Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

35 results about "Public-key cryptography" patented technology

Public-key cryptography, or asymmetric cryptography, is a cryptographic system that uses pairs of keys: public keys which may be disseminated widely, and private keys which are known only to the owner. The generation of such keys depends on cryptographic algorithms based on mathematical problems to produce one-way functions. Effective security only requires keeping the private key private; the public key can be openly distributed without compromising security.

Remote signature system and tamper resistant device

The present invention realizes a remote signature system in which identity verification is performed for each signing request by combining the remote signature system with public key cryptography. A terminal device (2) comprises a means for generating a key pair for authentication to perform the public key cryptography. A generated secret key is stored in the terminal device (2), and a generated public key is transmitted to the tamper resistant device (5) and is stored in relation with the corresponding signature key. The tamper resistant device comprises a signature key storage means (12) for storing the signature key, a decryption key and signature key identification information as pairs for each user. When requesting a digital signing, a signing request including the signature key identification information, plaintext verification information, and a crypto token including the encrypted verification information and the encrypted signature object data is created and is transmitted to the tamper resistant device (5). The tamper resistant device accesses to the signature key storage means (12) and searches both the decryption key and the signature key. The tamper resistant device decrypts the crypto token using the searched decryption key, and verifies consistency between the decrypted verification information and the plaintext verification information. If they do not match each other, the signing request is excluded from the digital signing.
Owner:KEY TECHNO CO LTD

Computer-implemented system and method for managing authentication between user device and authentication server using private-public key cryptography

A computer-implemented method and system for managing an authentication between user devices and authentication servers, is disclosed. The computer-implemented method includes: obtaining user credentials associated with users; retrieving information associated with device fingerprints corresponding to the user devices; generating cipher messages by at least one of: creating random numbers and encrypting the random numbers with keys derived from at least one of: the first and second index; transmitting the one or more user identities, the first index, the second index, and the cipher messages, to authentication servers; dynamically generating the private keys from private key variables; generating authentication responses by decoding authentication based questions obtained from the authentication servers, using cipher messages and the private keys; and transmitting the authentication responses to the authentication servers for adapting the authentication servers to authenticate the user devices.
Owner:HAWCX INC

Digital certificate request file generation and verification method supporting anti-quantum algorithm

The invention discloses a digital certificate request file generation and verification method supporting an anti-quantum algorithm. The method comprises the following steps that T1, a user generates a traditional public key password signature key pair, an anti-quantum password signature key pair and an anti-quantum password encryption temporary key pair; t2, the user calculates a hybrid public key, performs hybrid signature on the hybrid public key, generates a hybrid signature certificate request file, and sends the hybrid signature certificate request file to the certificate issuing system; t3, the user calculates a temporary key request message, performs hybrid signature on the temporary key request message, generates an anti-quantum encryption temporary key request file of the hybrid signature, and sends the anti-quantum encryption temporary key request file to the certificate issuing system; t4, the certificate issuing system verifies the mixed signature certificate request file; and T5, the certificate issuing system verifies the anti-quantum encryption temporary key request file of the mixed signature. The method not only has the capability of resisting the quantum computing attack, but also can ensure the compatibility with the existing traditional PKI facility, and meanwhile, the security of the certificate request process is remarkably improved.
Owner:HEBEI PRIME NUMBER INFORMATION SECURITY CO LTD

Time-based one-time password on authentication token

The disclosed systems and methods are directed to an implementation of time-based authentication with a contactless card based on remotely provisioned timing data. In one described implementation the timing information is provided by an external agent such as a client device and / or a remote verification server associated with the user account. The timing information is then incorporated into a cryptogram generation process executing on the contactless card, resulting in creation of an encrypted time-based token. The authentication request message that includes the time-based authentication token, may be further supplemented by the inclusion of the timing information separately encoded using, for example, public key cryptography. This modification of the authentication request message generated by the contactless card, enables an additional time-based filtering mechanism that may be performed by a third-party client device.
Owner:CAPITAL ONE SERVICES LLC

Certificateless signature generation method and system based on SM9

The application is suitable for the field of information security technology, and provides a certificateless signature generation method and system based on SM9, which comprises the following steps: step S100, system initialization, selecting a master private key from the system, and calculating a master public key according to the master private key; step S200, extracting a partial private key, extracting the partial private key as a partial private key of a signer through the master private key; step S300, setting a secret value, selecting a signer secret value; and step S400, setting a public key. The application is based on the SM9 signature structure, then the certificateless cryptography, and an improved certificateless signature of SM9 is proposed. Compared with the traditional public key cryptography system, the application effectively guarantees the integrity and authenticity of data in the transmission process, fills the gap of the domestic identity cryptography system, and lays a solid underlying cryptography foundation for the application level security.
Owner:SHANGHAI MATRIXELEMENTS TECH CO LTD +1

A power plant data security processing method

PendingCN122457232AKey (cryptography)Ciphertext
The application provides a power plant data security processing method, and belongs to the technical field of power Internet of Things security and privacy computing, which can at least partially solve the problems of complex certificate management of power plant monitoring system, large data aggregation calculation overhead and privacy leakage risk of cloud analysis in the prior art. The application comprises: generating a double-factor private key based on a certificateless public key cryptography system; serializing and encoding multi-dimensional operation data into a single integer using the Chinese remainder theorem; performing homomorphic encryption and signature on the encoded data using the double-factor private key, verifying the signature in batches on the edge side and aggregating in the ciphertext state; loading a neural network model adapted to homomorphic encryption on the cloud to perform ciphertext domain reasoning on the aggregated ciphertext; and decrypting the operation state analysis result on the authorized side. The application realizes ciphertext availability of power plant core data while ensuring data transmission integrity and confidentiality, and reduces communication and calculation overhead.
Owner:XIAN THERMAL POWER RES INST CO LTD

A remote user trusted authentication system, method and medium in an internet of things environment

The application belongs to the technical field of trusted authentication, and discloses a remote user trusted authentication system, method and medium in an Internet of Things environment. The system comprises a registration center (RC), which is a trusted server and is used for safely registering or initializing other entities; an intelligent device, which is arranged in an environment and is used for collecting and transmitting data; a gateway, which supports interconnection between different protocol networks and has computing and storage capabilities; a user, who accesses remote intelligent devices through a login device; and the login device, which is used for user trustworthiness verification. The login device includes but is not limited to a mobile device, an intelligent card and a PC. Through the system and method, the trusted authentication of remote users can be realized, and safe communication between the user and the intelligent device is established. Meanwhile, the application can also solve the problems of public key cryptography complexity, user authentication vulnerability and symmetric cryptography limitations.
Owner:ZHONGNAN UNIVERSITY OF ECONOMICS AND LAW

Systems and methods of digital asset wrapping using a public key cryptography (PKC) framework

Systems, methods, and computer-readable storage media of wrapping digital assets. One method includes receiving, from a central provider system, a digital asset signed by a central private key associated with a digital asset on a central ledger, and verifying the digital asset based on a central public key. The method further includes updating the digital asset including an assignee field, and receiving an attribute for a second assignee of the digital asset. The method further includes wrapping utilizing the private key of the public and private key pair, the digital asset with the attribute and receiving environmental data. The method further includes determining the at least one condition of the attribute is satisfied, and updating the assignee field.
Owner:WELLS FARGO BANK NA

Systems and methods of exchanging digital assets using a public key cryptography (PKC) framework

Systems, methods, and computer-readable storage media of exchanging digital assets using a public key cryptography framework. One method includes encrypting at least one digital asset on an internal ledger and storing the encrypted at least one digital asset on an internal ledger. The method further includes receiving a signed exchange request signed by a first key corresponding with an encrypted digital asset on the internal ledger and providing, to an inter-provider ledger, a second key based on interfacing with the inter-provider ledger based on establishing a first data feed. The method further includes determining the signed exchange request was verified. The method further includes updating a central ledger by interfacing with of the central ledger via an application programming interface (API) based on establishing a second data feed and wherein at least one of a plurality of fields of the encrypted digital asset is a universal field.
Owner:WELLS FARGO BANK NA

A method and system for email data security based on identifier public key cryptography

This invention relates to a method and system for email data security based on identifier public-key cryptography, belonging to the field of information security technology. The method includes: the sender encrypting email attachments using a symmetric key to obtain ciphertext for the attachments; obtaining the recipient's identifier public key based on the recipient's email address; encrypting the email body using the symmetric key to obtain ciphertext for the body; generating email ciphertext structure data by creating a digital envelope based on the sender's identifier private key's signature of the body, the ciphertext, and key factors of the symmetric key encapsulated in the recipient's identifier public key, and sending this data to the recipient; the recipient obtaining the signature, ciphertext, and digital envelope based on the ciphertext structure data, and decrypting the digital envelope using the recipient's identifier private key to obtain the symmetric key; decrypting the ciphertext using the symmetric key to obtain the email body and verifying the signature using the sender's identifier public key; and decrypting the ciphertext for the attachments to obtain the email attachments. This invention achieves end-to-end security for email data, solving server-side performance bottlenecks and key management security issues.
Owner:BEIJING ZHONGHONG LIDA TECH DEV CO LTD +1

Cold storage cryptographic authentication apparatus and system

A cryptographic cold storage apparatus and system. Embodiments of the present disclosure provide for a cold storage apparatus configured to generate a private key, compute an associated PK / PKY and display the latter on a visual display screen. An associated interface apparatus is configured to retrieve the PK / PKH optically and store it in memory. The interface apparatus is configured to produce an associated message and render it at a visual display. The cold storage apparatus may retrieve the message optically, and cryptographically sign the message utilizing one or more public key cryptography methods. The cold storage apparatus produces a graphical output comprising the signed message and renders it at the visual display. The interface apparatus retrieves the signed message and verifies that the cold storage apparatus signed the message, utilizing the public key cryptography methods.
Owner:IPASSETS TECHNOLOGY HOLDINGS INC

Mail data security method and system based on identification public key password

The invention relates to a mail data security method and system based on an identification public key password, and belongs to the technical field of information security. The method comprises the following steps: a sender encrypts a mail attachment by using a symmetric key to obtain an attachment ciphertext; obtaining a receiver identification public key based on the receiver email address; encrypting the mail text based on the symmetric key to obtain a text ciphertext; based on the signature of the sender identification private key to the text, the text ciphertext and the digital envelope obtained by encapsulating the key factor of the symmetric key by the receiver identification public key, generating mail ciphertext structure data, and sending the mail ciphertext structure data to the receiver; the receiver obtains the signature, the body ciphertext and the digital envelope based on the mail ciphertext structure data, and decrypts the digital envelope based on the receiver identification private key to obtain the symmetric key; decrypting the body ciphertext based on the symmetric key to obtain the mail body, and verifying the signature through the sender identification public key; and decrypting the attachment ciphertext to obtain the mail attachment. According to the invention, the end-to-end security of the mail data is realized, and the problems of server performance bottleneck and key management security are solved.
Owner:BEIJING ZHONGHONG LIDA TECH DEV CO LTD +1

Public key password management method, system and device, electronic equipment and storage medium

The invention relates to the field of network security, and provides a public key password management method, system and device, electronic equipment and a storage medium, the method is applied to a password module, and the password module is arranged on a user side and integrated in an SIM card or a terminal; the method comprises the following steps: receiving a key parameter sent by an application; based on the key parameter and a locally stored root key seed, recovering to obtain a private key, and performing cryptographic operation by using the private key; the root key seed is a pre-generated fixed random number used for generating a key pair; and returning an operation result to the application and deleting the private key corresponding to the key parameter under the condition that the password operation is completed. According to the public key password management method provided by the invention, the password module does not need to store the key, the cost of the password module is reduced, and the key management efficiency of a digital identity scene is improved.
Owner:CHINA MOBILE COMM LTD RES INST +1

Systems and methods of exchanging digital assets using a public key cryptography (PKC) framework

Systems, methods, and computer-readable storage media of exchanging digital assets using a public key cryptography framework. One method includes encrypting at least one digital asset on an internal ledger and storing the encrypted at least one digital asset on an internal ledger. The method further includes receiving a signed exchange request signed by a first key corresponding with an encrypted digital asset on the internal ledger and providing, to an inter-provider ledger, a second key based on interfacing with the inter-provider ledger based on establishing a first data feed. The method further includes determining the signed exchange request was verified. The method further includes updating a central ledger by interfacing with of the central ledger via an application programming interface (API) based on establishing a second data feed and wherein at least one of a plurality of fields of the encrypted digital asset is a universal field.
Owner:WELLS FARGO BANK NA

Vehicle and roadside unit mutual authentication and key agreement method and device

ActiveCN120378875BKey (cryptography)Password
The application discloses a vehicle and roadside unit mutual trust authentication and key negotiation method, relates to vehicle networking communication entity identity authentication, and belongs to the field of vehicle networking information security. The method pre-sets a trusted center key, and embeds an unclonable device into a communication entity. After receiving a registration response, the communication entity stores a three-tuple in a memory thereof. An authentication message is constructed based on the identity identification of the communication entity, a password, a time stamp and an elliptic curve public key cryptography algorithm. The mutual trust authentication of the identity of the communication entity and the session key negotiation are realized through the interaction of the authentication message and the verification of the to-be-verified parameters. After the mutual trust authentication of the identity is passed, the received key message is verified by the receiving communication entity. The trusted center can track the identity of a false message sender. The communication entity adds the pseudo identity identification of the false message sender to an incremental pseudo identity identification revocation list, and completes the revocation of the false message sender, thereby improving the authentication efficiency of the vehicle and the roadside unit.
Owner:CHANGZHOU INST OF TECH

A registration code generation and verification method and system based on elliptic curve short signature

The present invention relates to a registration code generation and verification method and system based on elliptic curve short signature, belonging to the field of information security technology. The registration code generation method includes: generating a machine code based on the hardware information of the device on which the software is installed and the identification information of the software; generating a random elliptic curve key pair, and performing a short signature on the machine code based on the private key in the key pair to obtain a corresponding signature value (r, s); and generating a registration code based on the signature value (r, s). The verification method includes: generating a machine code corresponding to the device running the software; restoring the registration code to be verified to obtain a signature value (r′, s′); and verifying the registration code based on the machine code and the signature value (r′, s′). The registration code of the present invention is generated based on elliptic curve public key cryptography and a short signature algorithm. The length of the registration code is similar to that of a traditional registration code, and the registration code is bound to the running device to prevent the software from being used on unauthorized devices. This effectively shortens the length of the registration code while achieving copyright protection for the software.
Owner:BEIJING ZHONGHONG LIDA TECH DEV CO LTD +1

Communication system, method, and program

To provide a public key cryptography and system based on isogeny with which data sizes are suppressed and safety is enhanced.SOLUTION: Provided is an encrypting communication system adopting, as system parameters, integers a' and b', and dA,1=2a'-3b', dA,2=3b', d1=22a'+2a'3b'+32b', d2=32b', a=3a', p=2a*3f-1, and generation sources P0, Q0 of E0[2a]. The communication system includes a key generation unit for selecting a regular diagonal matrix A of 2×2 on Z / 2aZ and generating dA,1-isogenies φA,1:E0→EA' and PA'=φA,1(P0) and QA'=φA,1(Q0) from dA,1 and P0, Q0, and selecting dA,2-isogenies φA,2:EA'→EA, thereby generating a public key pk=(EA, RA, SA)((RA, SA)T=A(PA=φA,2(PA'), QA=φA,2(QA'))T and a secret key sk=(A, EA', PA', QA').SELECTED DRAWING: Figure 7
Owner:NIPPON TELEGRAPH & TELEPHONE CORP +1

Two-way authentication methods and related equipment

The application provides a bidirectional authentication method and related equipment, and relates to the fields of network technology and security technology.The method comprises the following steps: a first communication device sends a first time-varying parameter and a first device identifier to an authentication center; receives first authentication data; and verifies the first authentication data based on a first physically unclonable function chip, generates second authentication data in the case that the first authentication data is verified, sends the second authentication data to a second communication device, receives third authentication data, verifies the third authentication data, and the bidirectional authentication of the first communication device and the second communication device is successful in the case that the third authentication data is verified.The application can realize the bidirectional authentication of the two communication parties without sharing the key in advance, can cope with the quantum computing threat faced by the public key cryptography, solves the problem of traditional symmetric key management by using the physically unclonable function, and can prevent the communication device from being imitated, so that the security of the authentication is improved.
Owner:CHINA TELECOM CORP LTD +1

A lightweight public key cryptography calculation method for small IoT terminals

The present invention belongs to the field of computer security and discloses a lightweight public-key cryptographic calculation method for small-scale Internet of Things (IoT) terminals. The terminal generates a private key using a random number generator; the terminal interacts with an edge computing node to obtain a pre-calculated table for scalar multiplication, which is an i-multiplication point pre-calculated table stored in advance in the edge computing node or calculated in real time by the edge computing node; the terminal obtains all required multiplication point values ​​and obtains the final public-key cryptography through multiplication point addition. By using simplified pre-calculated tables for fixed and non-fixed points, the present invention reduces the computational complexity of scalar multiplication in public-key cryptography, effectively resolving the problem that scalar multiplication in ECC encryption consumes memory and computing power, making it difficult to apply to resource-constrained small-scale terminal devices. These terminal devices can also perform secure transmission using the ECC public-key cryptographic algorithm, resolving the security issue of small-scale terminal devices being unable to apply more secure public-key cryptographic algorithms.
Owner:NANJING UNIV OF POSTS & TELECOMM

Decentralized social network systems and methods

A decentralized social network architecture allows reliable, multi-device, censorship-resistant distribution of messages. Network messages include a profile ID identifying a cryptographic public key, a device ID identifying a device used by the profile, a payload, a vector clock for the profile including a scalar for each device used by the profile, a real-time timestamp, and a message signature generated with the cryptographic private key counterpart of the public key. The signature authenticates each message as a self-contained entity, without cryptographic reference to previous messages. A user profile can employ multiple, independent server(s) for message distribution, and can add and remove servers from its distribution network. Security is provided in a decentralized manner via public key cryptography and a decentralized web of trust.
Owner:FUTO HOLDINGS INC

Blockchain-based digital equity resource signature verification method and system

The application provides a kind of digital rights resources signature verification method and system based on block chain, it is related to the field of block chain technology.The method collects the signature of each specific permission node and the signature of each double permission node by signature verifier, if the number of specific permission node signature is equal to, then the verifier collects the signature of each ordinary permission node;If the sum of the number of signatures of double permission node and ordinary permission node is greater than or equal to t, then signature verification is carried out based on the preset elliptic curve public key cryptography algorithm, the allocation purpose of specific permission node is realized, the participants are signed with specific permission and ordinary permission qualification respectively, signature verification is carried out when the demand condition of specific permission is met, which greatly increases the signature verification efficiency of specific permission in the process of digital rights resources transaction, reduces the possibility of collusion and other destruction of consensus existence, thereby ensuring the validity of digital rights resources transaction in block chain signature verification.
Owner:ZHONGJINKE INFORMATION TECH CO LTD +1

Vector space data encryption method based on public key cryptosystem

The invention discloses a vector space data encryption method based on a public key cryptosystem. The method comprises the following steps: firstly, asymmetrically encrypting an integer part of a coordinate point of vector space data through an RSA principle; and secondly, scrambling and encrypting the asymmetrically encrypted vector space data through a chaotic sequence generated by a chaotic system to obtain final encrypted data. According to the method, the RSA and the chaotic system are combined for the first time, non-paired encryption and lossless decryption of the vector space data are achieved, and compared with a traditional vector space data encryption method, the method is wider in application range and higher in safety. Moreover, the method is not only suitable for vector space data, but also suitable for CAD data, three-dimensional point cloud, oblique photography three-dimensional models and other data.
Owner:LANZHOU JIAOTONG UNIV

Data confidentiality and integrity verification system and method based on multi-copy public key certification

The invention provides a data secrecy and integrity verification system and method based on multi-copy public key certification. The system performs block encryption on data at a user side and then uploads the data to a cloud storage server side, and the cloud storage server side generates a plurality of copy data blocks and stores the copy data blocks on different copy servers. Through the public key cryptography technology, the cloud storage server only masters the public key, the replica server share set and the replica data block, the original data cannot be obtained reversely, and the confidentiality of the data is ensured. Meanwhile, the user can verify the ownership of the copy through the private key and the public key, and the integrity of the data is ensured. In addition, the system also has a key management function, provides a specific key for a data file needing to be shared, and ensures that the confidentiality of other files is not influenced. The method has the beneficial effects of improving data confidentiality, reducing calculation complexity and storage overhead, enhancing data integrity verification and improving system security. Through the anti-counterfeiting capability and the anti-collusion attack mechanism, the security and reliability of the data in the cloud storage environment are further enhanced.
Owner:NAVAL UNIV OF ENG PLA

A terminal device dual authentication method and system

The application relates to the technical field of cryptography, and particularly provides a terminal device double authentication method and system, which has the following steps: S1, a factory stage; S2, an initialization stage; S3, an authentication stage; and S4, an ending stage. Compared with the prior art, the zero-knowledge nature of the zero-knowledge proof is used to make the terminal device calculate a corresponding symmetric key, and the resource-restricted device end only needs to verify the proof to judge whether the authentication is successful, thereby avoiding a large amount of public key cryptography operation when the resource-restricted device performs identity authentication.
Owner:SHANDONG INSPUR SCI RES INST CO LTD

Communication system, method, and program

To materialize a public key cryptograph based on isogeny in which data sizes and calculation costs are suppressed.SOLUTION: Provided is a communication system for materializing cryptographic communication using isogeny-based cryptography that adopts, as system parameters, integers a' and b' determined from a security parameter λ, integers dA=2a'+k*3b' and d1=2a'-k*3b' (k=natural number) which are larger than 22λ and are not smooth numbers, integers a=2a', b=2b', d2=3b, primes p=2a*3f-1 (f=natural number), and generation source P0, Q0 of E0[2a]. The communication system includes a key generation unit for selecting a random regular diagonal matrix A of 2×2 on Z / 2aZ and generating dA-isogeniesφA:E0→EA and PA=φA(P0) and QA=φA(Q0) from dA and P0, Q0 by RandIsogImages, thereby generating a public key pk=(EA, RA, SA)(where, RA and SA satisfy (RA, SA)T=A(PA, QA)T) and a secret key sk=A.SELECTED DRAWING: Figure 8
Owner:NIPPON TELEGRAPH & TELEPHONE CORP +1

Low-code development platform management system and method

The invention discloses a low-code development platform management system and method, and the system comprises a management system body which comprises a safety management unit, an after-sales service unit, a customer resource management unit, a human resource management unit, an administrative collaborative office unit, and a project management unit. The after-sales service unit, the customer resource management unit, the human resource management unit, the administrative collaborative office unit and the project management unit are all connected with the safety management unit, and the safety management unit comprises a digital signature management module and a public key password management module. The digital signature management module and the public key password management module decrypt and check'no code 'to improve the use safety of the management system body, and the management system body can cover the application requirements of most enterprise management through an enterprise daily application system established through a low-code development platform. And a reasonable and high-safety management platform can be quickly built.
Owner:ZHIYUAN SHENGKE (BEIJING) TECH CO LTD

High integrity communications utilising public key cryptography signatures

PCT designated stageWO2026176175A1Computer networkKey (cryptography)
A method for verifying messages sent over a shared network, comprising generating at least one key pair comprising a private key and a public key and assigning the key pair to a first element connected to a shared media. The public key is distributed to at least a second element on the shared media. A message is transmitted from the first element to the second element. The message comprises an identifier, a data set, a message digest, and an encrypted message digest, generated by encrypting the message digest with the private key. The second element verifies the message received at the second element by decrypting the encrypted message digest using the public key corresponding to the identifier and comparing the decrypted message digest with a calculated message digest.
Owner:BAE SYSTEMS PLC