Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

185results about "Public key infrastructure trust models" patented technology

Systems and methods for implementing a service identity platform with cloud-based Public Key Infrastructure (PKI)

Systems and methods for implementing a service identity platform with cloud-based Public Key Infrastructure (PKI) include providing security as a service via a cloud-based system for a plurality of tenants, wherein the cloud-based system includes a plurality of components communicatively coupled and adapted to communicate with one another based on mutual Transport Layer Security (mTLS) authentication; responsive to a new component requiring deployment within the cloud-based system, performing an enrollment process for the new component; and subsequent to the enrollment process, utilizing the new component within the cloud-based system for providing security as a service.
Owner:ZSCALER INC

Hash-based digital signatures for hierarchical internet public key infrastructure

Techniques for signing internet data are disclosed. The techniques include accessing a plurality of internet data records. The techniques also include generating, using at least one electronic processor, leaf nodes from the plurality of internet data records, and constructing a recursive hash tree from the plurality of leaf nodes. The techniques also include deriving information sufficient to validate the root node, and publishing, in an internet public key infrastructure (PKI) as a synthesized public key, the information sufficient to validate the root node. The techniques also include providing, through the internet and as a signature on at least one of the plurality of internet data records, validation data including sibling path data from the recursive hash tree, such that an internet client validates the at least one of the internet data records using at least the validation data and the synthesized public key.
Owner:VERISIGN INC

Multi-party token-based authorization for a data storage system

Examples described herein provide a computer-implemented method that includes receiving, at a token generation service, a contract token request from a data non-owner, the contract token request indicating a condition of an agreement between the data non-owner and a data owner that owns data stored in a data storage system. The method further includes generating, by the token generation service, a contract token based on the contract token request, the contract token including an attribute that defines the condition of the agreement between the data non-owner and the data owner. The data storage system enables the data owner to execute an operation on the data based at least in part on the contract token.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

AI / ML and blockchained based automated reservoir management platform

A system for managing well site operations comprising a well site operations module, a chain of blocks of a distributed network, and a sensor bank and control module. The operations module generates earth model variables using a physics model, well log variables or seismic variables, or both, and a trained AI / ML algorithmic model. The chain of blocks comprises a plurality of subsequent blocks. Each subsequent block comprises a well site entry and a hash value of a previous well site entry. A well site entry comprises transacted operation control variables. The well site operations module generates production operation control variables or development operation control variables from earth model variables. The well site entry can also include transacted earth model variables and sensor variables. The sensor bank and control module provides well log variables and the operations module couples control variables to the control module to control well site equipment.
Owner:LANDMARK GRAPHICS CORP

Method, apparatus and device for constructing token for cloud platform resource access control

The present application discloses a method, apparatus and device for constructing a token for cloud platform resource access control. The method includes: acquiring a token application request of an authentication user; according to the token application request, generating an authorization metadata token corresponding to the authentication user; performing digital signature on the authorization metadata token by using a digital certificate, so as to generate a user token; and encrypting the user token by using a user public key, so as to generate an encrypted user token, and sending the encrypted user token and the digital certificate to a client of the authentication user, so that the client performs resource access challenge response by using the authorization metadata token.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

Systems and methods for data authentication using composite keys and signatures

A system for enhanced public key infrastructure is provided. The system includes a computer device. The computer device is programmed to receive a digital certificate including a composite signature field including a plurality of signatures. The plurality of signatures includes at least a first signature and a second signature. The computer device is also programmed to retrieve, from the digital certificate, a first key associated with the first signature from the digital certificate. The computer device is further programmed to retrieve the first signature from the composite signature field. In addition, the at least one computer device is programmed to validate the first signature using the first key.
Owner:CABLE TELEVISION LAB INC

Cryptographic attestation of data object attributes in a distributed system

A request to provide a data object attestation authority certificate to a second cluster of secure environments is received at a first cluster of secure environments. The request comprises a cluster certificate of the second cluster issued by a cluster enrollment certificate authority (CA). The cluster certificate is validated using a public key of the enrollment CA. An encrypted message comprising the attestation authority certificate and a digital signature of the first cluster is generated. The encrypted message is encrypted using a public key indicated in the cluster certificate of the second cluster. The digital signature is associated with a cluster certificate of the first cluster issued by the enrollment CA. The encrypted message is provided to the second cluster to be decrypted using a private key associated with the cluster certificate of the second cluster, and to be validated using at least the public key of the enrollment CA.
Owner:FORTANIX INC

Method of operating a public key certificate validation system for facilitating a secure communication between an aircraft and a ground entity

A method of operating a public key certificate validation system for facilitating a secure communication between an aircraft and a ground entity includes: sending a public key certificate of the ground entity from the ground entity to a trusted responder; at the trusted responder, validating the public key certificate of the ground entity and storing a trust indication regarding the public key certificate of the ground entity in a pre-cached validation database; and at the trusted responder, maintaining the pre-cached validation database for providing a validation response regarding the public key certificate of the ground entity, when a validation request, associated with the secure communication between the aircraft and the ground entity, reaches the trusted responder, wherein the validation response is based on the trust indication regarding the public key certificate of the ground entity from the pre-cached validation database.
Owner:ARINC INC

Smart contract executed within a blockchain

There is provided a method and system for selection of response message(s), comprising: receiving from an initiator client terminal a function message including an unencrypted target value and a public key, receiving respective response messages to the function message from responding client terminals, each respective response comprising an unencrypted partial value of the target value and a parameter encrypted with the pubic key, receiving, from the initiator client terminal, a selection of response message(s) according to a ranking of the encrypted parameters, wherein a sum of the unencrypted partial values of the selected response message(s) is according to a requirement of the target value, and receiving a validation for the selected response message(s) from corresponding responding client terminals, wherein each of the corresponding responding client terminals is provided with all partial values and all unencrypted parameters associated with all of the selected response message(s).
Owner:LENDOIT TECH ISRAEL LTD

Chain of authentication using public key infrastructure

A method for sequential authentication based on chain of authentication using public key infrastructure (PKI) is provided. The method includes generating, by a user, a first private key and a first public key corresponding to each other; generating, by an nth service provider, an nth private key and an nth public key corresponding to each other; transmitting, from the user to the nth service provider, a level n key; verifying, by the nth service provider, the level n key; generating, by the nth service provider, a level (n+1) key by concatenating the level n key and the nth public key signed with the nth private key; and transmitting, by the nth service provider, the level (n+1) key to the user, where n is a natural number, and when n=1, the level 1 key is the first public key signed with the first private key.
Owner:CHOI OK

Method and apparatus for automatic digital certificate validation

The public key can be recorded on the blockchain by the certificate authority in such a way that any third party can quickly and easily verify that the public key is certified by the certificate authority and that the certification has not been revoked. The certificate authority can revoke a certification almost instantaneously, and / or can certify a new key for the same entity at the same time as revoking the old key. The verification can be incorporated into a new transaction so that there is no gap between reliance on the certificate and verification of its validity. In some cases, each transaction in which a certificate is used can also serve as a certification transaction that links to update the certificate to enable subsequent use.
Owner:ENCHEN CHARTER CO LTD

A method for handling connection loss during a sharing process of a digital vehicle access key, a system for carrying out the method and a hardware token

The invention relates to a method for handling connection loss during a sharing process of a digital vehicle access key from a sharing device to a hardware token in a digital , comprising detecting a loss of communication between the hardware token and the sharing device during the sharing process of a digital key; attempting to restore the communication and retrying the failed sub-sequence of commands; continuing the sharing process once the communication is successfully re-established. The invention also relates to a system for carrying out this method and to a hardware token.
Owner:BAYERISCHE MOTOREN WERKE AG

Computational function transformation (CFT) in computer implemented cryptography

Data is processed by cryptographic operations selected from encryption, decryption, hashing, and public key exchange (PKI). Data elements are processed as n-state data elements with n an integer at least greater than 3 based on an n-state reversible n-state inverter. The n-state reversible inverter is a self-propagating n-state inverter generating different other n-state reversible inverters. The n-state reversible inverter is derived from a sequence of n n-state data elements with at least a first n-state data element occurring at least twice in different positions in the sequence and a second n-state data element not occurring. The n-state reversible inverter is created from the sequence of n-state data elements. A sequence of n n-state elements is created from a set of k n-state elements with k smaller than n. The k n-state elements are provided by a public key exchange method.
Owner:LABLANS PETER MR

Advanced authentication techniques and applications

A system, apparatus, method, and machine-readable medium are described for performing advanced authentication techniques and associated applications. For example, one embodiment of a method comprises: receiving a policy identifying a set of acceptable authentication capabilities; determining a set of client authentication capabilities; and filtering the set of acceptable authentication capabilities based on the determined set of client authentication capabilities to arrive at a filtered set of one or more authentication capabilities for authenticating a user of the client.
Owner:NOK NOK LABS INC

PKI smart-card threat detection and endpoint use visibility

Provided is a Middleware comprising an Event Generator to generate events related to access and usage of the authenticator device by one or more apps executing on an end-point; an Event Viewer that makes visible events related to certificate based PKI authenticator device interactions by the one or more apps; and an Event Uploader to upload the events. An Analytics Engine on a server side identifies an application usage status of the authenticator device in view of event and application correlations, builds analytics on usage patterns from the application usage status on PKI authenticator device interactions by the one or more apps, and reports anomalies and potential attacks on the authenticator device in view of the analytics based on an event threat analysis.
Owner:THALES DIS CPL USA INC

Using a single AES key to encrypt PKCS #7 files

Cryptographic systems and methods are provided. A method, according to one implementation, includes a step of generating a plurality of key pairs in response to receiving a request from a client for one or more digital certificates. The key pairs are associated respectively with the one or more digital certificates. Also, each key pair includes a public key and a private key. The method further includes a step of utilizing at least the plurality of key pairs to generate the one or more digital certificates. Also, the method includes a step of encrypting the one or more digital certificates and respective private keys using a single Advanced Encryption Standard (AES) key. The method also includes a step of sending the encrypted one or more digital certificates and private keys back to the client.
Owner:DIGICERT INC

Methods and systems for using smart network interface cards to secure data transmission between an initiator host running an object and a target host equipped with a disaggregated hardware device that satisfies hardware specifications of the object

This disclosure is directed to methods and systems that establish a secure data channel between a host and a disaggregated hardware device (“DHD”) of a data center. The system comprises an initiator host that runs objects, such as virtual machines and containers. The host includes an initiator smart network interface card (“SNIC”). The initiator SNIC includes a virtual device, a trust platform module (“TPM”) and a security engine. The system also comprises a target host equipped with a DHD and a target SNIC. The target SNIC includes a TPM and a security engine. The TPM and the security engine of the initiator SNIC and the TPM and the security engine of the target SNIC establish a secure data channel between an object running on the host and the DHD.
Owner:VMWARE INC

Vehicle communication system and vehicle communication methods

Vehicle communication system, comprehensive: an on-board device (130); and one or more vehicle controllers (120) connected to a vehicle network (NW1, NW2) wherein the on-board device (130) is configured to perform the following steps: Transmitting an encrypted message (MS), encrypted outside of a vehicle, to one or more vehicle controllers (120) connected to the vehicle network (NW1, NW2); and if the encrypted message (MS) is an individual message to one of the vehicle controllers (120), transmission of the encrypted message (MS) to one of the vehicle controllers (120) via the vehicle network (NW1, NW2); and if the encrypted message (MS) is a common message to the one or more vehicle controllers (120), decrypt the encrypted message (MS) using an encryption key (K2, K5) belonging to the on-board device (130), and then transmit the decrypted message to the one or more vehicle controllers (120) via the vehicle network (NW1, NW2).
Owner:TOYOTA JIDOSHA KK

Public key infrastructure based session authentication

Techniques are disclosed for public key infrastructure (PKI) based session authentication. An example network device includes one or more processors and memory coupled to the one or more processors. The memory stores instructions that, upon execution, cause one or more processors to: receive, from a source client device, a packet including a header for routing the packet to a destination client device specified within the header and metadata distinct from the header, the metadata specifying public key infrastructure (PKI) information and identity context information identifying a user or device participating in a session between the source client device and the destination client device; verify, based on the PKI information within the metadata, the metadata; and in response to verifying the metadata, apply, based on the identity context information, one or more policy rules for the session associated with the packet.
Owner:JUNIPER NETWORKS INC

Computer-implemented method for secure communication, computer-readable medium, and system for secure communication

The invention relates to a Computer-implemented method for secure communication between a first entity (A) and a second entity (B), wherein the first entity (A) is associated with a first public key (PKA) and a corresponding first private key (SKA), and the second entity (B) is associated with a second public key (PKB) and a corresponding second private key (SKB), and wherein the method comprising the following steps: a) requesting, by the second entity (B), the first public key (PKA) from a communication network security database, in particular hosted on a server (20); b) receiving, by the second entity (B), at least the following data: - the first public key (PKA); - a first key verification mechanism (IPA) associated with the first public key (PKA); - database integrity data (RH) related to the communication network security database; c) verifying, by the second entity (B), the first public key (PKA) using the first key verification mechanism (IPA); d) sending, by the second entity (B) to the first entity (A), at least the following data: - the first key verification mechanism (IPA); - the database integrity data (RH); and - a first message (M1) being asymmetrically encrypted with the first public key (PKA) and signed with the second private key (SKB); e) verifying, by the first entity (A), the first public key (PKA) using the first key verification mechanism (IPA); f) decrypting, by the first entity (A), the first message (M1) using the first private key (SKA); g) verifying, by the first entity (A), an integrity and authenticity of the first message (M1) using the second public key (PKB).
Owner:PLANCK SECURITY SA

Certificate chain compression to extend node operational lifetime

A battery-powered device (BPD) node compresses certificate chains to generate compressed certificate chains. The BPD node includes a compression dictionary that indexes various data entries that occur across many certificate chains and / or repeat within a particular certificate chain. The BPD node compresses a given certificate chain by replacing data entries within the given certificate chain with indices to corresponding data entries in the compression dictionary. The indices are smaller in size than the corresponding data entries. A neighboring BPD node also includes the compression dictionary and decompresses a compressed certificate chain by replacing indices included in the compressed certificate chain with the indexed data entries stored in the compression dictionary. Performing certificate exchanges with compressed certificate chains reduces the amount of limited battery power that is depleted during certificate exchanges, thereby extending BPD node operational lifetime and helping to prevent the need for premature battery replacement.
Owner:ITRON INC

Software distribution in wireless AD HOC networks for AD-HOC data processing at source nodes

This application relates to software distribution in wireless AD HOC networks for AD-HOC data processing on source nodes, a method of acquiring software by a source node in a wireless ad hoc network is disclosed. The method includes the source node executing an application software, identifying from the application software a need to process a particular data modality, and determining that the source node is unable to process the particular data modality. In response to the determination, the source node searches a local module repository (MR) of the source node for a software module usable to process the particular data modality, and in response to the source node failing to locate the software module in the local MR, broadcasts a request for the software module to a neighbor node of a plurality of nodes within radio range of the source node. The source node receives the software module from the neighbor node and processes the particular data modality using the software module.
Owner:THE BOEING CO

Software integrity protection and verification method, and device

Embodiments of this application disclose a software integrity protection method and apparatus, and a software integrity verification method and apparatus. A protection process includes: A first device obtains a first software package, where the first software package includes a first signature made by a first party for a second software package by using a first private key; and the first device performs a signing operation on the first software package by using a second private key, to obtain a third software package including a second signature, where the first private key is controlled by the first party, and the second private key is controlled by a second party. After the third software package is sent to a second device, a verification process includes: The second device obtains the first software package, where the first software package includes the first signature, the second signature, and the second software package; and the second device verifies the first signature and the second signature respectively based on a first public key and a second public key that are prestored, to obtain a verification result. In this way, software integrity protection is performed by using keys provided by a manufacturer and a user, to provide the user with a dual software integrity verification basis, and a trust issue is resolved for the user.
Owner:HUAWEI TECH CO LTD

Accessing hosts in a computer network

A security function is provided by an intermediate device located between hosts and devices requesting for access to the hosts in a computerized network. The intermediate device receives a request for access to a host, and obtains at least one authenticator for use in the requested access to the host. The intermediate device then monitors for communications that use the at least one authenticator.
Owner:SSH COMMUNICATIONS SECURITY

Cryptographic apparatus administrated remotely from a high-security trust center

Cryptographic apparatus (41) administrated remotely from a high-security trust center (30) comprising, - a service interface (43) configured to receive a request for processing a data object, and to output in return at least a resulting data object, - a processing module (45) comprising an access-controlled storage element (47) storing at least one cryptographic key and a cryptographic processing element (46) configured for processing the data object using the at least one cryptographic key, and - an administration interface (44) configured to establish a mutually authenticated communication connection (49) with the high-security trust center (30) for administrating the processing module (45) by the high-security trust center (30).
Owner:SIEMENS AG

Public key infrastructure based session authentication

Techniques are disclosed for public key infrastructure (PKI) based session authentication. An example network device includes one or more processors and memory coupled to the one or more processors. The memory stores instructions that, upon execution, cause one or more processors to: receive, from a source client device, a packet including a header for routing the packet to a destination client device specified within the header and metadata distinct from the header, the metadata specifying public key infrastructure (PKI) information and identity context information identifying a user or device participating in a session between the source client device and the destination client device; verify, based on the PKI information within the metadata, the metadata; and in response to verifying the metadata, apply, based on the identity context information, one or more policy rules for the session associated with the packet.
Owner:JUNIPER NETWORKS INC