Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

45 results about "Static key" patented technology

A cryptographic key is called static if it is intended for use for a relatively long period of time and is typically intended for use in many instances of a cryptographic key establishment scheme. Contrast with an ephemeral key.

Computer network data secure transmission system and method

The invention discloses a computer network data secure transmission system and method, and particularly relates to the technical field of network data secure transmission, and the system comprises a dynamic key management module which generates a key seed through a quantum random number generator, generates a dynamic key bound with a data packet in combination with a timestamp, and transmits the dynamic key to a server; after being encrypted by a receiving end public key, the data are transmitted through an independent verification channel; the dual-path transmission control module is used for establishing dual channels of a main path and a shadow path, a data packet of the main path is embedded into a random camouflage protocol header to simulate a non-sensitive protocol, and a blank data packet is filled in the shadow path to maintain traffic characteristics; according to the real-time verification engine, a receiving end constructs an encrypted hash tree to achieve fragment-level integrity verification, and meanwhile, requests key state three-state verification from the key management module. Through key dynamic generation and separation transmission, dual-path adaptive fragmentation distribution, fragmentation hash tree reconstruction and key linkage verification, and abnormal triggering fragmentation level retransmission, the problems of long-term effectiveness of a static key, predictable transmission path and verification lag are solved.
Owner:陈俊奕

Multistage video watermark embedding and extracting method and system

The invention discloses a multistage video watermark embedding and extracting method and system, and the method comprises the steps: carrying out the perception analysis of an original video through a space-time attention neural network, and dynamically dividing a time domain stable region and a space domain sensitive region; a three-level watermark system is constructed, the three-level watermark system comprises a basic-level watermark, a first-level enhanced watermark and a second-level enhanced watermark, the basic-level watermark adopts an anti-rotation binary matrix generated by a Fourier descriptor, the first-level enhanced watermark is a DCT frequency domain Hash sequence, and the second-level enhanced watermark is a semantic fingerprint generated based on a motion vector. According to the method, through multi-dimensional collaborative optimization of the anti-attack capability, the dynamic security mechanism and the verification efficiency, the core defects that erasing is easy due to insufficient reversibility in a traditional video watermarking technology and counterfeit affiliation chaos is caused by a static key are overcome, and reliable technical guarantee is provided for digital content copyright protection.
Owner:CHINESE PEOPLES LIBERATION ARMY NAVAL ACAD

Data encryption method, encryption equipment and storage medium

The invention relates to the technical field of data encryption, and discloses a data encryption method, encryption equipment and a storage medium. In the method, an encryption device obtains to-be-encrypted data uploaded by a terminal, and extracts a plurality of data features from the to-be-encrypted data, the data features including a data sensitive feature, a business risk feature and a user behavior feature; performing quantitative scoring on the plurality of data features to obtain a plurality of feature scores, and calculating a total data score according to the plurality of feature scores; inputting the total data score into a preset trained decision tree model to determine the security level of the to-be-encrypted data; according to the security level, determining a target encryption algorithm from a preset corresponding relationship between the security level and the encryption algorithm; and encrypting the to-be-encrypted data according to the target encryption algorithm and the dynamically generated encryption key. By means of the method, the problems that differential protection is difficult to achieve according to data characteristics in a related encryption method, and security risks are caused by key management staticization are solved.
Owner:SHANGHAI TELECOMM ENG

Data security protection method for power transaction

The invention relates to the field of power transaction security, in particular to a data security protection method for power transaction. Comprising the following steps: a registration authentication stage: completing identity registration through triple authentication of a physical token, biological feature recognition and a dynamic password and GPS positioning white list verification; in the key initialization stage, an SM2 asymmetric key pair and an SM4 symmetric communication key are dynamically generated according to a transaction time window and main body attributes, and are issued through a point-to-point encryption channel and updated in time; in the data encryption and binding stage, a transaction instruction is encrypted, signed and subjected to double-layer integrity verification; a matching and on-chain registration stage: executing matching after verifying the signature, encrypting a result, writing the result into the block chain, and generating a zero-knowledge proof; and in the settlement and supervision stage, settlement or alarm responsibility investigation is started after decryption verification. According to the invention, the problems of single identity authentication, static key, easy data tampering and the like in the prior art are solved, full-flow security protection of power transaction is realized, and data confidentiality, integrity and traceability are improved.
Owner:SHANDONG ENERGY POWER SALES CO LTD

AI-based satellite communication encryption strategy dynamic optimization method and system

The invention relates to an AI-based satellite communication encryption strategy dynamic optimization method and system. According to the method, a space-time network model is constructed by collecting dynamic topological data of satellite multicast members, a member connection behavior is predicted by using a space-time diagram convolutional network and a probability matrix is generated, and the multicast key tree structure depth and a key distribution path are dynamically optimized based on a prediction result. Self-adaptive switching of a post-quantum cryptographic algorithm is realized in combination with quantum attack threat assessment, model parameters are continuously adjusted and optimized through a closed-loop verification mechanism, and finally collaborative improvement of key updating efficiency and security protection capability is realized in a satellite communication high-dynamic environment, so that key reconstruction delay and signaling overhead are remarkably reduced, and the security protection capability is improved. Meanwhile, quantum computing attack resistance and cross-protocol-layer cooperative protection capability are enhanced, and the problem of insufficient adaptability of a traditional static key management scheme in a dynamic topology scene is effectively solved.
Owner:SHANDONG STAR NETWORK GAOFEN DATA IND CO LTD

Scroll compressor cross ring stress detection system and method

The invention provides a scroll compressor cross ring dynamic strain wireless measuring device, which relates to the technical field of compressor state monitoring and comprises a high-temperature-resistant strain gauge, a wire fixing system and a wireless sensor. Wherein the high-temperature-resistant strain gauges are respectively attached to stress sensitive areas of a static key, a ring beam and a movable key of the cross ring every time; the wire fixing system comprises a three-stage fixing structure formed by an adhesive, an internal wire, an external wire and an internal binding post; the three stages of fixing structures are a strain gauge end fixing structure, a lead transition section fixing structure and a binding post end fixing structure in sequence; the high-temperature-resistant strain gauge is connected with the wireless sensor through an internal wire, a binding post and an external wire, and continuous signal collection is achieved. By implementing operation according to the technical route, the impact load borne by the cross ring at the moment of starting and stopping of the compressor can be collected in a high-quality mode, data collection in a closed cavity is achieved, and an experimental basis is provided for subsequent strength design of the cross ring.
Owner:DALIAN SANYO COMPRESSOR

Solid state disk controller circuit and solid state disk

The invention relates to the technical field of electric digital data processing, and discloses a solid state disk controller circuit and a solid state disk. The controller circuit comprises a physical unclonable function unit based on an SRAM (Static Random Access Memory), which is used for dynamically generating a stable hardware trust root key during power-on; the secure boot and firmware decryption engine is used for deriving a firmware decryption authentication key and a data key packaging key by using the key, and carrying out decryption and integrity verification on the encrypted firmware; the runtime firmware execution monitoring unit is used for detecting illegal jump in real time and triggering safe shutdown through a hardware-level control flow diagram; and the dynamic data encryption key management unit recovers the plaintext data key and sends the plaintext data key to the encryption engine only during operation, and power failure disappears. By means of the scheme, end-to-end security protection of firmware and data is achieved, and the risks of static key leakage and firmware tampering are eradicated.
Owner:深圳市彦胜科技有限公司

Secure data transmission system based on dynamic encryption authentication

According to the secure data transmission system based on dynamic encryption authentication provided by the invention, a trust root which cannot be tampered is established for the whole system through the hardware password module, and continuous derivation and rotation of a session key are realized by the dynamic key management module on the basis, so that the security risk caused by long-term use of a static key is effectively solved. And the secure communication gateway module executes bidirectional authentication and anti-hijacking challenge response by using a dynamic key, so that the real-time credibility and session continuity of the communication process are ensured. And the strategy control engine uniformly coordinates the behaviors of key management and the communication gateway by receiving and compiling the declarative strategy, so that flexible deployment and centralized management and control of the security strategy are realized. According to the system, a cryptographic basis, a dynamic strategy, real-time monitoring and automatic response are deeply fused, a self-adaptive and automatic deep defense system with the capability of continuously resisting advanced threats is constructed, and the overall safety level and the operation efficiency of data transmission are remarkably improved.
Owner:HUANENG INFORMATION TECH CO LTD

Low-power-consumption radio frequency encryption communication system

The invention, which relates to the technical field of network security, discloses a low-power-consumption radio frequency encryption communication system comprising a front-end data acquisition module which communicates with a plurality of data acquisition terminals through a central gateway; the encryption channel establishment module quickly verifies the legality of the data acquisition terminal and the central gateway, dynamically generates a one-time shared session key as an encryption key, and optimizes an AES algorithm to perform encryption transmission on a plaintext data block; and the back-end result output module processes the decrypted transmission data and outputs a result according to a service demand. Through four-stage fusion of identity authentication, physical layer secret key, optimization encryption and data processing, the channel encryption problem is solved, a full-process security closed loop from physical world information collection to digital world application output is constructed, a session key is generated by using the physical characteristics of a wireless channel, and the security of the session key is improved. Each communication key is unique and unpredictable, the traditional static key reuse risk is thoroughly solved, and forward security is achieved.
Owner:SHENZHEN DECARD SMART CARD TECH

Vehicle-mounted dynamic key management and verification method, device, equipment and medium

The invention discloses a vehicle-mounted dynamic key management and verification method and device, equipment and a medium, and relates to the technical field of computer networks. In response to an encryption request for target firmware in a target vehicle, acquiring firmware information of the target firmware issued by the cloud; the firmware information comprises an identification code of a target vehicle and a firmware version number of the target firmware; performing slicing processing on the target firmware to obtain at least one firmware slice in the target firmware; generating a firmware key tree corresponding to the target firmware based on the firmware information and the original entropy; the firmware key tree comprises a root key of the target firmware and a slice key of each firmware slice. By adopting the technical scheme, the key can be dynamically managed based on firmware information such as the firmware version number, the binding of the key with the vehicle-mounted equipment and the firmware is realized, the risk that the existing static key is easy to leak is solved, and the safety of the vehicle function is improved.
Owner:CHINA FAW CO LTD

Method and system for securely selecting applications

The disclosure relates to a method and system for securely selecting applications using application identifiers. The method for securely selecting applications using Application Identifiers (AIDs), wherein application-specific static keys are utilized to encrypt AIDs, ensuring privacy and preventing inference about the selected application. The method includes generating a random number to embed in the encryption for uniqueness and replay attack prevention, authenticating the selection command with a Message Authentication Code (MAC) for integrity, and transmitting the encrypted selection command to a recipient device for further processing.
Owner:ASSA ABLOY AB

Payment routing method and device based on voiceprint encryption, equipment and medium

PendingCN121921028AStrengthen identity authentication security levelFast and seamless accessKey distribution for secure communicationEncryption apparatus with shift registers/memoriesPaymentEngineering
The invention discloses a payment routing method and device based on voiceprint encryption, equipment and a medium, and the method comprises the steps: obtaining a plurality of voiceprint secret key fragments containing voiceprint features and payment information based on a voice payment instruction of a user, and obtaining a plurality of static secret key fragments used for access authorization; performing routing evaluation on a plurality of preset cross-border payment paths to obtain a target path for payment settlement; performing encryption processing on each voiceprint key fragment to obtain a plurality of anonymous identifiers matched with the target path; performing combined verification on each voiceprint key fragment and each static key fragment according to each anonymous identifier to obtain a routing verification result; and sending the route verification result and each anonymous identifier to the target path for payment settlement. According to the method, payment authentication security is enhanced through a dual verification mechanism of voiceprint key fragmentation and static key fragmentation, and the method is suitable for a high-sensitivity financial scene and can assist a financial institution to quickly access a mainstream cross-border payment network.
Owner:PING AN TECH (SHENZHEN) CO LTD

Safe starting system and method based on dynamic environment binding and heterogeneous inspection

The invention belongs to the field of embedded device security design, and particularly relates to a security starting system and method based on dynamic environment binding and heterogeneous inspection. A safe starting framework is constructed through a triaxial accelerometer, a main control chip and a verification module, wherein the main control chip integrates an annular oscillator array, a temperature sensor and a hardware hash engine, and the verification module comprises an AI coprocessor and a block chain communication module. The system firstly collects three-dimensional acceleration and environment temperature data, combines dynamic physical signals generated by an annular oscillator array, and generates a dynamic decryption key through fusion of a hardware hash engine; and then heterogeneous dual-channel verification is formed through the AI coprocessor and the block chain communication module, so that the key validity is ensured. According to the method, a static key is replaced by a dynamic trust root, the bottleneck of a single chain is broken through heterogeneous verification, protection is enhanced through environmental data binding, security and light weight are considered, a real-time industrial control scene with limited adaptive resources is adapted, and attacks such as physical detection and environmental simulation are effectively resisted.
Owner:XIAN MICROELECTRONICS TECH INST

Power grid BIM data dynamic layering encryption method based on function disturbance and chaotic mapping

The invention provides a power grid BIM data dynamic layering encryption method based on function disturbance and chaotic mapping. According to the method, geometric information of a power grid BIM model is converted into a mathematical function set through an NURBS parameterization decomposition technology, disturbance parameters are generated through a double-chaos system, and an NURBS function set is encrypted. Local updating and tampering prevention of attribute data are achieved through a dynamic hash tree and an evidence storage technology, and safe storage, dynamic authority control and efficient updating of the BIM data of the power grid project are ensured. Compared with the prior art, the method has the advantages that the problems of encryption and analysis conflict, static key risk and insufficient compatibility caused by a traditional encryption algorithm are solved, dynamic layered encryption of the power grid BIM data is realized, and the security and availability of the data are improved.
Owner:SOUTHWEST ELECTRIC POWER DESIGN INST OF CHINA POWER ENG CONSULTING GROUP CORP +2

Virtual machine key management method and device, equipment, storage medium and program product

The invention provides a virtual machine key management method and device, equipment, a storage medium and a program product, and relates to the technical field of information security, the method comprises the following steps: constructing a security state vector of a virtual machine based on state information of the virtual machine; key derivation is carried out based on a root key of a host machine where the virtual machine is located, the identity label of the virtual machine, the security state vector and the system time, and a master key of the virtual machine is generated; and performing key derivation based on the master key, the context information of the virtual machine, the random number and the system time, and generating a session key of the virtual machine. According to the method, multilevel dynamic key derivation is realized by constructing the security state vector of the virtual machine, so that the binding of the key with the identity, the real-time running state and the physical environment of the virtual machine is completed, the rigidity and lag risks caused by long-term fixed use of a static key are overcome, the self-adaption to the dynamic life cycle of the virtual machine is realized, and the dynamic life cycle of the virtual machine is improved. And finally, key isolation management is realized.
Owner:CHINA MOBILE COMM GRP CO LTD +1

A data processing method, client, server, and system

Embodiments of the present application provide a data processing method, a client, a server and a system. The method is applied to the client and includes: for a login request, using a first encryption algorithm and a static key in a WebAssembly module to encrypt data transmitted by the login request, and sending the login request to a server; receiving first business data and a dynamic key in response to the login request from the server, and using the first decryption algorithm and the static key in the WebAssembly module to decrypt the first business data and the dynamic key; for a non-login request, using a second encryption algorithm and the dynamic key in the WebAssembly module to encrypt data transmitted by the non-login request; and sending the non-login request to the server; and receiving second business data in response to the non-login request from the server, and using the second decryption algorithm and the dynamic key in the WebAssembly module to decrypt the second business data.
Owner:CHINA CONSTRUCTION BANK +1

Short message signature intelligent filing verification system

The invention discloses a short message signature intelligent filing verification system, and belongs to the technical field of Internet security services. According to the method, the problem that security defects exist in the face of key leakage, permission abuse and content fraud due to the fact that the prior art depends on a static key and a fixed strategy and lacks a behavior analysis and security mechanism is solved, and the authenticity and legality of a filing subject are ensured by introducing multi-factor authentication and combining a behavior portrait technology; based on dynamic trust evaluation and permission policy adjustment, intelligent access permission management is realized, normal business requirements can be met, abnormal behaviors can be timely handled, and system security is guaranteed; through Hash operation and dynamic instruction binding, the uniqueness and non-tampering performance of each short message request are ensured; and based on a response mechanism driven by a multi-layer check and decision tree model, efficient, safe and reliable operation of short message communication is further guaranteed.
Owner:深圳众投互联信息技术有限公司

File processing method and device and program product

The invention discloses a file processing method and device and a program product. Relates to the field of financial science and technology, and the method comprises the steps: generating a data encryption key under the condition that a to-be-encrypted file of a first object is received, and the first object comprises an object for creating the to-be-encrypted file; the file attribute of the to-be-encrypted file and the object attribute of the first object are obtained, and the object attribute comprises at least one of a department to which the first object belongs in the financial institution and a post in the financial institution; determining a key encryption key based on the file attribute and the object attribute of the first object; the to-be-encrypted file is encrypted based on the data encryption key and the key encryption key to obtain a target encryption result, and the target encryption result comprises the encrypted file. Through the file processing method and device, the problem of file processing caused by the fact that the file is encrypted by adopting a static key in an enterprise and the static key is independently managed by an encryptor in the related technology is solved.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Device authentication and key derivation method based on FPGA physical binding and electronic device

This invention relates to the field of network hardware security technology, specifically disclosing a device authentication and key derivation method and electronic device based on FPGA physical binding. The method includes: in response to device power-on, blocking the protected data path; calling the underlying hardware primitives of the FPGA to read the chip's unique physical identifier sequence; comparing the unique physical identifier sequence with preset authentication information to generate an authentication result; and generating a working key based on the unique physical identifier sequence and an external input key when authentication is successful. This invention restricts the protected data path at the initial power-on stage of the device and combines the chip-bound physical identifier sequence with the external input key to dynamically generate the working key, reducing reliance on static key storage mechanisms and mitigating the risk of configuration data being copied to unauthorized chips and continuing to operate.
Owner:HEFEI UNIV OF TECH

Security authentication method and system for switch access terminal

The invention provides a switch access terminal security authentication method and system, and the method comprises the steps: detecting a terminal access request through a switch, executing initial authentication based on a terminal hardware fingerprint and a user certificate, and generating and issuing a static key seed corresponding to a session after the authentication is passed; during the terminal access period, according to the track offset degree of the current behavior relative to the historical behavior, calculating the behavior abnormity membership degree; updating the dynamic trust value according to the abnormal behavior membership degree, and generating a security parameter containing a key strength parameter and a micro-isolation strategy identifier; and performing multiple rounds of hash derivation on the static key seed based on the key strength parameter to obtain a dynamic session key, retrieving an access control rule from a policy library in combination with the micro-isolation policy identifier, and issuing the access control rule to a switch to realize communication encryption and dynamic network access control. By adopting the scheme of the invention, adaptive regulation and control of the dynamic key and access control based on terminal behavior perception can be realized, so that the security protection response capability of the switch access environment is improved.
Owner:GUANGZHOU SHENGJIA JIANYE TECH CO LTD

Efficient data governance method for encrypted database based on key management system

This invention discloses an efficient data governance method for encrypted databases based on a key management system. The method comprises the following steps: Step 1: storing the database in a distributed storage system, establishing a multidimensional feature vector for each type of data based on the business attributes of the data in the database, and determining a preliminary average optimal number of shards for all encrypted data blocks in the distributed storage system; Step 2: integrating the operating parameters of each storage node and the permission levels allowed for user roles in the distributed storage system to obtain an access control vector; Step 3: performing data integrity verification and consistency checks; and calculating a load balancing factor to guide the average optimal number of shards for all encrypted data blocks in the distributed storage system toward an optimal state. This invention overcomes the problems of traditional static keys, single security policies, and insufficient resource allocation.
Owner:HENGHUI XINDA TECH CO LTD

Offline payment fraud prevention system and method based on dynamic encryption technology

The invention relates to the technical field of payment security, and discloses an offline payment fraud prevention system and method based on a dynamic encryption technology, and the system comprises a dynamic key generation module, a payment data encryption module, a payment data encryption module, a fraud detection module, and a fraud detection module. The method comprises the steps that a high-dimensional chaotic system generates a dynamic payment secret key, payment data is subjected to nonlinear topology encryption and secondary encryption, a transaction verification module decrypts and verifies legality of the payment data, a transaction verification result is generated, a fraud detection module analyzes the verification result, a fraud behavior is recognized, and a defense strategy is adjusted. The payment confirmation module judges whether payment is executed or not according to verification and detection results, and payment transaction is completed or refused. Compared with the prior art, the method has the advantages that the problems of static key multiplexing, fraud detection lagging and transaction verification incompleteness are effectively solved, the safety and protection capability of a payment system are improved, and complex payment fraud risks can be better coped with.
Owner:HEBEI JUNHUIHUI TECHNOLOGY CO LTD

Method for embedded device firmware segmentation randomization and upgrade

PendingCN122365537AData segmentAlgorithm
This invention provides a method for segmented random encryption and upgrade of embedded device firmware. The method includes: generating overall firmware segmentation rules based on function entry address offsets; generating data segments based on data structure boundary identifiers; segmenting the firmware and recording the segment index and segment index offset of each segment; randomly assigning encryption algorithms to each segment using a pre-set multi-type encryption algorithm pool; obtaining the actual independent key for each segment through hash operation by concatenating dynamic factors; independently encrypting each segment and storing the encryption algorithm pool index and encryption key metadata corresponding to each segment; reassembling the encrypted segments in their original order into complete ciphertext firmware, and attaching the encryption algorithm pool index and encryption key metadata to generate encrypted firmware ciphertext. This invention ensures that each segment key is unique and unpredictable through dynamic random segmentation and random allocation of algorithm pools, completely avoiding the defects of static keys and blocking firmware imitation paths at the source.
Owner:CHANGZHOU INST OF MECHATRONIC TECH

Dynamic data encryption transmission method and system and storage medium

The invention discloses a dynamic data encryption transmission method and system and a storage medium, and belongs to the technical field of data communication security. The method aims to solve the problems of high key leakage risk and high key management overhead in a traditional static key encryption scheme. According to the method, the initial key and the initial vector are pre-shared at the sending end and the receiving end, and the encryption key of each data block is dynamically generated by depending on the ciphertext content of the previous data block in the transmission process. Specifically, a sending end and a receiving end synchronously calculate a current dynamic key according to a previous ciphertext block through hash and a key derivation function, and encrypt and decrypt a current data block by using the key. Due to the chained evolution characteristic of the secret key, cracking of a single ciphertext does not affect the security of other data, and data tampering can cause subsequent decryption failure, so that extremely high security, built-in integrity verification and replay attack resistance are provided, additional transmission of the secret key is not needed, and the communication overhead is reduced.
Owner:白玉

Data transmission method based on service characteristics

The data transmission method based on service characteristics comprises the following steps: a sub-node obtains data from a center node: the sub-node sends a data obtaining request to the center node; the center node queries target data according to the data obtaining request, extracts a feature according to a service to which the target data belongs, generates a first key, encrypts the target data by using the first key to obtain a first data packet, and transmits the first data packet to the sub-node in pieces; the sub-node assembles the first data packet by receiving all the pieces of the first data packet, extracts a second key according to the feature of the service to which the target data belongs, and decrypts the first data packet by using the second key; if the logic of the features of the service to which the target data belongs is the same, the decryption is successful, and the sub-node obtains the target data. The application avoids the problem that the traditional static key is easily cracked, greatly increases the diversity and security of the key, and makes the data encryption more flexible and secure.
Owner:CHENGDU JIUZHOU ELECTRONIC INFORMATION SYSTEM CO LTD

Secure payment communication method and system based on dynamic PUF (Physical Unclonable Function)

The invention provides a security payment communication method and system based on a dynamic PUF (Physical Unclonable Function), two communication parties exchange the same challenge value C to establish connection, and then generate a PUF response PUFA (C) and a PUF response PUFB (C) based on the same challenge value C and exchange the PUF response PUFA (C) and the PUF response PUFB (C); and the two communication parties calculate and obtain a session key K according to the PUF response PUFA (C) and the PUF response PUFB (C), establish transaction communication according to the session key K, and update the challenge value C after the communication is finished. Therefore, zero static secret key storage is realized, and the risk of secret key leakage is avoided; and the key is dynamically updated in each transaction to defend replay attacks, so that the forward security is greatly improved.
Owner:HANGZHOU GUZI CULTURE TECHNOLOGY CO LTD

File transmission encryption method and device based on device identification, equipment and medium

PendingCN122660992AFile transmissionEngineering
The application relates to the technical field of computer data security, and provides a file transmission encryption method and device based on device identification, equipment and medium, the method comprises the following steps: receiving a file stream encryption result sent by a client; wherein the file stream encryption result is obtained by encrypting a read file stream by the client using a target session key; the target session key is obtained by decrypting a received encryption key by the client using a locally generated device private key; the encryption key is obtained by encrypting a dynamically generated initial key by the client using a device public key based on the legality verification of the device identification sent by the client; the validity of the file stream encryption result is verified, and based on the verification, the file stream encryption result is stored. The application can effectively prevent the key from being stolen or tampered with during transmission, realize efficient, dynamic and safe encryption of sensitive file streams, and effectively prevent the security risks caused by long-term use of static keys.
Owner:WEBRAY TECH BEIJING CO LTD

A method and system for encrypted communication based on dynamic key agreement

The application discloses an encryption communication method and system based on dynamic key negotiation. The method comprises the following steps: in response to a communication request sent by a printer to a consumable chip, the consumable chip generates a first random number and sends the first random number to the printer; the printer generates a second random number, and dynamically negotiates a session key according to the first random number, the second random number and a pre-shared root key; and the printer and the consumable chip perform encrypted transmission on interactive data based on the session key. Through the dynamic key negotiation mechanism of the double random numbers combined with the pre-shared root key, the application realizes independent generation or periodic update of the session key between the printer and the consumable chip in each communication, effectively prevents the data leakage risk caused by interception or cracking of the static key, guarantees the confidentiality and integrity of the interactive data, and significantly improves the security of the communication data between the printer and the consumable chip.
Owner:ZHONGSHAN YUANSHI MICRO TECH CO LTD

A safety control method for an industrial control cabinet

The application relates to the technical field of intelligent control, and discloses an industrial-grade control cabinet safety control method, which comprises the following steps: step 1, collecting quantum arbitrary number generator data to generate a key and evaluating the key entropy by using an edit distance measure; step 2, adjusting a key update strategy by using Markov decision according to the key generated in step 1 and updating the key when an attack is detected; step 3, collecting network traffic according to the update strategy in step 2 to build a topology analysis model, determining a network attack by using persistent homology, and issuing an alarm; and step 4, building an adjacency matrix according to the traffic data and equipment connection information in step 3 and calculating a graph Laplacian matrix. The application adopts quantum arbitrary number generation and Markov decision to optimize the key update strategy, dynamically updates the key when an attack is detected, guarantees the randomness of the key and the anti-attack ability, and can effectively reduce the key leakage risk and improve the system anti-quantum computing attack ability compared with the existing static key management scheme.
Owner:中胜(北京)建设有限公司