Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

474 results about "Shared secret" patented technology

In cryptography, a shared secret is a piece of data, known only to the parties involved, in a secure communication. This usually refers to the key of a symmetric cryptosystem. The shared secret can be a password, a passphrase, a big number or an array of randomly chosen bytes.

Privacy protection for a-iot device identifiers

An apparatus and system for privacy protection for Ambient Internet-of-Things (A-IoT) devices are disclosed. A-IoT devices transmit obfuscated identifiers (OIDs) instead of actual identifiers, which are de-obfuscated by the network to retrieve the original identifiers. The device identifiers are obfuscated using shared secret parameters and periodically updated configurations. Hash-based lightweight privacy mechanisms, temporary identifiers (TempIDs), and pseudonym generation may be used to ensure secure communication and prevent replay attacks.
Owner:INTEL CORP

Data encryption transmission method and system based on national cryptographic algorithm

The invention discloses a national secret algorithm data encryption transmission method and system. The method comprises the steps of obtaining to-be-encrypted data and network parameters, establishing a Bayesian network probability ablation model, performing Monte Carlo sampling ablation national secret encryption and evaluating attack risks, and generating a probability security encryption strategy; and extracting a Brinell feature set, constructing a long and short-term memory network time prediction model, and optimizing by using a simulated annealing algorithm to obtain an optimal encryption parameter configuration sequence. Generating a key pair according to the sequence and SM2, establishing a shared key by means of an elliptic curve Diffie-Hellman protocol, deriving an SM4 session key through SM3, and establishing a hybrid encryption key system; constructing a teacher and student network model, optimizing multi-thread scheduling through adversarial distillation training and a retrieval enhancement technology, and generating a multi-thread parallel encryption architecture; and network parameters are monitored in real time, a reinforcement learning adaptive decision engine is constructed, a strategy is dynamically adjusted, and adaptive encryption transmission is completed. According to the invention, the optimal balance between the security and the efficiency in the data encryption transmission process is realized.
Owner:GUIZHOU BLUESKY INNOVATIVE SCI & TECH CO LTD

Anti-quantum fuzzy keyword processing method and system and electronic equipment

The invention provides an anti-quantum fuzzy keyword processing method and system and electronic equipment, and relates to the technical field of networks and security. The method comprises the following steps: a client performs wildcard character extension on a keyword set based on a target shared key, generates an encryption index, performs authentication encryption on file identifiers by using the target shared key, forms an encrypted file identifier set, constructs an index table, and uploads the index table and the encrypted file set to a cloud server. The server generates a second wildcard character set according to the query keyword and a fault-tolerant threshold value, generates a trap door set based on the same target shared key and a pseudo-random function and sends the trap door set to the cloud server, and the cloud server traverses the index table, compares the index table with the trap door set and sends the trap door set to the server; and finding out the matched target encryption index and the associated target encryption file identifier and returning the matched target encryption index and the associated target encryption file identifier to the server, and decrypting and acquiring the target file from the cloud server by the server. In this way, high-safety, high-efficiency and extensible privacy protection search service is achieved.
Owner:中电信量子信息科技集团有限公司

Method and device for dynamic secure communication between micro-services based on chaos cryptography

The invention provides an inter-micro-service dynamic secure communication method and device based on chaos cryptography. The method comprises the steps that a service provider instance registers a public key and chaos initial parameters to a service registration center; before calling, the service consumer instance acquires a public key and a chaos initial parameter of a target service provider instance from a service registration center; the service consumer instance performs key negotiation with the acquired public key by using a private key of the service consumer instance to determine a shared key; performing key derivation on the shared key and the chaotic initial parameter to generate an initial key; respectively using the initial keys to initialize the chaotic system so as to generate synchronous encryption key streams; and the two communication parties perform real-time stream encryption and decryption on the communication data between the micro-services by using the encryption key stream. The unpredictability of a chaotic system and modern cryptography can be combined, and a micro-service design mode is deeply integrated, so that a lightweight and high-security communication security mechanism which does not need to share a key in advance and can be adaptive to dynamic change of service is realized.
Owner:浪潮智能终端有限公司

Sharing keys for a wireless accessory

Embodiments described herein provide for a non-transitory machine-readable medium storing instructions to cause one or more processor to perform operations to share a set of keys used to communicate with a wireless accessory device. By sharing the set of keys, functionality of the wireless accessory device can be delegated by an owner to other individuals.
Owner:APPLE INC

Channel secure transmission method for protecting data privacy of edge gateway of Internet of Things

The invention discloses a channel security transmission method for protecting data privacy of an edge gateway of the Internet of Things, and relates to the technical field of security and privacy protection of the Internet of Things, and the method comprises the steps: constructing an edge gateway security architecture, generating a quantum key through a QKD module based on the constructed edge gateway security architecture, and generating sensitivity data through an IPS vNSF; calculating noise based on the sensitivity data, generating disturbance data based on the noise, calculating a shared key, generating an encryption key in combination with the quantum key and the shared key, segmenting the encryption key through Shamir secret sharing, and encrypting and decrypting the key; encrypting the noise by using the decrypted key, generating global noise based on the encrypted noise, and calculating secondary disturbance data based on the global noise; and generating coded data based on the secondary disturbance data, and generating reconstruction data based on the coded data. According to the invention, the comprehensive security authority of the edge gateway in the aspects of key security and privacy protection intensity is improved.
Owner:ZHEJIANG IND POLYTECHNIC COLLEGE +1

Communication methods and communication devices

Provided are communication methods and communication devices. One method comprises: on the basis of a shared key, a first device generates a first key; the first device receives a second random number of a second device; on the basis of the first key, the first device generates first authentication information of the first device; and the first device sends a first message to the second device, the first message comprising the first authentication information, and the first authentication information being generated according to one or more of the following information: device information, service-related information, an identifier of a device forwarding the first message, and a first random number and a second random number of the first device.
Owner:GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD

Executing cryptographic operations in a secure element platform runtime environment

A system performs a set of cryptographic operations at least by utilizing an API to cause execution of a set of one or more secure element (SE) applications within the SE platform runtime environment of a first computing entity. The set of cryptographic operations include generating a first shared secret, generating a ciphertext at least by encapsulating the first shared secret with a first public key associated with a second computing entity in accordance with an encapsulation algorithm, and transmitting the ciphertext from the first computing entity to the second computing entity. The second computing entity derives the first shared secret by decapsulating the ciphertext with a private key corresponding to the first public key. The first computing entity and the second computing entity then exchange at least one encrypted message, encrypted with an encryption key that includes, or is based at least in part on, the first shared secret.
Owner:ORACLE INT CORP

Secure transmission method and system for encrypted network data

The invention relates to a secure transmission method and system for encrypted network data. According to the method, a resource state vector is generated by collecting resource state data of Internet of Things equipment, and an environmental risk level is evaluated by using a pre-training decision model in combination with attacked information; performing content feature scanning on the to-be-transmitted data, and performing data sensitivity grading based on key field identification; querying an encryption decision matrix according to the resource state vector, the environmental risk level and the data sensitivity level, and determining a target encryption scheme; a private key and a public key are dynamically generated at an equipment end, a shared key seed is calculated after the public key is exchanged with a communication opposite end, and a target encryption scheme and the shared key seed are used for encrypting data to generate a transmission frame; periodically optimizing the encryption decision matrix through a reinforcement learning algorithm based on encryption time consumption, resource consumption and transmission success rate indexes; the encryption strength is adaptively adjusted, resource utilization is optimized while the security is ensured, and the overall efficiency of the system is improved through continuous feedback optimization.
Owner:TONGLING POWER SUPPLY CO OF STATE GRID ANHUI ELECTRIC POWER CO

Anti-quantum key packaging method and device, medium and equipment

The invention discloses an anti-quantum key packaging method and device, a medium and equipment, and the method comprises the steps that a first node generates a first public key and a first private key based on an asymmetric encryption algorithm, and generates a second public key and a second private key based on an anti-quantum encryption algorithm; sending the first public key and the second public key to a second node, so that the second node encrypts a third public key based on the second public key to obtain a public key ciphertext, and generates a shared key based on the first public key and a third private key; receiving a public key ciphertext sent by the second node, and decrypting the public key ciphertext based on the second private key to obtain a third public key; generating the shared key based on a third public key and the first private key; wherein the third public key and the third private key are generated by the second node based on an asymmetric encryption algorithm. According to the invention, by combining an anti-quantum encryption algorithm and a widely used asymmetric encryption algorithm, a secure key exchange mechanism which can resist future quantum computing threats and has high compatibility is provided.
Owner:BEIJING HONGTENG INTELLIGENT TECH CO LTD

Data forwarding method and device, network equipment and SRv6 data forwarding system

The embodiment of the invention provides a data forwarding method and device, network equipment and an SRv6 data forwarding system, and relates to the technical field of IPv6 forwarding. The method comprises the following steps: a network device receives a shared key generated and issued by a controller based on network topology information of the SRv6 data forwarding system, encrypts a preset header field of an original message based on the shared key when the shared key is used as a source node of data forwarding, and forwards the encrypted message; when serving as an intermediate node for data forwarding, verifying and re-encrypting a preset header field of the received message based on the shared key, and forwarding; and when the received message is used as a destination node for data forwarding, the preset header field of the received message is verified and decrypted based on the shared key to obtain the original message, so that an attacker is prevented from obtaining path information through a plaintext, and network topology exposure is avoided.
Owner:MAIPU COMM TECH CO LTD

Halftone image reversible information hiding method, halftone image reversible information extraction method, equipment and medium

The invention discloses a halftone image reversible information hiding and extracting method and device and a medium, and relates to the field of image encryption, and the method comprises the steps: obtaining an original halftone image and original secret information; using a Hash algorithm to calculate summary information of the original halftone image; synthesizing the summary information with the original secret information to form to-be-hidden secret information, and storing the to-be-hidden secret information as a secret image; encrypting the original halftone image by using a ZUC encryption algorithm to obtain an encrypted halftone image; according to the encrypted halftone image, using a polynomial secret sharing algorithm to obtain N shared original images; according to the secret image, utilizing a polynomial secret sharing algorithm to obtain N shared secret images; and synthesizing the N shared original images and the N shared secret images to obtain N secret-carrying shared images. According to the method, the applicability, the confidentiality and the correctness of halftone image sharing are improved.
Owner:BEIJING INSTITUTE OF GRAPHIC COMMUNICATION

Personalization of a secure element

A method for personalizing an integrated secure element, which is permanently installed in a mobile end device. The method involves the agreement of a shared secret between the secure element and an HSM, encrypting an operating system, and possibly personalization data and / or one or several profiles, in the HSM based on the shared secret and transferring the encrypted operating system to the secure element, and re-encrypting the operating system in the secure element for storage in the NVM memory of the mobile end device.
Owner:GIESECKE DEVRIENT MOBILE SECURITY GERMANY GMBH

Method of generating shares of a shared secret

A computer-implemented method of generating shares of a shared secret, wherein each of a group of participants has a respective first secret share of the shared secret, wherein the method is performed by a first participant of the group and comprises: generating a respective blinding share of a shared blinding secret, obtaining at least a threshold number of respective intermediary shares from each of the first group of participants, wherein each respective intermediary share is generated based on a respective blinding share and a respective first secret share; generating an intermediary value based on each of the obtained intermediary shares; and generating a respective second secret share of the shared secret, wherein the respective second secret shared is generated based on the intermediary value and the respective blinding share.
Owner:NCHAIN LICENSING AG

Secure shell protocol traffic evidence obtaining and decryption method and system based on key injection

The invention belongs to the technical field of network security and communication, and provides a secure shell protocol flow evidence obtaining decryption method and system based on key injection, and the method comprises the steps: injecting a user-defined dynamic library into a service process, intercepting a key encryption function, and extracting a session key as a shared key when a secure shell protocol server runs; carrying out session identification on the encrypted traffic in the grabbed network, and completing the recombination of the IP fragment and the TCP fragment to obtain the recombined encrypted traffic; carrying out matching and integrity verification on the shared key and the recombined encrypted traffic, and then decrypting to generate a plaintext message; and analyzing the plaintext message into a structured operation record according to a channel type, and classifying and storing the structured operation record in combination with a timestamp, a session ID and a user identifier to form auditing evidence data. According to the method, system files do not need to be modified, complete decryption and behavior restoration of multiple types of sessions such as Shell, SCP and SFTP can be achieved, and the method is suitable for network security audit and judicial evidence obtaining scenes.
Owner:YUANBAO TECH

Access control using mediated location, attribute, policy, and purpose verification

An access control system is disclosed for controlling access to a resource. A request is received by a location attribute policy (LAP) server to access an encrypted resource. The LAP server accesses a resource policy that identifies requirements for granting access to the encrypted resource, such as a list of attributes of the requestor that are required and a dynamic attribute requirement of the requestor. The LAP server receives a cryptographic proof from the computing device that the requestor possesses the attributes and validates the proof based at least on information obtained from a trusted ledger. Once the proof is validated, the LAP server provides a shared secret associated with the dynamic attribute requirement to a decryption algorithm. The decryption algorithm uses the dynamic attribute shared secret in combination with one or more attribute shared secrets from the requestor to generate a decryption key for the encrypted resource.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Systems and methods using DNS tunneling for fast symmetric session encryption key establishment using a computing device

ActiveUS12457101B1Key distribution for secure communicationDomain nameConfidentiality protection
A method, system, and machine-readable recording medium for accelerated exchange and secure provisioning of symmetric session encryption-keys between systems by tunneling over the public Internet domain name service (DNS) to establish an encrypted communication session, a method referred to as DNS Fast Open (DFO), which improves on the speed of the prior-art by routing data more efficiently across the internet with fewer round trips, thereby reducing time, bandwidth and network computing resources, as well as improving security by utilizing shared-secret key-derivation keys to generate symmetric encryption-keys which may provide quantum-safe confidentiality protection to information in electronic communications, particularly for use in an e-commerce environment.
Owner:BENNISON JAMES E

Anti-quantum identity authentication and key encapsulation-based secure access method for Internet of Things

The invention provides an Internet of Things secure access method based on anti-quantum identity authentication and key encapsulation, and the method comprises the steps that a client side sends a first message to a server side, and the first message comprises a first ciphertext shared key and a first key parameter; the server performs an unsealing operation on the first ciphertext shared key based on the server private key to obtain a first shared key; performing key derivation operation on the first shared key to obtain a first session key; decrypting the first key parameter based on the first session key to obtain a second dynamic identity and a second static public key; the server generates a third static public key based on the second dynamic identity label; if the third static public key is matched with the second static public key, determining that anti-quantum identity authentication of the server is successful; and if the third static public key is not matched with the second static public key, determining that the anti-quantum identity authentication of the server fails. Through the technical scheme of the invention, the calculation burden of the authentication process can be reduced, and the method is suitable for resource-constrained equipment.
Owner:HANGZHOU HIKVISION DIGITAL TECHNOLOGY CO LTD

Secure communication protocol for communication devices

A method for transmitting secured Ethernet frames on a communication line, the method including the following in a transmitter module: receiving an Ethernet frame comprising payload data from a network layer; retrieving a secure policy, defining the type of security to be applied to the Ethernet frame; producing an initialization vector based on an encryption counter and a physical address of the transmitter module; creating an authentication tag by applying an authentication algorithm on the secure policy, the initialization vector and the payload data using a shared key and the initialization vector; adding the secure policy, the initialization vector and the authentication tag to the payload data to create a secured Ethernet frame; and sending the secured Ethernet frame to a data link layer for transmission on the communication line.
Owner:SCHNEIDER ELECTRIC IND SAS

Time-sensitive network end-to-end secure communication method

The invention relates to a time-sensitive network end-to-end secure communication method, and belongs to the technical field of communication. According to the method, a TSN terminal system of Linux is used for realizing bidirectional identity authentication and key agreement based on an SM2 cryptographic algorithm, and an SM4-CCM algorithm is used for realizing time-sensitive network security communication and data integrity verification; the SM2 national secret algorithm is an asymmetric encryption algorithm, a signature pair is generated based on an elliptic curve discrete logarithm problem, the two parties negotiate a shared key through elliptic curve point operation, a public key of a receiver is used for encryption, and only a private key can be used for decryption; sM4-CCM is a combination of an SM4 block cipher algorithm and a CCM mode, and is used for providing confidentiality, integrity and authenticity of data; according to the CCM mode, through combination of CTR encryption and CBC-MAC authentication, efficient authentication encryption is realized. The method can be used for real-time secure communication in a high-reliability industrial scene.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Sharing Keys for a Wireless Accessory

Embodiments described herein provide for a non-transitory machine-readable medium storing instructions to cause one or more processor to perform operations to share a set of keys used to communicate with a wireless accessory device. By sharing the set of keys, functionality of the wireless accessory device can be delegated by an owner to other individuals.
Owner:APPLE INC

BMS Bluetooth security communication method and system based on SM2 key negotiation

The invention discloses a BMS Bluetooth secure communication method and system based on SM2 key agreement, and the method comprises the following steps: constructing a BMS Bluetooth secure communication architecture composed of a battery analog front end (AFE), a low-power-consumption Bluetooth SOC and a secure coprocessor, and writing an SM2 static private key and a device ID in a secure storage unit; after a user terminal initiates a BLE connection request, a security coprocessor sends a wake-up instruction and generates a temporary SM2 private key dT, and then point multiplication operation is executed to generate a temporary public key PT; and sending to a user terminal through a BLE link, performing format analysis and elliptic curve equation verification, executing an SM2 key agreement protocol after confirming that the information is legal, calculating to obtain a shared key material Z, performing re-verification, and if the verification is effective, establishing an AES encryption communication link, monitoring abnormity, clearing sensitive information and performing whole-process closed-loop management on the dynamic session key K. According to the invention, the security and reliability of BMS Bluetooth communication can be improved.
Owner:HUIZHOU CHAOLIYUAN TECH CO LTD

Third-party quantum summation method with bidirectional identity authentication mechanism based on cluster state

The invention relates to the technical field of quantum security computing communication, and discloses a cluster state-based third-party quantum summation method with a bidirectional identity authentication mechanism, which comprises the following steps of: firstly, realizing bidirectional identity authentication between a participant and a third party in a quantum channel by pre-sharing secret identity information and a hash function in combination with a decoy photon technology; and impersonation and man-in-the-middle attack are fundamentally eradicated. And after the authentication is passed, the participant randomly executes measurement or reflection operation on the particle to which the participant belongs, so that an encrypted private key can be generated under the assistance of a third party, and external eavesdropping and internal participant attack can be jointly detected according to an operation combination to form multi-level security protection. Finally, the third party can only calculate the bitwise modular binary sum of the private bit string of each party, and cannot obtain any single input value. According to the method, authentication and calculation are organically fused, unconditional security is guaranteed, and meanwhile, the quantum capability requirements of participants are remarkably reduced.
Owner:SUZHOU UNIV

Method and device for post-quantum secure shared secret generation from zero trust

A method and system for generating a secure shared secret between a first device and a second device. The first / second device sends a public key and a public key certificate of the first / second device to the second / first device and receives a public key and a public key certificate of the second / first device from the second / first device, respectively. The first and second devices verify the public key certificate of the other device, respectively, and if the verification is successful, generate a ciphertext by encrypting its own secret with the public key of the other device, and send the ciphertext to the other device, respectively. The first and second devices decrypt the received ciphertext using its own private key and retrieve the secret of the other device. The first and second devices then generate a shared secret by combining its own secret with a secret of the other device.
Owner:INTEL CORP

Electric power communication data transmission method, system, equipment and medium

The invention discloses an electric power communication data transmission method, system, device and medium, which are applied to cloud equipment, and the method comprises the following steps: obtaining a first parameter set according to a preset credible strategy and a preset master key, and sending the first parameter set to an edge gateway; receiving a third parameter set sent by the edge gateway, and determining the legality of the edge gateway according to the third parameter set; if the edge gateway is illegal, determining that the edge gateway is illegal, and stopping data transmission; if yes, obtaining a first shared key pair according to the first parameter set and the third parameter set; and sending data to the edge gateway through the first shared key pair. According to the invention, the security of power communication data transmission can be improved.
Owner:CHINA SOUTHERN POWER GRID COMPANY

Ciphertext quantum key management and relay method and system

PendingCN122316607ACiphertextTrunking
This invention discloses a method and system for ciphertext quantum key management and relay. The method includes sending routing control information to relay nodes to relay quantum key ciphertext received from connected QKD devices to destination nodes according to the routing control information; sending first encryption information corresponding to each relay node on the relay path to the destination node, so that the destination node converts the XOR value of the quantum key ciphertext based on each of the first encryption information to obtain a first key ciphertext; the quantum key ciphertext is obtained by the QKD device encrypting its generated quantum key using a local key encryption key, the first encryption information carrying a first key encryption key that is the same as the key encryption key corresponding to each relay node, and the first key ciphertext being the ciphertext obtained by encrypting the shared key with the local key encryption key of the QKD device connected to the destination node; this invention can reduce the risk of quantum key leakage.
Owner:QUANTUMCTEK CO LTD +1

Data development, transmission, optimization and storage method based on big data processing

PendingCN122053053AKey distribution for secure communicationPathPingFinite state transducer
The invention discloses a data development, transmission and optimization storage method based on big data processing. The method comprises the following steps: acquiring original key data and processing the original key data to generate a state activation vector; constructing a full-state space structure of the finite-state transduction device; executing state observability cutting processing to obtain an observable state subspace; establishing a semantic mapping relation and determining a legal state transduction path sequence; executing data transmission processing on the target data according to the legal state transduction path sequence; recording a time slice identifier, a key derived fragment and a historical path access mark, and establishing a binding relationship; executing path uniqueness verification processing, judging a failure legal state transduction path sequence and stopping data transmission; and after failure, state observability cutting processing is executed again until the data closed-loop transmission process is completed. According to the method, a shared key driven finite state transduction method is adopted, rapid, safe and stable safe closed-loop transmission of data is realized, and the method has the advantages of unique path and dynamic encryption.
Owner:SHANDONG YUANCHANG GUANGHE INFORMATION TECHNOLOGY CO LTD

Third party based key exchange method, system and components thereof

The application provides a third-party-based key exchange method and system, a trusted third party and an entity, wherein the trusted third party only participates in identity authentication of the entity and assists in negotiation of a key between the two entities, and cannot obtain a shared key between the two entities, effectively solving the problem that the trusted third party cannot avoid obtaining the exchanged key in the existing key exchange scheme based on the trusted third party, and ensuring that the finally exchanged key is only owned by the two entities participating in the key exchange. In addition, in the application, the trusted third party can also provide a random number to participate in the final key generation, thereby ensuring the strength of the final key, meeting the requirement that the trusted third party needs to manage the strength of the exchanged key in a specific application scenario, and enhancing the management and control capability of the system.
Owner:QUANTUMCTEK CO LTD +1

Communication method, device and system, electronic equipment, computer readable storage medium and computer program product

The embodiment of the invention provides a communication method, device and system, electronic equipment, a computer readable storage medium and a computer program product. Relates to the communication field. The method comprises the following steps: performing an encrypted call with a second terminal according to a shared key with the second terminal; determining a first encryption result; a first request is sent to the first node, so that the first node sends a second request to the second node, the first encryption result is used for the second node to perform legal verification on the first terminal, a second encryption result is sent to a third terminal through the first node when the first terminal is verified to be legal, and the second encryption result is used for the third terminal to determine a shared key; the shared key is used for the third terminal to carry out encrypted communication with at least one of the first terminal and the second terminal. According to the invention, in the encrypted call between the first terminal and the second terminal, the secret key distributed to the third terminal by the second node is forwarded through the first node, so that secure communication is established between different terminals, and the security of transmission between the terminals is effectively ensured.
Owner:CHENGDU TD TECH LTD

Communication system, communication apparatus, method, and program

A communication system according to one embodiment is a communication system including a plurality of communication apparatuses, in which each communication apparatus includes: an application program configured to perform encrypted communication with another communication apparatus; a protocol conversion unit configured to transmit a message representing a predetermined procedure when a key request for a shared key to be used in the encrypted communication is received from the application program; a state management unit configured to receive a message from the protocol conversion unit to manage an execution state of the procedure, and to transmit the message to a protocol driver supporting a predetermined key sharing protocol; and a protocol driver configured to request a key sharing system that executes the key sharing protocol, to generate the shared key, when the message is received from the state management unit.
Owner:NT T INC