Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

1107 results about "Session key" patented technology

A session key is a single-use symmetric key used for encrypting all messages in one communication session. A closely related term is content encryption key (CEK), traffic encryption key (TEK), or multicast key which refers to any key used to encrypt messages, as opposed to other uses, like encrypting other keys (key encryption key (KEK) or key wrapping key).

Control method of multi-protocol switching anti-quantum security gateway

The invention relates to a control method for a multi-protocol switching anti-quantum security gateway, and the method comprises the steps: carrying out the safety self-inspection of a hardware environment after the security gateway is powered on, generating a unique root key of equipment based on a physical unclonable function, continuously collecting and analyzing the network traffic characteristics, and carrying out the self-inspection of the hardware environment. Based on a machine learning model, a quantum attack mode is identified and an encryption algorithm mode is dynamically decided, protocol analysis is carried out on a communication data packet, dynamic conversion and adaptation are carried out between a traditional protocol and an anti-quantum cryptography protocol according to an instruction and a preset rule, and an anti-quantum cryptography engine is called to carry out encryption or signature operation. And dynamically deriving and managing a session key in a complete period based on a root key, switching an algorithm mode, a communication protocol and a key in a linkage manner according to a quantum attack detection result, and starting anti-side channel attack protection and hardware security response. According to the method, active protection of the security gateway on quantum attacks, multi-protocol seamless compatibility and full-life-cycle security management of keys are realized.
Owner:WEIDE GUANGDONG INFORMATION TECH CO LTD

Secure communication method for edge node and terminal equipment based on dynamic key negotiation

The invention relates to a secure communication method for an edge node and terminal equipment based on dynamic key negotiation. The method comprises the following steps: the terminal equipment sends an initial signal when initiating a communication request; the edge node generates a scenarized first key negotiation parameter and feeds back the scenarized first key negotiation parameter after passing dual identity and state verification; after the terminal device decrypts the parameter, a dynamic entropy value is collected by combining a network adaptive sensor, and a second key negotiation parameter associated with the first parameter feature is generated; the two parties calculate session keys based on an ECDH algorithm, and the consistency of the keys is ensured through dynamic entropy verification and Hash comparison; and after the key negotiation succeeds, entering a hierarchical encrypted data transmission stage, and dynamically updating a session key based on a multi-dimensional trigger mechanism. According to the method, through hardware credibility verification, a scenarized key strategy, dynamic entropy enhancement and national secret algorithm adaptation, dynamic management of keys and adaptive matching of terminal resources are achieved, attacks such as equipment counterfeiting and parameter tampering are effectively resisted, and the high-security and compliance requirements in the fields of industrial control and the like are met.
Owner:BEIJING HUAKUN ZHENYU INTELLIGENT TECH CO LTD

File digitalization full life cycle encryption integrity verification method and system

The invention discloses an archive digitization full-life-cycle encryption integrity verification method and system, relates to the field of digital archive safety management, and is used for solving the problem of integrity and safety guarantee in archive digitization management. Logic units are divided through a semantic analysis engine, non-uniform blocks are generated based on sensitivity dynamic partitioning, local hash values are calculated, and a multi-level verification tree is constructed to generate root hash and a hash path mapping table; acquiring visitor identities, terminal environments and timestamps in each stage of an archive life cycle, generating state snapshots in combination with a hash path, and constructing a life cycle state snapshot chain; reconstructing a target logic unit verification path according to the access request, analyzing the structural difference between a current path and a historical snapshot chain through a path reconstruction type difference verification algorithm, and identifying structural offset, node tampering or path loss; and response control is triggered for abnormal verification, including session key updating and permission freezing, so that the security integrity guarantee of the digital archive in the full life cycle is improved.
Owner:FOSHAN POWER SUPPLY BUREAU GUANGDONG POWER GRID

Real estate full life cycle intelligent management method and system based on Internet of Things perception

The invention provides a real estate full life cycle intelligent management method and system based on Internet of Things perception, and the method comprises the steps: distributing a unique hardware identifier of equipment, combining a lightweight digital certificate with a pre-shared key to achieve two-factor authentication, and storing a root certificate in a cloud end; an access authentication process is optimized, an identity label and a certificate signature request need to be submitted when a node accesses for the first time, a temporary session key is generated after the gateway verifies, and abnormal access is immediately isolated and reported; data integrity verification is implemented, and after a sensor collects data, an abstract is generated and data encryption transmission is carried out; after decryption, the receiving end recalculates the abstract for comparison, and if not, the abstract is discarded and nodes are marked to be abnormal; a data anomaly detection model is constructed, energy consumption fluctuation is determined based on historical data, a frequency baseline is collected, data reasonability is monitored in real time, secondary authentication is triggered when the data is abnormal, and node data access is suspended if the data fails; a hierarchical key system is established, hardware is solidified by a root key, session keys are alternated for 24 hours, and data encryption keys are dynamically derived and distributed through encryption channels.
Owner:LERUAN CENTURY (BEIJING) INFORMATION TECHNOLOGY CO LTD

OBD tamper-proof two-way verification method

The invention discloses an OBD tamper-proof two-way verification method, which comprises the steps of obtaining OBD equipment data and vehicle sensor data, registering to a cloud end based on the OBD equipment data, obtaining registration data, obtaining key data and non-key data according to the vehicle sensor data, symmetrically encrypting the key data by using a session key in the registration data, and verifying the key data and the non-key data. Performing approximate homomorphic encryption on the non-key data, obtaining a double-entropy source dynamic salt value according to the time entropy of the ciphertext and the OBD equipment operation entropy, reversely reconstructing the dynamic salt value by the cloud according to the timestamp and the registration data, verifying the ciphertext structure by using the dynamic salt value and generating a random challenge containing a salt value check code, and sending the random challenge to the cloud; the equipment verification result and the challenge value are signed and then transmitted back, the OBD equipment carries out reverse verification on the salt value according to the signature and the equipment verification result, and the cloud generates an authority token based on the reverse verification result. According to the method, the data authenticity and integrity of the diagnostic equipment are guaranteed through packet encryption, dynamic salt value generation and bidirectional identity verification of transmission data.
Owner:INST OF ACOUSTICS CHINA ACAD OF TESTING TECH

Browser tab page data storage method supporting data encryption

The browser tab page data storage method supporting data encryption comprises the steps that browser tab page interaction behaviors are monitored in real time to generate a dynamic factor, and a session key dynamically changing along with the life cycle of a tab page is generated in combination with a process ID of the tab page; based on a self-adaptive encryption strategy, respectively encrypting structured data and unstructured data of the label page; wherein the structured data are encrypted according to field sensitivity levels, and the unstructured data are encrypted through mapping binding of a secret key and the data; the encrypted data and a timestamp voucher of the session key are stored in an associated mode, decryption operation is only allowed to be completed in a label page process memory generating the session key, and the session key is not stored in a landing mode; and when the label page is closed, synchronously clearing the decryption data in the session key and the process memory. According to the method and the device, the defects that the dynamic generation of the key cannot be realized and the key cannot fall to the ground at present are overcome.
Owner:BEIJING NORTH LATITUDE 30 DEGREE NETWORK TECH CO LTD

NFC encrypted IMS server security data exchange method

The invention belongs to the technical field of communication, and particularly relates to an NFC (Near Field Communication) encrypted IMS (IP Multimedia Subsystem) server security data exchange method, which comprises the following steps of: in response to a near field communication connection event, acquiring an original service data message of service equipment to be opened and physical environment data monitored when the event occurs, forming a seed data set, executing Hash operation to generate an initial data fingerprint, and sending the initial data fingerprint to a server; and generating a symmetric session key through a key derivation algorithm by combining a device identifier in the original service data message, so as to encrypt the original service data message, packaging an encrypted data packet and the initial data fingerprint into a transmission data packet, sending the transmission data packet to an IMS server, reconstructing the session key by the server based on expected service parameters stored locally, and sending the session key to the IMS server. According to the method, decryption verification of the encrypted data packet is carried out, and service opening is executed after the verification is passed, so that deep binding of an encryption process and data integrity verification is realized, and the security of data exchange and the system processing efficiency are improved.
Owner:SHANXI ELECTRIC POWER CO POWER COMM CENT

Dual-mode communication encryption synchronization method of power internet of things and power internet of things system

The invention provides a dual-mode communication encryption synchronization method of power internet of things and a power internet of things system, and the method comprises the steps: a power terminal sends an identity authentication request to a master station after completing initialization, so as to carry out the bidirectional identity authentication with the master station; after the bidirectional identity authentication is completed, the power terminal and the master station negotiate to generate a session key for encrypting transmission data; the power terminal encrypts the collected service data through the session key to obtain encrypted service data, and sends the encrypted service data to the master station; and the master station decrypts the received encrypted service data based on the session key to obtain and store the service data. In the mode, through bidirectional identity authentication and session key negotiation between the power terminal and the master station, end-to-end encryption protection of service data can be realized, so that the security and stability of equipment communication in the power Internet of Things system are effectively improved.
Owner:HOLLEY METERING LTD

Switch secure communication encryption method based on quantum key distribution

The invention discloses a switch secure communication encryption method based on quantum key distribution. The method comprises the following steps: a service party submits a'security-delay-bandwidth 'intention to a zero-trust brain through a quantum policy intention description language; evaluating the real-time quality, key margin and topology accessibility of an optical fiber quantum channel, a classical ultra-high-speed channel and a radio frequency space channel according to intention requirements; triggering a QKD transmitting end and a receiving end to perform quantum state transmission of polarization and OAM coding along the optimal quantum path, completing basis vector comparison, error code verification and privacy amplification, generating a root quantum key, and injecting the root quantum key into an on-chip quantum memory; when a data packet arrives at a switch port, the assembly line takes out Kroot from the first-level key pool, and derives a one-time session key through the HMAC-SHA3; continuously monitoring a quantum channel bit error rate, a key pool margin and an AI abnormal score; and the transmitting and receiving parties synchronously confirm and destroy the session key, write all key life cycle events into a quantum invariant account book, and realize second-level auditing evidence obtaining through block chain hash anchoring.
Owner:SHENZHEN TIANBO COMM EQUIP CO LTD

Dynamic incentive federal learning method based on trusted execution environment and block chain

The invention belongs to the technical field of block chains and federated learning, and particularly discloses a dynamic incentive federated learning method based on a trusted execution environment and a block chain. The method comprises the following steps: firstly, constructing a core computing security area by utilizing TEE, and executing key links such as model aggregation, client screening and contribution measurement in a hardware isolated trusted environment; and then, a block chain and an intelligent contract technology are adopted as a decentralized trust root to realize effective management of identities of participants, tamper-proof records of key certificates and automatic distribution of economic incentives. Secondly, establishing a set of dynamic excitation and reputation mechanism executed in the TEE, and performing credible quantification and automatic reward on the contribution of the client based on multi-dimensional indexes such as model quality, historical reputation, asset pledge, participation stability and the like; and finally, end-to-end data encryption is realized through a session key mechanism in the TEE, so that the data privacy of the client is effectively protected.
Owner:CHINA UNIV OF PETROLEUM (EAST CHINA)

Safety communication method and device for upper computer and ECU, storage medium and program product

The invention provides a secure communication method and device for an upper computer and an ECU (Electronic Control Unit), a storage medium and a program product, which are respectively applied to an upper computer end and an ECU end, and the method comprises the following steps: the upper computer obtains an encryption public key of the ECU and a decryption private key of the upper computer, generates a session key for data encryption and decryption, and sends the session key to the ECU; and the session key is subjected to double encryption by sequentially using an encryption public key of the ECU and a decryption private key of the ECU, and a communication ciphertext is generated and sent to the ECU end. And after receiving the communication ciphertext, the ECU end performs dual decryption by using the encryption public key of the upper computer and the decryption private key of the ECU end in sequence, so that the session key is recovered. And after the key negotiation is completed, the two parties encrypt and decrypt communication data through a symmetric encryption mode based on the session key. According to the invention, a hybrid encryption communication mechanism taking the public key infrastructure as the root of trust is constructed, confidentiality and integrity protection of communication data is realized, and the authentication capability of the identity of the communication entity is remarkably enhanced.
Owner:SHANGHAI GEOMETRICAL PERCEPTION & LEARNING CO LTD

Data encryption transmission method and system based on national cryptographic algorithm

The invention discloses a national secret algorithm data encryption transmission method and system. The method comprises the steps of obtaining to-be-encrypted data and network parameters, establishing a Bayesian network probability ablation model, performing Monte Carlo sampling ablation national secret encryption and evaluating attack risks, and generating a probability security encryption strategy; and extracting a Brinell feature set, constructing a long and short-term memory network time prediction model, and optimizing by using a simulated annealing algorithm to obtain an optimal encryption parameter configuration sequence. Generating a key pair according to the sequence and SM2, establishing a shared key by means of an elliptic curve Diffie-Hellman protocol, deriving an SM4 session key through SM3, and establishing a hybrid encryption key system; constructing a teacher and student network model, optimizing multi-thread scheduling through adversarial distillation training and a retrieval enhancement technology, and generating a multi-thread parallel encryption architecture; and network parameters are monitored in real time, a reinforcement learning adaptive decision engine is constructed, a strategy is dynamically adjusted, and adaptive encryption transmission is completed. According to the invention, the optimal balance between the security and the efficiency in the data encryption transmission process is realized.
Owner:GUIZHOU BLUESKY INNOVATIVE SCI & TECH CO LTD

Symmetric encryption key secure transmission method and system

The invention relates to the field of information security, and provides a symmetric encryption key secure transmission method and system. The method comprises the following steps: acquiring a unique fingerprint of equipment and a system parameter, and deriving the unique fingerprint of the equipment and the system parameter through a Hash algorithm to generate a seed key; deriving an initial symmetric key through a Hash algorithm based on the seed key, and performing recursive calculation in combination with key update parameters to obtain a session key; generating a plurality of random components, equally dividing the session key, and then carrying out XOR operation on the session key and each random component to obtain a key fragment set; and carrying out encryption verification on the session key and the plurality of key fragments in the key fragment set, generating verification values corresponding to the plurality of key fragments, and respectively transmitting the plurality of key fragments and the corresponding verification values through a plurality of different transmission paths. According to the invention, dynamic derivation and secure fragmentation transmission of the symmetric key without hardware protection and asymmetric encryption are realized, and the system security is improved.
Owner:E-SURFING DIGITAL LIFE TECH CO LTD

Safe communication method and system for V2G charging pile and energy storage system, and storage medium

The invention provides a safe communication method and system for a V2G charging pile and an energy storage system and a storage medium. The system comprises an energy management system EMS, a charging pile EVSE, a vehicle battery management system BMS and an energy storage battery management system BMS. A session key is established through certificate bidirectional authentication and ECDH negotiation, encryption and anti-replay are realized based on AES / SM4-GCM and additional authentication data, and digital signature verification and REST / TLS transmission are performed on a cross-domain instruction; and when the cloud is unreachable, the EVSE locally executes cooperative control and virtual droop voltage stabilization, or the EMS adopts model prediction control to issue an optimal charging and discharging track. According to the protocol, the confidentiality, integrity and availability of V2G communication and control and the stability of the micro-grid are improved.
Owner:SHENZHEN JIMU ENERGY CO LTD

End-cloud collaborative large model secret state operation method and system

The invention discloses an end-cloud collaboration large model secret state operation method and system, the method is applied to an end-cloud collaboration trusted execution environment, and the application-end cloud collaboration trusted execution environment comprises an end-side security access layer and a cloud-side secret calculation layer for deploying a TEE cluster. The method comprises the following steps: terminal equipment negotiates with a cloud side encryption layer through an end side security access layer to generate a session key, and sends a first ciphertext generated based on the session key to a TEE cluster; and receiving a second ciphertext formed by the TEE cluster based on the first ciphertext, and decrypting the second ciphertext to obtain an interaction result. According to the method, large model secret state operation is carried out by utilizing a two-stage framework of an end side security access layer and a cloud side secret calculation layer, and cloud large model service privacy protection is realized. Meanwhile, the trusted execution environment constructed by the TEE and the heterogeneous AI expansion TEE is adopted, so that the large-model secret-state operation can be operated on a multi-architecture server and a multi-type GPU, and the requirements of diversified deployment scenes are met.
Owner:SHENZHEN CONFIDENTIAL COMPUTING TECH CO LTD

Power real-time data dynamic encryption transmission method and system based on national secret algorithm

The invention discloses an electric power real-time data dynamic encryption transmission method and system based on a national secret algorithm. According to the method, the real-time updating of the session key is realized by fusing the SM3 Hash algorithm and the multi-dimensional dynamic factor, and the anti-attack capability of data transmission of the power system is improved. A timestamp and data counter double-trigger mechanism is introduced in the key generation process, so that the key is automatically alternated under a fixed time interval or a data volume threshold value, a key exposure window is shortened, and the security risk caused by using the same key for a long time is reduced. Key synchronization is carried out in combination with an SM2 bidirectional authentication channel, the confidentiality of key distribution is ensured, access of unauthorized equipment is avoided through an identity authentication mechanism, full-closed-loop security protection from key generation to transmission is formed, the high-security requirement of the power industry for key data transmission is met, and the security of key data transmission is improved. Through deep combination of a cryptographic algorithm system and a dynamic adaptation mechanism, the high efficiency and compliance of power real-time data transmission are considered while the security is ensured.
Owner:GUIZHOU WUJIANG HYDROPOWER DEV

Session key generation method and related apparatus

The application discloses a session key generation method and related device, and relates to the technical field of quantum encryption; when a first SIM card needs to interact information with a second SIM card, a private key team and a public key team can be generated; since the first SIM card is pre-configured with a hybrid key encapsulation algorithm, the public key team includes a public key that can resist quantum attacks, so after the public key team is sent to the second SIM card, the second SIM card can generate key generation information by using an encapsulation algorithm in the hybrid key encapsulation algorithm, encrypt the key generation information by using the public key team, obtain ciphertext information, and send the ciphertext information to the first SIM card; in this way, the first SIM card can decrypt the ciphertext information by using the private key team, obtain the key generation information, and thus obtain a session key.
Owner:ORIGIN QUANTUM COMPUTING TECH (HEFEI) CO LTD

Audio and video signal fusion transmission method and device, equipment and medium

The invention belongs to the technical field of audio and video fusion transmission, and discloses an audio and video signal fusion transmission method and device, equipment and a medium, and the method comprises the steps: extracting 512-dimensional semantic feature vectors of an audio and a video, and generating a joint feature matrix through a cross-modal attention mechanism; calculating a fusion feature flow based on a coefficient alpha output by the scene classification model; a quantum random number generator is used for generating a session master key Kmain, the session master key Kmain is packaged into an encrypted session key Kenc through a Kyber-768 algorithm, and frame-level dynamic encryption is carried out on the fusion feature flow; and selecting a GPMI Type-B wired protocol or wireless transmission based on QUIC according to the transmission environment. According to the invention, the transmission efficiency, the anti-interference capability and the anti-quantum-attack security are improved, and multi-scene requirements are met.
Owner:JIE XUN TECH (GUANGZHOU) CO LTD

Data trusted sharing method based on block chain consensus mechanism

The invention discloses a trusted data sharing method based on a block chain consensus mechanism. The method comprises the following steps: S1, constructing an alliance chain network; s2, completing KZG polynomial commitment generation, ML-KEM algorithm encryption storage and pointer registration; s3, the data provider medical institution completes an evidence storage transaction of the FROST threshold signature; s4, the target medical institution completes the access request transaction; s5, the data provider medical institution sends a KZG unpacking proof and a data item, the target medical institution obtains a storage pointer and a commitment value, KZG verification check is executed, and after verification is passed, an ML-KEM algorithm is executed for depacking to obtain a session key; and S6, the target medical institution completes the audit transaction, and after the alliance chain network broadcast, the consensus node executes rule verification of the access control contract and the audit contract. The multi-node electronic medical record sharing and tamper-proof evidence storage method is high in performance and traceability, and is suitable for credible circulation of sensitive health data among multiple medical institutions.
Owner:HUNAN YUNHANG EDUCATION TECH CO LTD

Distributed quantum security encryption method, system and device

The invention provides a distributed quantum security encryption method, system and device. The method comprises the following steps: monitoring the quality of a quantum key distribution link in real time, and dynamically selecting a quantum key, a post-quantum session key or a fusion key of the quantum key and the post-quantum session key as a working key; and when the node cannot be directly reached, the trusted relay node generates an end-to-end key seed by using a quantum key and a post-quantum cryptography shared key which are respectively established with the two ends, the end-to-end key seed is encrypted and distributed by a public key and then a session key is independently derived by the two communication parties, and the relay node cannot decrypt. The system adopts a distributed Mesh network architecture supporting a terminal / relay dual mode. The device integrates a quantum random number generator, a post quantum cryptography coprocessor and a mixed key engine. The method integrates the advantages of quantum physical security and post quantum cryptography, has high security and availability, and is suitable for constructing a key infrastructure security communication network resisting quantum computing attack.
Owner:INFORMATION & COMMNUNICATION BRANCH STATE GRID JIANGXI ELECTRIC POWER CO

Zero-trust quantum key remote secure injection method and system based on PQC

The invention relates to the technical field of quantum communication, discloses a quantum key remote security injection method and system based on PQC and zero trust, and aims to solve the problems that post-quantum authentication is high in calculation overhead, difficult in terminal adaptation due to resource limitation and lack of continuous verification capability. The method comprises the following steps: presetting a secret seed; the terminal generates a disturbance public key based on the seed and the basic temporary public key and initiates a request; the server carries out implicit authentication by comparing the disturbance public key and executes key encapsulation to generate a session key; the server encrypts the quantum key and signs and sends the quantum key; and after the terminal verifies the signature, the basic private key is used for de-encapsulation to obtain the quantum key. The system comprises a key injection server, a terminal security agent and a disturbance function module. According to the method, authentication logic is integrated into a cryptographic primitive algebraic structure, so that authentication internal biochemistry and light weight are realized, the terminal power consumption and storage occupation are remarkably reduced, the resource exhaustion attack resistance is enhanced, and the continuous authentication requirement of a zero-trust architecture is met.
Owner:ELECTRIC POWER RES INST OF STATE GRID ZHEJIANG ELECTRIC POWER COMAPNY

Encryption transmission method and device, equipment and storage medium

The invention relates to an encryption transmission method and device, equipment and a storage medium, and relates to the technical field of communication. The method comprises the following steps: acquiring plaintext data to be transmitted, and partitioning the plaintext data to obtain plaintext partitioned data; under the condition of supporting a hardware encryption instruction set, encrypting the plaintext block data by adopting a hardware encryption channel and / or a software encryption channel based on a derived public key in the derived session key pair, and adding an encryption channel identifier in the encrypted ciphertext block data; the encryption channel identifier is used for representing that the adopted encryption channel is a hardware encryption channel or a software encryption channel; and sending the ciphertext block data to a receiving end, so that the receiving end performs decryption by adopting an adaptive hardware decryption mode or software decryption mode based on a derived private key in the derived session key pair to obtain plaintext block data. Encryption is carried out by polling a hardware encryption channel and a software encryption channel, and CPU resources consumed in the data encryption process are effectively relieved.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD +1

Transformer area edge safety linkage method based on electricity utilization information acquisition terminal

The invention discloses a zone area edge security linkage method based on an electricity utilization information acquisition terminal, and relates to the technical field of power distribution terminal security, and the method comprises the steps: only reading an object, an action and a time window to generate an intention fingerprint, building an edge security access partition, and allowing a certificate and a one-time token to enter and carrying out retention audit; generating an exclusive session window, and implementing selective communication between virtual segments and a switch array, carrier communication session key rolling (secret exchange), four and eight exclusive sessions and white list current limiting; a shadow integrity label and a sequence commitment are calculated in the end, abnormity is judged in combination with physical fingerprints, grading processing is carried out according to the minimum influence range, and bypass mirror images and equivalent migration mapping are recorded; performing dual authorization and time limit and range checking on the related control, solidifying an evidence chain, and completing rotation and upgrading of a key certificate; on the premise of not changing the meter, the reading and control reliability, traceability and compliance verifiability are improved, the port layer contention is reduced, and the influence radius is reduced.
Owner:LIYANG HUAPENG ELECTRIC POWER METER

Block chain-based key generation and issuing method and device, electronic equipment, medium and program product

The invention provides a key generation and issuing method and device based on a block chain, electronic equipment, a medium and a program product, relates to application of a large model in a financial science and technology scene, and can be applied to the technical field of artificial intelligence and the technical field of block chains. The method comprises the following steps: acquiring key application information, and performing multi-modal analysis on the key application information to obtain key analysis data; submitting a block chain evidence containing the key analysis data to a target block chain network, and obtaining returned evidence reference information; quoting the key analysis data based on the evidence quoting information, performing security policy and environmental risk analysis on the key analysis data, and constructing a target encryption scheme based on an analysis result; and generating target key data by using the target encryption scheme, performing key negotiation with a target terminal based on the target key data, and establishing a secure session key.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Short message privacy protection method and device based on block chain, equipment and storage medium

The invention relates to the technical field of information security, can be applied to the medical field and the financial science and technology field, and discloses a short message privacy protection method, device and equipment based on a block chain, and a storage medium, which are applied to payment verification and transaction confirmation scenes or remote medical consultation scenes. The method comprises the following steps: generating a sender private key and a sender public key in a trusted execution environment, and recording the sender public key in a public key warehouse on a block chain through a smart contract; when a short message sending request is received, generating an elliptic curve key pair, performing key verification, and generating a key negotiation parameter and a temporary session key; performing hierarchical encryption and assembly on the short message content, the temporary session key, the receiver identifier and the sender identifier to generate an encrypted short message packet; calculating a hash value of the encrypted short message packet as a short message identifier; and sending the encrypted short message packet to a receiver terminal for hierarchical decryption and verification. According to the invention, the security of short message privacy is improved.
Owner:PING AN TECH (SHENZHEN) CO LTD

Safe starting method, device and equipment and readable storage medium

The invention provides a safety starting method, device and equipment and a readable storage medium, and the method comprises the steps: responding to a request for starting chip firmware, and building communication connection with a safety chip through inter-core communication; obtaining a trusted key root from the security component according to the security chip, and performing mutual challenge authentication with the security chip; according to a mutual challenge authentication with the security chip, a mutual legal authentication result is obtained, and the security chip is requested to start security signature verification; and starting the chip firmware according to a result fed back by the security chip that the signature verification is legal through security starting of the security component. Through the technical scheme of the specification, the isolation security component forms a hardware-level protection island, the risk of physical detection or bypass attack is eradicated, the security chip agents all operations to ensure that the root key cannot be directly accessed by the main MCU, the two-way challenge authentication is combined with the dynamic session key to realize tamper-proofing of inter-core communication, and on the premise of completely eradicating the tamper-proofing process from being hijacked, the security of the main MCU is improved. And the starting reliability and timeliness of the chip are ensured.
Owner:XINHUASAN INFORMATION TECH CO LTD

Multi-level key dispersion method supporting cross-domain interoperation of tunnel electromechanical system

The invention discloses a multi-level key dispersion method supporting tunnel electromechanical system cross-domain interoperation. The method comprises the steps that a trusted center generates a non-singular elliptic curve parameter, a system main private key and a system public key and then issues a public parameter; safely distributing to the tunnel electromechanical equipment through the tunnel management center; the tunnel electromechanical equipment combines a traceable identifier, a provincial domain identifier, a city domain identifier and a tunnel identifier to construct a dispersion factor; based on a dispersion factor, a part of private keys and a self-selected private key of the equipment, a unique session key and an authentication key are derived through a national cryptographic hash function to realize strong binding between the key and the physical position and management attribution of the equipment; according to the method, the device key is strongly bound with the physical position and the management attribution of the device key through the hash function, the problems of identity mutual trust and risk isolation in cross-domain interoperation are solved, the calculation and communication overhead of resource-limited industrial devices is reduced, and the problem of high-performance security protocol application of embedded devices is solved.
Owner:RES INST OF HIGHWAY MINIST OF TRANSPORT

Identity authentication method and system based on national secret algorithm

The invention discloses an identity authentication method and system based on a national secret algorithm, and the method comprises the steps: building a hierarchical key management system based on a national secret IBE framework, generating a system master key pair through employing an SM2 algorithm, and achieving a decentralized key distribution mechanism; constructing a domain perception differential privacy protection module, defining a privacy budget allocation strategy according to the security level, and adding calibrated Laplace noise to the user identity feature vector; designing a distributed batch matrix multiplication protocol, and decomposing the distributed batch matrix multiplication protocol to a plurality of computing nodes for parallel processing through a secret sharing technology; a zero-knowledge proof verification mechanism is implemented, and identity verification is completed through a commitment scheme based on an SM3 hash algorithm; deploying a self-adaptive key updating strategy, and analyzing threat level change through a threat situation evaluation function; and establishing a secure communication channel based on SM4 symmetric encryption, and performing encryption processing by using the temporary session key. The security and expandability of the system are improved, the privacy of the user is effectively protected, and the system adapts to a dynamically changing network threat environment.
Owner:GUIZHOU BLUESKY INNOVATIVE SCI & TECH CO LTD

Electrical drawing safety collaborative management method, system and equipment based on cloud computing technology and medium

The invention discloses an electrical drawing security collaborative management method, system and device based on a cloud computing technology and a medium. The method comprises the steps that an initial key is generated through a quantum key distribution device, the key is divided into a plurality of sub-blocks, and a dynamic session key is generated; encrypting data blocks divided by the electrical drawing file according to the logic structure through the dynamic session key, and transmitting the encrypted data blocks to a cloud computing platform for storage; generating a temporary key to encrypt the modified content, adding a digital signature and position information, and combining the modified content after the cloud verifies the signature to generate a new electrical drawing; synchronizing the new electrical drawing full-text security operation credential update record to the block chain, and verifying the consistency of the data on the chain and the cloud drawing version; and splitting the dynamic session key into a plurality of fragments and storing the fragments in different cloud nodes. According to the invention, safe transmission, efficient collaborative management and accurate data tracing of the electrical drawings are realized, and the safety, reliability and efficiency of full-life-cycle management of the electrical drawings are remarkably improved.
Owner:GUIZHOU POWER GRID CO LTD

Identity authentication and key negotiation method, gateway equipment and terminal

The invention relates to an identity authentication and key negotiation method, gateway equipment and a terminal. The method is applied to gateway equipment and comprises the following steps: receiving an equipment certificate sent by a terminal and digital signature information based on first timestamp information; verifying the validity and legality of the device certificate, the validity of the first timestamp information and the validity of the digital signature information; when the verification is passed, randomly generating a session key, and setting a calculation initial value and current time; sending a first encryption result of the calculation initial value and the current time and a second encryption result of the session key to the terminal; and receiving a ciphertext which is sent by the terminal and encrypted by the session key, and determining that terminal identity authentication and key negotiation are successful under the condition that the result of decrypting the ciphertext is a target value which is the sum of the calculation initial value and the preset change value. By adopting the method, the security and reliability of communication between the terminal and the gateway equipment can be improved.
Owner:SHENZHEN POWER SUPPLY BUREAU