Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

662 results about "Session key" patented technology

A session key is a single-use symmetric key used for encrypting all messages in one communication session. A closely related term is content encryption key (CEK), traffic encryption key (TEK), or multicast key which refers to any key used to encrypt messages, as opposed to other uses, like encrypting other keys (key encryption key (KEK) or key wrapping key).

Control method of multi-protocol switching anti-quantum security gateway

The invention relates to a control method for a multi-protocol switching anti-quantum security gateway, and the method comprises the steps: carrying out the safety self-inspection of a hardware environment after the security gateway is powered on, generating a unique root key of equipment based on a physical unclonable function, continuously collecting and analyzing the network traffic characteristics, and carrying out the self-inspection of the hardware environment. Based on a machine learning model, a quantum attack mode is identified and an encryption algorithm mode is dynamically decided, protocol analysis is carried out on a communication data packet, dynamic conversion and adaptation are carried out between a traditional protocol and an anti-quantum cryptography protocol according to an instruction and a preset rule, and an anti-quantum cryptography engine is called to carry out encryption or signature operation. And dynamically deriving and managing a session key in a complete period based on a root key, switching an algorithm mode, a communication protocol and a key in a linkage manner according to a quantum attack detection result, and starting anti-side channel attack protection and hardware security response. According to the method, active protection of the security gateway on quantum attacks, multi-protocol seamless compatibility and full-life-cycle security management of keys are realized.
Owner:WEIDE GUANGDONG INFORMATION TECH CO LTD

Real estate full life cycle intelligent management method and system based on Internet of Things perception

The invention provides a real estate full life cycle intelligent management method and system based on Internet of Things perception, and the method comprises the steps: distributing a unique hardware identifier of equipment, combining a lightweight digital certificate with a pre-shared key to achieve two-factor authentication, and storing a root certificate in a cloud end; an access authentication process is optimized, an identity label and a certificate signature request need to be submitted when a node accesses for the first time, a temporary session key is generated after the gateway verifies, and abnormal access is immediately isolated and reported; data integrity verification is implemented, and after a sensor collects data, an abstract is generated and data encryption transmission is carried out; after decryption, the receiving end recalculates the abstract for comparison, and if not, the abstract is discarded and nodes are marked to be abnormal; a data anomaly detection model is constructed, energy consumption fluctuation is determined based on historical data, a frequency baseline is collected, data reasonability is monitored in real time, secondary authentication is triggered when the data is abnormal, and node data access is suspended if the data fails; a hierarchical key system is established, hardware is solidified by a root key, session keys are alternated for 24 hours, and data encryption keys are dynamically derived and distributed through encryption channels.
Owner:LERUAN CENTURY (BEIJING) INFORMATION TECHNOLOGY CO LTD

Data encryption transmission method and system based on national cryptographic algorithm

The invention discloses a national secret algorithm data encryption transmission method and system. The method comprises the steps of obtaining to-be-encrypted data and network parameters, establishing a Bayesian network probability ablation model, performing Monte Carlo sampling ablation national secret encryption and evaluating attack risks, and generating a probability security encryption strategy; and extracting a Brinell feature set, constructing a long and short-term memory network time prediction model, and optimizing by using a simulated annealing algorithm to obtain an optimal encryption parameter configuration sequence. Generating a key pair according to the sequence and SM2, establishing a shared key by means of an elliptic curve Diffie-Hellman protocol, deriving an SM4 session key through SM3, and establishing a hybrid encryption key system; constructing a teacher and student network model, optimizing multi-thread scheduling through adversarial distillation training and a retrieval enhancement technology, and generating a multi-thread parallel encryption architecture; and network parameters are monitored in real time, a reinforcement learning adaptive decision engine is constructed, a strategy is dynamically adjusted, and adaptive encryption transmission is completed. According to the invention, the optimal balance between the security and the efficiency in the data encryption transmission process is realized.
Owner:GUIZHOU BLUESKY INNOVATIVE SCI & TECH CO LTD

Data trusted sharing method based on block chain consensus mechanism

The invention discloses a trusted data sharing method based on a block chain consensus mechanism. The method comprises the following steps: S1, constructing an alliance chain network; s2, completing KZG polynomial commitment generation, ML-KEM algorithm encryption storage and pointer registration; s3, the data provider medical institution completes an evidence storage transaction of the FROST threshold signature; s4, the target medical institution completes the access request transaction; s5, the data provider medical institution sends a KZG unpacking proof and a data item, the target medical institution obtains a storage pointer and a commitment value, KZG verification check is executed, and after verification is passed, an ML-KEM algorithm is executed for depacking to obtain a session key; and S6, the target medical institution completes the audit transaction, and after the alliance chain network broadcast, the consensus node executes rule verification of the access control contract and the audit contract. The multi-node electronic medical record sharing and tamper-proof evidence storage method is high in performance and traceability, and is suitable for credible circulation of sensitive health data among multiple medical institutions.
Owner:HUNAN YUNHANG EDUCATION TECH CO LTD

Distributed quantum security encryption method, system and device

The invention provides a distributed quantum security encryption method, system and device. The method comprises the following steps: monitoring the quality of a quantum key distribution link in real time, and dynamically selecting a quantum key, a post-quantum session key or a fusion key of the quantum key and the post-quantum session key as a working key; and when the node cannot be directly reached, the trusted relay node generates an end-to-end key seed by using a quantum key and a post-quantum cryptography shared key which are respectively established with the two ends, the end-to-end key seed is encrypted and distributed by a public key and then a session key is independently derived by the two communication parties, and the relay node cannot decrypt. The system adopts a distributed Mesh network architecture supporting a terminal / relay dual mode. The device integrates a quantum random number generator, a post quantum cryptography coprocessor and a mixed key engine. The method integrates the advantages of quantum physical security and post quantum cryptography, has high security and availability, and is suitable for constructing a key infrastructure security communication network resisting quantum computing attack.
Owner:INFORMATION & COMMNUNICATION BRANCH STATE GRID JIANGXI ELECTRIC POWER CO

Zero-trust quantum key remote secure injection method and system based on PQC

The invention relates to the technical field of quantum communication, discloses a quantum key remote security injection method and system based on PQC and zero trust, and aims to solve the problems that post-quantum authentication is high in calculation overhead, difficult in terminal adaptation due to resource limitation and lack of continuous verification capability. The method comprises the following steps: presetting a secret seed; the terminal generates a disturbance public key based on the seed and the basic temporary public key and initiates a request; the server carries out implicit authentication by comparing the disturbance public key and executes key encapsulation to generate a session key; the server encrypts the quantum key and signs and sends the quantum key; and after the terminal verifies the signature, the basic private key is used for de-encapsulation to obtain the quantum key. The system comprises a key injection server, a terminal security agent and a disturbance function module. According to the method, authentication logic is integrated into a cryptographic primitive algebraic structure, so that authentication internal biochemistry and light weight are realized, the terminal power consumption and storage occupation are remarkably reduced, the resource exhaustion attack resistance is enhanced, and the continuous authentication requirement of a zero-trust architecture is met.
Owner:ELECTRIC POWER RES INST OF STATE GRID ZHEJIANG ELECTRIC POWER COMAPNY

Identity authentication method and system based on national secret algorithm

The invention discloses an identity authentication method and system based on a national secret algorithm, and the method comprises the steps: building a hierarchical key management system based on a national secret IBE framework, generating a system master key pair through employing an SM2 algorithm, and achieving a decentralized key distribution mechanism; constructing a domain perception differential privacy protection module, defining a privacy budget allocation strategy according to the security level, and adding calibrated Laplace noise to the user identity feature vector; designing a distributed batch matrix multiplication protocol, and decomposing the distributed batch matrix multiplication protocol to a plurality of computing nodes for parallel processing through a secret sharing technology; a zero-knowledge proof verification mechanism is implemented, and identity verification is completed through a commitment scheme based on an SM3 hash algorithm; deploying a self-adaptive key updating strategy, and analyzing threat level change through a threat situation evaluation function; and establishing a secure communication channel based on SM4 symmetric encryption, and performing encryption processing by using the temporary session key. The security and expandability of the system are improved, the privacy of the user is effectively protected, and the system adapts to a dynamically changing network threat environment.
Owner:GUIZHOU BLUESKY INNOVATIVE SCI & TECH CO LTD

Hardware-level identity authentication and end-to-end encryption near-field data interaction method and system for electric red-in secure connection terminal

The invention relates to the technical field of near-field communication security, in particular to a hardware-level identity authentication and end-to-end encryption near-field data interaction method and system for an electric red-connected terminal, and the method comprises the steps: a first electric red-connected terminal and a second electric red-connected terminal initiate pairing based on a Bluetooth secure connection pairing protocol, and negotiate to generate a long-term key through an ECDH algorithm; performing bidirectional identity verification by adopting an application layer authentication protocol; activating AES-CCM encryption by using a session key derived from a long-term key; bluetooth signal strength and a connection state are monitored in real time, and a negotiation key is automatically paired again when abnormity occurs; generating an interaction log, digitally signing the log by using a locally stored private key, and securely storing the signed log in a local secure storage area of the terminal; the digital signature of the latest log is verified, and if interaction abnormity is found, the local security module of the terminal recovers the local data to the pre-interaction state according to the last credible log record. The problem that traditional Bluetooth communication is prone to eavesdropping and tampering can be solved.
Owner:ELECTRIC POWER RES INST OF GUANGXI POWER GRID CO LTD

Management method and device for preventing BMS firmware from being flashed

The invention provides a management method and device for preventing BMS firmware from being flashed, and relates to the technical field of asymmetric encryption, and the method comprises the steps: generating a unique response, and reconstructing an equipment root key, so as to establish a trusted firmware execution environment and complete firmware digital signature verification; digital certificate exchange and bidirectional verification of the BMS and the diagnostic instrument are carried out in the trusted firmware execution environment, a dynamic session key is generated, and a challenge response mechanism is executed to ensure that firmware flashing operation is only authorized in the trusted communication environment; performing hash check, control flow monitoring and access auditing by using the security reference data based on the dynamic session key, performing real-time hardware processing when an exception is detected, and recording a security event at the same time; and the BMS uploads the log and attack behavior characteristics corresponding to the security event to a cloud platform, and the cloud platform analyzes and generates a detection rule or certificate revocation list and issues and updates the detection rule or certificate revocation list. Through the dynamic BMS firmware flashing protection method, the safety of the BMS firmware is improved.
Owner:XIAOGAN CORNEX NEW ENERGY INNOVATION TECHNOLOGY CO LTD

2.4 GHz wireless remote control method and device based on hardware code matching

The invention provides a 2.4 GHz wireless remote control method and device based on hardware code matching, and relates to the technical field of wireless remote control. The present invention is applied to control communication between at least one transmitting end and at least one receiving end. The group identifier and the role information are analyzed by reading the hardware address setter to realize rapid networking; generating a session key and establishing a secure session according to the pre-shared root key in a handshake stage; a sending end collects man-machine input data to form a control frame, and the control frame is sent according to a token rotation or time slice distribution mechanism after encryption and message authentication; and the receiving end drives the controlled object and returns feedback data after completing verification and decryption. The system adaptively adjusts communication parameters according to feedback information and a channel state, so that secure, stable and intelligent control of multi-terminal wireless remote control is realized.
Owner:HANGZHOU ZHIZHI SCI & EDUCATION SUPPLIES CO LTD

Method and system for mutual authentication and key agreement between vehicles

The invention discloses an inter-vehicle bidirectional authentication and key agreement method and system, and relates to the technical field of Internet of Vehicles information security, and the method comprises the steps: a registration stage: a vehicle and a trusted mechanism derive a temporary session key based on ECDH and HKDF, and achieve the secure interaction; the trusted institution generates a basic identity label, a part of private key, a signature and a basic certificate for the vehicle, and encrypts and transmits the basic identity label, the part of private key, the signature and the basic certificate to the vehicle; the vehicle generates a hardware fingerprint and extracts a secret key by using the embedded PUF, and part of the private key is encrypted and then is locally and safely stored with the basic certificate; in the authentication stage, the two communication parties dynamically recover part of private keys through PUF, and generate dynamic pseudo names, temporary ECDH key pairs and cryptographic evidence; and calculating a cross item and a binding item by interaction parameters of the two parties, negotiating a unique session key, and completing bidirectional confirmation through a message authentication code. According to the method and the device, efficient, physical attack-resistant and privacy-protecting V2V security mutual recognition and key agreement are realized in a resource-limited vehicle-mounted environment.
Owner:CHANGZHOU INST OF TECH

Public network interphone with quantum chip

The invention relates to the technical field of wireless communication, in particular to a public network interphone with a quantum chip. According to the interphone, a master control module and a quantum security chip work cooperatively, a quantum random number generator is used for dynamically deriving a session key, and offline security distribution of a group master key is realized by encrypting a two-dimensional code; in a communication process, a system adaptively switches a voice coding mode according to a network condition, end-to-end authentication encryption is carried out on voice data by using a hardware encryption engine, and low-delay transmission is guaranteed through a network priority mark; the device establishes a complete key life cycle management mechanism, supports regular update and forward security of session keys and instant update and backward security of a group master key when members change, and ensures that all key operations are completed in a quantum chip. According to the invention, various eavesdropping and tampering attacks are effectively resisted, and safe, real-time and clear high-confidentiality voice communication in a public network environment is realized.
Owner:ZHEJIANG HAIGAOSI COMM TECH CO LTD

Hybrid collaborative signature method fusing SM2 and post quantum cryptography algorithm

The invention belongs to the technical field of information security, and discloses a hybrid collaborative signature method fusing SM2 and a post-quantum cryptography algorithm, and the method comprises the steps that a client generates a first session key based on a first post-quantum signature key pair and a first post-quantum asymmetric encryption and decryption key pair, generating a first public key ciphertext corresponding to the first public key parameter based on the first session key; the server decrypts the first public key ciphertext based on the first session key, and applies for obtaining a digital signature certificate after generating a common public key through an SM2 algorithm; performing collaborative signature according to a second session key generated by a second post-quantum signature key pair and a second post-quantum asymmetric encryption and decryption key pair, calculating by the server to obtain a first signature component intermediate value, and calculating by the client to obtain a second signature component; the client calculates a target signature value according to the second signature component, the first signature component intermediate value ciphertext and the digital signature certificate; through the method, the safety of the hybrid collaborative signature is improved.
Owner:GUANGDONG CERTIFICATE AUTHORITY

Near field communication matching processing method and system for unmanned aerial vehicle in communication area without public network

The invention provides an unmanned aerial vehicle near field communication matching processing method and system without a public network communication area, and relates to the technical field of intelligent control, and the method comprises the steps: generating a session key and an equipment authority topological graph according to a quantum random number; based on the equipment authority topological graph and the channel state tensor, communication capability matching is carried out on equipment in an unmanned aerial vehicle cluster, and a matching equipment pair set and a communication parameter mapping relation thereof are generated; performing joint coding on reconnaissance data, a control instruction and state information according to the session key, the equipment permission topological graph and the matching equipment pair set to generate a coding symbol stream; and according to the communication parameter mapping relation of the matching device to the set, performing directional transmission scheduling on the coding symbol stream to complete near field communication matching processing between the unmanned aerial vehicles. According to the invention, the cooperative operation efficiency and task success rate of the unmanned aerial vehicle rescue cluster in a public-network-free mountainous complex environment are improved.
Owner:国网四川省电力公司电力应急中心

Data transmission method and system for meteorological satellite communication system

The invention discloses a data transmission method for a meteorological satellite communication system, and relates to the technical field of data transmission. Receiving original meteorological data, performing security level analysis on the original meteorological data, determining a security level, and processing the key change parameter by using the master key based on a preset key derivation function to obtain an encrypted session key; performing encryption processing on the original meteorological data based on the encrypted session key to obtain first ciphertext data; combining the key change parameter with the communication identification information to obtain first associated data; performing message authentication code calculation on the first associated data and the first ciphertext data to obtain a message authentication code; assembling the security level, the first associated data, the first ciphertext data and the message authentication code based on a preset format to obtain a target data frame; and sending the target data frame to a meteorological data center so as to decrypt the target data frame to obtain original meteorological data. By implementing the technical scheme provided by the invention, the security in the transmission process is ensured.
Owner:ZHONGMAN TECH (BEIJING) CO LTD

Method and host machine for executing computing task through GPU (Graphics Processing Unit)

The invention provides a method for executing a computing task through a GPU and a host machine, the GPU is configured on a target host machine, a first confidential virtual machine containing a first client and a second confidential virtual machine containing a first agent program run on the target host machine, and the second confidential virtual machine loads an encryption and decryption kernel into the GPU in advance. The method comprises the following steps: a first client transmits a calculation task to a first agent program through an encryption channel pre-established with the first agent program; the first agent program encrypts the calculation task through a session key negotiated in advance with the encryption and decryption kernel, and sends an obtained first encryption result to the GPU; the GPU decrypts the first encryption result according to the session key, and restores and executes the calculation task to obtain a calculation result; encrypting the calculation result according to the session key, and sending an obtained second encryption result to the first agent program; and the first agent program decrypts the second encryption result according to the session key, and sends the restored calculation result to the first client through the encryption channel.
Owner:ALIPAY (HANGZHOU) INFORMATION TECH CO LTD

Method for resisting quantum cryptographic migration of Internet of Things equipment based on national cryptographic algorithm

The invention discloses an Internet of Things device anti-quantum password migration method based on a national cryptographic algorithm, and relates to the field of data security, the method comprises the following steps: configuring a Hash agility module taking a national cryptographic SM3 as a default algorithm, and dynamically switching to an anti-quantum or compatibility alternative algorithm based on monitoring; carrying out identity authentication and temporary key negotiation by adopting SM2, and generating a key pair only used for a single session; deriving a session key based on the key pair, and adopting a differential double-layer signature verification mechanism according to the data security level; for firmware updating, a differential package is generated through function level differential analysis, and atomic updating and rollback are achieved through A / B system partition. According to the method, quantum computing threats are effectively resisted, national security compliance and forward security are ensured, the volume of an update package is remarkably reduced through a resource optimization technology, memory occupation is reduced, verification efficiency is improved, and the method is particularly suitable for resource-limited Internet of Things equipment.
Owner:HUAZHONG NORMAL UNIV

Power data hybrid encryption transmission method, system and device and readable storage medium

The invention relates to a power data hybrid encryption transmission method, system and device, and a readable storage medium. The method comprises the following steps: S1, encrypting a power data plaintext by using a session key to obtain a ciphertext; s2, cutting the ciphertext into a plurality of sections of sub-ciphertexts, combining the sub-ciphertexts with unique random numbers to obtain a plurality of combinations of the sub-ciphertexts and the random numbers, and combining the random numbers to obtain a random number group; randomly sorting the plurality of sub-ciphertexts and random number combinations to obtain a random ciphertext array; s3, encrypting the session key and the random array, and performing digital signature on the random ciphertext array; s4, transmitting the encrypted random array, the session key, the random ciphertext array and the digital signature to a receiver in a parallel communication mode; s5, the receiver verifies and decrypts for many times to obtain the electric power data, the problem that data safety and data transmission efficiency cannot be considered in the existing electric power transmission process is solved, the data transmission safety is improved, and it is ensured that the transmission speed cannot be greatly reduced.
Owner:YUNNAN POWER GRID CO LTD

Quantum key management method and system for satellite internet biological characteristics

The invention relates to a quantum key management method and system for satellite internet biological characteristics, and the method comprises the following steps: carrying out the registration of biological characteristics and the initialization of communication protocol parameters for a user terminal which is accessed for the first time; for the registered user terminal, before initiating communication each time, binding the real-time biological characteristics with the quantum key, and carrying out encrypted transmission of the session key by using the bound quantum key, so as to carry out encrypted transmission of satellite internet transmission data by using the session key; and in the encryption transmission process of the satellite internet transmission data, according to a preset period, performing satellite link security level adjustment and quantum key dynamic updating. According to the invention, identity authentication and terminal authentication in a high-delay and narrow-bandwidth application scene can be realized, the security problems of identity counterfeiting, key leakage and the like are solved, and the method can be applied to satellite internet scenes such as emergency communication, field operation and the like, and has the advantages of strong compatibility, low deployment cost and the like.
Owner:SPACE STAR TECH CO LTD

Secure data transmission system based on dynamic encryption authentication

According to the secure data transmission system based on dynamic encryption authentication provided by the invention, a trust root which cannot be tampered is established for the whole system through the hardware password module, and continuous derivation and rotation of a session key are realized by the dynamic key management module on the basis, so that the security risk caused by long-term use of a static key is effectively solved. And the secure communication gateway module executes bidirectional authentication and anti-hijacking challenge response by using a dynamic key, so that the real-time credibility and session continuity of the communication process are ensured. And the strategy control engine uniformly coordinates the behaviors of key management and the communication gateway by receiving and compiling the declarative strategy, so that flexible deployment and centralized management and control of the security strategy are realized. According to the system, a cryptographic basis, a dynamic strategy, real-time monitoring and automatic response are deeply fused, a self-adaptive and automatic deep defense system with the capability of continuously resisting advanced threats is constructed, and the overall safety level and the operation efficiency of data transmission are remarkably improved.
Owner:HUANENG INFORMATION TECH CO LTD

Internet of vehicles cross-domain identity authentication method based on PUF (Physical Unclonable Function) and certificateless

The invention provides an Internet of Vehicles cross-domain identity authentication method based on PUF and certificateless, and the method comprises the steps: firstly generating a system master key and a master public key through a KGC, and disclosing system parameters; secondly, the vehicle generates a physical response and extracts a stable key, interacts with the KGC to complete generation of a certificateless key pair, and stores registration information to a block chain; then the edge server registers in the KGC, obtains a certificateless key pair, initiates an authentication request to the KGC, and obtains a block chain data reading authority; finally, bidirectional authentication is carried out between the vehicle and the edge server based on the certificateless signature and the PUF response, and a session key is generated; and the cross-domain vehicles are assisted by the edge server to complete mutual identity authentication and session key negotiation. According to the method, the key escrow and certificate management burden is eliminated by adopting a certificateless cryptosystem, the high computing load is released to the edge server in combination with the PUF hardware security characteristic and the block chain distributed trust, the computing and communication overhead is remarkably reduced, and the method is suitable for a large-scale Internet of Vehicles cross-domain authentication scene.
Owner:GUIZHOU UNIV

Data sharing method and system for metabolic acidosis patients

The invention relates to the technical field of computers, discloses a data sharing method and system for patients suffering from metabolic acidosis, and aims to solve the problem of out-of-control safety caused by extensive authority, bare transmission and traceless behaviors in cross-institution medical data circulation. A dynamic authority strategy based on roles and scenes is constructed by extracting and standardizing patient diagnosis and treatment data from a hospital system; end-to-end encrypted transmission is realized through bidirectional authentication and a temporary session key; establishing a three-layer block chain type audit log tracking access, a secret key and a data flow direction; dynamic desensitization, quality verification, cache acceleration and intelligent contract extension mechanisms are integrated, and a visual authority topology monitoring and credit scoring system is supplemented. According to the technical scheme, data field-level accurate authorization, encryption and anti-theft in the whole transmission process, traceability in the whole operation period and use compliance self-feedback are achieved, and the scientific research value of clinical data is released to the maximum extent while the privacy safety of a patient is effectively guaranteed.
Owner:THE FIRST MEDICAL CENT CHINESE PLA GENERAL HOSPITAL

Node communication adaptive encryption method and system for high-availability cluster

The invention discloses a node communication adaptive encryption method and system for a high-availability cluster. The method comprises the following steps: a source node and a destination node perform SM2 key negotiation to generate a shared session key SK; the application layer of the source node sends a message to a high-availability trunking communication service; a high-availability trunking communication service firstly calls a hook function serving as a universal encryption signature interface on a message outbound path by using a communication protocol module, if a specified encryption mode is SM4 encryption, a message is encrypted by using a shared session key SK through an SM4 encryption module to generate an encrypted data packet, otherwise, other encryption modules are called to generate the encrypted data packet; sending the encrypted data packet to a destination node; and the destination node decrypts the generated plaintext data packet and sends the plaintext data packet According to the method, the SM4 algorithm is seamlessly integrated into a communication system of a high-availability cluster, and the performance overhead is controlled within an acceptable range while security encryption is provided through optimization.
Owner:HUNAN KYLIN XINAN TECH CO LTD

Fire-fighting Internet of Things equipment authentication method supporting anti-quantum algorithm

The invention relates to the technical field of information security, in particular to a fire-fighting Internet of Things equipment authentication method supporting an anti-quantum algorithm, comprising the following steps: before fire-fighting Internet of Things equipment and an Internet of Things platform server are started through Internet of Things MQTT communication connection, the fire-fighting Internet of Things equipment initiates a first TLS handshake packet to the Internet of Things platform server, the fire-fighting internet-of-things equipment receives a server digital certificate returned by the internet-of-things platform server, verifies the validity of the server digital certificate, and sends an equipment certificate to the internet-of-things platform server after the verification is passed, so that the internet-of-things platform server generates a random session key ciphertext by using a public key in the equipment certificate, and sends the random session key ciphertext to the fire-fighting internet-of-things equipment; the fire-fighting internet-of-things equipment unpacks the random session key ciphertext by using a private key to obtain a shared session key K; and the fire-fighting Internet of Things equipment establishes a security encryption communication channel with the Internet of Things platform server based on the shared session key K, and executes MQTT message transmission in the communication channel.
Owner:HANGZHOU INNOVATION RES INST OF BEIJING UNIV OF AERONAUTICS & ASTRONAUTICS

Automatic session quality detection method applied to customer service scene

The invention relates to the technical field of digital data processing, in particular to an automatic session quality detection method applied to a customer service scene. The detection method comprises the following steps: model training: selecting an LLaMA pre-training large language model as a core engine, and guiding training by means of cue words with session key element extraction and semantic consistency comparison functions; judging the format of the target session data to be subjected to quality detection, and converting the voice format into a text format; performing key element extraction and comparative analysis on the session data in the text format by means of the trained model; consistency comparison is carried out on the robot reply and a corresponding standard reply in a knowledge base; verifying whether business data contained in the robot reply is consistent with real data of a back-end business system; and generating a detailed report of the quality inspection result. Defects are accurately recognized, understood and expressed by means of the large model reasoning ability, and robot reply and a semantic verification closed loop of a knowledge source are achieved.
Owner:国家电网有限公司客户服务中心

Secure interaction method and system for data space sandbox and data source

The invention discloses a secure interaction method and system for a data space sandbox and a data source, and the method comprises the steps: initializing and authenticating a sandbox environment, and generating a unique environment identifier EnvID; based on the threshold signature scheme, negotiating among the plurality of key management nodes, the sandbox and the data source to generate a session key; the method comprises the following steps: sending a data request to a data source through a sandbox, requesting data added with an environment identifier EnvID based on a sandbox private key signature, after the data source receives the data request and verifies the signature, encrypting outer-layer data based on a session key, encrypting inner-layer data based on an attribute-based encryption algorithm, and generating Merkle root hash of response data; and decrypting outer-layer data based on the session key in a memory through a sandbox, decrypting and processing inner-layer data based on an attribute-based encryption private key, generating a zero-knowledge proof zkProof, and submitting Merkle root hash and the zero-knowledge proof zkProof to a block chain for evidence storage and auditing.
Owner:AISINO CORPORATION

Cross-domain quantum key charging method and system

The invention relates to the field of information security, and discloses a cross-domain quantum key charging method and system.The method comprises the steps that a first key charging site responds to a first service terminal request, analyzes a target terminal identifier and reports step by step when cross-domain judgment is conducted; the cross-domain key charging management center generates a cross-domain master key based on a quantum true random number according to the target attribution, and distributes the cross-domain master key to a source domain key charging service center and a target domain key charging service center through a quantum secure channel; the service centers of the two parties negotiate a derived session key by using the shared master key and issue the derived session key; and after receiving the session key, the site generates a service key in combination with the service context and charges the service key to the terminal. The system also integrates a dynamic request triggering mechanism based on consumption rate, a hybrid encryption channel mechanism and a storage unit physical overwriting destruction mechanism. According to the method, a hierarchical cascade architecture is adopted, and a quantum entropy source and a post-quantum algorithm are combined, so that the problem of trust transfer between heterogeneous domains is solved, and quantum computing attack-resistant key full-life-cycle safe closed-loop management is realized.
Owner:GUIYANG BUREAU OF CHINA SOUTHERN POWER GRID CO LTD EHV TRANSMISSION CO

Vehicle communication data processing method, vehicle and storage medium

The embodiment of the invention provides a vehicle communication data processing method, a vehicle and a storage medium, and the method comprises the steps: obtaining target feature data and real-time state data of a target vehicle, the target feature data being used for representing multi-dimensional physical features associated with the target vehicle, and the real-time state data being used for representing real-time state data of the target vehicle; the real-time state data is used for representing an engine running state and an ignition state of the target vehicle; generating key seed data based on the target feature data and the real-time state data; a vehicle session key is generated according to the key seed data, and the vehicle session key is used for encrypting and decrypting the session data packet; and performing data communication of the target vehicle by using the vehicle session key. According to the method and the device, the technical problems of low security of a fixed key management scheme and great influence of an encryption authentication mechanism on real-time performance in related technologies are solved.
Owner:CHERY AUTOMOBILE CO LTD

Secure communication for unmanned aerial vehicle in integrated ecosystem

A secured communication for an Unmanned Aerial Vehicle (UAV) is established. A user terminal receives a UAV battery charge level from the UAV in response to the user terminal's request to the UAV. Based on the UAV battery charge level and a threshold battery charge level received in the delivery response, the user terminal transmits the delivery response to the UAV. The UAV verifies a signature in the delivery response using a unique public key of a public and private key pair and transmits an acknowledgement for the delivery response to the user terminal upon verifying the signature. Subsequently, the user terminal, upon receiving the acknowledgement, generates and transmits a session key to the UAV for establishing a secure communication between the UAV and the server for transportation. The UAV establishes the secure communication with the server using the session key.
Owner:CONTINENTAL AUTOMOTIVE TECHNOLOGIES GMBH

Intelligent household equipment communication method driven by physical unclonable function

The invention relates to the technical field of smart home devices, in particular to a smart home device communication method driven by a physical unclonable function, which is used for establishing a secure session between a resource-limited initiating device and a resource-limited receiving device, and comprises the following steps: A, generating a physical unclonable function key; b, anti-quantum key negotiation; c, combining identity authentication and signature; d, establishing a secure session key; and E, safely transmitting the instruction. According to the method, the non-persistent key is generated and established through the physical unclonable function key, so that the problems of physical attack and key stealing are solved; anti-quantum key negotiation and lattice ciphertext de-encapsulation provide anti-quantum security, and the problem of future calculation threats is solved; identity authentication and signature are combined to realize single handshake, delay and power consumption are reduced, and the requirements of low power consumption and high efficiency are met; drift calibration is implemented, so that the stability of the key of the physical unclonable function is guaranteed, and the reliability is improved; and the confidentiality and the integrity of the instruction are ensured by the final secure transmission of the instruction.
Owner:DONGGUAN LAIMSEN TECH BUILDING MATERIAL CO LTD