Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

703 results about "Secret sharing" patented technology

Secret sharing (also called secret splitting) refers to methods for distributing a secret amongst a group of participants, each of whom is allocated a share of the secret. The secret can be reconstructed only when a sufficient number, of possibly different types, of shares are combined together; individual shares are of no use on their own.

Edge cloud hierarchical collaborative task unloading optimization method fusing federal learning

The invention discloses an edge cloud hierarchical collaborative task unloading optimization method fused with federal learning. According to the method, a three-level collaborative architecture of a terminal equipment layer, an edge node layer and a cloud center layer is constructed, and a task is split into a sub-task set containing a dependency relationship through a task analysis module. The edge node adopts a mixed model of a graph attention network and a double-delay depth deterministic strategy gradient, generates an unloading proportion in combination with an edge cloud topology and a real-time resource state, and realizes differential privacy protection through Laplace noise. In the federal learning process, the edge node only uploads Parel encryption parameters after local training, and the cloud generates a global meta-model through secret sharing aggregation and issues and updates the global meta-model. The multi-objective optimization model takes time delay, energy consumption and communication traffic as objectives, dynamically adjusts weight coefficients, and forms a'unloading-execution-learning-optimization 'closed loop. The method gives consideration to privacy protection and real-time performance, and is suitable for scenes with high requirements for privacy and timeliness.
Owner:CHINA UNIV OF PETROLEUM (EAST CHINA)

Financial data processing method and system based on machine learning and storage medium

The invention discloses a financial data processing method and system based on machine learning, and a storage medium. The method comprises the following steps: encrypting customer credit data of a financial institution through Paillier homomorphic encryption and extracting a risk feature vector; performing secret sharing segmentation on the local gradient parameters and then safely aggregating the local gradient parameters into global gradient parameters through a BGW protocol; on the basis of the privacy level, global gradient parameter differential privacy noise is injected and subjected to federal training to obtain a cross-institution credit evaluation result; calculating risk characteristics and evaluation results through homomorphic encryption to obtain an encrypted credit score, and performing secure multi-party calculation and decryption to generate a customer credit report; and block chain supervision compliance verification is carried out to generate an audit record, and a privacy budget optimization scheme is dynamically adjusted according to the business emergency degree. The technical problems that in an existing financial data processing method, information is incomplete due to data islands, data leakage risks are caused by insufficient privacy protection mechanisms, and an effective supervision compliance verification mechanism is lacked are solved.
Owner:ICBC SANMENXIA BRANCH

Education data privacy security protection method based on block chain and federal learning

The invention relates to the technical field of data privacy and security protection, in particular to an educational data privacy security protection method based on a block chain and federated learning, and the method comprises the steps: dividing participating nodes into workers, verification committee and aggregation committee based on a dynamic role distribution mechanism of stock right weight, decentralized election is realized through Hash ring mapping; in combination with a double-layer privacy protection strategy of Diffie-Hellman key agreement and Shamir threshold secret sharing, counteractable differential disturbance is added to a local model, and verifiability of gradient exchange and noise elimination are ensured; a Byzantine detection algorithm is used, and poisoning attacks under non-IID data are effectively identified through gradient-based symbol clustering and similarity threshold filtering; based on a contribution degree incentive model of a block chain smart contract, the weight of the committee is dynamically adjusted through proven of interest (PoS), and Sybil attacks and centralized monopoly are prevented. By adopting the method, the effectiveness and privacy security of the education data in the distributed training process can be guaranteed.
Owner:GUANGXI NORMAL UNIV

Government affair data dynamic authorization management method based on secure multi-party computing

The invention discloses a government affair data dynamic authorization management method based on secure multi-party computing, and relates to the field of government affair data security authorization management, and the method comprises the steps: distributing a unique identity identifier for each participant, generating an asymmetric key pair through employing a national secret SM2 algorithm, registering a public key and mechanism attribute information to an alliance chain smart contract, and generating an identity certificate package; and based on attribute information in the identity credential packet, the participants cooperatively generate anti-quantum dynamic attribute-based encryption key fragments through a secure multi-party computing protocol, and the anti-quantum dynamic attribute-based encryption key fragments are distributed to the participants by adopting a threshold secret sharing technology. Threshold decryption and token verification are achieved through an alliance chain verification intelligent contract, an authorization record is generated, an access control strategy of an edge computing node is configured according to the authorization record, an oblivious transmission protocol is adopted to respond to data query, and an audit node monitors an access log, dynamically adjusts attribute weight parameters and synchronizes the attribute weight parameters to a key fragment.
Owner:CHINA NAT INST OF STANDARDIZATION

Self-random cross-chain dynamic cooperative supervision method based on zero knowledge proof

The invention discloses a self-random cross-chain dynamic cooperative supervision method based on zero knowledge proof, which is used for realizing safe and supervisible privacy protection transactions in a block chain cross-chain environment. The method comprises the following steps: dynamically screening users through MACRO credit scores to form supervision chains, the number of which is consistent with that of application chains, and generating public and private keys; deploying a contract and a ZKP circuit in each chain, wherein ZKP generation adopts self-random hash; according to the supervision chain secret key and the self-random hash, the transaction is encrypted, verified and signed, and a random block header and a transaction link are recorded in a linker (TEE); after the supervision chain verifies the signature, the transaction is linked and stored in a supervision chain Merkel mountain range, and a linker is updated at the same time; a supervision chain of any party puts forward a supervision application, and after the supervision application is agreed by the opposite party, two rounds of two-layer secret sharing technology collaboratively supervise the recoverable transaction. According to the method, self-random encryption, zero-knowledge proof and dynamic supervision mechanisms are fused, and multi-key supervision, self-random encryption key dynamic change and multi-supervision-chain dynamic cooperative supervision are realized.
Owner:XIAN UNIV OF TECH

Medical data sharing method and system based on multi-party security computing

The invention provides a medical data sharing method and system based on multi-party security computing, and the method comprises the steps: carrying out the credible access control of participants through zero-knowledge proof and biological feature authentication, and enabling the participants to comprise a medical institution, a medicine enterprise / research institution, a patient and a supervision institution; after credible access control is passed, when a medical institution extracts patient data, k-anonymity, differential privacy and homomorphic encryption technologies are utilized to encrypt and desensitize the extracted patient data and store the data to a block chain; receiving a calculation task request and calculation parameters published on the block chain by a medicine enterprise / research institution, realizing mixed circuit and secret sharing mixed multi-party security calculation by a calculation node based on an ABY3 framework, and verifying the compliance of a calculation result; and receiving a result verification and auditing request of the supervision mechanism, and if the calculation result is verified to be within an authorization range through the smart contract, allocating rewards to the medical mechanism, the calculation node and the block chain platform according to a preset proportion, thereby effectively improving the security and timeliness of medical data sharing.
Owner:INSPUR YUNZHOU (SHANDONG) IND INTERNET CO LTD

Alliance chain identity privacy protection method and system based on multilevel group signature and distributed key management

The invention relates to an alliance chain identity privacy protection method and system based on multi-level group signature and distributed key management, and belongs to the field of block chain technology, network and information security. According to the method, a multi-level group signature structure is adopted, anonymous identity verification is achieved in the transaction process, privacy protection is further enhanced through zero-knowledge proof, anonymous identity verification is achieved in the transaction process, it is ensured that privacy of participants is not leaked, a homomorphic encryption algorithm is used in the signature and verification process of transaction data, and the transaction data are subjected to identity authentication. And privacy leakage is prevented. And meanwhile, the Shamir secret sharing algorithm divides the master key and stores the master key in a plurality of sub-group members in a distributed manner, so that the anti-attack capability and the key security are enhanced. According to the method, a dynamic group member management and double signature verification mechanism is further introduced, so that the flexibility and the overall security are improved. The method has significant advantages in the aspects of identity anonymity, data integrity and efficiency, and is suitable for alliance chain application scenarios with high privacy and security requirements.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Quantum threshold resistant digital signature method and system capable of tolerating high network delay

The invention belongs to the field of passwords, and discloses an anti-quantum threshold digital signature method and system capable of tolerating high network delay. The method comprises the following steps: in a secret key generation stage, a trusted third party randomly selects a secret key and performs Shamir secret sharing on the secret key, and distributes a secret sharing value to each signer; in a distributed signature stage, each signer carries out packaging and secret sharing on a secret sharing value, a proving sub-circuit of a public key is operated based on a secure multi-party computing protocol, and each participant outputs a signature through two rounds of interaction. The anti-quantum threshold digital signature scheme has function interchangeability, that is, the signature generated by the threshold scheme and the signature generated by the original signature scheme can be verified by the same verification algorithm; meanwhile, the threshold digital signature scheme is efficient and achievable, and a threshold signature protocol in a scene of two parties of a wide area network only needs 2 seconds; moreover, the method has a better number of rounds, and the signature algorithm only needs two rounds.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI

Privacy information retrieval system and method based on block chain and function secret sharing

The invention relates to the technical field of information retrieval, and provides a privacy information retrieval system and method based on a block chain and function secret sharing, and the method comprises the steps: carrying out the encryption and keyword extraction of a data document; generating a Bloom filter index table between the keyword and the document based on the keyword trap door; uploading the encrypted file and the Bloom filter index table to a DSSP end, and transmitting the hash value of the encrypted file and the Bloom filter index table to a block chain for on-chain storage; storing the encrypted file in a distributed storage node under the chain according to the divided share; and the block chain calculates data of each column of the Bloom filter index table through consensus to obtain a message verification code, and the message verification code is stored on the block chain. According to the method, the index is constructed through symmetric encryption and the Bloom filter, and block chain evidence storage and FSS distributed storage are combined, so that data privacy protection and index credibility are realized. Through verification and tampering prevention, the problem that the existing FSS lacks verification and auditing mechanisms is solved.
Owner:SHANDONG COMP SCI CENTNAT SUPERCOMP CENT IN JINAN

Key sharing and detection scheme based on intelligent electric meter

The invention discloses a key sharing and security detection scheme based on an intelligent electric meter, and aims to solve the problems that an untrusted electric meter in an intelligent power grid is difficult to identify effectively, the detection scale is uncontrollable and the communication security is insufficient. According to the scheme, the elliptic curve cryptography, the threshold secret sharing mechanism and the physical unclonable function are combined, and hardware-level binding of the unique identity of the equipment and the secret key is achieved in the registration stage. Through a threshold password mechanism, a plurality of intelligent electric meters cooperatively participate in key reconstruction and encryption communication, and the intelligent electric meters can still work normally when part of the electric meters fail or are broken through. The center node can actively identify a fault or a malicious ammeter and dynamically adjust a communication strategy according to the integrity and correctness of the feedback information. Meanwhile, the scheme supports dynamic identity updating and integrity verification, and effectively resists modeling attacks, Sybil attacks, replay attacks and DoS / DDoS attacks. According to the invention, secure identity authentication, reliable key distribution and efficient anomaly detection are realized, and the security of smart grid terminal communication is improved.
Owner:CHUXIONG POWER SUPPLY BUREAU OF YUNNAN POWER GRID CO LTD

Super-threshold data set intersection method and system for security information processing

The invention belongs to the technical field of information security, and particularly relates to a super-threshold data set intersection method and system for security information processing. The method comprises the following steps: S1, carrying out casual key value pair storage OKVS encoding and decoding between each participant and other participants; s2, each participant constructs a hash table according to a decoding result and elements of the participant; and S3, sending the constructed hash table to a specified party, summarizing information in the hash tables of all participants by the specified party, and finally obtaining a super-threshold intersection result by using a secret sharing scheme. The method has the characteristics that the hardware and operation and maintenance cost can be reduced, the data security is enhanced, and the calculation efficiency is improved, so that the industrial control requirement of short-time response is met.
Owner:ZHEJIANG SCI-TECH UNIV

Federal learning security training method and system based on differential privacy

The invention discloses a federal learning security training method and system based on differential privacy, belongs to the technical field of artificial intelligence, and aims to solve the technical problem of how to realize data privacy protection and model precision balance in cross-mechanism model training. Comprising the following steps: constructing a distributed structure comprising a plurality of clients and a server; each client constructs a noise variance calculation model by taking the gradient feature, the privacy budget coefficient, the data sensitivity level coefficient and the training stage coefficient as calculation parameters after each round of local training is finished, and Gaussian noise is calculated according to the noise variance; verifying the noise variance of each round, and adjusting the calculation parameters of the noise variance based on the comparison result of the accumulated budget consumption and the global privacy budget; dynamically allocating the data sensitivity level of the local training data and the budget allocation proportion of the client; and the server performs secure aggregation through a secret sharing algorithm, and distributes the updated global model parameters to each client.
Owner:INSPUR SOFTWARE TECH CO LTD

Decision tree security reasoning method and framework based on efficient element selection protocol

The invention provides a decision tree security reasoning method and framework based on an efficient element selection protocol, and belongs to the technical field of data security processing. According to the method, nodes and user attributes of a decision tree are converted into two-dimensional matrix representation from one-dimensional vectors, and a constant round communication conversion protocol is designed based on function secret sharing, so that a ciphertext selection index is converted into two ciphertext one-hot vectors; and performing ciphertext dot product operation on the two-dimensional matrix and the two one-hot vectors to complete an element security selection function. After a one-dimensional vector is converted into a two-dimensional matrix, through ciphertext dot product operation, the communication size is not directly proportional to the number of nodes and the number of attributes any more and is only directly proportional to the square root of the number of elements. According to the method, a secure dot product and function secret sharing technology based on secret sharing is combined, the communication size is reduced to be in direct proportion to a square root from being in direct proportion to the number of nodes and the number of attributes, communication and calculation expenses are remarkably reduced, and an efficient privacy protection decision tree reasoning framework is provided.
Owner:FUDAN UNIVERSITY

Thermal power generating unit collaborative frequency modulation method and system based on block chain federated learning

The invention relates to the technical field of power system frequency modulation control, in particular to a thermal power generating unit collaborative frequency modulation method and system based on block chain federated learning. According to the method, a decentralized P2P network is constructed through a block chain technology, and model parameters are initialized based on a secret sharing mechanism; carrying out local training by adopting an adaptive federal near-end optimization algorithm, measuring data isomerism through KL divergence and dynamically adjusting a regular coefficient; carrying out noise addition on a sample by adopting differential privacy, and carrying out homomorphic encryption to realize parameter encrypted transmission; selecting representative nodes based on a block chain consensus mechanism to execute parameter aggregation in the encryption domain; and multi-unit collaborative frequency modulation is realized through model prediction control. According to the method, the problems of data privacy protection, heterogeneous data adaptation and decentralized cooperative training are solved, and the stability of power grid frequency regulation and control is improved.
Owner:STATE GRID JIANGXI ELECTRIC POWER CO LTD RES INST

Reasonable entrustment federal learning method and system based on differential privacy

The invention discloses a rational entrustment federated learning method and system based on differential privacy, and the method achieves the purpose that a client controls the expected income of a server through constructing a rational calculation model based on a zero determinant strategy and establishing a linear income relation between the server and the client, and further achieves the purpose that the client controls the expected income of the server through a bounded differential privacy protection mechanism. And finally, whether the servers execute correctness aggregation or not is checked through an aggregation result verifiable algorithm of differential privacy based on secret sharing, meanwhile, offline of a certain number of servers can be tolerated, the influence of network abnormality, power failure and other emergencies on training can be weakened, and the training efficiency can be improved. The technical problem that the normal operation of model training in federated learning still cannot be ensured because only the aggregation result of the server can be checked in the existing research and the correct aggregation operation of the server is not considered is solved.
Owner:GUIZHOU UNIV

Privacy protection multi-task allocation method for unmanned aerial vehicle crowdsourcing perception system

The invention provides a privacy protection multi-task allocation method for an unmanned aerial vehicle crowdsourcing perception system, which combines addition secret sharing and homomorphic encryption to realize bilateral privacy protection of a task side and an unmanned aerial vehicle position. The task requester and the working party split a task position and a UAV departure position into two secret shares [.] 1 and [.] 2 by adopting an additive secret sharing mechanism respectively, and send the two secret shares [.] 1 and [.] 2 to the two independent service parties S1 and S2 respectively; the service party calculates an encrypted square Euclidean distance between the UAV and the task based on the shared share, and generates two distance matrix shares D1 and D2. On the basis, the two service parties cooperatively execute privacy comparison and a minimum index protocol under the optimized Paillier, and multi-task encryption shortest path distribution is realized in combination with a Hungary algorithm. According to the method, addition secret sharing is fused, Paillier encryption and task matching optimization are optimized, the total flight path of the UAV is remarkably reduced while position information privacy of the whole task allocation process is guaranteed, and good safety and deployability are achieved.
Owner:ELECTRIC POWER RES INST CHINA SOUTHERN POWER GRID CO LTD +1

Identity authentication method and system based on national secret algorithm

The invention discloses an identity authentication method and system based on a national secret algorithm, and the method comprises the steps: building a hierarchical key management system based on a national secret IBE framework, generating a system master key pair through employing an SM2 algorithm, and achieving a decentralized key distribution mechanism; constructing a domain perception differential privacy protection module, defining a privacy budget allocation strategy according to the security level, and adding calibrated Laplace noise to the user identity feature vector; designing a distributed batch matrix multiplication protocol, and decomposing the distributed batch matrix multiplication protocol to a plurality of computing nodes for parallel processing through a secret sharing technology; a zero-knowledge proof verification mechanism is implemented, and identity verification is completed through a commitment scheme based on an SM3 hash algorithm; deploying a self-adaptive key updating strategy, and analyzing threat level change through a threat situation evaluation function; and establishing a secure communication channel based on SM4 symmetric encryption, and performing encryption processing by using the temporary session key. The security and expandability of the system are improved, the privacy of the user is effectively protected, and the system adapts to a dynamically changing network threat environment.
Owner:GUIZHOU BLUESKY INNOVATIVE SCI & TECH CO LTD

Multi-user hierarchical data cloud storage sharing method and system based on secret sharing

According to the multi-user hierarchical data cloud storage sharing method and system based on secret sharing provided by the invention, storage protection is provided for an encryption key by using a secret sharing mechanism, so that the security of the key can be effectively ensured; different shared user groups and shared data grading contents are set according to different key shares, and attribute encryption can be equivalently realized; the access control server performs processing such as interpolation, slicing and transposition on an external storage key share, so that proxy re-encryption can be efficiently and equivalently realized; the secret key share is simultaneously used for realizing the processes of shared user group setting, shared data grading encryption, shared user and access control server bidirectional authentication, proxy re-encryption and the like, so that password resources are fully utilized. In addition, a key generation center is not needed, the interaction process of roles in the system is reduced, and the working process is simplified; and only simple Hash operation is needed, so that the generation of password resources is quicker, and the calculation is simpler and more efficient.
Owner:QUANTUMCTEK CO LTD

Lightweight differential privacy federal learning method for cross-domain management and control of power data

The invention discloses a lightweight differential privacy federal learning method for cross-domain management and control of power data. The method comprises the following steps: S1, performing initialization setting; s2, performing local training and parameter processing on the client; s3, uploading and aggregating parameters; s4, privacy loss evaluation and parameter adjustment; s5, pruning and compressing the model; s6, privacy protection and full mask multiplexing based on secret sharing; and S7, preventing collusion attacks. According to the method, the calculation complexity is remarkably reduced, and the core contradiction that privacy protection and model practicability are difficult to consider in cross-domain cooperation of power data is solved; the problems of high communication overhead and insufficient computing power of edge equipment during massive power data processing of traditional federated learning are solved, and the real-time performance and expandability of cross-domain cooperation are remarkably improved; while data availability is guaranteed, complex threats such as multi-client collusion and man-in-the-middle attack are effectively handled, and a privacy protection framework with a higher security level is provided for multi-agent cooperation of a power system.
Owner:ELECTRIC POWER SCI RES INST OF STATE GRID XINJIANG ELECTRIC POWER CO LTD

Channel secure transmission method for protecting data privacy of edge gateway of Internet of Things

The invention discloses a channel security transmission method for protecting data privacy of an edge gateway of the Internet of Things, and relates to the technical field of security and privacy protection of the Internet of Things, and the method comprises the steps: constructing an edge gateway security architecture, generating a quantum key through a QKD module based on the constructed edge gateway security architecture, and generating sensitivity data through an IPS vNSF; calculating noise based on the sensitivity data, generating disturbance data based on the noise, calculating a shared key, generating an encryption key in combination with the quantum key and the shared key, segmenting the encryption key through Shamir secret sharing, and encrypting and decrypting the key; encrypting the noise by using the decrypted key, generating global noise based on the encrypted noise, and calculating secondary disturbance data based on the global noise; and generating coded data based on the secondary disturbance data, and generating reconstruction data based on the coded data. According to the invention, the comprehensive security authority of the edge gateway in the aspects of key security and privacy protection intensity is improved.
Owner:ZHEJIANG IND POLYTECHNIC COLLEGE +1

VPN dynamic hierarchical encryption system and method for cross-border data transmission

The invention relates to the technical field of data encryption, in particular to a VPN dynamic hierarchical encryption system and method for cross-border data transmission, and the method comprises the steps: dividing a data flow into different hierarchies based on information entropy; the high-entropy core data is embedded in a steganography mode through a chaos algorithm by means of the low-entropy redundant space; carrying out global basic encryption on the mixed carrier, and respectively executing chaotic scrambling and differential iterative diffusion for the steganography region and the middle entropy region; dynamically injecting a filling block according to entropy feedback to realize flow homogenization shaping; and splitting the deconstructed index through threshold secret sharing, and performing hidden distribution. According to the method provided by the invention, the concealment and security of cross-border data transmission can be effectively improved.
Owner:JIANGSU ZHIMENG INTELLIGENT TECH CO LTD

Privacy computing protocol compounding method based on parameter security conversion

The invention relates to the technical field of privacy computing, and discloses a privacy computing protocol composition method based on parameter security conversion, comprising clients for data conversion, a plurality of MPC servers and a communication interface, S100, each client executes model training on a local private data set, generates local model update parameters, and sends the local model update parameters to the client; the method comprises the following steps: S200, a parameter encryption and conversion stage: a client calls an MPC encryption module to carry out security encryption on local model parameters, secret state conversion is carried out on the parameters by adopting a secret sharing and homomorphic encryption mechanism, and ciphertext parameter representation is generated, and S300, an encryption parameter transmission stage: the client transmits the secret state parameters to an MPC server through a communication interface, and the client transmits the encrypted parameters to the MPC server through a communication interface. The data transmission is protected by adopting an encrypted channel, S400, a security aggregation stage: the MPC server side receives encrypted state parameters from each client side, and S500, an aggregation result decryption and synchronization stage, and the device has the advantages of realizing protocol deep fusion, enhancing security and robustness and the like.
Owner:BEIJING INST OF TECH

Encryption and decryption method and system fusing quantum key and secret sharing, and medium

The invention relates to the technical field of information security, and discloses an encryption and decryption method and system fusing a quantum key and secret sharing, and a medium. According to the encryption and decryption method, a QKD method is adopted to generate a master key and a data encryption key, the master key is divided into a plurality of encryption fragments under the condition of encryption operation, storage nodes of the plurality of encryption fragments are determined by a dynamic method, enough encryption fragments are obtained under the condition of decryption operation, the master key and the data encryption key are recovered, and the encryption and decryption efficiency is improved. Therefore, the decryption of the data is realized. According to the encryption and decryption method, the master key and the data encryption key are generated based on the QKD device, hierarchical protection is formed, a secret sharing algorithm is set to be combined with a Hash dynamic method, storage nodes of encryption fragments are automatically migrated, targeted attacks are resisted, the data security of a database is guaranteed, the master key is obtained through a Lagrange interpolation method, the decryption efficiency is high, and the encryption and decryption efficiency is high. And the recovery time is controllable.
Owner:STATE GRID ANHUI ELECTRIC POWER CO LTD +1

Balanced SM9 digital signature multi-party adapter signature generation method and system

The invention discloses a balanced SM9 digital signature multi-party adapter signature generation method and system, a secret key generation center initializes system parameters according to security parameters in a symmetric environment, generates participant private key fragments by using a secret sharing technology, and generates a public and private key pair for a multiplication-to-addition ideal function for each participant; the participant requesting the pre-signature generates a difficult relation instance and a zero-knowledge proof and broadcasts the difficult relation instance and the zero-knowledge proof, the other participants calculate the pre-signature after verification, the legality of the pre-signature is verified by verifying a temporary variable, and a complete signature is calculated under the condition that the pre-signature is legal; adapter signature evidences are extracted according to the pre-signatures, the complete signatures and the difficult relation instances, evidence extraction is completed under the condition that instances generated by the adapter signature evidences are consistent with the difficult relation instances, and the national secret SM9 pre-signatures with the adapter function can be cooperatively generated under the condition that multiple participants jointly participate in operation in the symmetric environment; and the signature of the adapter is completed.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

Efficient communication data opening and sharing method and system based on privacy set intersection

The invention discloses a communication efficient data opening and sharing method and system based on privacy set intersection. In order to solve the problem that when the number of participants is large, the communication bandwidth of the participants in a privacy calculation scene is limited, the invention proposes that different element insertion sequences have influences on the calculation result of the confusion Bloom filter for the first time; an efficient optimal element insertion sequence search algorithm assisted by a counting bloom filter is provided based on a greedy strategy, and meanwhile, a theoretical lower bound and a theoretical upper bound for improving the storage space of the confusion bloom filter under a new algorithm are analyzed; a secret sharing principle of an improved confusion bloom filter is changed from XOR calculation to additive calculation, so that a related algorithm of the improved confusion bloom filter can perform homomorphic calculation in a ciphertext encrypted by a public key; based on the improved confusion Bloom filter, a multi-party privacy set intersection protocol with high communication efficiency is realized, and the protocol can be used for calculating a multi-party intersection and also can be used for calculating a threshold multi-party intersection of a self-defined threshold.
Owner:GUANGXI POWER GRID CORP

Short message data encryption and secure transmission system

The invention discloses a short message data encryption and secure transmission system, which relates to the technical field of short message encryption and comprises an environmental parameter monitoring module, an encryption granularity adjusting module, a key management module, a data transmission module and a security audit module. The environment information is acquired in real time through the environment parameter monitoring module, accurate evaluation of environment risks is achieved, the encryption granularity adjusting module dynamically adjusts the encryption granularity according to the environment information, the problem of resource waste or insufficient safety caused by the fixed encryption granularity is solved, the effect of improving the resource utilization efficiency while the safety is guaranteed is achieved, and the user experience is improved. The secret key management module adopts a Shamir secret sharing technology to carry out fragmentation storage and recovery verification on the secret key, the problem that the secret key is easy to leak in centralized storage is solved, the effect of improving the secret key security is achieved, on the whole, the system can flexibly adjust the encryption strategy according to the environmental risk, and the encryption efficiency is improved. And the reliability and adaptability of short message data encryption and secure transmission are remarkably improved.
Owner:BEIJING XUNYIN TECH CO LTD

Decentralized virtual identity key collaborative management system based on block chain

The invention discloses a decentralized virtual identity key collaborative management system based on a block chain, and belongs to the field of block chain technology and cryptography. The system comprises a block chain network layer used for distributed storage of key fragments and execution of an automation strategy; the virtual identity management module is used for generating a unique identity identifier (DID) through a threshold signature algorithm after fusing the biological characteristics and the device fingerprints; the key collaborative management module is used for storing the main key in a fragmented manner through a Shamir secret sharing algorithm, and dynamically selecting an encryption algorithm to generate a sub-key according to the security score of the target platform; the verification and auditing module is used for verifying the holding legality of the secret key through a zk-SNARKs technology and injecting random noise to resist side channel attacks; and the block chain network layer, the virtual identity management module, the key collaborative management module and the verification and auditing module are connected with an encrypted communication protocol through an intelligent contract interface.
Owner:HENAN INFORMATIZATION GRP CO LTD

Sensitive data collaborative auditing platform and method based on multi-party network security computing

The invention provides a sensitive data collaborative auditing platform and method based on multi-party network security computing, and relates to the technical field of multi-party security computing. The platform comprises a data input layer which is used for each data holder to acquire original data, standardize the original data, perform differential privacy processing on the standardized data, encrypt private data by adopting a Paillier homomorphic encryption algorithm to obtain a ciphertext, segment the ciphertext by adopting Shamir secret sharing to obtain a plurality of segment ciphertexts, uploading the fragmented ciphertext to a confusion layer; the confusion calculation layer is used for aggregating the fragmented ciphertexts to obtain aggregated ciphertexts, fragmenting the aggregated ciphertexts by adopting Shamir secret sharing to obtain a plurality of fragmented aggregated ciphertexts, and distributing the fragmented aggregated ciphertexts to audit layer nodes; performing target calculation on the fragmented aggregation ciphertext by adopting MPC calculation logic; and the auditing execution layer is used for converting the auditing rule into MPC computational logic. According to the application, the security, efficiency and cross-domain compatibility of multi-party collaborative auditing can be improved.
Owner:CICC DATA (WUHAN) SUPERCOMPUTING TECH CO LTD

Data management method and system for trusted data delivery platform

The invention discloses a data management method and system for a data credible delivery platform. Access is realized through symmetric encryption of source data, and credible right confirmation is realized by relying on identities of owners and users of alliance chain evidence storage, source data hash and authorization rules; adding a timestamp to the encrypted data stream verified by the certificate to form a traceability mark, and encrypting or desensitizing privacy data; the trusted computing is provided with three modes: a local mode executes an algorithm in an ownership party isolation environment and records a log on a chain, a third-party mode constructs a trusted sandbox based on TEE, executes computing and links log hash after remote certification, and an algorithm privacy mode realizes cooperative computing through a Shamir secret sharing splitting algorithm in combination with MPC, a confusion circuit and zero-knowledge certification; and the result delivery adopts public key encryption, a decryption key is issued after the receipt of the user is verified, and the result hash and the receipt are linked for evidence storage, so that the problems that the existing trusted platform cannot support the execution of various algorithms and is lack of effective supervision are solved.
Owner:GUIZHOU DIGITAL INNOVATION HLDG (GRP) CO LTD

Secure multi-party computing method and system based on secret sharing

The invention discloses a secure multi-party computing method and system based on secret sharing, and relates to the technical field of information security, and the method comprises the steps: obtaining original computing data, and dividing the original computing data into a plurality of data fragments; homomorphic encryption and symmetric encryption are respectively and sequentially carried out based on all the data fragments to obtain a plurality of layered encryption fragments; generating a random mask value and correspondingly binding the random mask value with the layered encryption fragment to obtain a final encryption fragment; based on all the final encryption fragments, distributing the final encryption fragments to each computing node for security computing, and correspondingly obtaining an intermediate result and a corresponding zero-knowledge proof; performing verification based on all zero-knowledge proof, and aggregating corresponding intermediate results based on verification results to generate an encryption calculation result; and decrypting based on the encrypted calculation result to obtain a plaintext calculation result. And the calculation efficiency is improved on the basis of ensuring the safety of the calculation data.
Owner:BEIJING YINSUAN QUANTITY TECHNOLOGY CO LTD