Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

39 results about "Revocation list" patented technology

In cryptography, a certificate revocation list (or CRL) is "a list of digital certificates that have been revoked by the issuing certificate authority (CA) before their scheduled expiration date and should no longer be trusted".

Secure dynamic loading method for peripheral adapter plug-in in embedded low-resource environment

The invention relates to a safe dynamic loading method for a peripheral adaptive plug-in in an embedded low-resource environment, and belongs to the technical field of plug-in loading. The method comprises the following steps: executing digital signature identity authentication and lightweight increment integrity verification; analyzing the metadata, and distributing a physical isolation memory area by utilizing a memory management unit; initializing and analyzing the peripheral dependency list in the isolation memory, dynamically generating an encryption capability token bound with an isolation domain identifier, and embedding a monitoring hook to verify the authority of the token; performing lightweight behavior auditing during operation, triggering a response mechanism based on a result, and checking a certificate state by using a pre-downloaded certificate revocation list incremental data packet when the system is idle; verifying the new-version plug-in independently, pausing the old-version capture state snapshot, switching the peripheral control right to the new-version plug-in through the atomic operation sequence, recovering the token and safely erasing the memory. The whole mechanism ensures high-security isolation and dynamic protection. The efficient and safe loading and operation of the peripheral adaptive plug-in under the embedded low-resource environment are realized.
Owner:SHANGHAI TUYOU INFORMATION TECH CO LTD

Management method and device for preventing BMS firmware from being flashed

The invention provides a management method and device for preventing BMS firmware from being flashed, and relates to the technical field of asymmetric encryption, and the method comprises the steps: generating a unique response, and reconstructing an equipment root key, so as to establish a trusted firmware execution environment and complete firmware digital signature verification; digital certificate exchange and bidirectional verification of the BMS and the diagnostic instrument are carried out in the trusted firmware execution environment, a dynamic session key is generated, and a challenge response mechanism is executed to ensure that firmware flashing operation is only authorized in the trusted communication environment; performing hash check, control flow monitoring and access auditing by using the security reference data based on the dynamic session key, performing real-time hardware processing when an exception is detected, and recording a security event at the same time; and the BMS uploads the log and attack behavior characteristics corresponding to the security event to a cloud platform, and the cloud platform analyzes and generates a detection rule or certificate revocation list and issues and updates the detection rule or certificate revocation list. Through the dynamic BMS firmware flashing protection method, the safety of the BMS firmware is improved.
Owner:XIAOGAN CORNEX NEW ENERGY INNOVATION TECHNOLOGY CO LTD

Secure certificate chain transition

Some embodiments provide proxies or other servers in a computing network with independent certificate chains which facilitate mitigation of certificate problems. Independence criteria are enforced against two or more installed certificate chains on a given server, identifying and avoiding dependencies such as cross-certification, shared certificate authorities, shared revocation lists, or shared certificate status protocol endpoints between the certificate chains. Some embodiments serve independent certificates concurrently in an active-active certificate server configuration. The certificate chains' coexistence and their independence from one another facilitates transitioning the network from a failing issuer or a failed chain to a chain that works better, thereby improving network resilience and limiting damage from certificate problems. By dynamically updating certificate bindings, some embodiments also facilitate safe deployment of new certificates during migration from one issuer to another. Certificate distributions are computed from issuer ratios, network topology, or both.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Network node and control method

This network node comprises: a reception unit that acquires a certificate revocation list (CRL); a control unit that identifies a device in which a certificate has expired on the basis of the CRL, and identifies an opposing entity having said device as a communication destination; and a transmission unit that transmits, to the opposing entity, a setting for excluding said device from the communication destination.
Owner:NTT DOCOMO INC

A secure and revocable anonymous authentication method for internet of things

The application discloses a kind of enhanced security revocable anonymous authentication method of Internet of Things, including the following steps, S1: system initialization, for generating public parameters and user registration;S2: authentication between user and gateway, for identity authentication and session key establishment;S3: password update and revocation, authorized user can update password, gateway can revoke malicious user.It is beneficial to generate a pseudonym using the random number of gateway, provide a safe and effective identity privacy protection scheme, perfectly solve the problem of anonymity and message unlinkability.Add an effective revocation mechanism, when malicious user appears, gateway will record it to revocation list, and gateway does not provide key generation service for the user, so as to realize user revocation, realize identity authentication, anonymity, unlinkability, password update and revocation, etc.Security requirements such as.
Owner:ANHUI AGRICULTURAL UNIVERSITY

Revocation determination method, certificate-revocation-list creation method, non-transitory computer-readable recording medium, revocation determination system, and certificate-revocation-list creation system

A revocation determination method involves acquiring an electronic certificate, acquiring a certificate revocation list including one or more invalid certificates that are revoked electronic certificate, and determining, based on a serial number and one or more condition information items, whether the acquired electronic certificate is valid or invalid, the serial number being included in the acquired certificate revocation list, the one or more condition information items being indicated in one or more extension regions included in the acquired certificate revocation list.
Owner:PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD

Method and system for a secure platform driven root of trust (ROT) for information handling system components

A method for securely updating a firmware (FW) of a component of an information handling system (IHS) includes: receiving an update package for the component; analyzing the update package to extract at least a manifest and an FW update file associated with the component; making a first determination that the manifest is authenticated; making, based on the first determination, a second determination that a key revocation criterion is met, in which the key revocation criterion specifies that a certificate revocation list (CRL) does not specify an authentication key to be used to authenticate an updated FW of the component; updating, based on the second determination, the FW of the component using the FW update file, in which, after being updated, the component has the updated FW; and initiating notification of a user of the IHS about the updated FW of the component.
Owner:DELL PROD LP

X.509-compatible anonymous identity authentication and supervision method on a blockchain

The application provides a kind of anonymous identity authentication and supervision method on X.509 compatible blockchain, and each user party calculates the middleware that is legally held according to its own private key and the legal certificate held by itself and generates the first zero-knowledge proof;Combined with Merkle tree and accumulator, the identity certificate identification number of itself is proved to the service party that it is not in the revocation list of service party to obtain the second zero-knowledge proof, and multiple secret values and public values are generated;Request is sent to the service party and the first zero-knowledge proof, the second zero-knowledge proof and the public value are provided, and the service party is authenticated, if the three are verified, the request sent by the user party is responded to.The application uses standard X.509 specification certificate anonymous access service party Various services provide basic privacy protection, while designing a proof scheme supporting large-scale certificate revocation, greatly reducing the zero-knowledge proof overhead of generating proof not in the revocation list.
Owner:XIDIAN UNIV

Revocable attribute-based encryption method based on block chain and policy hiding

The embodiment of the invention provides a revocable attribute-based encryption method based on a block chain and policy hiding, and belongs to the technical field of data security. Comprising the following steps: constructing an access strategy, generating a symmetric key, encrypting a data file and the symmetric key, and outputting an intermediate ciphertext; replacing an access strategy in the intermediate ciphertext through a Bloom filter, outputting a final ciphertext and a ciphertext header component, and storing a hash value of the final ciphertext to a block chain BC; verifying a decryption token for applying for accessing the data file by the data user DU; if the verification is passed, judging whether the attribute set of the data user DU is in a revocation list; under the condition that the attribute set is not in the revocation list, verifying whether the attribute meets an access strategy or not; if yes, executing an outsourcing decryption operation, and returning a part of decryption result to the data user DU; verifying the correctness of the partial decryption result according to a hash value stored on the block chain BC; and if the verification is passed, final decryption is carried out to obtain a plaintext data file.
Owner:ANHUI RUIXIN SOFTWARE CO LTD +1

Revokeable access control method based on cloud-edge collaboration

The application relates to a revocable access control method based on cloud edge cooperation, which comprises the following steps: a blockchain execution system is set, and global parameters are generated; a data owner is set, and a public key and a master key are generated; an edge node executes a setting algorithm, and outputs a public key and a master key of the edge node; a user decryption key is composed of the key of the data owner and the key of the edge node; the data owner firstly executes partial encryption of data according to an access strategy and plaintext information, generates partial ciphertext, and then the edge node performs secondary encryption on the partial ciphertext to obtain final ciphertext; the blockchain performs key legality checking on the user decryption key, and the user with the key passing the checking can continue to access the data; the edge node firstly performs semi-decryption on the final ciphertext to obtain semi-decrypted ciphertext, and then the user performs final decryption on the semi-decrypted ciphertext to obtain correct plaintext; after the revocation operation is executed, the ciphertext is updated by using an updated revocation list and the key, and the updated ciphertext is stored in the cloud.
Owner:HEBEI UNIVERSITY

Method and system for safely sharing data in untrusted cloud environment

The invention discloses a method and a system for safely sharing data in an untrusted cloud environment. The method comprises the following steps: 1) when a trusted program is started for the first time, initializing a service key RKEY and a revocation list in a trusted execution environment TEE memory; encrypting the RKEY and storing the encrypted RKEY in a storage program; loading the encrypted RKEY into the TEE memory and decrypting the RKEY when the RKEY is not started for the first time, and loading the revocation list into the TEE memory and decrypting the revocation list; 2) the trusted program generates an identity ID, an identity key IKEY and an authentication report TCERT for a to-be-registered user; encrypting the IKEY by using the RKEY, and storing the encrypted IKEY in a storage program; 3) the trusted program generates an ABE master key pair for the user, and binds the MSK with the ID of the user; 4) the trusted program generates a private key SK for the user and binds the private key SK with the ID of the user; and 5) the trusted program decrypts the ciphertext by using the SK after receiving the data decryption request of the user.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

Fine-grained data dynamic access control method based on attribute-based encryption

The invention relates to a fine-grained data dynamic access control method based on attribute-based encryption. The method comprises the steps of obtaining to-be-shared data, and performing symmetric encryption on the to-be-shared data according to a randomly generated symmetric encryption key to obtain a data ciphertext; based on an access control strategy, encrypting the symmetric encryption key by using an ABE encryption algorithm to obtain a convertible ciphertext header; in response to the obtained data access request, performing user identity verification according to a user identity public key and an access data identifier in the data access request based on a current system state version number, a revocation list and metadata of to-be-shared data in the smart contract of the block chain to obtain a verification result; and if the verification result is that the verification is passed, obtaining a corresponding convertible ciphertext header according to the access data identifier, and performing re-encryption processing on the convertible ciphertext header according to the proxy re-encryption private key, the current system state version number and the revocation list to obtain a new ciphertext header. By adopting the method, large-scale and frequent permission change can be dealt with.
Owner:侯金轩

Privacy enhancement access control method for medical data sharing

The invention discloses a privacy-enhanced access control method for medical data sharing, which is characterized in that an efficient and privacy-protected attribute revocation mechanism is innovatively added on the basis of an original decentralized multi-authority attribute verification and strategy hiding mechanism, and an attribute revocation list (ARL) based on a Merkle tree and corresponding ZKP constraints are introduced, so that the privacy-protected access control method for medical data sharing is realized. Fine-grained dynamic authorization is supported, the security problem that user permission changes along with time in a medical environment is effectively solved, and triple privacy security of user attributes, access strategies and attribute validity states is ensured. Through cooperative work of a system initialization stage, a strategy deployment stage, an access request submission stage, an access control decision stage and a data access stage, strong privacy protection, decentralized architecture, fine-grained control and dynamic authorization in medical data sharing are realized; the problems of single-point failure, privacy disclosure and strategy stiffness in a traditional scheme are effectively solved, and a safe and reliable technical basis is provided for cross-institution medical cooperation.
Owner:XINJIANG UNIVERSITY

Remote key injection method and system based on asymmetric cryptography

The invention discloses a remote key injection method and system based on asymmetric cryptography. The method comprises the following steps: establishing a three-level CA system, presetting a certificate, and strictly defining a theme identifier and an expansion key usage of the terminal certificate; both the device side and the server side verify the certificate chain and the extended key usage of the opposite side, actively acquire and verify the certificate revocation list of the intermediate CA of the opposite side, and perform anti-replay certificate state verification in combination with the OCSP; the two parties are bound with a specified communication party by comparing the certificate theme identifier with a preset authorization list; the two parties generate a temporary key pair, and an initial key is securely transmitted by adopting an asymmetric cryptography mechanism; and S4, the device end decrypts to obtain the initial key and securely stores the initial key. Through bidirectional peer-to-peer deep verification, service binding and forward security key negotiation mechanisms, the problems of insufficient authentication strength, easy replay attack, lack of forward security and poor flexibility in the prior art are solved.
Owner:FUJIAN MOREFUN ELECTRONICS TECH CO LTD

Certificate Revocation List Management Services

Operations may include receiving, from a first network entity, a first request for a first certificate revocation list (CRL) that identifies a first CRL distribution point (CDP) corresponding to the first CRL; mapping the first CDP to a first CRL identifier of a set of available CRL identifiers; locating, in a CRL repository, a first CRL based on the first CRL identifier; and transmitting the first CRL to the first network entity.
Owner:ORACLE INT CORP

Power system digital certificate state synchronization method, system and device and medium

The invention relates to the technical field of network security, and discloses an electric power system digital certificate state synchronization method, system and device and a medium, and the method comprises the steps: representing a trust list and a revoked list of an electric power system digital certificate through an OR-Set type conflict-free complex data structure, forming a trust OR-Set and a revoked OR-Set, each node in the power system network stores a corresponding copy; when the concurrent operation of adding the certificate trust and revoking the certificate exists, enabling the revoking operation to take effect preferentially; the certificate state change operation is signed and authorized through a plurality of pre-trusted authority subjects, and then is broadcasted in the power system network; and each node exchanges an incremental log of a certificate state change operation through a peer-to-peer network, so that the trust OR-Set and the revoked OR-Set of each node are kept consistent in state. According to the method, centerless and high-fault-tolerance certificate revocation and trust list synchronization can be realized in the power control network.
Owner:GUO JIA DIAN WANG YOU XIAN GONG SI XI NAN FEN BU

A method for automatic key negotiation and management of a link-layer transparent encryption device based on an identifier algorithm

This invention discloses a method for automatic key negotiation and management of link-layer transparent encryption devices based on the SM9 identifier cryptography algorithm. Addressing the problem of extremely high certificate management costs in existing link-layer transparent encryption devices that use a PKI system for key negotiation, this invention proposes a certificateless key negotiation scheme based on the SM9 identifier cryptography algorithm. This method uses a Key Generation Center (KGC) to pre-configure a private key generated from the node's identity identifier. When the sending node detects raw data packets flowing to the target intranet, it directly extracts the receiving node's identity identifier (such as the device serial number) as the public key to initiate SM9 negotiation. This invention eliminates the cumbersome certificate exchange, revocation list maintenance, and verification steps of traditional PKI systems, significantly reducing certificate management costs and negotiation message overhead while achieving implicit authentication.
Owner:BEIJING GUOLING TECH CO LTD

A non-interactive instant identity verification and secure data transmission method

The application discloses a non-interactive instant identity authentication and secure data transmission method, which generates global parameters through a trust authority and distributes them to edge terminals, an authentication center and an edge computing server, and adopts a non-interactive identity authentication technology to perform edge terminal authentication. In the authentication process, the edge terminal generates and sends instant authentication credentials to realize secure connection with the edge computing server. Hash functions and public key cryptography technology are adopted to ensure the security of communication, and a non-member proof and revocation list mechanism are adopted to prevent illegal terminals from accessing the system. Temporary symmetric keys are used for encryption between the edge terminal and the server to ensure the confidentiality and integrity of data transmission. The application has efficient identity authentication, reliable data transmission security and optimized computing and bandwidth utilization, is suitable for resource-limited edge computing scenarios, and has good security, efficiency and scalability.
Owner:SHANGHAI MARITIME UNIVERSITY +1

An attribute-based dual access control data sharing method for internet of vehicles

The application discloses a kind of attribute-based Internet of Vehicles dual access control data sharing methods, user generates attribute key, and proxy key is generated using attribute key;Data owner is encrypted to data using attribute-based encryption algorithm according to defined semi-hidden access structure, considering the limited computing capacity of vehicle end, and the encryption process is divided into offline and online two stages;Cloud server filters out the false information sent by malicious user;(Access control is carried out to the download request sent by the user who wants to access data, so as to refuse EDOS attack;Only the user who satisfies access policy can decrypt ciphertext, and the decryption stage is also divided into two stages of outsourcing decryption and user decryption;Malicious user is revoked, and after malicious user is revoked, only the ciphertext related to revocation list needs to be updated, without updating the entire ciphertext.The application can realize the safe data sharing in Internet of Vehicles, and promotes the wide application of vehicle network.
Owner:ANHUI UNIV

Vehicle and certificate validation method of vehicle

A certificate validation method of a vehicle may include: receiving, by a controller of a vehicle and from an external device, a certificate for authenticating the external device; and based on a determination that wireless communication is available between the controller and a certificate validation server: sending, by the controller and to the certificate validation server, the certificate without a certificate revocation list (CRL) for verification of validity of the certificate; and requesting the certificate validation server to validate the certificate without the CRL.
Owner:HYUNDAI MOTOR CO LTD +1

Industrial Internet of Things anonymous responsibility-traceable data editing method and system based on block chain

PendingCN121967028APut an end to illegal exchangesPrevent permission abuseKey distribution for secure communicationUser identity/authority verificationComputer networkEngineering
The invention belongs to the technical field of blockchain security, and discloses an industrial Internet of Things anonymous responsibility-traceable data editing method and system based on a blockchain. The method comprises the following steps: generating a chameleon Hash trap door by a trusted mechanism, splitting the chameleon Hash trap door into shares by using threshold secret sharing, distributing the shares to verifier nodes, and initializing a dynamic accumulator; the owner encrypts the production data and formulates a modification strategy, and generates a hash value and an initial voucher by using chameleon hash and uploads the hash value and the initial voucher to a chain; the modifier initiates a request containing zero-knowledge proof, after verification is passed, the verifier node generates partial vouchers by using the trap door share, and the modifier aggregates the partial vouchers into a one-time voucher to complete editing; and the trusted mechanism decrypts the identity of the malicious modifier, moves the malicious modifier out of the dynamic accumulator and updates the revocation list. According to the method, trap door leakage is prevented through a threshold sharing mechanism, zero knowledge proof and a dynamic accumulator are combined, and effective tracking and permission revocation of malicious behaviors are realized while identity privacy of a modifier is guaranteed.
Owner:ANHUI UNIV

Lattice-based fine-grained attribute encryption method supporting user and attribute double revocation

The invention discloses a lattice-based fine-grained attribute encryption method supporting user and attribute double revocation, and belongs to the technical field of information security and cryptography. The method comprises the following steps: S1, initializing a system; s2, public key distribution; s3, generating a private key; s4, encrypting and uploading the data; s5, requesting and decrypting data; s6, releasing the user revocation list; and S7, distributing the attribute revocation list. According to the method, fine-grained access control on encrypted data in a cloud environment is realized, user revocation and attribute revocation are supported at the same time, the attribute revocation does not need to re-execute a discrete Gaussian sampling algorithm to generate a user private key, and ciphertext updating is realized by cloud service without participation of an encryptor; the user revocation only needs to regenerate the ciphertext component related to the user revocation by the encryption party, and any user private key does not need to be updated; according to the double revocation mechanism, the system calculation amount and the communication burden are effectively reduced, and low-overhead and dynamic fine-grained authority management facing the cloud environment is realized.
Owner:NANJING UNIV OF SCI & TECH

A time-limited group signature method with double privacy

The application provides a time-limited group signature method with double privacy. The method comprises the following steps: a system initialization operation: generating system parameters and creating a time tree; an administrator initialization operation: the administrator generates his own public and private keys, pseudonym parameters, a register and a revocation list; a user joining a group operation: the user generates his own public and private keys, generates his own pseudonym and applies to join a group; a group certificate generation operation: the administrator issues a group certificate to the user who is approved and makes the user a group member; a group revocation operation: the administrator uses the time tree to obtain the current encryption time and verifies, and adds the group member whose time limit is invalid to the revocation list; a group signature generation operation: a message is sent to the group member, the group member signs the message and sends it to a signature verifier; a signature verification operation: the signature verifier verifies the group signature; and a signature tracker operation: if there is a dispute between the signature verifiers, the administrator is requested to arbitrate, and the administrator tracks the real identity of the corresponding group member.
Owner:HENAN UNIVERSITY

Encrypted OTA upgrading method for air conditioner controller

The invention relates to the technical field of air conditioner upgrading, and provides an encrypted OTA upgrading method for an air conditioner controller, which comprises the following steps: generating model keys corresponding to different model identifiers, constructing a multi-level intermediate key corresponding to different area identifiers and upgrading batch identifiers, pre-encrypting an original firmware package layer by layer, and updating the firmware package layer by layer; generating batch-level encrypted packets stored in a classified manner; receiving an upgrade request carrying equipment identity information, matching a target batch-level encrypted packet, issuing a dynamic revocation list abstract, generating a unique session key of a single session based on joint negotiation of an equipment random number and a cloud random number, performing block encryption on the batch-level encrypted packet, and issuing the encrypted packet; decrypting the received encrypted blocks layer by layer by using the session key and a locally stored key of a corresponding level, and restoring to obtain original firmware blocks; and writing the restored firmware into a backup partition, and executing partition switching update after determining that the new firmware has a starting condition.
Owner:GUANGDONG SANHUA VANADIUM SOUND TECH CO LTD

Vehicle and roadside unit mutual authentication and key agreement method and device

ActiveCN120378875BKey (cryptography)Password
The application discloses a vehicle and roadside unit mutual trust authentication and key negotiation method, relates to vehicle networking communication entity identity authentication, and belongs to the field of vehicle networking information security. The method pre-sets a trusted center key, and embeds an unclonable device into a communication entity. After receiving a registration response, the communication entity stores a three-tuple in a memory thereof. An authentication message is constructed based on the identity identification of the communication entity, a password, a time stamp and an elliptic curve public key cryptography algorithm. The mutual trust authentication of the identity of the communication entity and the session key negotiation are realized through the interaction of the authentication message and the verification of the to-be-verified parameters. After the mutual trust authentication of the identity is passed, the received key message is verified by the receiving communication entity. The trusted center can track the identity of a false message sender. The communication entity adds the pseudo identity identification of the false message sender to an incremental pseudo identity identification revocation list, and completes the revocation of the false message sender, thereby improving the authentication efficiency of the vehicle and the roadside unit.
Owner:CHANGZHOU INST OF TECH

Gateway admission determination method and device, client device and storage medium

The embodiment of the invention discloses a gateway admission determination method and device, client equipment and a storage medium, and the method comprises the steps: transmitting a gateway admission request and a verification certificate to a verification end through a gateway admission program, and enabling the verification end to continuously use a certificate authority to verify the real-time validity of the verification certificate, the verification certificate is obtained from the server side by using a gateway access program, the verification certificate is activated by the server side in a certificate issuing mechanism according to a local feature code sent by the client device, and the local feature code is obtained by encrypting user information and device information one by one by the client device by using cascade key derivation; when the target user continuously surfs the Internet, continuously receiving a real-time validity verification result determined by the verification end according to the certificate revocation list; when the real-time validity verification result is an admission instruction, determining that the gateway admission request is admission; and when the real-time validity verification result is a security protocol alarm, determining that the real-time validity of the verification certificate is invalid, and determining that the gateway admission request is failed.
Owner:DIGITAL GUANGDONG NETWORK CONSTR CO LTD

Methods and devices for authentication and verification of non-revocation

Method and device for authentication of non-revocation. A revocation list includes at least one pair extracted from a signature generated by a revoked entity, where hi is an element of a mathematical group and ki=hixi, where xi is a secret of the revoked entity. A first entity sends, to a second entity, to authenticate itself therewith: a signature generated by the first entity for this authentication; a character string; an element of the group for each pair in the revocation list; and a zero-knowledge proof that the first entity used a secret of this first entity and the character string to obtain the group element for each pair. The second entity rejects the first entity if the zero-knowledge proof is not valid or if, for at least one the pair, the group element is such that Ci=hiA, where A is a known value.
Owner:ORANGE SA

Verifiable revocation multi-authority attribute-based encryption method and system

PendingCN122640110ACiphertextEngineering
The application discloses a verifiable revocation multi-authority attribute-based encryption and decryption method and system, which comprises the following steps: when any data user is revoked, a corresponding authority attribute institution updates a revocation list and a verifiable commitment and publishes them; a data owner updates an aggregated revocation state according to the latest verifiable commitment, generates an update key based on the aggregated revocation state before and after the update, and sends the update key to a cloud server; the cloud server updates a ciphertext package according to the update key and generates a cryptographic proof for proving the correctness of the update operation of the ciphertext; any data user verifies the consistency of the revocation state and the correctness of the update operation according to the latest verifiable commitment and the cryptographic proof before decrypting the latest ciphertext package; and the data user decrypts the latest ciphertext package after the verification. Therefore, the data user can verify the correctness of the update operation of the cloud server before decryption.
Owner:WUHAN UNIV

Network security password verification method and system

The invention provides a network security password verification method and system. The method comprises the following steps: acquiring a revocation list when group members sign; determining a secret revocation voucher and a personal key pair of each group member; in response to a plurality of signature requests of any group member for the plurality of event topics, performing anti-quantum attack processing on each event topic and the personal key pair to obtain an anonymous identifier for identity authorization when the group member is signed; carrying out anti-quantum encryption on the secret revocation voucher, and carrying out zero-knowledge proof on the anonymous identifier and the legality of the encryption process based on an encryption form to obtain a group signature of a hidden group member identity; and performing revocation detection on the group signature according to the anonymous identifier and the revocation list, and revoking the signer identity when the anonymous identifier corresponds to different signature messages under the same event theme based on a revocation detection result. By adopting the scheme of the invention, group signature verification of user privacy protection can be realized under the condition of resisting quantum computing attacks.
Owner:GUANGZHOU SHENGTONG QUALITY TESTING OF CONSTR

Identification password cross-domain authentication system and method based on block chain revocation list

The invention provides an identification password cross-domain authentication system and method based on a block chain revocation list, the identification password cross-domain authentication system based on the block chain revocation list comprises an IBC trust domain A, and the IBC trust domain A comprises a cross-domain authentication server CASA; an IBC trust domain A key generation center; a block chain platform; the authentication method of the identification password cross-domain authentication system based on the block chain revocation list comprises the steps that a first user applies for a revocation certificate from the server CASA through a first predetermined operation; the server CASA queries a certificate in the block chain platform; the server CASA generates block chain revocation information; and the block chain platform revokes a certificate according to the block chain revocation information. The block chain certificate revocation process is realized through the block chain platform, and the technical problem of lack of authentication under the centerless multi-organization cooperation condition at present is solved.
Owner:WUHAN SHIP COMM RES INST (NO 722 RES INST OF CHINA STATE SHIPBUILDING CORP)