User authentication method, authentication apparatus, electronic information storage medium, and program for terminal

To provide a user authentication method, an authentication device, an electronic information storage medium, and a program for a terminal capable of achieving user authentication with higher security by using an existing system without separately preparing a device.SOLUTION: The user terminal 3 transmits a generation request of signature data corresponding to each of the common key encryption method and the public key encryption method to the IC card 2 in response to an authentication request from the authentication server 4, acquires an AC generated by the IC card 2 using an AC key according to the common key encryption method and an SDAD generated by the IC card 2 using an ICC private key according to the public key encryption method, verifies the SDAD using an ICC public key according to the public key encryption method, and transmits verification information indicating a result of the verification of the SDAD and an unverified AC to the authentication server 4.SELECTED DRAWING: Figure 8
Owner:DAI NIPPON PRINTING CO LTD

Vehicle control data transmission method and vehicle

PendingCN122640115AKey (cryptography)Attack
The embodiment of the application provides a vehicle control data transmission method and a vehicle, and relates to the technical field of vehicles. The method comprises the following steps: receiving digital key information sent by a terminal through an REE module; receiving an encrypted digital key from the terminal under the condition that the digital key information indicates that the terminal has post-quantum cryptographic encryption capability through a TEE module; decrypting the encrypted digital key through the TEE module to obtain the digital key; verifying the quantum digital signature and the operation permission through the TEE module, and outputting an operation instruction corresponding to an operation request after verification. By adapting the post-quantum cryptographic encryption algorithm to the vehicle processor, the vehicle adopts quantum encryption when transmitting data, thereby achieving the purpose of effectively preventing quantum attacks, and further solving the technical problem of poor security in the vehicle control data transmission process caused by the fact that the traditional public key cryptography cannot effectively prevent quantum attacks in the related art.
Owner:ANHUI KAIYANG TECHNOLOGY CO LTD +1

A construction method of a lattice-based quantum-resistant random permutation function

The application discloses a kind of based on the construction method of lattice anti quantum trapdoor random permutation function, belong to public key cryptography algorithm design technical field, including S1, according to actual demand, select the parameter meeting requirement;S2, according to the parameter selected, select auxiliary function S3, generate the permutation function defined on;S4, the trapdoor inverse operation is carried out to the permutation function value output in step S3, obtains trapdoor random permutation function;The construction method of a kind of based on lattice anti quantum trapdoor random permutation function provided by the application, the one-wayness of function, anti-collision property is established on the difficulty of lattice problem, and then provides the ability of resistance quantum computer attack for function, solves the security hidden danger of existing trapdoor permutation function in post quantum era.
Owner:NAVAL UNIV OF ENG PLA

Time-based one-time password on authentication token

PendingAU2025211679A1Generation processPassword
The disclosed systems and methods are directed to an implementation of time-based authentication with a contactless card based on remotely provisioned timing data. In one described implementation the timing information is provided by an external agent such as a client device and / or a remote verification server associated with the user account. The timing information is then incorporated into a cryptogram generation process executing on the contactless card, resulting in creation of an encrypted time-based token. The authentication request message that includes the time-based authentication token, may be further supplemented by the inclusion of the timing information separately encoded using, for example, public key cryptography. This modification of the authentication request message generated by the contactless card, enables an additional time-based filtering mechanism that may be performed by a third-party client device.
Owner:CAPITAL ONE SERVICES LLC