Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

33 results about "Security parameter" patented technology

In cryptography, a security parameter is a way of measuring of how "hard" it is for an adversary to break a cryptographic scheme. There are two main types of security parameter: computational and statistical, often denoted by κ and λ, respectively. Roughly speaking, the computational security parameter is a measure for the input size of the computational problem on which the cryptographic scheme is based, which determines its computational complexity, whereas the statistical security parameter is a measure of the probability with which an adversary can break the scheme (whatever that means for the protocol).

Bls traceable secure threshold signature method and system based on distributed key generation

The present application belongs to the technical field of information security, and particularly relates to a BLS traceable security threshold signature method and system based on distributed key generation. The method comprises the following steps: S1, generating a bilinear pairing environment, and initializing public security parameters; S2, determining a group mapping relationship based on a symmetric balanced incomplete block design, each participant interacting in a group to generate respective key shares and a system global public key; S3, a signer performing partial signature and zero-knowledge proof corresponding to the partial signature on a message according to the corresponding key share; S4, an aggregator collecting and verifying the partial signature, screening out an effective signature set, aggregating to generate a final signature, and generating a commitment ciphertext; S5, a verifier verifying the final signature, and confirming the signature as valid if the verification is passed; S6, when the verification is not passed, a tracing mechanism is activated, and a tracer traces the signature group; and S7, according to the group mapping relationship, regularly performing active refreshing of the key shares.
Owner:ZHEJIANG SCI-TECH UNIV +1

A method for supporting time-constrained data security controllable flow in a cloud-edge environment

ActiveCN121907585BImplement fine-grained write control functionsDouble constraints on encryption permissionsPlaintextCiphertext
This invention discloses a time-constrained, secure, and controllable data flow method in a cloud-edge environment, belonging to the field of mobile edge cloud computing. Specifically, it involves: First, establishing a communication scenario including an authorizing agency for both the sender and receiver, the sender, edge nodes, a cloud server, and the receiver. Given security parameters, the authorized agency for the receiver runs a global initialization algorithm, outputting public parameters and domain public / private keys. Then, the authorized agency for the sender inputs the public parameters and domain public key, outputting its own domain public / private key. For each sender, an access structure and a valid time interval are assigned, and an encryption key is generated. For each receiver, an attribute set is assigned, and a decryption key is generated. Finally, the sender runs the encryption algorithm and outputs the original ciphertext; the edge node verifies the sender's sending authority and outputs the cleaned ciphertext; and the legitimate receiver decrypts and outputs the plaintext. This invention meets the requirements for secure and controllable data flow in a cloud-edge environment.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Method and device for joint evaluation of security boundary and communication performance based on 5g-a industrial internet

PendingCN122339853AJoint evaluationComputer network
This application provides a method and apparatus for jointly evaluating security boundaries and communication performance based on 5G-A industrial internet. The method includes: acquiring current network load data and current security policy parameter combinations, and inputting the current network load data and current security policy parameter combinations into a nonlinear latency prediction model to obtain the current overall latency; utilizing the current security policy parameter combinations and the current overall latency to generate a current security-communication global score; when the current security-communication global score is lower than a preset threshold, determining the fine-tuning amount of each security parameter from a multidimensional coupling relationship matrix library based on the current network load data and the current security policy parameter combinations to obtain the optimal security policy parameter combination. Through the nonlinear latency prediction model and the multidimensional coupling relationship matrix library, coupled modeling of security and communication is achieved; it also enables comparison and integration of security and communication in the same dimension, achieving synergistic optimization of security and communication resources.
Owner:CHINA UNITED NETWORK COMM CO LTD SHENZHEN BRANCH +2

A practical federated learning malicious security aggregation method and device

ActiveCN117035110BMachine learningSecuring communicationEngineeringSecurity parameter
The application discloses a practical federated learning malicious security aggregation method and device, the method comprises the following steps: receiving a training model initialized by an initiator; negotiating the total number of participating users n, the input vector dimension d, the input vector definition domain D and the system security parameter λ with the initiator and broadcasting; broadcasting the training model obtained after the last round of federated learning task to the general user i, so that each general user i and / or the initiator who is willing to participate in the current round of federated learning task locally trains the training model obtained after the last round of federated learning task, and combines the input vector dimension d, the input vector definition domain D and the system security parameter λ to mask the gradient vector updated in the training process; after the aggregation of the received masked vector, the mask in the obtained aggregated result with the mask is removed to obtain the training model obtained after the current round of federated learning task. The application can ensure the malicious security of the protocol execution and has high efficiency without losing practicability.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

Apparatus in a wireless communication system and data processing method of the apparatus

A device in a wireless communication system and a data processing method thereof are provided. The device receives a paging message containing first device identification information and confirms whether the first device identification information matches second device identification information stored in the device. Furthermore, based on the confirmation of the match, the device sends a Media Access Control (MAC) message containing upper-layer data, wherein the paging message includes a first security parameter and information indicating the presence of the first security parameter.
Owner:KT CORP

Security protection of user equipment (UE)-to-UE relay discovery

ActiveUS12666254B2Security arrangementNetwork data managementTrunkingSecurity parameter
Various aspects of the present disclosure generally relate to wireless communication. In some aspects, a user equipment (UE) may encrypt a discovery message associated with a relay service based at least in part on a set of code-sending security parameters (CSSPs) associated with the relay service. The UE may transmit the encrypted discovery message. In some aspects, a UE may receive an encrypted discovery message. The UE may decrypt the encrypted discovery message based at least in part on a set of code-receiving security parameters (CRSPs) associated with the relay service. Numerous other aspects are provided.
Owner:QUALCOMM INC

Methods, systems, and computer readable media for enhanced security edge protection proxy (SEPP) firewall filtering for health check messages

PendingUS20260149694A1Securing communicationInternet privacyHealth check
A method for enhanced SEPP firewall filtering for health check messages includes performing an N32-c security capability exchange with at least one remote SEPP to establish security parameters for communicating with the at least one remote SEPP over an N32-f interface. The method further includes maintaining N32-f context information for the at least one remote SEPP with which an N32-c security capability exchange has been successfully completed. The method further incudes receiving a health check message and accessing the N32-f context information to determine whether an originator of the health check message corresponds to a SEPP with which an N32-c security capability exchange has been successfully completed. The method further includes performing a network security action when the SEPP determines that the health check message does not correspond to a SEPP with which an N32-c security capability exchange has been successfully completed.
Owner:ORACLE INT CORP

Method and device for processing ambient IoT data

PendingUS20260189918A1Communications systemEngineering
Provided are a method and device for processing ambient Internet of Things (IoT) data in a wireless communication system. The device receives a paging message including first device identification information, and checks whether the first device identification information matches second device identification information stored in the device. Further, based on a result of the checking, the device transmits a medium access control (MAC) message including upper layer data, wherein the paging message includes a first security parameter and information indicating presence of the first security parameter.
Owner:KT CORP

Network on chip (NoC) memory addressable encryption and authentication

ActiveUS12647276B2User identity/authority verificationMemory circuitsDistributed security
Techniques for network-on-chip (NoC) memory addressable encryption and authentication. In an embodiment, NoC circuitry includes NoC routing circuitry, memory circuitry that stores a security parameter, and security circuitry that secures (e.g., encrypts and / or authenticates) a payload based on the security parameter. The security circuitry may secure the payload before the payload is packetized for transmission through the NoC, after the payload is de-packetized for output to an endpoint, or as the payload transits the NoC. The security circuitry may be centralized or distributed amongst access points of the NoC. Distributed security circuitry may exchange a security parameter over a secure link of the NoC circuitry. The security circuitry may include decryption circuitry that decrypts a response from a first endpoint before the response is packetized for transmission through the NoC, after the response is de-packetized for output to a second endpoint, or as the response transits the NoC.
Owner:XILINX INC

Electronic protected health information flow method and system based on temporary access control

PendingCN122372249APlaintextCiphertext
This invention discloses a method and system for the circulation of electronically protected health information based on temporary access control. The method is as follows: Security parameters, epoch parameters, and attribute set are obtained; an epoch public key and an epoch private key are generated through cryptographic operations; a fog node time key, a cloud time key, and a local key are generated based on these two; an attribute key is obtained by combining the epoch private key with the medical provider attribute set; the plaintext ePHI, fixed and temporary access policies are obtained; the plaintext ePHI is encrypted and encapsulated to obtain ePHI ciphertext; cloud auditing is performed based on the ePHI ciphertext, attribute key, and cloud time key, and the audit result is sent to the fog node; after verification, the fog node converts the ePHI ciphertext using its own time key to obtain converted ciphertext; finally, the original plaintext ePHI is decrypted using the local key. This invention can solve problems such as inaccurate time unit attribution determination, high key and parameter overhead, and inefficient policy deployment in ePHI temporary access control.
Owner:XIDIAN UNIV

Iterative use control method, device and equipment for data sharing, and medium

The present application relates to the technical field of data processing, and provides an iteration use control method, device and equipment and medium for data sharing, aiming at solving the problem that the use control strategy cannot be dynamically adjusted and the differentiated operation cannot be performed according to the data category and use scene when the data is shared in the data domain or across the domains. The method comprises the following steps: based on an initial classification strategy set and an initial scene strategy set, the shared data is labeled to obtain first data; based on a first operation request, an operation algorithm set and a first scene description, the first data is subjected to differentiated control processing to obtain second data; and based on the second data, a first security parameter, a second security parameter and a second scene description, the second data is subjected to iteration use control. According to the present application, even if the original system is disconnected, the effective use control of the whole life cycle of the multiple transmissions of the original data and the copy can be realized, and the differentiated operation can be performed according to the use control strategy.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

A method for ciphertext range query with fine-grained authorization for multiple users

PendingCN122372284APlaintextCiphertext
This application relates to a method for multi-user fine-grained authorization of encrypted range queries. The method includes: a data owner inputting security parameters to generate public parameters and a system private key; the data owner using the system private key to encrypt plaintext data and its corresponding identity identifier, generating ciphertext bound to the identity identifier, and uploading the ciphertext to a cloud server; the data owner using the system private key to generate an authorization key for the target user's target identity identifier, and sending the authorization key to the target user; after receiving the authorization key, the target user generating a query trapdoor based on query conditions using the authorization key, and sending the query trapdoor to the cloud server; after receiving the query trapdoor, the cloud server performing a matching judgment on the stored ciphertext using the query trapdoor to obtain a set of target ciphertexts that meet the query conditions; and the cloud server returning the set of target ciphertexts to the target user. This method significantly improves the privacy protection level of encrypted databases in multi-query scenarios.
Owner:NAT UNIV OF DEFENSE TECH

An edge-assisted multi-factor user authentication method for industrial internet

PendingCN122457267ATicketThe Internet
The application relates to an edge-assisted multi-factor user authentication method for an industrial internet, which comprises a registration stage and an authentication and key agreement stage. The registration stage comprises the following steps: an edge gateway completes registration to a cloud server CS, a user completes multi-factor registration to the cloud server CS through an intelligent device, and an initial trust relationship and security parameters of cloud-edge-end are established; the multi-factor registration is combined with three types of identity factors of the user, namely, an identity identifier, a password and a biological feature; and the authentication and key agreement stage is constructed based on a credential multiplexing mechanism and an ASCON associated data authentication encryption primitive. The application proposes the credential multiplexing mechanism, multiplexes a session key of baseline communication of the edge gateway and the terminal as a ticket to encapsulate a trust root, and combines the ASCON lightweight authentication encryption primitive, so that authentication delay is effectively reduced and single-point failure risk is eliminated.
Owner:FUZHOU UNIV

A network-connected data management system and method for network security

PendingCN122316640AShardSecure communication
This invention discloses a grid-connected data management system and method for network security, relating to the field of data security technology. In a power system, when different participants need to negotiate and manage grid-connected data using a task function, the different participants determine unified security parameters and establish secure communication channels between each other. Each data point in the time-series data stream is divided into data fragments, which are then sent to all participants through the secure communication channels. All data fragments of the same data point received by all participants constitute a secret share. The task function is transformed into an arithmetic circuit, which inputs the secret share and triplet of the grid-connected data held by each participant. Based on the optimized real-time grid topology, addition gates, multiplication gates, and constant gates are calculated one by one, and the secret share after gate operations is finally output.
Owner:GUANGDONG POWER GRID CO LTD +1

A privacy-oriented verifiable distributed matrix multiplication outsourcing method

The application provides a privacy protection-oriented verifiable distributed matrix multiplication outsourcing method, and relates to the technical field of outsourcing cloud computing services. The method involves a data owner, a cloud server and a client. The data owner first performs a keyGen algorithm, generates a public key, a private key, a verification key and a decryption key of a matrix by inputting a security parameter and the matrix. The data owner then performs a probGen algorithm, obtains an encrypted vector, auxiliary information and a decryption key of the vector by inputting the private key and a vector. The cloud server performs a Comp algorithm, inputs the public key and the encrypted vector, and each cloud server outputs a respective operation result. The client performs a Verify algorithm, inputs the verification key, the auxiliary information and the operation result sent by the first s cloud servers, and outputs a verification operation result. The data owner performs a Solve algorithm, inputs the encrypted operation result, and obtains a correct operation result. The method avoids the delay of weak computing power nodes on the entire calculation.
Owner:NORTHEASTERN UNIV CHINA +1

Coding method and apparatus

The application provides a coding method and device, relates to the technical field of media, and comprises the following steps: performing a coding operation on a plurality of display images and a plurality of CRR images to obtain a code stream. First information is used to authenticate to-be-authenticated data to obtain first tree top abstract data. Second information is used to perform signature calculation on the first tree top abstract data to obtain a digital signature. The digital signature is encapsulated into an authentication data set. The code stream comprises a security parameter set and the authentication data set, the security parameter set comprises the first information and the second information, the first information is used to represent an algorithm adopted for generating tree top abstract data, and the second information is used to represent an algorithm adopted for performing digital signature. The first tree top abstract data is tree top abstract data of an encoding end, and the first tree top abstract data comprises tree top abstract data of N main bit streams and / or M CRR slice bit streams, wherein N and M are positive integers.
Owner:HUAWEI TECH CO LTD

A key policy attribute-based encryption fast decryption method based on SM9

ActiveCN117200987BEfficient integrationImprove decryption efficiencyCiphertextTheoretical computer science
This invention relates to a fast decryption method for attribute-based encryption using a key policy based on SM9. The method includes: a key generation center first generates system public parameters and a system master private key based on given system security parameters; secondly, it defines the system's attribute space based on the attributes used in the system; finally, it publishes the system public parameters but keeps the master private key secret; the data owner encrypts the message based on the attribute set corresponding to the data, generating corresponding ciphertext; the key generation center sets an access policy based on the user's decryption permissions, where a matrix is ​​used to map rows in the matrix to attributes in the attribute set, generating a private key corresponding to the corresponding access policy; after receiving the ciphertext, the data receiver can successfully decrypt it if and only if the attribute set in the ciphertext satisfies the access policy on the key; otherwise, decryption fails. This invention overcomes the decryption efficiency problem in attribute-based encryption algorithms using a key policy based on SM9.
Owner:FUJIAN NORMAL UNIV

Communication system with secure access point discovery function

PendingCN122373003ACommunications systemStation
A communication system with secure access point discovery capability is provided. The system allows communication between a Basic Service Set (BSS) Privacy Enhancement (BPE) Access Point (AP) and a BPE Site (STA). Prior to association, the STA generates an STA-ID by inputting the current addresses of both the AP and the STA, along with the AP's identity key, into a hash algorithm. The STA can discover the AP using a Pre-Association Security Negotiation (PASN) procedure. The STA can send a PASN MSG1 containing the STA-ID to the AP. The AP can use the STA-ID to verify that the STA is authorized to receive AP security parameters. In response to successful verification, the AP can send a PASN MSG2 to the STA. The STA and AP can use information from the PASN message to derive a Transient Key (TK) and can transmit a management frame encrypted using the TK. The management frame can be used to associate the STA with the AP.
Owner:APPLE INC

Defining a security perimeter using knowledge of user behavior within a content management system

Methods, systems, and computer program products for content management systems. Multiple components are operatively interconnected to carry out operations for content management systems. Content objects of a content management system (CMS) are managed from original creation through to final disposition (e.g., deletion). The CMS communicates with a security threat management facility (STMF). In operation, the STMF establishes a first set of security parameters corresponding to information derived from packet inspection, whereas the CMS establishes a second set of security parameters corresponding to information derived at least in part by analysis of user activities or contents of the content object. A security perimeter is formed by combining the first set of security parameters and a second set of security parameters. Risks or vulnerabilities corresponding to the content object are minimized by choosing the lower of any two compared parameters to define a lower risk perimeter for the content object.
Owner:BOX INC

Bios method for securing and protecting end point with ownership information

Disclosed systems and methods for securing an information handling system monitor for certain predetermined events, and, upon detecting any one of the predetermined events, requesting ownership data indicative of the authorized or recognized owner. In some embodiments, the ownership data is conveyed via a digital certificate establishing a trusted relationship between the owner and the information handling system. The digital certificate cryptographically associates a manifest of the system's key components and a device identifier such as a service tag. The predetermined requests and events may include, as non-limiting examples, requests to wipe, clear, or sanitize a persistent storage resource, request to change an encryption key, chassis intrusion events, requests to modify an OS image of a platform, requests to modify a security parameter, requests to modify or restore a factory setting of a configuration parameter, incorrect password events exceeding a predetermined threshold, and SPI probe detection events.
Owner:DELL PROD LP

A post-quantum key encapsulation method and system

PendingCN122372202AKey (cryptography)Ciphertext
This invention discloses a post-quantum key encapsulation method and system, relating to the fields of cryptography and network security. Based on the difficult problem of modular learning with errors, it combines FO transform to achieve the IND-CCA2 security level, including key generation, encapsulation, and decapsulation steps. Key generation generates a public-private key pair based on the security parameter λ. The encapsulation step obtains the public key to generate ciphertext and a shared key. The decapsulation step verifies the ciphertext and recovers the key. The system includes six modules such as parameter configuration and key management, adaptable to scenarios such as industrial control systems. This invention optimizes computational efficiency, compresses ciphertext volume, integrates side-channel protection, and solves the problems of weak resistance to quantum attacks and poor adaptability of traditional solutions. It balances security and real-time performance and can be widely applied in industrial control, IoT, and other fields.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

Key derivation method and device

PendingCN122122947ASecurity arrangementComputer networkThird generation
The application relates to a key derivation method, device, computer readable storage medium, computer program product and computer program. The method comprises: a terminal receiving a next hop chaining counter (NCC) associated with a first third generation partnership project (3GPP) connection, wherein the first 3GPP connection is one of multiple 3GPP connections of the terminal; and the terminal deriving an access stratum (AS) key associated with the first 3GPP connection, wherein the AS key associated with the first 3GPP connection is derived based on a security parameter associated with the first 3GPP connection, the security parameter associated with the first 3GPP connection comprises the NCC associated with the first 3GPP connection, and the AS keys associated with different 3GPP connections of the multiple 3GPP connections of the terminal are different.
Owner:GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD

Systems and methods to map attack paths to applications assets in a visualization interface

A system and a method to map attack paths in a visualization interface may include storing in a memory asset inventory indicating application assets, attack vector parameters configured to indicate vulnerabilities of one or more of the application assets, and asset mapping information. A processor may determine multiple vulnerable assets in the application assets based at least in part upon the attack vector parameters. Further, the processor may obtain security parameters from a security framework indicating one or more attack techniques, associate each of the vulnerable assets to one or more of the security parameters, and generate a visual interface showing the vulnerable assets and the security parameters. The processor may determine an attack path connecting the vulnerable assets based at least in part upon the asset mapping information, and map the attack path to the application layers and the security parameters in the visual interface.
Owner:CISCO TECHNOLOGY INC

A verifiable range searchable symmetric encryption method for large-scale datasets

PendingCN122457326ATree rootData set
The application discloses a verifiable range searchable symmetric encryption method for large-scale data sets and relates to the technical field of encrypted data retrieval. The application initializes the cryptographic parameters and storage structure based on the security parameters and the maximum document quantity of the database; accumulates the inverted index according to the database construction sequence, divides the sub-partitions and constructs the local binary search tree; generates the encryption related data and the Merkle tree for the keywords of each sub-partition, retains the core data of the client and uploads the rest to the server after the mapping relationship is established; the client generates a token and sends the token in the query stage, and the server returns the encrypted bitmap and the verification path; the client completes the verification by comparing the recalculated Merkle tree root hash with the local reference value; the bitmap is decrypted after the verification is passed, and the query result is obtained through the document set difference set operation. The application realizes the lightweight integrity verification of the query result, is suitable for the scene that needs to perform the range query on the large-scale encrypted data and needs to guarantee the integrity of the retrieval result, and has wide application value.
Owner:CIVIL AVIATION FLIGHT UNIV OF CHINA

A UTXO type blockchain group covert communication method based on orthogonal code words and revocable management and control, a computing device and a computer readable storage medium

PendingCN122348812AComputer hardwareCovert communication
The application discloses a UTXO type blockchain group covert communication method based on orthogonal code words and revocable control, a computing device and a computer readable storage medium, wherein the method comprises the following steps: S1, group offline initialization and security parameter maintenance; S2, joint encoding and load construction; S3, transaction field embedding and chain loading; S4, on-chain monitoring screening and index recovery; S5, projection type local decoding; S6, group revocable control; the orthogonal code word joint encoding, UTXO transaction field bearing and address marking screening mechanism can realize multi-receiver shared load bearing and separable decoding without introducing additional protocol fields; and through the group dynamic control and revocation update mechanism, the dishonest members can be excluded and the seed / epoch can be updated, so that the concealment, bearing efficiency and continuous controllability can be considered in the dynamic member environment.
Owner:YANGZHOU POLYTECHNIC COLLEGE +1

Bls traceable secure threshold signature method and system based on distributed key generation

ActiveCN122160071BDistributed key generationCiphertext
The present application belongs to the technical field of information security, and particularly relates to a BLS traceable security threshold signature method and system based on distributed key generation. The method comprises the following steps: S1, generating a bilinear pairing environment, and initializing public security parameters; S2, determining a group mapping relationship based on a symmetric balanced incomplete block design, each participant interacting in a group to generate respective key shares and a system global public key; S3, a signer performing partial signature and zero-knowledge proof corresponding to the partial signature on a message according to the corresponding key share; S4, an aggregator collecting and verifying the partial signature, screening out an effective signature set, aggregating to generate a final signature, and generating a commitment ciphertext; S5, a verifier verifying the final signature, and confirming the signature as valid if the verification is passed; S6, when the verification is not passed, a tracing mechanism is activated, and a tracer traces the signature group; and S7, according to the group mapping relationship, regularly performing active refreshing of the key shares.
Owner:ZHEJIANG SCI-TECH UNIV +1

Systems and methods for sensor response management

PCT designated stageWO2026112660A1AlarmsSecurity frameworkSecurity parameter
Disclosed are systems and methods that provide a novel security framework for a dynamic, intelligent approach to location protection through flexible zone management. Each location or entry point can be treated as a configurable "zone" with multiple layers of customizable security parameters. The framework goes beyond traditional armed / disarmed states via alarm profiles that can computationally, dynamically and / or automatically control, manage, modify and / or trigger sensor response to particular types of events detected or not detected at a location. The framework's ability to learn, adapt and respond contextually transforms security from a passive, alarm-driven model to an active, intelligent protection ecosystem.
Owner:RESIDEO LLC

Communication method and device

A terminal includes a processor and a memory communicating with the processor. The memory is configured to store instructions which, when executed by the processor, cause the terminal to perform: receiving first configuration information from a first access network device, wherein the first configuration information comprises first security parameter(s) corresponding to at least one candidate access network device, and the first security parameter(s) comprise at least one of: an indication of a key derivation manner, or a first next hop chaining counter (NCC).
Owner:GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD

A CSIDH-based quantum-resistant identity-based encryption and decryption method and system

This invention discloses a quantum-resistant identity-based encryption and decryption method and system based on CSIDH, including a key generation process. Taking security parameters, a CSIDH parameter set, a common curve, and the number of ideal class groups as input, the KGC determines the number of master keys and user keys, randomly selects ideal class group elements as the master public key, and calculates the corresponding image curve as the master public key. The user key extraction process involves the KGC generating a private key for the user, randomly selecting ideal class group elements, calculating the image curve, calculating and splitting the hash value corresponding to the user ID, calculating the ideal class group elements based on the hash value, and returning the user's private and public keys. The encryption process involves the encryptor encrypting the message, randomly selecting ideal class group elements, calculating and splitting the hash value corresponding to the user ID, calculating the image curve based on the hash value, calculating the hash value, and returning the ciphertext. The decryption process involves the user decrypting the ciphertext, splitting the ciphertext, verifying whether it is a supersingular elliptic curve, and if so, calculating the image curve and hash value to obtain the output plaintext.
Owner:WUHAN UNIV