Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

60 results about "Side channel attack" patented technology

In computer security, a side-channel attack is any attack based on information gained from the implementation of a computer system, rather than weaknesses in the implemented algorithm itself (e.g. cryptanalysis and software bugs). Timing information, power consumption, electromagnetic leaks or even sound can provide an extra source of information, which can be exploited.

Control method of multi-protocol switching anti-quantum security gateway

The invention relates to a control method for a multi-protocol switching anti-quantum security gateway, and the method comprises the steps: carrying out the safety self-inspection of a hardware environment after the security gateway is powered on, generating a unique root key of equipment based on a physical unclonable function, continuously collecting and analyzing the network traffic characteristics, and carrying out the self-inspection of the hardware environment. Based on a machine learning model, a quantum attack mode is identified and an encryption algorithm mode is dynamically decided, protocol analysis is carried out on a communication data packet, dynamic conversion and adaptation are carried out between a traditional protocol and an anti-quantum cryptography protocol according to an instruction and a preset rule, and an anti-quantum cryptography engine is called to carry out encryption or signature operation. And dynamically deriving and managing a session key in a complete period based on a root key, switching an algorithm mode, a communication protocol and a key in a linkage manner according to a quantum attack detection result, and starting anti-side channel attack protection and hardware security response. According to the method, active protection of the security gateway on quantum attacks, multi-protocol seamless compatibility and full-life-cycle security management of keys are realized.
Owner:WEIDE GUANGDONG INFORMATION TECH CO LTD

Low-overhead processor cache micro-architecture defense method and device and computer equipment

PendingCN121561900APlatform integrity maintainanceSpeculative executionLoad instruction
The invention relates to a low-overhead processor cache micro-architecture defense method and device and computer device.The low-overhead processor cache micro-architecture defense method comprises the steps that when a missing state keeping register module takes out a loading instruction waiting for data from a replay queue, a target branch mask of the loading instruction is obtained; the replay queue is used for storing an instruction which is stagnated due to miss of the cache; judging whether the loading instruction is in a speculative execution state or not according to the target branch mask; and when the loading instruction is in the speculative execution state, stopping a cache write-in operation corresponding to the loading instruction. Through the method and the device, the problem of sensitive information leakage caused by incapability of defending against the cache side channel attack is solved, defending against the cache side channel attack is realized, and sensitive information leakage is prevented.
Owner:HANGZHOU HIGH-TECH ZONE (BINJIANG) INSTITUTE OF BLOCKCHAIN & DATA SECURITY +1

Binomial sampling circuit for side-channel attack resistance in post-quantum cryptography

The application discloses a binomial sampling circuit applied to post-quantum cryptographic algorithm and resisting side channel attacks, comprising a random number generation unit, a binomial sampling unit and a control logic unit; the random number generation unit is used for generating pseudo random numbers according to input data; the pseudo random numbers comprise true data and false data; the binomial sampling unit is used for synchronously performing binomial sampling on the true data and the false data; and the control logic unit is used for controlling the random number generation unit and the binomial sampling unit to operate according to external instructions. The binomial sampling circuit applied to post-quantum cryptographic algorithm and resisting side channel attacks disclosed by the application increases the difficulty of analysis of attackers by generating pseudo random numbers, synchronously samples the true data and the false data to interfere with the attackers, and jointly realizes the protection against side channel attacks, thereby effectively improving the security of a Kyber cryptographic system and reducing the risk of being attacked by side channels.
Owner:HUAZHONG UNIV OF SCI & TECH +1

A private AI model calling method and system based on encrypted data interaction

The application belongs to the technical field of artificial intelligence, and particularly relates to a private AI model calling method and system based on encrypted data interaction, which comprises the following steps: S1, a client generates a series of structured random numbers through a key derivation function based on a main random number seed and each dimension index, encrypts an original input vector into an initial ciphertext vector by using a partial homomorphism encryption public key and the structured random numbers, generates a conditional re-encoding key pair for nonlinear calculation in the AI model, and sends a re-encoding public key to a server. The application can eliminate the confusion ciphertext, so that the server side constructs a quasi-gradient noise based on the intermediate state of the calculation process and injects the result, resisting side channel attacks on the output ciphertext; and the client can reconstruct and remove the noise, so that the lossless calling result is obtained without sacrificing any calculation accuracy, and end-to-end privacy protection of the whole model reasoning process is realized.
Owner:XIAN MINGFU CLOUD COMPUTING CO LTD

Satellite-borne safe intelligent computing system

A satellite-borne safety intelligent computing system is used for guaranteeing safety of a satellite edge computing system and comprises a host processor, an AI accelerator and a safety bus connected with the host processor and the accelerator. The satellite-borne safe intelligent computing system further comprises a bus stream encoding and decoding engine which is embedded in the interface controller of the data bus and used for encrypting and decrypting transmission data of the data bus. By encrypting the cache stream on the data bus, key data such as Bias bias cache and the like can be protected. In addition, an attacker can be prevented from stealing structural information of the neural network model through interrupt signals by interrupting obfuscated codes, dual protection of'signal + data 'is formed, and time sequence detection Trojan horse and side channel attacks can be effectively resisted.
Owner:BEIJING BLUE TOWER OPTICAL TRANSMISSION INTELLIGENT TECHNOLOGY CO LTD

Physical-level anti-quantum key packaging device and method

The invention discloses a physical-level anti-quantum key packaging device and method, and the method comprises the steps: cutting off a byte stream to a first modulus through a bit mask operation, and generating a polynomial matrix in a constant physical clock period; calculating an inner product of a private key vector of the polynomial matrix, executing logic combination operation, compressing modulus, and generating a public key vector; after receiving the public key vector, the second communication node reconstructs a system state by using the temporary private key and outputs a ciphertext; and the first communication node receives the ciphertext, performs fault-tolerant restoration and re-encryption, drives a bottom multiplexer to generate a mask, and selects one of a real session key and a random noise key to be output in a constant physical clock period. According to the anti-quantum cryptography algorithm, logic combination operation, algebraic divide-and-conquer and physical circuit characteristics are utilized, hardware simplification is achieved, meanwhile, safety is improved, strategic expansion capacity is achieved, and the problems that an existing anti-quantum cryptography algorithm faces the computing power bottleneck and the side channel attack risk in a low-power-consumption node lacking a hardware divider circuit are solved.
Owner:SUZHOU LANGKONGHOU QUANTUM TECHNOLOGY CO LTD

Training method and device of side channel attack identification model, and prediction method and device

This specification provides a method and apparatus for training a side-channel attack identification model, as well as a method and apparatus for predicting side-channel attacks. In this method, a device is deployed as a simulated target device, and a side-channel information acquisition device is deployed within a predetermined distance range outside the device. The side-channel information acquisition device collects side-channel information generated during device operation; it collects first side-channel information generated when the device is running but the acquisition device is not running; it collects second side-channel information generated when both the device and the acquisition device are running. Using the first and second side-channel information, a side-channel attack identification model is trained. This model is then used to predict side-channel attacks. This specification's embodiments can more accurately predict whether a side-channel attack has occurred against a device.
Owner:ALIPAY (HANGZHOU) INFORMATION TECH CO LTD

Encryption chip random mask generation system and method for preventing side channel attack

The invention discloses an encryption chip random mask generation system and method for preventing side channel attacks, and belongs to the technical field of encryption chip information security protection. Comprising an encryption operation unit, a mask generation unit, an FPGA real-time power consumption anomaly detection unit, an attack risk level identification unit, a mask order adjustment unit and an anti-shake stabilization unit. The FPGA real-time power consumption anomaly detection unit collects and filters power consumption trajectory data, the attack risk level identification unit judges the attack risk level accordingly, the mask order adjustment unit dynamically adjusts the mask order according to the risk level, the anti-shake stabilization unit avoids timing sequence disorder caused by frequent order switching, and encryption operation is not interrupted in the adjustment process. According to the method, the dynamic adaptation of the mask order is realized, the security protection and the chip performance are balanced, the continuity and the stability of the encryption operation are ensured, and the side channel attack resistance of the encryption chip is effectively improved.
Owner:SHENZHEN BOSSTON TECHNOLOGY CO LTD

A method and apparatus for generating random clock against side channel attack

ActiveCN117010033BRandom number generatorsCounting chain synchronous pulse countersAlgorithmParallel computing
The application relates to a random clock generation method and device against side channel attacks, wherein the method comprises the following steps: S1, selecting a reference clock as an input clock of a first round of multi-path frequency multiplication to obtain frequency multiplication clocks with different frequency multiplication coefficients; S2, randomly selecting a frequency multiplication clock from the frequency multiplication clocks, performing spur filtering, and then outputting the frequency multiplication clock as a system clock; S3, performing multi-path frequency division on the randomly selected frequency multiplication clock to obtain frequency division clocks with different frequency division coefficients; S4, randomly selecting a frequency division clock from the frequency division clocks, and performing multi-path frequency multiplication on the frequency division clock as an input clock of a next round of multi-path frequency multiplication to obtain frequency multiplication clocks with different frequency multiplication coefficients; and S5, repeating steps S2 to S4, and obtaining a system clock with various and random frequencies through multiple rounds of iteration. The application effectively improves the side channel attack protection effect.
Owner:XINGTANG TELECOMM TECH CO LTD +2

Digital management method and device based on intelligent door lock

The invention relates to the field of smart home, in particular to a digital management method and device based on an intelligent door lock, and the method comprises the following steps: constructing a multi-modal biological behavior identity identifier of a user, and generating a one-time dynamic token bound with a context for a temporary user based on the identifier; dynamic arbitration is carried out on multi-person concurrent requests according to real-time risk scores; for the suspected false triggering behavior, starting non-inductive authentication based on a behavior mode to complete secondary verification; after the user passes the initial authentication and before the operation is executed, continuous behavior monitoring is carried out, and the process is immediately interrupted once the identity is recognized or the behavior is abnormal; when the main verification fails, a request is initiated to a preset collaborative verification node, and auxiliary verification is completed through a distributed voting mechanism; when the control instruction is executed, random cryptographic delay is injected to resist side channel attacks, and graph calculation is carried out on the temporary permission to analyze the associated risk of the temporary permission.
Owner:HANGZHOU QIANTANG WASU DIGITAL TV CO LTD

Network based side channel attack (SCA) detection

Some embodiments include a method for detecting and interrupting a cache-based side-channel attack. The method includes: (1) at least calibrating one or more chiplets of a network by calculating a threshold; (2) determining one or more device heartbeat vectors of the one or more chiplets, the one or more device heartbeat vectors being derived at least part from one or more measurements of activity of one of more dedicated security processors associated with the one or more chiplets; (3) determining that a particular chiplet of the one or more chiplets is being attacked with a cache-based side-channel attack, the determining being based at least in part on a computed disparity exceeding the threshold; and (4) employing countermeasures against the cache-based side-channel attack of the particular chiplet, the countermeasures including revoking one or more access rights of the particular chiplet on the network.
Owner:CEREMORPHIC INC

A secret key signature method against side channel attacks

PendingCN122372215AKey (cryptography)Attack
This invention relates to a commercial cryptographic signature method resistant to side-channel attacks, comprising the following steps: Step 1: Network configuration initialization: Key generation and transaction signing in the system both occur within a designated network; Step 2: Private key conversion and public key generation: Incoming data is converted to an integer using the private key sk and a private key sk object is constructed. The corresponding public key is derived based on elliptic curve cryptography rules; Step 3: Public key and address generation: A hash operation is performed on the public key to generate a public key hash value. Combined with the address format generated by the version, a locking script is constructed based on the public key hash; Step 4: Noise injection operation: A delayed random noise is added during the commercial signature process. By injecting random noise into the signature algorithm, side-channel information is disrupted, preventing attackers from inferring the user's secret data based on the time information leaked during the transaction process, thus improving the system's ability to resist side-channel attacks.
Owner:GUIZHOU WUJIANG HYDROPOWER DEV

Ocean location privacy protection task offloading method based on improved laplace mechanism

ActiveCN121665226BEffectively resist collusive inference attacksDefend against collusive inference attacksNetwork traffic/resource managementSecurity arrangementPrivacy protectionBuoy
The application discloses a marine position privacy protection task offloading method based on an improved Laplace mechanism. First, a system model considering the collusion threat of multiple buoy servers is constructed, the feasible angle interval is determined in combination with the buoy coverage range and the transmission power constraint, and the user pseudo position with geographical indistinguishability is generated in the constraint area by using the clipping Laplace mechanism. Secondly, under the condition of the virtual channel corresponding to the pseudo position, the weighted sum of offloading energy consumption and delay is modeled as a discrete optimization problem, and the grey wolf optimization algorithm is used to realize the task offloading decision. Finally, through a power control-based offshore received signal strength simulation method, the signal strength received by the buoy server is consistent with the user pseudo position. The application can effectively reduce the position privacy leakage risk in the task offloading process under the multi-side channel attack scene, and realize safe and reliable marine task offloading.
Owner:NANJING UNIV

Terminal information security protection system and method

The invention discloses a terminal information security protection system and method, and relates to the technical field of information security. The encryption round number is dynamically determined through terminal hardware state data and to-be-protected data attributes, and self-adaptive matching of encryption strength and terminal resources is achieved; generating an initial key and a secret parameter according to the key material, and driving key expansion and encryption structure configuration through the secret parameter to obtain a key matched with the size of the data block; and performing multi-round encryption on the data by adopting a preset encryption strategy, and adding the meta-information to a ciphertext header for verification and decryption. The dynamic nature and the unpredictability of the secret key and the encryption structure are enhanced while light weight is guaranteed, the resistance to differential analysis, linear analysis and side channel attacks is effectively improved, and the reliability and the practicability of terminal information security protection are improved.
Owner:STATE NUCLEAR POWER NETWORK SECURITY TECHNOLOGY (SHANGHAI) CO LTD

Cross-device modeling side channel attack monitoring system and method based on adversarial learning

The invention discloses a cross-equipment modeling side channel attack monitoring system and method based on adversarial learning, and relates to the technical field of information security, and the method comprises the steps: labeling curve data of modeling equipment; pre-training the curve feature extraction model by using the labeled curve data of the modeling equipment to obtain a preliminary curve feature extraction model; constructing an adversarial training framework, and performing iterative training by taking the labeled curve of the modeling equipment and the unlabeled curve of the target equipment as input; the discriminator judges the source of the equipment by taking the feature vector and the output of the classifier as conditions; jointly optimizing parameters of the encoder and the classifier, and learning feature representation with unchanged equipment; monitoring the relative distance or overlapping degree of the feature distribution of the modeling equipment and the target equipment in the hidden space in real time; when the relative distance or the overlapping degree tends to be stable and exceeds a preset threshold value, determining that the curve feature extraction model is converged; and analyzing the attack curve of the target equipment by using the curve feature extraction model.
Owner:SHANGHAI JIAOTONG UNIV

Ocean position privacy protection task unloading method based on improved Laplacian mechanism

The invention discloses an ocean position privacy protection task unloading method based on an improved Laplacian mechanism. The method comprises the following steps: firstly, constructing a system model considering a multi-buoy server serial threat, determining a feasible angle interval by combining a buoy coverage range and a transmitting power constraint, and generating a user pseudo position with geographically indistinguishable property in the constraint area by using a cutting Laplacian mechanism; and secondly, under the condition of a virtual channel corresponding to the pseudo position, modeling the weighted sum minimization of unloading energy consumption and time delay as a discrete optimization problem, and realizing a task unloading decision by using a grey wolf optimization algorithm. And finally, enabling the signal intensity received by the buoy server to be consistent with the pseudo position of the user through an offshore received signal intensity simulation method based on power control. According to the method, the location privacy leakage risk in the task unloading process can be effectively reduced in a multi-side channel attack scene, and safe and reliable ocean task unloading is realized.
Owner:NANJING UNIV

PCIe-based hardware acceleration AES remote dynamic encryption method and system

The invention relates to the field of encryption processing, and provides a PCIe-based hardware acceleration AES remote dynamic encryption method and system. The method comprises the following steps: generating an initial encryption key, and transmitting the initial encryption key to a local host to obtain local key data; sending the to-be-encrypted data to the FPGA hardware module, and performing encryption processing on the to-be-encrypted data through a pipeline to obtain encrypted output data; during encryption processing, receiving updated key information through the double-buffer key storage structure, and switching keys through the updated key information to obtain dynamically updated encryption configuration; performing randomized adjustment on the time sequence characteristics and the power consumption characteristics in the pipeline encryption processing process to generate an encryption execution environment; and performing encryption processing on the encrypted output data based on the encryption execution environment and the dynamic update encryption configuration to obtain final output data. On-line dynamic updating of the secret key is achieved through a double-buffering secret key storage structure, the PCIe bus bandwidth is fully utilized in combination with a full-assembly-line encryption architecture, and side channel attacks are effectively resisted through random delay insertion and a power consumption balancing mechanism.
Owner:TIANJIN JINHANG COMP TECH RES INST

A side channel black box attack method, device, equipment and storage medium

The application discloses a side channel black box attack method, device and equipment and a storage medium. Side channel information is collected according to a preset first collection scheme, a feature selection model is used to determine feature points of side channel leakage, and a feature vector is generated according to the determined feature points. Training data is collected according to a preset second collection scheme, the training data is cropped according to the feature vector to obtain a training data set, and labels are marked for the training data set. A deep learning model is trained according to the training data set with the marked labels to generate an attack model. Data is collected according to a preset third collection scheme, and an attack data set is generated by cutting according to the feature vector. The attack data set is input into the attack model to generate a probability vector of a key, and a side channel black box attack is completed by taking the key with the highest score as an attack key. Compared with the prior art, the universality of side channel attacks is realized, and the efficiency of side channel attacks is improved.
Owner:GUANGDONG POLYTECHNIC NORMAL UNIV

Encryption and decryption method and device, equipment, medium, program product and chip

The invention relates to an encryption and decryption method and device, equipment, a medium, a program product and a chip, and the encryption and decryption method comprises the steps: operating a first preset algorithm and a second preset algorithm to execute an encryption process or a decryption process, and determining target output information. Through the design of the first preset algorithm and the second preset algorithm, the first operation of the first preset algorithm and the second operation of the second preset algorithm are in one-to-one correspondence with the second operation of the second preset algorithm and the first operation of the second preset algorithm within the preset time range of the running state of the first preset algorithm and the second preset algorithm. Therefore, the overall power consumption at each moment in the preset time range is the sum of the power consumption of the first operation and the power consumption of the second operation, efficient defense against side channel attacks and error injection attacks is achieved in a mode of controlling the power consumption to be constant, and the safety and stability are further improved. And the method has the characteristics of simplicity in implementation, low optimization cost, high universality and the like.
Owner:BEIJING X RING TECHNOLOGY CO LTD

Data contract strategy trusted execution and traceability system and method

The invention discloses a data contract strategy credible execution and traceability system and method, and relates to the technical field of computer information security and cryptography application, and the method comprises the following steps: strategy formalized compiling and circuit generation, key generation and security initialization, verifiable execution and proof generation, and differential privacy watermark generation and injection. Safe destruction and result return; the digital policy trusted execution and traceability system comprises a policy compiling module, a key management module, a verifiable calculation engine, a differential privacy watermark module, a security sandbox and destruction module and an audit traceability module. According to the method, the dependence on a specific hardware architecture is replaced by a cryptographic algorithm and a formalized verification method, so that the side channel attack risk, high cost and compatibility limitation existing in a hardware scheme are effectively overcome, and the deployment and operation and maintenance threshold of a trusted computing environment is remarkably reduced; and a universal trusted infrastructure is provided for a large-scale data circulation scene.
Owner:山东腾安信息科技有限公司

Method, device and equipment for resisting industrial network attack and computer storage medium

The embodiment of the invention provides a method, device and equipment for resisting industrial network attacks and a computer storage medium. The method for defending the industrial network attack comprises the following steps: acquiring communication data packet information, network state information and side channel signals of an industrial network; according to the communication data packet information, a malicious data packet and signal-to-noise ratio information are obtained; inputting the side channel signal into an autoregression integral moving average model, and determining the attack protection capability of the side channel; determining a side channel attack defense strategy according to the malicious data packet, the signal-to-noise ratio information and the side channel attack defense capability; constructing a network state model based on the network state information, and inputting the network state model into a service attack denial model to obtain a service attack denial strategy; and deploying the side channel attack defense strategy and the service attack denial strategy to the industrial firewall so as to defend the industrial network attack. According to the invention, the comprehensiveness of industrial network attack resistance of the industrial network can be improved, and the application range is widened.
Owner:CHINA MOBILE GRP GUANGDONG CO LTD +3

Fault detection method and system for cryptographic chip

The invention belongs to the technical field of integrated circuit design and information security, and particularly relates to a fault detection method and system for a cryptographic chip. The fault detection method for the cryptographic chip comprises the following steps: when the cryptographic chip runs a cryptographic algorithm, injecting a preset test vector into input data of algorithm logic; obtaining an actual output result of the algorithm logic corresponding to the test vector; comparing the actual output result with a pre-calculated expected output result under a fault-free condition; and judging whether the password chip has a fault or not according to a comparison result. The invention also correspondingly provides a system for realizing the method. According to the method, the test vector is actively injected and the output result is compared, so that the calculation error of the cryptographic chip caused by hardware faults, side channel attacks or natural aging and the like can be effectively detected, and the method has the advantages of high detection real-time performance, low hardware overhead, high universality and the like.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

Method for securing modular exponentiation or point multiplication operations against side-channel attacks

The present invention relates to a method for securing against side channel attacks an execution of a cryptographic process comprising either: - an elliptic curve scalar multiplication operation of a secret key k with a first point P of an elliptic curve, thereby computing a scalar multiplication operation result Q = k.P, with k a scalar, or - a modular exponentiation operation of a base P, which is a first positive integer number, with a secret key k, k being an integer, computing a modular exponentiation operation result Q = Pk mod m. The main idea of the invention is to store pre-computed results of an ECC scalar multiplication Si=si.P or of an exponentiation Si= Psi mod m and then, for computing a target result of a scalar multiplication k.P or of an exponentiation Pk mod m, to compute the difference between the target result and a pre-computed result (k-s).P or Pk-s. The target result can then be easily obtained by combining the pre-computed result and the computed difference.
Owner:THALES DIS FRANCE SA

Deep neural network learning based tools for embedded systems under side channel attacks

Disclosed is a method for detecting a side-channel attack (SCA) of an electronic target device, which method includes the steps of:a remote sensing EM radiations emanating from the target device;comparing the EM radiations with base line radiations; andidentifying anomalies in said EM radiation.
Owner:BLACK FUR IND LLC

Method for protecting against side-channel attacks lattice-based post quantum cryptographic schemes

The present invention relates to a method for securing against side channel attacks execution of a Compress function designed to be used in a decapsulation algorithm of a Kyber Lattice-based Post Quantum cryptographic key-encapsulation mechanism, wherein said Compress function converts an input polynomial P(X) into an output polynomial B(X) such that each coefficient bi of the output polynomial B(x) equals 1 if the corresponding coefficient Pi of the input polynomial P(X) is in ](q-1) / 4, 3(q-1) / 4[ and bi equals 0 otherwise, with i in {1,..,n}, n being an integer and q being a prime number, each coefficient Pi of said input polynomial P(x) being masked using an arithmetic splitting masking and represented by L arithmetic shares Ai1, Ai2, …,AiL such that Ai1+ Ai2+ …+ AiL = Pi modulo q, with L an integer, and each coefficient bi of said output polynomial B(X) being masked with a Boolean splitting masking and represented by a plurality of Boolean shares, said method being performed by the key requesting device comprising a processor and a memory and comprising, instead of applying Compress function to said input polynomial P[X], for each coefficient Pi of said input polynomial P(X): - obtaining said L polynomial shares A1i, A2i, …, ALi of said coefficient Pi, - for each polynomial share Aji with j in {1,…,L}, computing an intermediate share vji equal to 0 when floor([2Aji+ Zj.(q-1) / 2] / q ) is even and equal to 1 when it is odd with Zj such that Z1 + Z2 + …+ ZL = 1 and Zj.(q-1) / 2 is an integer, - computing an additional intermediate share vL+1i equal to 0 when floor([ Σ j (2 Aji + Zj.(q-1) / 2) mod q)] / q) is even and equal to 1 when it is odd, - obtaining said plurality of Boolean shares (b1i, b2i,…,bLi) from said L computed intermediate shares (v1i, …, vLi) and said computed additional intermediate share (vL+1i).
Owner:THALES DIS FRANCE SA

Identity authentication method and device, computer equipment and storage medium

The invention provides an identity authentication method and device, computer equipment and a storage medium, and belongs to the technical field of security protection, the method is applied to an NFC card integrated with a fingerprint recognition function, and the method comprises a registration stage and an authentication stage: the registration stage collects a fingerprint image of a user, extracts a fingerprint feature vector and generates a pseudo-random key and auxiliary data; further forming a registered ciphertext hash value; storing the preset original text, the registered ciphertext hash value and the auxiliary data in a card security storage unit; in the authentication stage, a user fingerprint image is collected in real time, a real-time fingerprint feature vector is extracted, a temporary authentication key is reconstructed in combination with stored auxiliary data, and then an authentication ciphertext hash value is generated; comparing the authentication ciphertext hash value with a stored registration ciphertext hash value; if the two are consistent, the fingerprint authentication is passed, and NFC communication is allowed; if not, the authentication fails, and the card is kept silent. Therefore, the hidden danger of information leakage under the side channel attack can be effectively solved.
Owner:CHINA UNIV OF MINING & TECH

Multi-party secure communication method and device based on key negotiation, equipment and medium

The invention discloses a multi-party security communication method, device and equipment based on key agreement and a medium, and relates to the technical field of network security communication, and the method comprises the steps: reconstructing a private key of a sender based on a root key generated by an SRAM PUF (Static Random Access Memory Physical Unclonable Function); generating a first curve, a second curve, a first target point and a second target point by using an SIKE algorithm; performing homologous calculation by using a Montgomery ladder algorithm based on the first target point and the reconstructed private key to obtain a first target kernel; generating a first homologous mapping starting from the starting point to the first curve by using the reconstructed private key and based on the first target kernel; generating a first generation point starting from the second target point based on the first homologous mapping, and generating a public key based on the first generation point and the first curve; sending the public key to a receiving end to generate a packaged ciphertext; and recovering the shared key by using the encapsulated ciphertext so as to carry out encrypted communication. According to the invention, various types of side channel attacks can be resisted, the risk of key leakage is avoided, and the security of multi-party communication is guaranteed.
Owner:CCORE TECH CO LTD

A quantum secure direct communication method based on passive encoding

The application discloses a quantum secure direct communication method based on passive coding. An information receiver uses two phase random coherent pulses to generate weak coherent pulses in different quantum states through CPBS beam combination and BS attenuation. The information receiver inputs the state of one port output of the BS into a PBS, measures the light intensity ratio of two output ports of the PBS, obtains the state information of the pulse output from the other port of the BS, and sends the state to be sent to an information sender according to the information. The information sender sends the photon pulse back to the information receiver after coding. The information receiver decodes the information sent by the information sender according to the initial pulse information sent by the information receiver. The method does not need to actively modulate the initial quantum state of the light source, realizes passive coding, simplifies the experimental operation, resists side channel attacks of a third-party eavesdropper on the light source modulator, and enhances the communication security.
Owner:NANJING UNIV OF POSTS & TELECOMM

Certificate network integration AI architecture security scheduling system based on trusted computing

The invention relates to the field of intelligent scheduling, and particularly discloses a trusted computing-based computing network integration AI architecture security scheduling system, which is characterized in that firstly, by acquiring network topology, node telemetering and link probe data in real time, vectorization integration is carried out on node static credibility and link dynamic stability (such as time delay and jitter) of a physical side; constructing a global resource attribute graph; meanwhile, a directed acyclic graph of an AI task is analyzed based on a data flow definition, interaction frequency and sensitivity characteristics between subtasks are extracted, and a weighted task interaction graph is generated. On the basis, the system quantifies the matching cost between task requirements and bottom layer resource attributes by constructing a scheduling cost matrix, and solves an optimal mapping scheduling scheme by utilizing an algorithm based on subgraph isomorphism, so that the session timeout or side channel attack risk caused by network jitter is avoided; and the endogenous safety of the whole life cycle of the distributed AI task is ensured.
Owner:STATE GRID HENAN INFORMATION & TELECOMM CO