Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

37 results about "Stream cipher" patented technology

A stream cipher is a symmetric key cipher where plaintext digits are combined with a pseudorandom cipher digit stream (keystream). In a stream cipher, each plaintext digit is encrypted one at a time with the corresponding digit of the keystream, to give a digit of the ciphertext stream. Since encryption of each digit is dependent on the current state of the cipher, it is also known as state cipher. In practice, a digit is typically a bit and the combining operation an exclusive-or (XOR).

Systems and methods for establishing a secure digital network environment

According to the instant application, there are provided systems and methods to create a quantum secure / resistant secure communication channel (QSR-SCC) for communication between two or more end-points at or within devices, applications, services, APIs, secure communication protocols, etc. In one example of a QSR-SCC, a quantum secure / resistant private network (QSR-PN) extends existing VPN solutions using one time pad (OTP) based keys, augmented handshake mechanisms, and interchangeable ciphers, for example, stream ciphers or block ciphers, for enhancing security associated with the QSR-PN.
Owner:QDS HLDG INC

Memory systems and devices including examples of accessing memory and generating access codes using an authenticated stream cipher

Examples of systems and methods described herein provide for accessing memory devices and, concurrently, generating access codes using an authenticated stream cipher at a memory controller. For example, a memory controller may use a memory access request to, concurrently, perform translation logic and / or error correction on data associated with the memory access request; while also utilizing the memory address as an initialization vector for an authenticated stream cipher to generate an access code. The error correction may be performed subsequent to address translation for a write operation (or prior to address translation for a read operation) to improve processing speed of memory access requests at a memory controller; while the memory controller also generates the encrypted access code.
Owner:MICRON TECHNOLOGY INC

Security data isolation and information exchange method and system based on lightweight protocol

The invention relates to a security data isolation and information exchange method and system based on a lightweight protocol, belongs to the technical field of industrial automation control system security, and solves the technical problems of low transmission efficiency, high analysis overhead, high security risk and high resource consumption of an existing method. Comprising the following steps: collecting and preprocessing original plaintext data at an industrial control network side; an external unit identifier, a timestamp and a pre-shared key on the industrial control network side are used as encryption factors, lightweight stream cipher encryption and packaging are carried out on the preprocessed data, and a lightweight protocol data packet is generated; through a special physical isolation device, the light-weight protocol data packet subjected to deep detection is unidirectionally isolated and ferried from an industrial control network side to an internal network side; performing post-processing on the received lightweight protocol data packet at the intranet side to restore original data; and delivering the restored original plaintext data to an intranet service application. And safe and efficient information data exchange is realized.
Owner:BEIJING JINGHANG COMPUTING & COMM RES INST

Sensor data acquisition security authentication system based on block chain

The invention relates to the technical field of data security and block chains, and particularly discloses a sensor data acquisition security authentication system based on a block chain. The system comprises a sensor node module, a dynamic key management module, a ciphertext processing engine, a block chain consensus module and an authentication decision module, a key is dynamically generated through a physical unclonable function and environmental noise, and decryption-free integrity authentication of ciphertext data is realized in combination with stream cipher encryption and block chain distributed verification. According to the method, the security and the system throughput in the data acquisition process are improved, and meanwhile, the calculation overhead is reduced.
Owner:SHENZHEN LOLAAGE TECH CO LTD

Hardware circuit to perform round computations of ARX-based stream ciphers

Systems and methods for efficient computation of stream ciphers. An example system for implementing a stream cipher, may comprise: a sub-round computation circuit of a first type configured to perform a subset of transformations of a cipher computation round on a round input state, each transformation of the subset of transformations including at least one of: a bitwise addition operation, a bitwise exclusive disjunction operation, or a bitwise rotation operation. The sub-round computation circuit of the first type may comprise: one or more of sub-round computation circuits of a second type, wherein each sub-round computation circuit of the second type is configured to perform the subset of transformations of the cipher computation round on a respective part of the round input state.
Owner:CRYPTOGRAPHY RESEARCH INC

Optical secure communication system

[Problem] To provide an optical secure communication system with higher safety by carrying a QNSC signal using a coherent Hermite-Gaussian pulse, multiplexing the QNSC signal using coherent Hermite-Gaussian pulses of different orders, and adding a masking effect in a time domain. [Solution] An optical secure communication system for a quantum noise stream cipher (QNSC) signal for masking the phase and / or the amplitude level of an optical signal using quantum noise, wherein carrier light in a transmission unit and locally oscillated light in a reception unit of the QNSC signal comprise a coherent Hermite-Gaussian pulse with an amplitude given by an Hermite-Gaussian function.
Owner:TOHOKU UNIV

Method for multi-user confidential querying of the presence of a record in a database

A method for confidentially querying the presence of a record in a database hosted by a server, the records being stored in the database in the form of digital footprints obtained by hashing a record by a public hash function. The footprints are masked by a stream cipher using a symmetric key of a first user. The first user may grant a second user authorisation to query the database by transmitting the inverse masks of various rows, encrypted by the public key of an additive homomorphic cryptosystem of the second user. The rows of the database are unmasked in the homomorphic domain and the second user transmits an encrypted request to query the base according to a PIR protocol. The second user can decrypt the response from the server using the private key of their homomorphic cryptosystem and determine whether the footprint sought is present in the response thus decrypted.
Owner:COMMISSARIAT A LENERGIE ATOMIQUE ET AUX ENERGIES ALTERNATIVES

A bio-information authentication method and device based on a stream cipher, and a medium

The application relates to a biological information authentication method and device based on a stream cipher, and a medium, the method is applied to a server side, and comprises the following steps: establishing a connection with a client, obtaining a preprocessed face biological feature vector from the client; obtaining an original password from the client, generating key information according to the original password; encrypting the face biological feature vector and the key information through a 256-stream cipher to obtain encrypted ciphertext; calculating the similarity index of the encrypted ciphertext and preset original biological information, judging whether the similarity index is less than a preset threshold, if yes, authentication is passed, and if not, authentication fails and a prompt information is sent. Compared with the prior art, the 256-stream cipher encryption mode is adopted, and the security and performance are effectively improved.
Owner:SHANGHAI JIAOTONG UNIV

Agricultural perception node-oriented lightweight secure communication method and system

PendingCN122457243APlaintextCloud data management
The application discloses a kind of light security communication method and system for agricultural perception node.The method includes that 256-bit static master key is preset in the bottom layer security storage area of perception node and heterogeneous convergence gateway, and the unique hardware serial number is read as node identification;Synchronous acquisition environmental data and visual feature data, splice into long payload plaintext;Derive dynamic session key, use dynamic session key to drive stream cipher to encrypt long payload plaintext, static master key drives block cipher to encrypt short header, and encapsulates into data frame;Data frame is sent through wireless channel, and heterogeneous convergence gateway receives and reversely decrypts short header to extract dynamic anti-fake factor, and replay attack verification is carried out;After verification, dynamic session key is reconstructed to restore data and uploaded to cloud data management server.The application also discloses a system using the above light security communication method for agricultural perception node, realizes the high security node legitimacy authentication and anti-replay attack under limited hardware computing power.
Owner:QIQIHAR UNIVERSITY

Efficient and safe sequence password generation device

The utility model relates to the field of cryptology, and discloses an efficient and safe sequence password generating device which comprises a shell, a cover plate is rotatably connected to the surface of the shell, a displayer is arranged on the cover plate, a fixing plate is detachably installed in the shell through bolts, and a password generator is inserted in the fixing plate. A clamping assembly is arranged on the fixing plate and used for clamping the password generator. An opening and closing assembly is arranged on the shell and used for overturning the cover plate. The clamping assembly comprises four sets of fixing sleeves inserted into the fixing plate, connecting columns are inserted into the fixing sleeves, limiting sleeves are connected into the fixing plate in a threaded mode, springs are arranged between the connecting columns and the limiting sleeves, and cross rods are integrally formed at the ends of the connecting columns. By means of the clamping assembly, the problems that when the password generator is not clamped and is vibrated, the password generator can move in the device, an internal connecting circuit is loosened, and normal electrical connection of the password generator is affected are solved.
Owner:BEIJING INSTITUTE OF GRAPHIC COMMUNICATION

Data encryption transmission method and device, equipment, system, storage medium and product

The invention discloses a data encryption transmission method and device, equipment, a system, a storage medium and a product, and the data encryption transmission method applied to sending equipment comprises the steps: carrying out the encryption and modulation processing of first plaintext data based on a quantum noise stream cipher technology, and generating a first modulation symbol; performing spatial expansion processing on the first modulation symbol based on preprocessed base information for spatial coding to generate a ciphertext signal; sending the ciphertext signal to a receiving device; wherein the constellation points in the preprocessed base information are in non-uniform distribution in the judgment boundary. Therefore, according to the embodiment of the invention, the base information is preprocessed, so that the ciphertext signal encrypted and modulated by the quantum noise stream cipher technology is located near the judgment boundary, even if the quantum noise is small noise, the high bit representing the ciphertext data in the ciphertext signal can also be influenced, the bit error rate of the high bit is improved, and the accuracy of the ciphertext data is improved. And the security of data transmission is improved.
Owner:CHINA MOBILE COMM LTD RES INST +1

Fast mac address rotation through existing stream cipher

Presented herein are techniques to efficiently rotate a Media Access Control (MAC) address. One or more stream ciphers for encrypting one or more data units are generated. A data unit of the one or more data units is encrypted using a stream cipher of the one or more stream ciphers to generate an encrypted data unit. A new MAC address to add to the data unit is generated based on the one or more stream ciphers and the encrypted data unit is wirelessly transmitted with the new MAC address.
Owner:CISCO TECHNOLOGY INC

Secure video data transmission method based on selective encryption technology

The invention discloses a secure video data transmission method based on a selective encryption technology, and belongs to the field of video data encryption transmission. The implementation method comprises the following steps of: performing discrete cosine transform on video frame image data, and converting a pixel value matrix in a video frame into a transformation coefficient TC matrix; carrying out binarization processing on the transformation coefficient through TRp; checking whether the transformation coefficient can be encrypted or not, and determining that the transformation coefficient at the current position does not influence the adjacent transformation coefficient at the current position; a CTR mode of an AES algorithm is adopted as a pseudo-random number generator, selected syntax elements are encrypted in a stream cipher form, it is ensured that the encrypted video stream can still be decoded by a standard decoder, and meanwhile the transmission data volume is not increased; the encrypted symbol is recovered by performing an XOR operation on the ciphertext and the same pseudo-random number generator output. According to the invention, secure video data transmission based on selective encryption can be realized, the transmission efficiency, security and reliability of video stream data can be improved, and the overhead of encryption calculation is significantly reduced.
Owner:BEIJING INST OF TECH

A device binding software encryption method and system based on multi-layer nested encryption

PendingCN122339760APlaintextReverse analysis
This invention discloses a device binding software encryption method and system based on multi-layer nested encryption, which addresses the problem that existing software encryption protection mechanisms cannot achieve reverse engineering, copying, and static analysis protection in environments with strong offline conditions and no reliable network connection. The method includes: generating a signing key and a verification key; constructing plaintext license information and performing three-layer nested encryption on the plaintext: encrypting the plaintext license information using AES, outputting AES ciphertext and an authentication tag; performing elliptic curve digital signature on the AES ciphertext using ECC to obtain an ECC signature value; concatenating the AES ciphertext and the ECC signature value, and encrypting the concatenated data using the ZUC stream cipher algorithm to obtain a ciphertext obfuscation; and performing reverse decryption and verification on the ciphertext obfuscation. Successful verification returns the function flag bit from the plaintext license information; otherwise, an error code is returned. This method effectively resists copying, tampering, reverse analysis, and unauthorized porting.
Owner:SICHUAN HAIGE HENGTONG PRIVATE NETWORK TECH CO LTD

Processing system and corresponding method of operation

Embodiments of the present disclosure relate to processing systems and corresponding methods of operation. A master device issues memory burst transaction requests via an interconnect bus to obtain data from a slave device. A cryptographic engine is coupled to the interconnect bus and decrypts the obtained data to produce plaintext data for the master device. The cryptographic engine selectively operates according to a stream cipher mode of operation, or a block cipher mode of operation. The cryptographic engine is configured to suspend a read data channel of the interconnect bus between the slave device and the master device in response to the cryptographic engine switching from the block cipher mode of operation to the stream cipher mode of operation. The read data channel is reactivated in response to a last beat of a read burst of plaintext data produced by the cryptographic engine.
Owner:STMICROELECTRONICS SRL

Face recognition building intercom system based on VOIP encryption transmission

The invention discloses a face recognition building intercom system based on VOIP encryption transmission, and relates to the technical field of building intercom communication, the system comprises an entrance machine, an indoor machine and a management platform, the entrance machine is integrated with a network state sensing module, a security policy management module, a biological characteristic key generation module and a human body posture recognition model, the entrance machine collects a face image and completes preliminary recognition, the biological feature key generation module extracts feature factors from the face image and dynamically generates a unique encryption key, the security policy management module switches encryption policies such as a ChaCha20 stream cryptographic algorithm and an AES-256 algorithm according to a call stage and network quality parameters, and the security policy management module carries out encryption on the face image. The redundancy error correction strategy is dynamically adjusted based on the data packet priority and the network condition, the management platform is responsible for coordinating system operation, storing logs and pushing strategy suggestions, dynamic balance of communication safety, real-time performance and reliability is achieved, system energy consumption is reduced, user privacy is protected, and the method is suitable for application scenes with complex network conditions.
Owner:SHENZHEN SKYRISE TECH CO LTD

Lightweight dynamic traceability system and method based on stream cipher and time synchronization

The invention relates to the field of Internet of Things, embedded systems and information security, in particular to a lightweight dynamic traceability system and method based on stream cipher and time synchronization, and aims to solve the problems that an existing static two-dimensional code is easy to copy, high in replay attack risk, poor in adaptive resource limited scene and the like. Calculating a time slice after triggering, and encrypting the stream cipher to generate a check code to construct a dynamic two-dimensional code; the user anonymously uploads information; the platform records traceability information after triple signature verification of the manufacturer identity, the replay attack and the equipment identity. The system comprises a read-write storage area, an encryption module, a real-time clock register, a power supply module and electronic paper or an ink screen capable of displaying the two-dimensional code. The method can resist copying and replaying attacks, is adaptive to scenes such as bottle cap chips, gives consideration to privacy and statistics, and guarantees the safety and effectiveness of traceability.
Owner:GUIZHOU UNIV

Data processing method, system and device and readable storage medium

The invention discloses a data processing method, system and device and a readable storage medium, and the method comprises the steps: obtaining target data and a secret key, and determining a working mode; determining a target core unit matched with the working mode from the first core unit and the second core unit; the communication line is communicated with the target core unit and the modular addition operation module; writing an initial parameter corresponding to a protocol supported by the target core unit into a replacement box shared by the first core unit and the second core unit; in the process of generating a stream key corresponding to the key by the target core unit, performing modular addition calculation by using a modular addition operation module, and performing data conversion and secure storage by using a substitution box; and processing the target data by using the stream key generated by the target core unit to obtain encrypted data or decrypted data. By multiplexing the modular addition operation module and the substitution box, the area of the algorithm core of the stream cipher is reduced, and the power consumption and the manufacturing cost of the algorithm core circuit are reduced.
Owner:SHANDONG YUNHAI GUOCHUANG CLOUD COMPUTING EQUIP IND INNOVATION CENT CO LTD

Fast mac address rotation through existing stream cipher

PCT designated stage expiredWO2025151318A1Security arrangementWireless transmissionMedia access control
Presented herein are techniques to efficiently rotate a Media Access Control (MAC) address. One or more stream ciphers for encrypting one or more data units are generated. A data unit of the one or more data units is encrypted using a stream cipher of the one or more stream ciphers to generate an encrypted data unit. A new MAC address to add to the data unit is generated based on the one or more stream ciphers and the encrypted data unit is wirelessly transmitted with the new MAC address.
Owner:CISCO TECHNOLOGY INC

System and method for establishing a secure digital network environment

According to the present application, systems and methods are provided for creating a quantum-secure / resistant secure communication channel (QSR-SCC) for communication between two or more endpoints to or within a device, application, service, API, secure communication protocol, etc. In one example of a QSR-SCC, a quantum-secure / resistant private network (QSR-PN) extends existing VPN solutions with one-time pad (OTP)-based keys, an extended handshake mechanism, and mutually substitutable ciphers, e.g., stream ciphers or block ciphers, to improve the security associated with the QSR-PN. (Selected Figure: Figure 5)
Owner:QDS HLDG INC

A Video Stream Encryption Method and Device Based on a Trusted Execution Environment

The present invention relates to the technical field of video data encryption, and specifically relates to a video stream encryption method and device based on a trusted execution environment. The method includes: the acquisition terminal randomly generates stream cipher parameters RP within the trusted execution environment, encrypts the parameters RP with the public key of the corresponding user, and packages them into data packets; the playback terminal generates an encryption key based on a key negotiation algorithm for encrypting frame metadata, where the frame metadata includes video frame timestamps and stream cipher parameters, and sends the encrypted frame metadata to the server module; the acquisition terminal uses the parameter RP as the stream cipher parameter, generates a corresponding stream cipher based on the video frame size, encrypts the video stream data by XORing with the stream cipher, and pushes it to the server module after encryption; the present invention realizes the asymmetric algorithm encryption and stream encryption of the video stream by the acquisition terminal and the playback terminal, ensures that the video transmission is more secure and reliable, and ensures that the user with the device and the corresponding playback terminal can decrypt and view the video.
Owner:HE FEI AN YONG XIN XI KE JI YOU XIAN GONG SI

Unmanned aerial vehicle sensitive data transmission method and system based on Beidou space-time encryption

The invention provides an unmanned aerial vehicle sensitive data transmission method and system based on Beidou space-time encryption. According to the method, firstly, based on Beidou positioning data, a credible timestamp and flight height and course angle data of an unmanned aerial vehicle, a space-time reference code is generated through fusion, secondly, channel pulse response characteristics are obtained by utilizing multipath fading characteristics, and the space-time reference code and the channel pulse response characteristics are jointly coded to generate a dynamic encryption seed; the method comprises the following steps: acquiring an encrypted insulator surface image data stream, and then adding Beidou positioning data and channel pulse response characteristics as verification metadata into a data packet while sending the encrypted insulator surface image data stream, so that a receiving end can synchronously restore a dynamic encryption seed to complete decryption operation; according to the technical scheme provided by the invention, the strong association binding of the encryption key and the specific time-space point is realized, the potential safety hazard that the key is fixed in the traditional encryption scheme is effectively overcome, and the unification of safety and availability is realized.
Owner:ZHONGLIAN GOLDEN CROWN INFORMATION TECH (BEIJING) CO LTD

A homomorphic evaluation method and device of a symmetric cipher algorithm

The application provides a homomorphic evaluation method and device of symmetric cipher algorithm, and belongs to the technical field of cryptography, to design a homomorphic evaluation scheme of symmetric stream cipher which meets a lower multiplication depth design standard and has high calculation efficiency and homomorphic friendliness under the condition of ensuring security. In the method, the homomorphic evaluation of SNOW 3G algorithm and ZUC algorithm can be respectively applied to a mixed homomorphic mode, such as performing the first part of operations of LFSR and FSM in a level 0 door bootstrap mode and performing a lookup table operation in a level 1 hierarchical homomorphic calculation mode, so as to realize the architecture and algorithm of homomorphic calculation of SNOW 3G algorithm and ZUC algorithm through fully homomorphic encryption, and further realize the homomorphic evaluation scheme of symmetric cipher algorithm which meets the lower multiplication depth design standard under the condition of ensuring security.
Owner:HUAWEI TECH CO LTD +1

A logistics privacy protection method based on encrypted two-dimensional code

The application provides a logistics privacy protection method based on encrypted two-dimensional codes, relates to the field of logistics privacy protection, divides two-dimensional codes into uniform blocks and non-uniform blocks, utilizes the characteristics of high embedding capacity of a binary image reversible data hiding algorithm based on pixel prediction, image recovery and data extraction separable technology, and the non-decodable of encrypted two-dimensional codes, and completes access control of the access rights of each party in logistics privacy protection. On this basis, multiple keys are further introduced to improve the security of embedded data. Not only the internal and external privacy leakage problems existing in the current express logistics process are solved, but also the anti-pollution ability of express two-dimensional codes in harsh environments is realized by virtue of the high error correction ability of two-dimensional codes and the reversibility of binary image hiding algorithm. The application combines separable technology and stream cipher encryption technology, is mainly based on an improved pixel prediction encrypted binary image reversible data hiding algorithm, and realizes logistics privacy protection for preventing internal and external leakage of privacy information.
Owner:XIAN UNIV OF POSTS & TELECOMM

A lightweight dynamic traceability system and method based on stream cipher and time synchronization

The present application relates to the field of Internet of Things, embedded system and information security, in particular to a lightweight dynamic traceability system and method based on stream cipher and time synchronization, aiming at the problems of easy copying of existing static two-dimensional code, high risk of replay attack, poor adaptation to resource limited scene, etc., the method comprises: writing identity information and activating real-time clock at product end; calculating time slice after triggering, generating check code by stream cipher encryption to construct dynamic two-dimensional code; uploading information anonymously by user; recording traceability information after three signatures of manufacturer identity, replay attack and device identity by platform. The system comprises read-write storage area, encryption module, real-time clock register, power module, and electronic paper or ink screen capable of displaying two-dimensional code. The present application can resist copying and replay attack, adapt to scenarios such as bottle cap chip, and balance privacy and statistics, ensuring safe and effective traceability.
Owner:GUIZHOU UNIV

Calculation device, terminal device, network, calculation method, and program

Provided is a calculation device that is provided with at least a processor and a memory and that, when the bit length of a common key which has been assigned to be used for communication between a terminal device and a network differs from the bit length of an input key which is used in a prescribed algorithm, increases or reduces the bit length of the assigned common key, thereby performing conversion into a key with a prescribed bit length, and performs encryption processing or decryption processing on a stream cipher, wherein at least one of a constant and an initial value that are used to initialize the stream cipher differs according to the bit length of the assigned common key.
Owner:KDDI CORP

Lightweight industrial control network transmission encryption method

The present application provides a kind of lightweight industrial control network transmission encryption method, and the data transmission between industrial control host and industrial control equipment adopts lightweight stream encryption mode, and each transmitted data is encrypted by XOR mode, and the encryption mode is approximately one-time pad, namely stream encryption.The present application respectively places stream key generation facility and stream cipher machine on the two sides of industrial control host and industrial control equipment, and both sides first negotiate the random key R of stream cipher to be generated for this time processing data transmission before processing each time key Then the ciphertext enc (R key , PcKey) is generated by using the public key PcKey of industrial control equipment for encryption, and the encrypted key enc (R key , PcKey) is sent to industrial control equipment, and the random key R of stream cipher is obtained by using the private key PsKey of industrial control equipment for decryption key , and the industrial control host is informed.The present application can provide security protection for the data transmission between industrial control host and industrial control equipment of industrial control system.
Owner:HUAZHONG UNIV OF SCI & TECH RES INST SHENZHEN +1

Memory systems and devices including examples of accessing memory and generating access codes using an authenticated stream cipher

Examples of systems and methods described herein provide for accessing memory devices and, concurrently, generating access codes using an authenticated stream cipher at a memory controller. For example, a memory controller may use a memory access request to, concurrently, perform translation logic and / or error correction on data associated with the memory access request; while also utilizing the memory address as an initialization vector for an authenticated stream cipher to generate an access code. The error correction may be performed subsequent to address translation for a write operation (or prior to address translation for a read operation) to improve processing speed of memory access requests at a memory controller; while the memory controller also generates the encrypted access code.
Owner:MICRON TECHNOLOGY INC

Encrypted image RDH method of hierarchical block variable length coding based on MSB plane prediction

The invention requests to protect an encrypted image RDH method of hierarchical block variable length coding based on MSB plane prediction, and belongs to the field of information hiding. Comprising the following main steps: S1, carrying out prediction error calculation on an original image, and generating an absolute value image and a symbol graph of a prediction error; s2, dividing a bit plane of the absolute value image, decomposing the bit plane into blocks of different levels according to local smoothness, and judging whether the blocks are further divided or not through a layering threshold value Ti; s3, after packaging the compressed auxiliary information, encrypting the compressed auxiliary information by using a stream cipher, and embedding secret data in an encrypted image; and S4, the receiver extracts data and recovers the original image according to different keys. Compared with the existing method, the method provided by the invention has the following main advantages: (1) through a dynamic partitioning strategy, the method adapts to sparse '1' distribution of different regions, and the embedding capacity is improved; and (2) by utilizing high prediction precision of MED and combining efficient compression of hierarchical block variable length coding, an embedding space is vacated to the greatest extent.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Privacy preserving identity data exchange based on hybrid encryption

A method is disclosed. The method includes receiving, by a processing network computer from a relying party computer associated with a relying party, a request for data associated with a user operating a user device. The processing network computer is capable of retrieving first encrypted data of the user having an encrypted user layer. The processing computer is then capable of generating a second symmetric key to add an encrypted relying party layer to the first encrypted data using a stream cipher. The double encrypted data can be transmitted to the user device, which removes the encrypted user layer on the first double encrypted data and then adds a second encrypted relying party layer to form a second double encrypted data. The second double encrypted data can be transmitted to the relying party computer, which is capable of removing both encrypted relying party layers to obtain access to the data associated with the user.
Owner:VISA INTERNATIONAL SERVICE ASSOCIATION