Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

82 results about "Rekeying" patented technology

Rekeying a lock is replacing the old lock pins with new lock pins.

Security operation and maintenance management method for power production management system based on national secret algorithm

The invention discloses an electric power production management system safety operation and maintenance management method based on a national secret algorithm. According to the method, the key and the real-time running state of the equipment are deeply bound through a dynamic key derivation mechanism, so that the key is dynamically adjusted along with parameters such as the load rate, the temperature and the bit error rate, state change, namely key updating, is realized, and the anti-cracking capability of the key is greatly improved; the SM2, SM3, SM4 and other national cryptographic standards are adopted from root key generation, identity authentication, data transmission encryption and log tampering prevention of the full-link application of the national cryptographic algorithm system, it is ensured that the encryption strength meets the national password management requirement, and the overall encryption protection level of the system is improved. Closed-loop protection is formed through deep linkage among multiple steps, fragmentation of a safety mechanism is avoided, meanwhile, the traceability and the fault recovery efficiency of system operation are further improved through the whole-process encryption archiving and emergency response rapid recovery process of audit logs, and transmission and storage safety of power production core data is guaranteed.
Owner:GUIZHOU WUJIANG HYDROPOWER DEV

Secure data transmission over constrained one-way channel

The sender stores a pair of sender's public and private keys and a public key of the receiver, and carries out the steps of:A—generating a master key, that is a secret shared with the receiver, by key derivation from a current root key and using the sender's private key and the receiver's public key, and updating the root key with the generated master key;B—generating, by key derivation from said master key, a chain of message keys for securing messages to communicate to the receiver;C—generating a next pair of sender's public and private keys, sending the next sender's public key to the receiver and executing again the steps A andB using the next sender's private key and the same receiver's public key;wherein the current root key used in the step A isat a first iteration of step A, an initial root key prestored in the sender, said initial root key being a secret shared with the receiver, andat each subsequent iteration of the step A, the root key that has been updated at the preceding iteration of step A.
Owner:NAGRAVISION SRL

A new physical layer encryption and authentication cooperation security method

The application provides a new physical layer encryption and authentication cooperation security method, solves the problem that the ability of encryption technology to resist differential attack depends on the rapid update of a key; at a sending end, a hash function is used to generate an encryption sequence by using the key and the digital features of information, and the information is subjected to the action of the encryption sequence; the encryption sequence will greatly change when the key is unchanged and the information changes, and the digital features of the information before and after encryption remain unchanged; at a receiving end, the received information can be used to regenerate a decryption sequence by using the digital features of the information and the key before decryption, and the decryption sequence is used for decryption; the requirement of key update is greatly reduced, and the rate requirement and the cost of key generation and distribution are reduced. The generation of the digital label required by the authentication does not depend on the ciphertext itself or the plaintext itself, but uses the same signal digital features, the key and the hash function as when the encryption sequence is generated, and better cooperation is achieved, that is, the cooperation realizes the physical layer security, prevents eavesdropping and attack.
Owner:ZHENGZHOU UNIV

Key update using relationship between keys for extended reality privacy

Systems and methods are provided herein for providing privacy while allowing interactions with virtual representations of sensitive objects. This may be accomplished by an extended reality (XR) system receiving information associated with a real-world environment of a user. The XR system may transmit the received information to one or more devices (e.g., server, XR device, etc.) for processing. Before transmitting the received information, the XR system can use the received information to identify and categorize objects in the real-world environment to identify sensitive objects. To protect the privacy of the sensitive objects, the XR system transforms features of the sensitive objects using one or more transform keys prior to transmitting the information to the one or more devices. The XR system may also update the transform keys after a first time period to further protect the privacy of the sensitive objects.
Owner:ADEIA GUIDES INC

Computer network data storage encryption method and system based on artificial intelligence

The invention discloses a computer network data storage encryption method and system based on artificial intelligence, and relates to the technical field of computer data storage, the system comprises an acquisition component, a processing component, a calculation component and an encryption management component, the calculation component comprises a data risk assessment unit, a key update adjustment unit and a dynamic key encryption unit, the security of the storage system is improved through the three core units, the data risk assessment unit integrates multi-dimensional parameters and fuses hardware features, AI anomaly confidence and the like, the blank of hidden anomaly perception is filled up, the security of the storage system is improved, the security of the storage system is improved, the security of the storage system is improved, and the security of the storage system is improved. The key updating and adjusting unit is coupled with physical space abnormity, authentication strength and performance risks, a self-adaptive period is achieved to balance safety and efficiency, the dynamic key encryption unit fuses hardware fingerprints, data versions and AI disturbance, a scenarized anti-attack key is generated, and the anti-cracking capacity is improved.
Owner:SHENZHEN LEIMENG NASHUN TECHNOLOGY CO LTD

Internet of vehicles heterogeneous signcryption communication system and method based on double-layer block chain

The invention discloses an Internet of Vehicles heterogeneous signcryption communication system and method based on a double-layer block chain, relates to the technical field of Internet of Vehicles, and solves the technical problems that the Internet of Vehicles technology is insufficient in expansibility and poor in compatibility, safety and efficiency are difficult to consider, and use requirements are difficult to meet. The system comprises a private key generation center PKG, a secret key generation center KGC, an on-board unit OBU, a roadside unit RSU and a double-layer block chain device. The private key generation center PKG is used for generating and distributing a public key and private key pair of the identity signcryption IBC; the key generation center KGC is used for key updating and management of the certificateless signcryption CLC; the OBU is used for performing communication between the vehicle and other vehicles or the road side unit; the roadside unit RSU is used for communication support and data forwarding; and the double-layer block chain equipment is used for carrying out data storage and security verification in the communication system. According to the invention, the calculation overhead and communication cost of the system are obviously reduced, and safe, efficient and extensible authentication and data transmission in a high-dynamic and large-scale V2X environment is realized.
Owner:SHENZHEN SEG SCI NAVIGATIONS CO LTD

Power distribution terminal key management method and system based on trusted computing

The invention provides a power distribution terminal key management method and system based on trusted computing, and relates to the field of power system management.The method comprises the following steps that key strength is determined according to risk indexes; encrypting the real-time data of the power distribution terminal by using the encryption key; transmitting to a key management center through a preset security access gateway; performing integrity verification on the encrypted real-time data, and associatively storing a verification result, a security risk index and a transmission timestamp to a block chain evidence storage node to form a tampering-free encryption key operation context record; and dynamically optimizing an encryption key updating strategy in combination with the historical change trend of the security risk index so as to realize closed-loop security management and control of the whole life cycle of the encryption key. According to the invention, the active immunity and the overall safety management and control level of the power distribution Internet of Things in a complex environment are significantly improved.
Owner:HEFEI ZHONGNENG POWER TECH

High-speed encryption and decryption engine and encryption and decryption implementation method

The application relates to a high-speed encryption and decryption engine and an encryption and decryption implementation method, wherein a plurality of physical channels are provided to provide a plurality of service processing modules with cryptographic services, the problem that a cryptographic card can only provide a single service channel is solved, secondary keys are imported into an FPGA chip for buffering, a session key is managed in a life cycle by the FPGA chip, the time cost of key updating required by cryptographic operation can be reduced, and the processing delay of the cryptographic service can be obviously reduced; the FPGA chip is used as a cryptographic operation processing core unit, multi-stage parallel pipeline processing is realized, and the processing performance is effectively improved.
Owner:QUANTUMCTEK CO LTD +1

Rekeyable lock cylinder

A rekeyable lock cylinder with a cylinder body, an inner sleeve, and a plug assembly is provided. The plug assembly includes a plurality of key followers and a corresponding plurality of first racks and second racks disposed in carriers. The first racks correspond to operation of a user key and the second racks correspond to operation of a master key. As such, the lock cylinder is usable in a user / master key system. Disengaging either of the first or second racks from the key followers allows rekeying of the lock cylinder for the user key or the master key.
Owner:ASSA ABLOY AMERICAS RESIDENTIAL INC

Low-voltage distribution line information safety acquisition control method adaptive to multi-load characteristic

The invention discloses a low-voltage distribution line information safety acquisition control method adaptive to multi-load characteristics, and aims to solve the problems that key updating depends on a central server, the response delay is high, and dynamic load change is difficult to adapt in the prior art. The method specifically comprises the following steps: triggering transient impedance characteristic acquisition when a load monitoring unit detects that a current change rate exceeds a threshold value in real time; the impedance feature extraction module calculates a specific frequency band phase angle and an amplitude to form a feature vector; the physical unclonable function generator binarizes the physical unclonable function and generates an encryption seed; the key synchronization module encrypts the root key and then broadcasts the encrypted root key to an adjacent node; and the security chip executes atomic operation to complete seamless key switching. By adopting the technical scheme, the generation and synchronization of the localized self-triggering key can be realized, the key updating delay time is shortened, and the safety response capability and the attack resistance of the low-voltage distribution line under the dynamic load are remarkably improved.
Owner:JINZHOU ELECTRIC POWER SUPPLY COMPANY OF STATE GRID LIAONING ELECTRIC POWER SUPPLY +1

A dynamic encryption method and system for secure transmission

This invention relates to the field of data encryption transmission technology, specifically disclosing a dynamic encryption method and system for secure transmission. The method includes: first, acquiring input parameters of the data to be transmitted and generating an initial encryption key; processing the data to be transmitted in blocks and determining the importance level of each data block; performing layered initial encryption transmission on each data block according to its importance level; collecting dynamic status parameters of the transmission link to generate key update parameters, adjusting the current encryption key to obtain an updated encryption key; detecting whether there are security risks in the transmission link, and if so, using an upgraded encryption algorithm and an updated encryption key to re-encrypt the incomplete data blocks and continue transmission through a backup encryption link; finally, decrypting the encrypted data blocks to obtain the original data blocks and performing integrity verification. This invention effectively solves the problems of easy key leakage, insufficient security, and low encryption efficiency in traditional static encryption methods.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

Key update methods, key management systems, devices, storage media and products

This application provides a key update method, a key management system, a device, a storage medium, and a product, relating to the field of information security. The method includes: a POS terminal backend management system calling the POS terminal's key generation interface to generate a public-private key pair via the POS terminal's PIN pad and returning the public key; forwarding the public key to a hardware security module and calling the hardware security module to generate a first working key; the hardware security module encrypting the first working key based on the public key to generate a first ciphertext and a corresponding key verification value, and sending them to the POS terminal; upon receiving the first ciphertext and the key verification value, the POS terminal obtains the first working key based on its private key and updates its current working key to the first working key. In this application, the POS terminal backend management system is used for instruction scheduling, and the encryption and decryption of information are configured in the POS terminal and the hardware security module, enabling remote and efficient updating of the POS terminal's working key.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Key updating method and device for full-mesh database, equipment and storage medium

The application discloses a key updating method, device and equipment of a full-mechanism database and a storage medium. The method comprises the following steps: creating a target client master key; using an initial client master key stored locally by a client to decrypt an initial column encryption key ciphertext, and obtaining column encryption key plaintext; using the target client master key to encrypt the column encryption key plaintext, and obtaining target column encryption key ciphertext; updating the target column encryption key ciphertext to a system table of a server, and using the target client master key to update the initial client master key stored locally by the client, so that the updating of the client master key in the full-mechanism database is realized, the security of a key storage device is ensured, and the consistency of the key of the client and the server is ensured during the updating of the client master key, so that the continuous availability of the key is ensured.
Owner:WUHAN DAMENG DATABASE

Key management system for multi-level encryption transmission of bank-enterprise direct connection

The application discloses a silver enterprise direct connection multi-level encryption transmission key management system and relates to the technical field of encryption transmission.The system comprises a first acquisition module, a second acquisition module, a configuration generation module, an evaluation and screening module and a driving execution module; and its technical key points are as follows: real-time collection of transaction parameters and encryption requirements in different business scenarios and inputting into a pre-constructed encryption requirement model and outputting a risk amplitude; obtaining a first condition of key hierarchical constraint and a second condition of key update constraint to quantize initial security parameters, performing multi-dimensional disturbance simulation on the initial security parameters, generating a plurality of to-be-optimized configuration vectors; mapping the to-be-optimized configuration vectors to a multi-level encryption process, performing safe collaborative evaluation based on time complexity and the risk amplitude, obtaining an evaluation result, constructing a multi-dimensional key performance response surface, identifying a sensitive area of the surface, screening an optimal configuration vector and driving execution; and the application improves the key security and management efficiency.
Owner:ZHEJIANG YOUCAI CLOUD CHAIN TECH CO LTD

A vehicle end ECU security key updating method and a computer storage medium

PendingCN122316621AAttack implementationavoid risk of leakageCiphertextIn vehicle
This invention discloses a method for updating a vehicle-mounted ECU security key and a computer storage medium. The method includes: an upper-level computer using the ECU's public key to perform asymmetric encryption on a business key to obtain ciphertext; signing the ciphertext using the upper-level computer's private key; concatenating and packaging the ciphertext, signature, and upper-level computer public key and sending it to the ECU; the ECU unpacking the received data to obtain the ciphertext, signature, and upper-level computer public key; verifying the upper-level computer public key; if the verification is successful, verifying the signature using the upper-level computer public key; if the signature verification is successful, decrypting the ciphertext using the ECU's private key; updating the vehicle-mounted ECU security key based on the decryption result; if either the upper-level computer public key or signature verification fails, sending a key update failure message to the upper-level computer and ending the ciphertext update. This invention features a simple algorithm and avoids the risk of brute-force key reading at the ECU, thus improving the security of in-vehicle terminal information.
Owner:ZHENGZHOU YUTONG BUS CO LTD

A power acquisition terminal device information security protection method and system

The application relates to the technical field of power collection terminal device information security protection, and discloses a power collection terminal device information security protection method and system. The method generates a unique identifier through the hardware characteristics of a collection device to prevent forgery and tampering. High-dimensional transformation improves the feature complexity and enhances the anti-reverse ability. Dynamic disturbance factors make the device identifier change over time to prevent replay attacks. Multi-factor key generation combines hardware characteristics, environmental parameters and time sequence factors to improve the security of the key and avoid cracking. The hierarchical challenge response mechanism enhances security through multiple levels of authentication to prevent attackers from easily bypassing verification. High-dimensional abnormal behavior detection can dynamically identify potential security threats. The multi-stage key update mechanism ensures that the device is kept encrypted for a long time, avoiding the risks caused by key leakage. The whole system works cooperatively to effectively improve the security of device authentication, data encryption and communication.
Owner:BEIJING BONA ELECTRIC CO LTD

Vehicle-mounted CAN bus safety communication method based on attribute grouping

The invention discloses a vehicle-mounted CAN (Controller Area Network) bus safety communication method based on attribute grouping. The method comprises the following steps: firstly, selecting a master key, a public key, a hash function and related parameters; the electronic control unit ECU registers with a gateway electronic control unit GECU; in the key generation stage, the GECU groups the ECUs and distributes key generation parameters to the ECUs in the groups, and the ECUs in the groups calculate group keys according to the key generation parameters; the ECUs in the group communicate with each other by using the group key; and in the key updating and ECU re-joining stage, the ECU can update the key without interaction. Through constructing a group key generation mechanism based on an access structure tree, group communication based on ECU function attributes is realized. And a key self-authentication mechanism is introduced, so that the interaction turns between the ECUs are reduced, and the communication load is reduced. The method is suitable for a vehicle-mounted network dynamic scene, and effectively resists attacks such as counterfeiting and replaying.
Owner:ANHUI UNIV

Forward-secure and quantum-attack-resistant updatable attribute-based conditional proxy re-encryption method

The present invention provides a computer-implemented method for forward-secure and quantum-attack-resistant updatable attribute-based conditional proxy re-encryption. The method includes: generating and disclosing public parameters by an authorization manager; generating public-private key pairs for delegator and delegatee; encrypting a plaintext using the delegator's public key and an attribute vector to produce a ciphertext; generating an updated public key and updated ciphertext for the delegatee; generating a re-encryption key associated with a control strategy; re-encrypting the ciphertext via a re-encryption component to produce a re-encrypted ciphertext; generating an updated private key by the delegatee; and decrypting the ciphertext or re-encrypted ciphertext using the updated private key. Based on lattice-based cryptography and an asynchronous key update mechanism, the method achieves forward security, quantum resistance, and fine-grained access control for secure data sharing.
Owner:JINAN UNIVERSITY

Key update system for updating cryptographic keys of arbitrary length

A method for updating an arbitrary length cryptographic key having a bit length greater than 256 bits by a cryptographic key update system includes transmitting, by a transmitter, a first transmission to one or more controllers that are part of a vehicle, and transmitting, by the transmitter, a second transmission to the one or more controllers, wherein the second transmission is symmetric key encryption under a concatenated key encryption key of the plurality of parameters and the new cryptographic key. The transmitter derives a key encryption key by converting a bit string of an authentication key and a constant value based on an N-bit compression function. The method includes transmitting, by the transmitter, a third transmission to the one or more controllers, the third transmission being an N-bit message authentication code concatenated under the first message authentication code (MAC) key of the first transmission and the second transmission.
Owner:GM GLOBAL TECHNOLOGY OPERATIONS LLC

Highly efficient side-channel attack resistant memory cryptography based on key update

A memory encryption system and method are disclosed, which rotates encryption keys to robustly resist side-channel analysis (SCA)-based attacks on the communication path between the encryption engine and external memory components within a trust boundary. A key data structure has multiple keys used to encrypt multiple blocks of memory in the external memory. The memory block encrypted using the oldest key in the key data structure is identified. Encrypted data is read from the identified memory block. The encrypted data from the identified memory block is decrypted. The data is then re-encrypted using a newly selected key (more recent than the oldest key) and rewritten to the identified memory block.
Owner:CRYPTOGRAPHY RESEARCH INC

A key update method and device for an external service

The application provides a key updating method and device for external connection service, and relates to the technical field of information security. The method comprises the following steps: sending a key updating request to a local quantum key distribution device, wherein the key updating request is triggered based on a key updating time strategy of a service system; receiving a quantum key pair returned by the local quantum key distribution device, wherein the quantum key pair is obtained through quantum key pair negotiation between the local quantum key distribution device and an external quantum key distribution device; and obtaining a new key according to the quantum key pair and a key component, wherein the key component is preset. The device is used for executing the above method. The key updating method and device for external connection service provided in the application embodiment improve the updating efficiency of the key.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Urban railway online key updating device, method and system and storage medium

The invention provides an online key updating device, method and system for urban railways and a storage medium. The device comprises a key management center, a certificate management center and key using equipment, the key management center is responsible for key encryption, secure connection establishment and key management; the certificate management center is responsible for issuing, updating, revoking and the like of the digital certificate; the secret key using device is responsible for digital certificate application and state query, secure connection establishment and online secret key management message processing; the method comprises the steps of login verification, secret key updating instruction issuing, identity verification, ciphertext information transmission, digital envelope manufacturing, secret key information distribution, feedback information reading and secret key updating condition verification. According to the method, a digital certificate management system is introduced, it is ensured that interaction content in the key updating process is completely encrypted, intercept and tampering risks of a man-in-the-middle are avoided, and key management safety is ensured.
Owner:SHANGHAI SHENTIE INVESTMENT CO LTD +1

A time window based cipher key smooth transition system

The application discloses a time window-based cipher machine key smooth transition system and relates to the technical field of key distribution. First, relevant operation data of a cipher machine is collected, and time window parameters of key smooth transition of the cipher machine are obtained through analysis, so that whether the time window parameters of key smooth transition of the cipher machine need to be adjusted can be evaluated. Through optimization and adjustment of the time window parameters, the situation that the performance of the cipher machine is reduced due to improper key transition can be reduced. Then, the key transition process of the cipher machine is analyzed, the security of the key can be evaluated, and the key that needs to be updated in advance can be found early, so that the key can be updated before the key is possibly leaked. Finally, the key smooth update result of the cipher machine is obtained through analysis, and the key is updated according to the key smooth update result of the cipher machine, so that the security of the cipher machine in the whole key life cycle can be improved, and security vulnerabilities caused by non-compliant key update can be reduced.
Owner:YUHENG POWER STATION OF SHAANXI HUADIAN YUHENG COAL POWER CO LTD

Real-time data encryption transmission method and device of weak current remote monitoring system

This invention relates to a real-time data encryption transmission method and apparatus for a low-voltage remote monitoring system, specifically in the field of low-voltage remote monitoring systems. By intelligently predicting network stability and precisely triggering key updates, it effectively avoids update failures caused by link fluctuations in dynamic network environments. A lightweight distributed consensus mechanism is used to generate secure key blocks, significantly reducing communication overhead while ensuring Byzantine fault tolerance. A precise distribution strategy based on topology difference identification greatly reduces redundant transmission, achieving efficient key delivery. An innovative chain-verification and zero-knowledge synchronization mechanism ensures the secure recovery of key states by offline nodes. The overall solution significantly optimizes transmission efficiency and resource utilization while improving system security, making it particularly suitable for large-scale, highly dynamic IoT monitoring scenarios.
Owner:INNER MONGOLIA RUNTONG NETWORK TECHNOLOGY CO LTD

Message transmission method and device, equipment and storage medium

The embodiment of the invention provides a message transmission method and device, equipment and a medium, and the method comprises the steps: enabling a client to only need to transmit key updating information to the server once and receive confirmation information when the key updating time is reached on the basis that the key updating mechanisms of the client and the server are consistent in advance; according to the invention, the new working key can be quickly determined only when the working key is updated, so that the consumption of a large number of asymmetric computing resources and a plurality of communication rounds caused by the fact that a complete handshake process needs to be executed in each key updating in the traditional TLCP protocol is avoided, the key updating efficiency is greatly improved, the delay and packet loss risk of service data transmission are reduced, and the user experience is improved. The technical problem of low key updating efficiency of the TLCP in a real-time communication scene is effectively solved.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Information processing device and key management device

The present disclosure provides an information processing apparatus that enables updating of a key for program verification without invalidating a program verification function. An information processing apparatus 1 that calculates a verification value using a key for program verification and that verifies whether the verification value matches a verification expected value stored in advance. The information processing apparatus 1 includes: a key updating control unit 12 that updates the key; a storage unit 100 that stores in advance a verification expected value corresponding to a key updated by the key updating control unit 12; and a verification expected value changing unit 13 that when a verification value calculated based on the updated key is verified, changes the verification expected value in the storage unit, the verification expected value being referred to for verification, to a verification value corresponding to the updated key.
Owner:ASTEMO LTD

Key management method, electronic control unit and vehicle

The invention discloses a key management method, an electronic control unit and a vehicle, and relates to the technical field of vehicle-mounted information security. The method provided by the invention comprises the following steps: the electronic control unit stores an encrypted first target key, and monitors a decryption access event of the key to generate access log information; before the key is updated, the management terminal firstly reads the access log information to carry out risk assessment, and judges whether the key has a leakage risk or not; if there is no risk, issuing a key update data packet including a second target key and a signature value, the signature value being generated by a first signature key paired with the first verification key; the electronic control unit decrypts the first target key to obtain a first verification key, and verifies the signature value according to the first verification key; and after the verification is passed, replacing the first target key with the second target key, and resetting the access log. According to the method, a closed-loop process of'monitoring-evaluation-updating 'is introduced, so that the secure in-service updating of the key is realized, potential attacks can be actively sensed, and the security of key management is remarkably improved.
Owner:DONGFENG COMML VEHICLE CO LTD

Three-layer cooperative secure transmission method and system for remote control of engineering machinery

The invention discloses a three-layer cooperative secure transmission method and system for remote control of engineering machinery. The three-layer cooperative secure transmission system is composed of a terminal sensing layer, an edge transmission layer and a cloud application layer, wherein the terminal layer realizes equipment identity bidirectional authentication and data grading marking; the edge layer designs a working condition self-adaptive encryption mechanism based on an SM4 algorithm, and improves the transmission reliability in a complex environment in combination with a multi-channel scheduling strategy of 4G / 5G and Beidou short messages; the cloud supports fine-grained authority control and operation auditing by adopting M-tree key management and alliance chain evidence storage; and the dynamic key updating protocol triggers local key reconstruction according to conditions such as equipment movement and session duration. An operation behavior learning model based on LSTM is introduced, abnormal operation is detected, a key freezing mechanism is linked, and illegal operation risks of legal users are prevented; while low-delay transmission of a P0-level control instruction is guaranteed, the overall security and anti-attack ability of the system are effectively improved, and the method is suitable for engineering machinery remote control scenes under high-dynamic and heterogeneous networks.
Owner:DAOJIANYOUXING (CHONGQING) TECH CO LTD +2

Key updating method, encryption communication method, device, equipment and storage medium

The invention relates to the technical field of cryptography, and provides a key updating method, an encryption communication method, a device, equipment and a storage medium, and the method comprises the steps: receiving a key updating request for a target service application represented by a key main index; determining a key sub-index corresponding to the key main index in the full-quantity cryptographic operation cluster; the key sub-index comprises an original key and a key group thereof; determining whether the master key tags corresponding to the original keys in the full-quantity cryptographic operation cluster are consistent; the master key label indicates a master key currently enabled by the original key in the key group; if yes, key updating is carried out on a current auxiliary key of the original key in the full-amount cryptographic operation cluster, and the auxiliary key is the other keys in the key group; and if not, prohibiting key updating on the target service application. According to the embodiment of the invention, the influence on the correctness and continuity of business transaction during key value updating and cryptographic algorithm switching can be reduced or solved.
Owner:CHINA EVERBRIGHT BANK

Distributed identity-based encryption against key leakage

The application discloses a kind of anti-key leakage distributed identity-based encryption method, by system initialization, key generation, key update, encryption, decryption step composition.In the key generation step, for the key escrow problem in identity-based encryption mechanism, the decryption key is calculated for user by distributed key generation technology, the privacy of user key is guaranteed, the problem that the right of key generation center is too large in traditional identity-based encryption is solved.In the key update step, by re-randomizing to the original key of user, the entropy loss of key caused by information leakage is filled, and the security and practicability of the scheme under continuous leakage attack are guaranteed.In the encryption step, by introducing the legality verification element of ciphertext, the ciphertext is not extensible, so that the scheme has the security of resisting selected ciphertext.The method of the application adopts anti-leakage cryptography mechanism and distributed key generation technology, and proposes a practical identity-based encryption scheme, which can be used in the field of access control technology.
Owner:SHAANXI NORMAL UNIV