Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

1641results about "Key distribution for secure communication" patented technology

Systems and methods for provisioning embedded Internet of Things Universal IDs (IoT UIDs) in Greenfield devices

A method for embedding an Internet of Things Universal Identifier (IoT UID) into one or more Greenfield devices is provided. The method includes manufacturing one or more Greenfield devices, and generating device property data based at least in part on the one or more Greenfield devices. The method further includes transmitting, to an Internet of Things (IoT) device registrar server, a registration request that includes the device property data. The method further includes interpreting one or more Internet of Things Universal Identifiers (IoT UIDs) generated in response to the transmitting of the registration request. The method further includes embedding the one or more IoT UIDs in the one or more Greenfield devices.
Owner:SOMOS INC

Application certificate provisioning process using connected vehicle

An example operation includes one or more of establishing a secure channel between a host platform and a vehicle based on a transport layer security (TLS) handshake between the host platform and the vehicle, downloading an authorization code to the vehicle through the secure channel between the host platform and the vehicle, receiving the authorization code from a mobile application installed on a mobile device, generating a mobile application certificate for the mobile device and transmitting the mobile application certificate to the mobile application on the mobile device, and establishing a secure connection between the host platform and the mobile application on the mobile device based on the mobile application certificate.
Owner:TOYOTA MOTOR NORTH AMERICA INC +1

Third party based key exchange method, system and components thereof

The application provides a third-party-based key exchange method and system, a trusted third party and an entity, wherein the trusted third party only participates in identity authentication of the entity and assists in negotiation of a key between the two entities, and cannot obtain a shared key between the two entities, effectively solving the problem that the trusted third party cannot avoid obtaining the exchanged key in the existing key exchange scheme based on the trusted third party, and ensuring that the finally exchanged key is only owned by the two entities participating in the key exchange. In addition, in the application, the trusted third party can also provide a random number to participate in the final key generation, thereby ensuring the strength of the final key, meeting the requirement that the trusted third party needs to manage the strength of the exchanged key in a specific application scenario, and enhancing the management and control capability of the system.
Owner:QUANTUMCTEK CO LTD +1

A stokes parameter encoder and a method of parameter encoding

ActiveCN116366167BKey distribution for secure communicationPhotonic quantum communicationBeam splitterPolarization-maintaining optical fiber
The application discloses a Stokes parameter encoder, which comprises a fiber optical circulator and an optical path round trip path; a polarization maintaining fiber Faraday rotator is arranged on the optical path round trip path to rotate the polarization of light by 45 degrees; the fiber optical circulator is a polarization maintaining fiber optical circulator; the fiber optical polarization beam splitter is a polarization maintaining fiber optical polarization beam splitter; the delay fiber is a polarization maintaining delay fiber; and the fiber optical phase modulator is a polarization maintaining fiber optical phase modulator. The application further discloses a parameter encoding method of the encoder. The above technical scheme can perfectly offset the rotation angle deviation problem caused by the device, can guarantee the stability of the rotation angle regardless of the angle deviation of the device, is easy to realize the driving circuit, is easy to integrate and small in size due to the pure fiber structure, and can realize the continuous variable quantum key distribution of the complete GG02 protocol based on the Stokes encoder.
Owner:ANHUI QASKY QUANTUM SCI & TECH CO LTD

Post-quantum constant-time key rotation verification

Certain aspects of the disclosure provide a method for verifiable key rotation of an encryption key. The method includes generating a ciphertext by encrypting a plaintext with a homomorphic probabilistic encryption scheme based on a first key. The method further includes generating an updating token based on a difference between the homomorphic probabilistic encryption scheme based on a second key and generating a second ciphertext by encrypting the first ciphertext with the updating token. The method further includes validating the key rotation by selecting a set of second ciphertext blocks from the second ciphertext; reverting the set of second ciphertext blocks with the updating token to a set of third ciphertext blocks; and computing a Hamming distance between blocks of the set of second ciphertext blocks and the corresponding set of third ciphertext blocks.
Owner:CIRCLE INTERNET GRP INC

Distribution and update of keys

Cluster storage systems (100) and methods provide secure generation, distribution, and update of encryption keys (132, 142) during initial cluster formation and cluster membership changes without using readable persistent media. A cryptographic co­processor (130) stores a key encryption key (132) in write-only memory and uses the unreadable key (132) for encryption and decryp­tion of a data encryption key (142). Methods to securely distribute the initial or updated the key (132) to be stored in the coprocessor (130) and securely update the key (132) when cluster membership changes are provided.
Owner:NVIDIA CORP

System and method for network policy simulation

ActiveUS12657049B2Key distribution for secure communicationCorrect operation testing
This disclosure generally relate to a method and system for network policy simulation in a distributed computing system. The present technology relates techniques that enable simulation of a new network policy with regard to its effects on the network data flow. By enabling a simulation data flow that is parallel and independent from the regular data flow, the present technology can provide optimized network security management with improved efficiency.
Owner:CISCO TECHNOLOGY INC

A novel centralized remote infusion management method and system for insulin

This invention discloses a novel centralized remote insulin infusion management method and system, relating to the field of diabetes telemedicine technology. The invention employs a dual-platform architecture separating monitoring and intervention, with the cloud server and dedicated monitoring station as independent cloud subsystems. A persistent WebSocket connection is established between the cloud and the execution terminal to complete identity verification and communication key negotiation. Remote commands are sequentially checked for legality and concurrent conflicts, and command issuance is controlled by a distributed concurrent lock at specified time intervals to prevent deadlock. After completing local security verification, the execution terminal forwards the command to the insulin pump, synchronizing the execution status to the cloud and management terminal in real time, achieving closed-loop control throughout the entire process. This invention significantly improves the real-time performance and security of remote insulin infusion, overcoming the shortcomings of traditional SMS remote control solutions, such as cumbersome processes, unreliable communication, and inability to adapt to centralized management.
Owner:SHENZHEN AIBAOWEI BIOTECHNOLOGY CO LTD

Key encapsulation methods and devices

Embodiments of the present application provide a key encapsulation method and device, the method comprising: in response to a key encapsulation request for transmitting data to a receiving end, obtaining a public key corresponding to the receiving end, and encoding a plaintext message to be encapsulated into a message polynomial on a polynomial ring; performing linear compression on the message polynomial using an inverse element of a preset small coefficient polynomial to obtain a compressed plaintext polynomial; generating a first ciphertext component based on a second public key component and an encryption polynomial, and generating a second ciphertext component based on a first public key component and the compressed plaintext polynomial. The encapsulation result containing the first ciphertext component and the second ciphertext component is sent to the receiving end, so that the receiving end uses a corresponding private key to unencapsulate the encapsulation result, obtains the compressed plaintext polynomial, and decodes the compressed plaintext polynomial to restore the plaintext message. This can effectively resist quantum computers, effectively reduce the ciphertext length of the encapsulated plaintext message, and further reduce storage and communication overhead.
Owner:BEIJING INFOSEC TECH CO LTD +1

Performing a digital signature operation in a secure element platform runtime environment

One or more embodiments perform a set of digitally signed operations in a secure element (SE) platform runtime environment executing on an SE processor of an SE hardware device. The system initializes a signature generation object in the SE platform runtime environment. The system determines, via the signature generation object, a private key corresponding to a hash-based signature protocol. The system generates, via the signature generation object, a digital signature of a message digest by performing the hash-based signature protocol on the message digest using the private key. The system outputs the digital signature to the hardware device.
Owner:ORACLE INT CORP

E-mail processing method and storage medium

PendingCN122073533AKey distribution for secure communicationCloud detectionDatabase
The invention discloses an E-mail processing method and a storage medium. The method comprises the following steps: acquiring a target E-mail; extracting target email features of the target email, determining a matching result of the target email features based on a preset abnormal email feature library, and determining a first category identifier of the target email according to the matching result; if the first category identifier represents that the target E-mail is a normal E-mail, sending an E-mail category detection request to a cloud server; receiving a second category identifier sent by the cloud server; the second category identifier is obtained by performing mail category detection on each target attribute feature by the cloud server based on a preset cloud detection strategy corresponding to each target attribute feature; if the second category identifier represents that the target E-mail is a normal E-mail, the target E-mail is sent to the target mail receiving account, the abnormal E-mail can be detected comprehensively, accurately and rapidly, and the probability that the user receives the abnormal E-mail is reduced.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

A two-dimensional coupling chaos-based lightweight security communication method for vehicle CAN bus

The application discloses a kind of based on two-dimensional coupling chaos vehicle CAN bus lightweight security communication method, belong to vehicle network security communication technical field.This method is applied to the layered vehicle network including gateway electronic control unit GECU, domain control unit DCU and electronic control unit ECU, including four stages of system initialization, identity authentication, key distribution and secure communication.Through two-dimensional coupling chaotic mapping, random challenge value, authentication random quantity and chaotic seed are generated, and combined with global round parameter epoch and domain key evolution parameter rand, a layered key management mechanism is constructed to realize the local derivation of inter-domain and intra-domain shared session keys.The sending node uses the shared session key to perform lightweight encryption and authentication on the service data, and encapsulates the ciphertext and authentication tag in the same CAN message for transmission.This method improves the communication performance of vehicle CAN bus without significantly increasing communication overhead and computational overhead.
Owner:HUNAN NORMAL UNIVERSITY

Key provisioning device, server, and method

A key provisioning device includes a communication circuit configured to receive, from a server, first key provisioning data including multiple key values and usage values for the keys. The key provisioning device also includes a control circuit configured to arbitrarily select at least one key value from among the multiple key values based on usage of a key required by a key data receiving device. The control circuit is also configured to generate second key provisioning data including the at least one key value. The control circuit is additionally configured to transmit the second key provisioning data to the key data receiving device via the communication circuit.
Owner:HYUNDAI AUTOEVER

Homomorphic encryption based sparse vector compression and hierarchical aggregation method and system

The application relates to the technical field of information security, and particularly discloses a sparse vector compression and hierarchical aggregation method and system based on homomorphic encryption, which comprises the following steps: constructing a corresponding subsystem on each terminal device, a relay device and a high-level root device; constructing a personnel information index table by each terminal device and obtaining personnel IDs meeting a condition; constructing a sparse vector by each terminal device according to the personnel IDs meeting the condition, encrypting the sparse vector into a ciphertext vector and uploading the ciphertext vector to a higher-level relay device; the number of personnel meeting the condition of each terminal device is not more than max, and the dimension of the sparse vector constructed by each terminal device is 2max; performing ciphertext aggregation on the ciphertext vector obtained by each relay device, and uploading the aggregated ciphertext vector; and decrypting the ciphertext vector obtained by the high-level root device into a plaintext vector, and calculating the personnel IDs meeting the condition from the plaintext vector. The application has high transmission efficiency and high security.
Owner:BEIJING ELECTRONICS SCI & TECH INST

Information processing system, control device, information processing method, and program

An information processing system (10) comprises an information terminal (20) and a control device (50). The information terminal (20) includes: a communication unit (21); and an information processing unit (22) that uses the communication unit (21) to transmit, to the control device (50), an advertising signal based on Bluetooth (registered trademark), the advertising signal including control information encrypted using an unlock token stored in a storage unit (23). The control device (50) includes: a communication unit (51) that receives the advertising signal; and a control unit (52) that, when the control information included in the received advertising signal is successfully decrypted using an unlock token stored in a storage unit (53), uses the communication unit (51) to transmit an advertising response based on Bluetooth (registered trademark) to the information terminal (20) and releases device restrictions.
Owner:PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD

Unified key management in a communication network environment

Unified key generation management in a communication network environment are disclosed. By way of one example, a method in user equipment generates a first cryptographic value, independent of generation of the same first cryptographic value at a first network entity of a first communication network, wherein the first network entity includes an access control and mobility function and the first cryptographic value is derived from a cryptographic value for a security anchor function. The method generates a set of one or more user plane cryptographic values from the first cryptographic value, independent of the generation of the same set of one or more user plane cryptographic values at the first network entity. The method uses the set of one or more user plane cryptographic values to securely communicate with a second network entity of the first communication network, wherein the second network entity includes an access user plane function.
Owner:NOKIA TECHNOLOGIES OY

Quantum image encryption method and device, electronic equipment, storage medium and computer program product

The application discloses a quantum image encryption method and device, electronic equipment, a storage medium and a computer program product. The method comprises the following steps: representing a to-be-encrypted image as a quantum image through a quantization process; determining the complexity of the quantum image; determining a target quantum encryption algorithm by using the complexity of the quantum image; and encrypting the quantum image by using the target quantum encryption algorithm.
Owner:CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1

Data security management method and system based on block chain

The invention relates to the technical field of data security, and discloses a data security management method and system based on a block chain. The method comprises the following steps: acquiring and standardizing encrypted data and main body request information; extracting identity attributes and access requirements, and matching data paragraph attributes to generate permission vectors; synchronizing to a block chain and screening an adaptation rule combination; planning a conversion path to adjust an encryption key; verifying the identity authority, and calculating the matching degree to generate a temporary access token; the verification token obtains the data and re-encrypts the data; isolating the unauthorized content to obtain an isolated data packet; and after secure transmission, recording the log, updating the permission vector and synchronizing the permission vector to the block chain. And dynamic accurate authority management and secure sharing of encrypted data are realized. According to the method, dynamic accurate authority management and secure sharing of encrypted data can be realized, and dual requirements of data privacy protection and efficient circulation in a complex scene are met.
Owner:ZHONG YI DING SHENG JIAN SHE JI TUAN YOU XIAN GONG SI

A contactless cryptographic device centralized management method and system

The application relates to a contactless password device centralized management method and system, and relates to the technical field of information security, which comprises the following steps: setting a management strategy in an edge management node in a password device area network according to a pre-set management strategy; the application sets the management strategy in the edge management node in the password device area network, establishes a Bluetooth communication connection with a management server in the password device area, scans and identifies a target password device through a monitoring terminal, constructs a space map of the password device, establishes a Bluetooth safe communication channel between the monitoring terminal and the edge management node, unlocks corresponding management functions according to the authority range in the credentials after authentication, the edge management node analyzes application contents to generate operation constraints, automatically approves based on a dynamic risk assessment model, creates an isolated session and pre-distributes communication resources after the approval, safely reports operation logs and key states, and realizes the safe and reliable effect of the data transmission process.
Owner:BEIJING CATHAY INTERNET INFORMATION TECH CO LTD +1

Hardware identity restoration post-device repair

Embodiments described herein involve building upon a hardware identity of a device and using it to match and detect hardware changes on the device and to identify potential identity mismatches. At initialization, the device also generates a globally-unique identification (GUID) marker that persists across operating system (OS) reinstallations. On the device, there is a periodic routine that detects hardware mismatches by comparing the current identity of the device with a cached version, along with the GUID. Once a change is detected, the device sends a request to a service that stores a hint (e.g., the GUID) for a later secure restoration attempt. A remote service (e.g., a cloud-based service) then attempts to restore the hardware identity of the device upon next check-in via a secure transmission of the updated identity, as well as resolving conflicts in a device record maintained by the remote service.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Method to establish a secure channel

PendingUS20260155963A1Key distribution for secure communicationUser identity/authority verificationCloud service providerSecure channel
Method to establish a secure channel between the owner of a software payload and the software payload itself when running into a hardware-based trusted execution environment, HW TEE, at the instance of a cloud service provider, including sending, by the owner, a nonce to the software payload; generating, by the software payload, a payload key pair: public key and private key; mixing, by the software payload, the payload public key with the nonce; computing, by the HW TEE, an attestation using this nonce mixed with the payload public key; sending, by the software payload, the attestation, and the payload public key to the owner; verifying, by the owner, the attestation using the sent nonce mixed with the received payload public key; generating, by the software payload and the owner, a session key; and establishing a secure channel between the owner and the software payload running into the HW TEE.
Owner:THALES DIS FRANCE SA

An internet of things device access monitoring method and system based on security protection technology

This invention belongs to the field of device access monitoring technology and discloses a method and system for monitoring IoT device access based on security protection technology. The method includes the following steps: using QKD and FHE technologies, generating corresponding FHE key pairs between the new IoT device and the access point; using the new IoT device, periodically collecting its own multi-dimensional monitoring data features and encrypting and sending them to the access point; using the access point, receiving the encrypted multi-dimensional monitoring data features transmitted by the new IoT device and inputting the encrypted multi-dimensional monitoring data features into a security protection detection engine; based on the encrypted multi-dimensional monitoring data features, network environment data, and key freshness, using the security protection detection engine to perform detection, obtain, and execute the access control decision for the new IoT device. This invention solves the problems of low encryption security, low monitoring and anomaly detection capabilities, and lack of dynamic and intelligent access control in existing technologies.
Owner:BEIJING KAMUFU SCI&TECH CO LTD

Full remote attestation without hardware security assurances

A computing device may generate a zero-knowledge proof that the computing device has one or more properties and may send an indication of the zero-knowledge proof to a. computing system. The computing system may verify that the zero-knowledge proof proves the computing device has the one or more properties and may, in response to successfully verifying that the zero-knowledge proof proves the computing device has the one or more properties, grant the computing device permission to perform an action that requires the computing device to have the one or more properties.
Owner:GOOGLE LLC

Device and method for performing quantum secure-based internet key exchange protocol in quantum communication system

According to various embodiments of the present disclosure, a method performed by a first node may comprise the steps of: transmitting, to a second node, an IKE_SA_INIT request including a quantum-secure transform type and a transform identifier (ID) of a quantum key distribution (QKD); receiving, from the second node, an IKE_SA_INIT response including the quantum-secure transform type and the transform ID of the QKD; transmitting, to the second node through a quantum channel, a quantum key exchange (QKE) message including a quantum key (QK) length (QK length), a quantum key (QK) basis, and a quantum seed; and receiving, from the second node through a classical channel, a quantum bit error rate (QBER) message including a QBER associated with an initial quantum key based on the QKE message.
Owner:LG ELECTRONICS INC

Multi-scene password application detection system for intelligent connected vehicles

The application provides a multi-scene password application detection system of an intelligent connected vehicle, and belongs to the technical field of intelligent detection.The system comprises a simulation intelligent connected vehicle subsystem deploying a national secret algorithm, a simulation TSP cloud platform, a user terminal deploying a digital key APP, and a password application detection module.The password application detection module is used for password technology application data based on an inter-domain communication network in the vehicle, a vehicle-cloud remote communication network, and a human-vehicle near field communication network, and performs password application detection based on the national secret algorithm.The application verifies through simulation experiments that the intelligent connected vehicle applies the national secret algorithm to realize the effectiveness of a safe data communication mechanism in the three scenes of the inter-domain communication network in the vehicle, the vehicle-cloud remote communication network, and the human-vehicle near field communication network.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

Operating method of security system in environment in which user information receiving device and key security device are separated

An operating method of a security system for authenticating a user on the basis of fast identity online (FIDO) according to an embodiment of the present disclosure includes: receiving first user information through a user information receiving device connected to a key security device; storing feature information generated on the basis of the first user information in the key security device; receiving second user information of which authentication is requested through the user information receiving device; and receiving a token for allowing user access from a FIDO server in response to a case in which the key security device determines that authentication feature information generated on the basis of the second user information matches the feature information.
Owner:AIRCUVE INC +1

Quantum artificial intelligence and machine learning in a next generation mobile network

Aspects of the subject disclosure may include, for example, a method of receiving, by a quantum processing system including a hybrid quantum-classical processor, qubits from one or more quantum communication channels by the quantum processor or hybrid quantum-classical processor, wherein each quantum processor or hybrid quantum-classical processor is physically distinct, and wherein the one or more quantum communications channels utilize quantum channel coding and quantum error detection; performing, by the quantum processing system, quantum logic operations on the qubits; and utilizing a plurality of end-to-end quantum and hybrid quantum-classical networked application resources to implement quantum artificial intelligence (QAI) and / or quantum machine learning (QML) services. Other embodiments are disclosed.
Owner:AT&T INTELLECTUAL PROPERTY I L P +1

Secure database storage system based on secret sharing

The application provides a secret sharing based secure database storage system, wherein the client comprises: encrypting plaintext according to an initial segmentation scheme to obtain encrypted data; and sending a current segmentation scheme code as a signature of a target operation behavior instruction to a server; and the server comprises: performing N times of segmentation on the encrypted data in parallel by using a Shamir threshold secret sharing algorithm to obtain N groups of secret segmentation schemes; storing shares in the N groups of secret segmentation schemes into different databases respectively, assigning a segmentation scheme code to each group of secret segmentation schemes, and initializing a current segmentation scheme identifier; matching and verifying the signature and the current segmentation scheme identifier, and if the verification is passed, analyzing the target operation behavior instruction and performing corresponding operations on the stored data, and feeding back an execution result to the client. The application can effectively solve the low security problem of traditional data storage.
Owner:SHANGHAI YINAN TECHNOLOGY CO LTD