Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

378 results about "Security parameter" patented technology

In cryptography, a security parameter is a way of measuring of how "hard" it is for an adversary to break a cryptographic scheme. There are two main types of security parameter: computational and statistical, often denoted by κ and λ, respectively. Roughly speaking, the computational security parameter is a measure for the input size of the computational problem on which the cryptographic scheme is based, which determines its computational complexity, whereas the statistical security parameter is a measure of the probability with which an adversary can break the scheme (whatever that means for the protocol).

Business data security protection method and system for digital enterprise management

The invention provides a service data security protection method and system for digital enterprise management, and the method comprises the steps: obtaining an access request sequence initiated by a target user at a service operation terminal, generating a dynamic access control strategy vector according to a historical behavior track associated with an access operation identifier, and carrying out the dynamic access control strategy vector; analyzing the dynamic access control strategy vector through a strategy decoder, and generating a real-time access permission instruction; based on the real-time access permission instruction, performing homomorphic encryption mapping on a sensitive data segment in the request context information to generate a ciphertext transmission channel, and performing security parameter synchronization on the ciphertext transmission channel and the cross-department conjoint analysis model; and calling a federated learning framework to carry out multi-modal feature fusion on the real-time operation flow of the service operation terminal, generating an abnormal operation confidence score, triggering a cross-level interception protocol when the abnormal operation confidence score exceeds a dynamic threshold, and rolling back the current session state to a security baseline version. According to the invention, the accuracy and response timeliness of anomaly detection can be improved.
Owner:BEIJING CHINASOFT LINKAGE TECHNOLOGY CO LTD

Security isolation deployment method and device, storage medium and program product

The invention provides a security isolation deployment method and device, a storage medium and a program product, relates to the field of network security, and can realize cross-domain risk situation awareness, dynamically adjust an isolation strategy and improve the security of big data platform operation, the method comprises the steps of obtaining a current data stream and a historical data stream of each risk domain in a plurality of risk domains; determining a risk grade score of the big data platform based on the current data streams and the historical data streams of the plurality of risk domains; the risk grade score is used for indicating the occurrence probability and the influence range of the cross-domain risk event; determining an optimal security parameter combination of a plurality of risk domains of the big data platform based on the risk level score; the optimal safety parameter combination is used for indicating the minimum cross-domain risk propagation probability and resource isolation cost; and based on the optimal security parameter combination, performing security isolation deployment on the plurality of risk domains of the big data platform.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD +1

Distributed key management and encryption communication method oriented to big data environment

The invention relates to the technical field of network security, in particular to a distributed key management and encryption communication method oriented to a big data environment. The method comprises the following steps: establishing a system architecture and configuring safety parameters; generating a master key and a session key through the random number; segmenting the master key into a plurality of segments and storing the segments to different nodes; encrypting the session key by using the public key of the receiver, distributing the session key through the secure channel, and decrypting the session key by the receiver to obtain the session key; constructing a Merkle tree through an AES-GCM function, and introducing a network adaptation factor into an encryption process by considering that security requirements and network conditions of data encryption in different environments are different; and regularly updating a secret key, implementing an access control strategy, and recording a log to perform system audit so as to guarantee long-term security. According to the invention, the efficient AES-GCM encryption algorithm is used, so that the speed and security of data encryption are improved. By implementing the access control strategy, only the authorized user can access and operate the key, and the security of the system is improved.
Owner:ZHENGZHOU DAXUAN ELECTRONICS TECH CO LTD

Universal Identity Verification for Video Conferencing

Systems, methods, and apparatuses are described for verifying a user identity in a video conference. A computing device may receive user data and a plurality of security parameters associated with accessing a video conference based on a confidentiality level of the video conference. The computing device may generate a security code that is encoded with user data. The computing device might cause the security code to be displayed on the mobile device for a predetermined time period. The computing device may receive an indication that the first device scanned the security code by using a camera. To verify the identity of a user, the computing device may decode the security code, compare the decoded user data of the decoded security code and expected user data associated with the video conference. The computing device may determine the authenticity of a user video and allow access to the video conference.
Owner:CAPITAL ONE SERVICES LLC

Anti-quantum identification signature method based on lattice SIS problem

The invention provides an anti-quantum identification signature method based on an on-lattice SIS problem. The method comprises the following steps: selecting system safety parameters and other related system parameters; generating a system public parameter and a master key by using the system security parameter and other related system parameters; generating a corresponding public and private key pair by using the user identity ID; the user generates a signature of the message by using the private key; and the verifier verifies the validity of the signature by using the system parameters and the user public key. According to the method, a lattice-based digital signature scheme is constructed by utilizing an SIS difficulty problem on a middle lattice, and quantum attack resistance security is provided for an information system for deploying the algorithm scheme; personal identity information of the user is used for registering and generating public and private keys, the key escrow problem participated by a third party is relieved, and the privacy security of the user is improved.
Owner:GUIZHOU UNIV +1

Network security gateway

A security gateway accesses data in a communications session between a client device and an application hosted by a server. The security gateway inspects security parameters corresponding to the data using one or more large language models (LLMs). In response to inspecting the security parameters corresponding to the data, the security gateway performs one or more security operations on the data in accordance with one or more security policies associated with the one or more LLMs.
Owner:AURADINE INC

Zk-SNARK-based power grid data security cleaning and credibility verification method

The invention provides a zk-SNARK-based power grid data security cleaning and credibility verification method. The method comprises the following steps: firstly, sequentially performing static range verification, adjacent time difference rate judgment, missing value interpolation and sliding window outlier detection on original scheduling data by an acquisition end, generating cleaned data, and calculating a hash value to form sub-constraints; the method comprises the following steps: generating a proof key and a verification key based on security parameters in a trusted initialization stage, uniformly expressing all sub-constraints in an algebraic form, performing coding arrangement, and constructing a Rank-1 constraint system meeting zk-SNARK proof requirements as a basic structure of a generation circuit; the submitter constructs a private witness vector with the cleaned data by using the circuit to generate a proof parameter, and the verifier verifies the proof through a public parameter to confirm that the data meets a preset rule. According to the method, various logical judgments and Hash integrity in the cleaning process are unified into polynomial equality constraints, so that data privacy and consistency are efficiently guaranteed, trust cost and calculation complexity are remarkably reduced by means of a zero-knowledge verifiable mechanism, the security, flexibility and expandability of a system are enhanced, and the method is suitable for popularization and application. The method is suitable for complex scheduling scenes needing to process large-scale power grid data.
Owner:BEIJING YINGYUN TECHNOLOGY CO LTD

HPV detection information management method and system based on privacy protection

The invention relates to the technical field of medical message management, in particular to an HPV detection information management method and system based on privacy protection, and the method comprises the steps: obtaining HPV detection information of a target subject, carrying out the feature extraction of the HPV detection information, and obtaining personal basic information and detection sample information; performing encryption processing on the detection sample information to obtain HPV detection encryption data, and performing privacy feature recognition on the HPV detection encryption data to obtain a privacy feature set; performing privacy risk assessment on the privacy feature set to obtain a privacy risk index; acquiring a whole-process information security parameter of the HPV detection information of the target subject; based on the whole-process information security parameters, performing privacy leakage influence quantitative evaluation on the privacy risk index to obtain a privacy leakage risk evaluation index; calling a corresponding privacy leakage risk threshold value based on the personal basic information, and performing leakage risk early warning judgment on the privacy leakage risk assessment index according to the corresponding privacy leakage risk threshold value; the threat identification precision can be improved, and risk early warning is realized.
Owner:THE THIRD HOSPITAL OF CHANGSHA

Safety design device, safety design method, and safety design program

To provide a safety design device, a safety design method, and a safety design program capable of deriving a security parameter whose safety is guaranteed in encryption design based on a Reused-A-LWE problem using a discrete Gaussian distribution as an error distribution.SOLUTION: A safety design device 1 includes: an inputting portion 11 that receives input of parameters n, m, q, s1, s2 of a Reused -A-LWE problem with a discrete Gaussian distribution as an error distribution; a calculation portion 12 that calculates a parameter sb of the LWE problem with the discrete Gaussian distribution as the error distribution from the parameter s1 and a constant C; an acquiring portion 13 that acquires a security parameter λ of the LWE problem by a calculation formula that guarantees predetermined safety; and an outputting portion 14 that outputs the acquired security parameter λ as a security parameter of the Reused -A-LWE problem.SELECTED DRAWING: Figure 1
Owner:KDDI CORP

Connectionless-virtual private network for secure cloud to user communication over the internet using a plurality of servers

The disclosure provides a system / method / scheme to securely send data from a cloud, or cloud service provider, to users via a secure connectionless system, referred to herein as a C-VPN communication infrastructure (C-VPN CI). In one example a method of communicating from a cloud service provider to a user via a C-VPN CI includes: (1) obtaining, by a cloud service provider, security parameters from a SDE Cloud server operating on a computing system of the cloud service provider, wherein the security parameters include a set of mathematical rules and values for converting plain text to ciphertext, (2) creating a secure communication using the security parameters received from the SDE Cloud server, wherein the secure communication includes a secure header and secure data, and (3) sending the secure communication to the user via a generic electronic message delivery system.
Owner:TALATI FAMILY

Balanced SM9 digital signature multi-party adapter signature generation method and system

The invention discloses a balanced SM9 digital signature multi-party adapter signature generation method and system, a secret key generation center initializes system parameters according to security parameters in a symmetric environment, generates participant private key fragments by using a secret sharing technology, and generates a public and private key pair for a multiplication-to-addition ideal function for each participant; the participant requesting the pre-signature generates a difficult relation instance and a zero-knowledge proof and broadcasts the difficult relation instance and the zero-knowledge proof, the other participants calculate the pre-signature after verification, the legality of the pre-signature is verified by verifying a temporary variable, and a complete signature is calculated under the condition that the pre-signature is legal; adapter signature evidences are extracted according to the pre-signatures, the complete signatures and the difficult relation instances, evidence extraction is completed under the condition that instances generated by the adapter signature evidences are consistent with the difficult relation instances, and the national secret SM9 pre-signatures with the adapter function can be cooperatively generated under the condition that multiple participants jointly participate in operation in the symmetric environment; and the signature of the adapter is completed.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

Satellite short message data transmission method and device

The invention relates to the technical field of satellite communication, in particular to a satellite short message data transmission method and device. The method comprises the following steps: a receiving end device establishes an initial communication link with a satellite through a preset guide sequence and performs time synchronization and frequency synchronization to generate a security parameter negotiation channel; sending an encryption capability message to the satellite through the security parameter negotiation channel and establishing an end-to-end corresponding encryption communication channel; sending a short message data transmission request to the satellite through the encrypted communication channel, and sending a beam configuration parameter to the receiving end device through the encrypted communication channel; and when the receiving end equipment adjusts a corresponding receiving antenna according to the beam configuration parameter to form a directional receiving beam and reaches a preset threshold value, a resource redistribution mechanism is triggered, so that beam resources occupied by the low-priority service are dynamically adjusted to the high-priority service for use. According to the invention, efficient and reliable transmission of satellite short message data can be realized.
Owner:AEROSPACE WANYUAN CLOUD DATA HEBEI CO LTD

Inner product encryption method, device and system based on GR-LWE problem

The invention discloses an inner product encryption method, device and system based on a GR-LWE problem, and belongs to the technical field of information encryption, and the method comprises the following steps: generating a main public key and a corresponding main private key based on a dihedral non-exchangeable group ring and preset security parameters; obtaining vector data used for decryption, and carrying out operation on the vector data and the main private key to generate a decryption key used for decryption operation; vector data to be encrypted and plaintext data to be encrypted are obtained and are operated with the public key part in the main public key to generate a ciphertext; and a decryption key is used for carrying out decryption operation on the ciphertext, and when and only when the inner product result of the vector data for decryption and the vector data to be encrypted is 0, correct plaintext data can be obtained. According to the invention, an inner product encryption scheme is expanded to the dihedral non-exchangeable group ring, so that the security of the encryption scheme is improved, and long-term security guarantee is provided for resisting quantum computer attacks.
Owner:QUAN CHENG LABORATORY

Federal recommendation privacy protection method and system based on ring signature and selective aggregation

The invention discloses a federal recommendation privacy protection method based on ring signature and selective aggregation, which realizes anonymization privacy protection and selective aggregation in a federal learning process through an innovative double-server architecture and a hierarchical security mechanism. The method comprises the following steps: 1) deploying an aggregation server and a security server in a system initialization stage, and completing parameter initialization and key distribution; 2) the client executes local model training, and anonymization privacy protection uploading is realized by adopting a ring signature technology; 3) the security server performs selective aggregation of credibility verification, and completes grouping and parameter fusion based on user similarity; and 4) ensuring the completeness and source credibility of model updating through a hierarchical security parameter distribution mechanism. While the recommendation precision is ensured, the user identity leakage and privacy tracking are effectively prevented, the comprehensive security guarantee is provided for the federal recommendation system, and the method has the advantages of low calculation overhead and high communication efficiency.
Owner:SOUTHEAST UNIV

Security execution environment construction method and system, chip and storage medium

The invention provides a secure execution environment construction method and system, a chip and a storage medium. The method comprises the following steps: creating an encrypted memory area; distributing an independent security data space in the encrypted memory area for each thread; storing the key encryption key and the security parameter in a locking register, and setting an access control strategy of the locking register by using a flag bit register; and monitoring illegal access to the locked register in real time by using an exception handling instruction. According to the secure execution environment construction method and system, the chip and the storage medium provided by the embodiment of the invention, a reliable hardware-level security mechanism is realized through physical isolation, thread-level encryption container, register locking and the like, and the capability of preventing side channel attacks is improved by introducing random elements of power disturbance according to the security level of the locked register.
Owner:ZHENGZHOU WEIGUANG SEMICONDUCTOR CO LTD

Parameter safety re-calibration and response method, device, equipment and medium

The invention relates to the technical field of artificial intelligence, can be applied to business scenes of financial science and technology, medical health and the like, and discloses a parameter security re-calibration and response method, device, equipment and medium, and the method comprises the steps: obtaining parameters of a basic model and a fine-tuned model, and comparing the parameters to obtain differential parameters; performing gradient sensitivity analysis on the differential parameters to generate an abnormal correlation map; detecting the fine-tuned model by using an abnormal association map to determine unsafe parameters; unsafe parameters are processed, safe re-calibration is completed, and basic model parameters are fused to form a re-calibration model; verifying the re-calibration model based on the scenarized security verification set and obtaining feedback; according to the feedback updating strategy, re-calibration is carried out again, and a security application model is generated; and processing the task request through the security application model to obtain a security response result. According to the method, unsafe parameters are identified and corrected through differential analysis and closed-loop recalibration, the safety and the compliance are enhanced while the model performance is kept, and reliable application in a complex scene is ensured.
Owner:PING AN TECH (SHENZHEN) CO LTD

Coding method and apparatus

The application provides a coding method and device, relates to the technical field of media, and comprises the following steps: performing a coding operation on a plurality of display images and a plurality of CRR images to obtain a code stream. First information is used to authenticate to-be-authenticated data to obtain first tree top abstract data. Second information is used to perform signature calculation on the first tree top abstract data to obtain a digital signature. The digital signature is encapsulated into an authentication data set. The code stream comprises a security parameter set and the authentication data set, the security parameter set comprises the first information and the second information, the first information is used to represent an algorithm adopted for generating tree top abstract data, and the second information is used to represent an algorithm adopted for performing digital signature. The first tree top abstract data is tree top abstract data of an encoding end, and the first tree top abstract data comprises tree top abstract data of N main bit streams and / or M CRR slice bit streams, wherein N and M are positive integers.
Owner:HUAWEI TECH CO LTD

Nursing service demand classification system based on kano internet

The invention discloses a kano-based internet nursing service demand classification system, and relates to the technical field of internet medical treatment and artificial intelligence, and the system comprises a local Kano model training module, a safety parameter aggregation module, a global model updating and distribution module, a local model updating and federated evaluation module, and a privacy enhancement module. According to the method, a federated learning framework and a multi-layer encryption protocol are adopted, a cross-mechanism data collaboration mechanism is constructed, user data of all participating mechanisms are subjected to local closed-loop processing, model iteration is completed only through encryption parameters, the cross-domain transmission risk of original data is avoided, fusion extraction of multi-source data features is also achieved, and the user experience is improved. The global model integrates nursing demand laws of different regions and different types of institutions to form a demand classification standard covering a whole scene, provides a cross-region and cross-crowd unified demand judgment standard for an Internet nursing platform, and supports cross-domain scheduling and configuration of service resources.
Owner:YANCHENG DAFENG PEOPLES HOSPITAL

Partial user plane protection in mobile networks

An apparatus of a mobile network, the apparatus comprising: a session management function (SMF) comprising: a means for determining a user plane (UP) security policy for a packet data unit (PDU) session of user equipment (UE), wherein the user plane security policy includes user plane security parameters that specify at least one of an integrity protection portion of a user plane packet to be integrity protected and an encryption portion of the user plane packet to be encrypted; and a means for providing the user plane security policy to a radio access network (RAN) node that serves the UE, indicating the user plane security parameters. The user plane security parameters of the user plane security policy may comprise: a full integrity protection parameter indicating that the entire user plane packet is to be integrity protected; and a full encryption parameter indicating that the entire user plane packet is to be encrypted. The integrity protection portion and the encryption portion may comprise one or more headers of the user plane packet. The SMF may further comprise means for determining the user plane security policy based on user plane protection preferences received from the UE during establishment of the PDU session.
Owner:NOKIA TECHNOLOGIES OY

Data security sharing method based on block chain

The invention discloses a data security sharing method based on a block chain, and belongs to the technical field of data sharing, and the method comprises the steps: storing shared data into the block chain, and carrying out the classification processing, so as to construct a hierarchical access tree model; performing data screening to obtain a target data set, and setting public safety parameters; a master key and a public key are generated through an authority center, and public key security parameters are calculated; encrypting each child node to obtain encrypted data; constructing a data access sharing model, and generating a user private key to calculate a user private key security parameter; and constructing a public contract in the block chain to output the encrypted data, and realizing data decryption based on the user private key security parameter to complete sharing. According to the method, classification processing is carried out on the data by utilizing an attribute encryption method, and encryption is carried out according to the data type, so that the security of the shared data is further improved; and a hierarchical access tree model is formed, so that a storage path is optimized, and the data sharing rate is improved.
Owner:云尖(北京)软件有限公司

System and method for artificial intelligence-driven multi-cloud security governance and automated compliance enforcement

A system and method for method for managing security governance and enforcing compliance across a plurality of cloud environments using an artificial intelligence model is disclosed. The method includes receiving, from the plurality of cloud environments, data indicative of one or more configurations, one or more operations, and one or more security parameters. The method includes generating a unified representation of a multi-cloud environment. The method includes detecting one or more deviations, one or more anomalies, and one or more non-compliance conditions. The method includes determining one or more governance actions. The method includes executing, through one or more control interfaces, at least a portion of the determined one or more governance actions across the plurality of cloud environments. The method includes updating one or more of one or more models, one or more policies, and one or more decision parameters.
Owner:BOMPALLY SANTOSH DATTA

Information processing method and apparatus, and communication device and storage medium

An information processing method is performed by a relay user equipment (UE).The method includes: sending a first request message to a network device, wherein the first request message at least comprises a Relay Service Code (RSC) to identify a relay service; receiving a first response message returned by the network device based on the first request message, wherein a relay UE is authorized to provide the relay service indicated by the RSC, and the first response message includes a security parameter for UE-to-UE relay discovery; after receiving the first response message, performing monitoring of a second request message from a source UE; and in response to the relay UE supporting the relay service indicated by the RSC included in the second request message, broadcasting a third request message according to the second request message and relay information.
Owner:BEIJING XIAOMI MOBILE SOFTWARE CO LTD

Communication method and apparatus

A communication method, performed by a first communication apparatus or a chip in the first communication apparatus, includes sending a first request to a first discovery key management network element. The first request is used to request a security parameter. The first request includes an identifier of a proximity-based service. The proximity-based service is a proximity-based service provided by a second communication apparatus for the first communication apparatus. The communication method also includes receiving the security parameter and an identifier of the security parameter from the first discovery key management network element. The communication method further includes receiving a discovery message from the second communication apparatus. The discovery message carries the identifier of the proximity-based service and the identifier of the security parameter. The communication method additionally includes processing the discovery message based on the security parameter corresponding to the identifier of the security parameter.
Owner:HUAWEI TECH CO LTD

Construction method of hybrid key encapsulation mechanism

The invention discloses a construction method of a hybrid key encapsulation mechanism, which comprises the following steps of: generating a public and private key pair of two PKE (Public Key Exchange) algorithms based on security parameters, and outputting a public and private key pair of the hybrid key encapsulation mechanism; taking a public key of a mixed key encapsulation mechanism as the input of an encapsulation algorithm, randomly selecting two plaintexts, respectively generating ciphertexts through public key encryption algorithms of two PKE algorithms, deriving a shared key through a key derivation function, and outputting the shared key; and taking the ciphertext and the private key of the mixed key encapsulation mechanism as the input of a de-encapsulation algorithm, and outputting a shared key. According to the method, a construction method based on the KEM is not used any more, universal construction of the hybrid KEM based on the PKE scheme is achieved, multiple PKE schemes can be adopted for instantiation, multi-level safety under classical and quantum models is achieved, a key derivation function of the KEM for achieving CPA and CCA safety only depends on a plaintext part, and therefore the key derivation function of the hybrid KEM is independent of the plaintext part. Running efficiency is improved by simplifying hash operations and removing redundant hash operations.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

RISC-V-based BFV homomorphic calculation acceleration system

The invention discloses a BFV homomorphic calculation acceleration system based on RISC-V. The BFV homomorphic calculation acceleration system comprises a user-defined extension instruction module, an instruction parser module and a BFV homomorphic calculation hardware acceleration module. And the custom extension instruction module is used for designing and defining a group of RISC-V custom extension instructions for BFV homomorphic calculation key operations, generating an instruction sequence according to the safety parameters and the operation types, and transmitting the instruction sequence to the instruction parser module. And the instruction parser module is used for identifying and parsing the received self-defined extension instruction in an instruction decoding stage. And the BFV homomorphic calculation hardware acceleration module is used for executing polynomial calculation and modular computation operation according to the tasks distributed by the instruction parser module. According to the method, the calculation efficiency and security of the BFV homomorphic encryption algorithm are remarkably improved, and a high-performance hardware-level guarantee is provided for encrypted data.
Owner:HANGZHOU DIANZI UNIV

Data aggregation method with fault tolerance and privacy protection functions

The invention discloses a data aggregation method with fault tolerance and privacy protection functions, and relates to the technical field of smart power grid data security. The method comprises the following steps: setting security parameters, and issuing public parameters; enabling the intelligent electric meter to randomly select a first private key and a blind factor to calculate and publish a first public key, and enabling the aggregation gateway to randomly select a second private key to calculate and publish a second public key; encrypting the collected power consumption data of the user by using the intelligent electric meter to generate a data report; when the aggregation gateway receives the data report, executing a traditional data aggregation algorithm, and if the data report receives the data report, executing a data aggregation algorithm supporting fault tolerance to generate an aggregation ciphertext; and verifying the validity of the data and the time in the data center, and performing data recovery by using the private key. According to the method, data aggregation with fault-tolerant and privacy protection functions can be realized for two application conditions of a fault ammeter and a fault-free ammeter.
Owner:GUIZHOU NORMAL UNIVERSITY

Video encryption transmission method, video decryption output method and device

The invention provides a video encryption transmission method and device and a video decryption output method and device. The video encryption transmission method comprises the following steps: constructing a security parameter set according to an encrypted video encryption key and an initialization vector of an image group; performing XOR operation on the first L-1 bytes of the original data byte stream by adopting the stream key to obtain encrypted byte stream data; setting a network abstraction layer header for each network abstraction layer unit after the image group is processed, wherein the network abstraction layer header at least comprises original coding standard information and encryption state information; performing hash signature processing on the encrypted byte stream data of the image group to generate signature data, and packaging the signature data into an authentication network abstraction layer unit; packaging the security parameter set, the network abstraction layer unit provided with the network abstraction layer head, the authentication network abstraction layer unit and the original parameter set of the image group according to the transmission sequence of the original code stream of the image group to obtain an encrypted video code stream; and sending the encrypted video code stream to a receiver.
Owner:BEIJING ZHONGYU WANTONG TECH CO LTD

Smart home security authentication management method and system based on wireless local area network

The invention provides a smart home security authentication management method and system based on a wireless local area network. The method comprises the following steps: constructing a home network security authentication domain; when a new smart home device is accessed, marking the new smart home device as a second smart home device, and obtaining a device authentication state matrix of a home network security authentication domain; generating an authentication challenge vector based on the device authentication state matrix, and sending the authentication challenge vector to the second smart home device and the first smart home device for cooperative verification; and if the authentication challenge vector passes the cooperative verification, updating keys of all smart home devices in the home network security authentication domain according to a preset dynamic key synchronization protocol. Through construction of a home network security authentication domain, intra-domain sharing of security parameters such as a device authentication state and key management is realized, when any key is updated, other devices update synchronously, and associated dependence exists among keys, so that a risk conduction path of a whole network falling situation caused by key leakage of a single device is blocked.
Owner:CVC CERTIFICATION & TESTING CO LTD +1

Trusted data encapsulation, decryption and transmission method and system based on attribute password

The invention relates to a trusted data encapsulation, decryption and transmission method and system based on an attribute password, and belongs to the technical field of information security. The trusted data encapsulation method comprises the following steps: randomly selecting an element R on an elliptic curve according to attribute password security parameters; generating a data encryption key based on the R, and encrypting the to-be-encrypted data to obtain ciphertext data; carrying out attribute encryption on the R based on an access control strategy and a system public key to generate a ciphertext strategy; and generating trusted data. The trusted data decryption method comprises the following steps: analyzing trusted data to obtain an access control strategy, a ciphertext strategy and ciphertext data; decrypting the ciphertext policy based on the access control policy and the attribute private key of the data user to obtain an element R '; a data encryption key is obtained based on the element R ', and ciphertext data is decrypted to obtain a data plaintext. Trusted data transmission comprises packaging and decryption, and the packaging system is used for generating and distributing trusted data. Efficient and safe sharing of data in the field of digital processing is achieved.
Owner:BEIJING ZHONGHONG LIDA TECH DEV CO LTD +1

Lightweight post-quantum authentication

A method, system, or apparatus for generating and / or verifying a signature on a message is provided. The method, system, or apparatus at a signer may include receiving a message, generating a security parameter, generating at least two seeds corresponding to at least two servers based on the security parameter, transmitting the at least two seeds to each server of the at least two servers, determine a private key based on the security parameter or the at least two seeds, and generating, on the message, a signature based on the private key. The method, system, or apparatus at a verifier may include receiving, from a signer, a signature on a message, obtaining at least two partial public keys, determining a full public key based on the at least two partial public keys, and authenticating the signature on the message based on the full public key. Other aspects, embodiments, and features are also claimed and described.
Owner:UNIV OF SOUTH FLORIDA