Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

305results about "Public key infrastructure trust models" patented technology

Methods, architectures, apparatuses, and systems for decentralized data control and access management

Procedures, methods, architectures, apparatuses, systems, devices, and computer program products for decentralized data control and access management. For example, a data owner may perform a subscription procedure to obtain verification credentials and an index (e.g., address, identifier) to public data control and access information. The data owner may perform a registration procedure to register ownership of data using the public data control and access information. The public data control and access information may include a public key. The public key is paired with a private trapdoor key to form a key pair. The data owner and a data consumer may perform an access procedure to grant access to registered data. For example, the registration procedure may verify collisions between a token hash, a data hash, and a data owner hash based on use of the key pair.
Owner:INTERDIGITAL PATENT HOLDINGS INC

Systems and methods for implementing a service identity platform with cloud-based Public Key Infrastructure (PKI)

Systems and methods for implementing a service identity platform with cloud-based Public Key Infrastructure (PKI) include providing security as a service via a cloud-based system for a plurality of tenants, wherein the cloud-based system includes a plurality of components communicatively coupled and adapted to communicate with one another based on mutual Transport Layer Security (mTLS) authentication; responsive to a new component requiring deployment within the cloud-based system, performing an enrollment process for the new component; and subsequent to the enrollment process, utilizing the new component within the cloud-based system for providing security as a service.
Owner:ZSCALER INC

OTA security update method and system for intelligent connected vehicles

An OTA security update method and system for intelligent connected vehicles are provided. The method includes: the downloaded software update packet from a CDN to UC-master is decrypted, and verified for the first time through signature verification; for the secondary verification, decomposing a current software update packet into a plurality of sub-packets; calculating HASH values of the sub-packets in sequence; thereafter, constructing a Merkle tree according to these HASH values; calculating a root HASH value of the Merkle tree; after the sub-packets are transferred from a UC-master to ECU-UAs through a gateway or a domain controller, recalculating the HASH values of the sub-packets; reconstructing the Merkle tree according to these HASH values; recalculating the root HASH value of the Merkle tree; comparing the two HASH values; if they are equal, starting a normal update procedure; otherwise, terminating this OTA update by the UC-master immediately.
Owner:CHANGZHOU INST OF TECH

Hosted device provisioning protocol with servers and a networked initiator

A network can operate a WiFi access point with credentials. An unconfigured device can (i) support a Device Provisioning Protocol (DPP), (ii) record responder bootstrap public and private keys, and (iii) be marked with a tag. The network can record initiator bootstrap public and private keys, as well as derived initiator ephemeral public and private keys. An initiator can (i) operate a DPP application, (ii) read the tag, (iii) establish a secure and mutually authenticated connection with the network, and (iv) send the network data within the tag. The network can record the responder bootstrap public key and derive an encryption key with the (i) recorded responder bootstrap public key and (ii) derived initiator ephemeral private key. The network can encrypt credentials using the derived encryption key and send the encrypted credentials to the initiator, which can forward the encrypted credentials to the device, thereby supporting a device configuration.
Owner:META PLATFORMS INC

AI / ML, distributed computing, and blockchained based reservoir management platform

A system, for controlling well site operations, comprising a machine learning engine, a predictive engine, a node system stack, and a blockchain. The learning engine includes a machine learning algorithm, an algorithmically generated earth model, and control variables. The learning algorithm generates a trained data model using the algorithmically generated earth model. The predictive engine includes an Artificial Intelligence (AI) algorithm. The AI algorithm generates a trained AI algorithm using the trained data model and earth model variables using the trained AI algorithm. The system stack is communicable coupled to the predictive engine, the learning engine, the blockchain, sensors, and a machine controller. The blockchain having a genesis block and a plurality of subsequent blocks. Each subsequent block comprising a well site entry and a hash of a previous entry. The well site entry comprises transacted operation control variables. The transacted variables are based on the generated earth model variables.
Owner:LANDMARK GRAPHICS CORP

Hash-based digital signatures for hierarchical internet public key infrastructure

Techniques for signing internet data are disclosed. The techniques include accessing a plurality of internet data records. The techniques also include generating, using at least one electronic processor, leaf nodes from the plurality of internet data records, and constructing a recursive hash tree from the plurality of leaf nodes. The techniques also include deriving information sufficient to validate the root node, and publishing, in an internet public key infrastructure (PKI) as a synthesized public key, the information sufficient to validate the root node. The techniques also include providing, through the internet and as a signature on at least one of the plurality of internet data records, validation data including sibling path data from the recursive hash tree, such that an internet client validates the at least one of the internet data records using at least the validation data and the synthesized public key.
Owner:VERISIGN INC

Method and system for authentication credential

An issuing authority (IA) may validate the identity of a user and issue a digital license to the user. IA may generate IA public-private key pair, and provide IA public key to the certification authority (CA). IA may sign the digital license with IA private key, and provision the signed digital license on the user device. IA may request CA to certify the digital license. CA may use IA public key to validate the digital license, and sign IA public key with CA private key, thereby generating a digital certificate associated with the issuing authority that is linked to the digital license. A relying party may use CA public key to validate the digital license. The relying party can retrieve the information from the digital license and trust that the retrieved information is legitimate.
Owner:VISA INTERNATIONAL SERVICE ASSOCIATION

Private service edge nodes in a cloud-based system for private application access

Systems and methods include, connecting to a first service edge node in a cloud-based system and obtaining one or more addresses each for one or more service edge nodes in the cloud-based system, wherein the one or more service edge nodes include public service edge nodes and private service edge nodes; connecting to a second service edge node of the one or more service edge nodes using the corresponding address; providing a request for an application to the second service edge node; and responsive to policy and accessibility determined via the cloud-based system, receiving access to the application via a connector adjacent to the application.
Owner:ZSCALER INC

Multi-party token-based authorization for a data storage system

Examples described herein provide a computer-implemented method that includes receiving, at a token generation service, a contract token request from a data non-owner, the contract token request indicating a condition of an agreement between the data non-owner and a data owner that owns data stored in a data storage system. The method further includes generating, by the token generation service, a contract token based on the contract token request, the contract token including an attribute that defines the condition of the agreement between the data non-owner and the data owner. The data storage system enables the data owner to execute an operation on the data based at least in part on the contract token.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

AI / ML and blockchained based automated reservoir management platform

A system for managing well site operations comprising a well site operations module, a chain of blocks of a distributed network, and a sensor bank and control module. The operations module generates earth model variables using a physics model, well log variables or seismic variables, or both, and a trained AI / ML algorithmic model. The chain of blocks comprises a plurality of subsequent blocks. Each subsequent block comprises a well site entry and a hash value of a previous well site entry. A well site entry comprises transacted operation control variables. The well site operations module generates production operation control variables or development operation control variables from earth model variables. The well site entry can also include transacted earth model variables and sensor variables. The sensor bank and control module provides well log variables and the operations module couples control variables to the control module to control well site equipment.
Owner:LANDMARK GRAPHICS CORP

Temporal key generation and PKI gateway

Temporal key generation devices and methods are described. One such device of a first domain receives a “seed” to generate a private key associated with a public key for use in a second domain. The device uses the private key in cryptographic operations with the second domain. When the device loses power or is no longer connected to the second domain, the private key may be erased or no longer stored on the device.
Owner:SULPIZIO JR RONALD FRANCIS

Method, apparatus and device for constructing token for cloud platform resource access control

The present application discloses a method, apparatus and device for constructing a token for cloud platform resource access control. The method includes: acquiring a token application request of an authentication user; according to the token application request, generating an authorization metadata token corresponding to the authentication user; performing digital signature on the authorization metadata token by using a digital certificate, so as to generate a user token; and encrypting the user token by using a user public key, so as to generate an encrypted user token, and sending the encrypted user token and the digital certificate to a client of the authentication user, so that the client performs resource access challenge response by using the authorization metadata token.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

Systems and methods for securing access rights to resources using cryptography and the blockchain

The present disclosure generally relates to securing access to resource and access rights using cryptography and the blockchain. Certain embodiments of the present disclosure generally relate to systems and methods that enhance the security of resource access using hierarchical deterministic (HD) cryptography and the blockchain. Certain embodiments of the present disclosure relate to systems and methods that securely and anonymously represent the identity of a user and the user's access code data on a distributed ledger represented across the blockchain.
Owner:LIVE NATION ENTERTAINMENT INC

Remote attestation transport layer security and split trust encryption

A method for remote attestation includes establishing, using a cryptographic protocol, a communication session between a first computing device and a second computing device. The communication session includes communications encrypted by an ephemeral session key. The method includes receiving, at the first communication device via the communication session, from the second computing device, an attestation request requesting the first computing device to provide an attestation report. The method includes generating, by the first computing device, the attestation report based on the ephemeral session key and sending, using the communication session, the attestation report to the second computing device.
Owner:GOOGLE LLC

Systems and methods for data authentication using composite keys and signatures

A system for enhanced public key infrastructure is provided. The system includes a computer device. The computer device is programmed to receive a digital certificate including a composite signature field including a plurality of signatures. The plurality of signatures includes at least a first signature and a second signature. The computer device is also programmed to retrieve, from the digital certificate, a first key associated with the first signature from the digital certificate. The computer device is further programmed to retrieve the first signature from the composite signature field. In addition, the at least one computer device is programmed to validate the first signature using the first key.
Owner:CABLE TELEVISION LAB INC

Cryptographic attestation of data object attributes in a distributed system

A request to provide a data object attestation authority certificate to a second cluster of secure environments is received at a first cluster of secure environments. The request comprises a cluster certificate of the second cluster issued by a cluster enrollment certificate authority (CA). The cluster certificate is validated using a public key of the enrollment CA. An encrypted message comprising the attestation authority certificate and a digital signature of the first cluster is generated. The encrypted message is encrypted using a public key indicated in the cluster certificate of the second cluster. The digital signature is associated with a cluster certificate of the first cluster issued by the enrollment CA. The encrypted message is provided to the second cluster to be decrypted using a private key associated with the cluster certificate of the second cluster, and to be validated using at least the public key of the enrollment CA.
Owner:FORTANIX INC

Method of operating a public key certificate validation system for facilitating a secure communication between an aircraft and a ground entity

A method of operating a public key certificate validation system for facilitating a secure communication between an aircraft and a ground entity includes: sending a public key certificate of the ground entity from the ground entity to a trusted responder; at the trusted responder, validating the public key certificate of the ground entity and storing a trust indication regarding the public key certificate of the ground entity in a pre-cached validation database; and at the trusted responder, maintaining the pre-cached validation database for providing a validation response regarding the public key certificate of the ground entity, when a validation request, associated with the secure communication between the aircraft and the ground entity, reaches the trusted responder, wherein the validation response is based on the trust indication regarding the public key certificate of the ground entity from the pre-cached validation database.
Owner:ARINC INC

Authentication chain using public key infrastructure

A sequential authentication method based on an authentication chain using a public key infrastructure (PKI) is provided. The method comprises: receiving, by an nth party from an (n-1) th party, an (n-1) th modified public key; generating an nth private key and an nth public key which correspond to each other by the nth party; generating, by the nth party, an nth modified public key by concatenating the (n-1) th modified public key and the nth public key signed with the nth private key; the nth modified public key is transmitted by the nth party, where n is a natural number greater than 1, and when n = 2, the first modified public key is the first public key signed with the first private key.
Owner:崔云虎

Smart contract executed within a blockchain

There is provided a method and system for selection of response message(s), comprising: receiving from an initiator client terminal a function message including an unencrypted target value and a public key, receiving respective response messages to the function message from responding client terminals, each respective response comprising an unencrypted partial value of the target value and a parameter encrypted with the pubic key, receiving, from the initiator client terminal, a selection of response message(s) according to a ranking of the encrypted parameters, wherein a sum of the unencrypted partial values of the selected response message(s) is according to a requirement of the target value, and receiving a validation for the selected response message(s) from corresponding responding client terminals, wherein each of the corresponding responding client terminals is provided with all partial values and all unencrypted parameters associated with all of the selected response message(s).
Owner:LENDOIT TECH ISRAEL LTD

Chain of authentication using public key infrastructure

A method for sequential authentication based on chain of authentication using public key infrastructure (PKI) is provided. The method includes generating, by a user, a first private key and a first public key corresponding to each other; generating, by an nth service provider, an nth private key and an nth public key corresponding to each other; transmitting, from the user to the nth service provider, a level n key; verifying, by the nth service provider, the level n key; generating, by the nth service provider, a level (n+1) key by concatenating the level n key and the nth public key signed with the nth private key; and transmitting, by the nth service provider, the level (n+1) key to the user, where n is a natural number, and when n=1, the level 1 key is the first public key signed with the first private key.
Owner:CHOI OK

Method and apparatus for automatic digital certificate validation

The public key can be recorded on the blockchain by the certificate authority in such a way that any third party can quickly and easily verify that the public key is certified by the certificate authority and that the certification has not been revoked. The certificate authority can revoke a certification almost instantaneously, and / or can certify a new key for the same entity at the same time as revoking the old key. The verification can be incorporated into a new transaction so that there is no gap between reliance on the certificate and verification of its validity. In some cases, each transaction in which a certificate is used can also serve as a certification transaction that links to update the certificate to enable subsequent use.
Owner:ENCHEN CHARTER CO LTD

Systems and methods for communication, storage and processing of data provided by an entity over a blockchain network

A computer-implemented method for submitting feedback for an entity to a blockchain is disclosed. The method, which is implemented at one of a plurality of participating nodes, includes: obtaining a first key, the first key being one of a fixed set of keys distributed to participating nodes that are eligible to submit feedback for the entity; generating first feedback (rj) of the entity for submission to the blockchain; encrypting the first feedback (rj) using at least the first key; and submitting the encrypted first feedback to a mixing service, the mixing service being configured to generate a mixed transaction based on the encrypted first feedback and at least one other encrypted feedback submission from one or more eligible participating nodes.
Owner:NCHAIN LICENSING AG

A method for handling connection loss during a sharing process of a digital vehicle access key, a system for carrying out the method and a hardware token

The invention relates to a method for handling connection loss during a sharing process of a digital vehicle access key from a sharing device to a hardware token in a digital , comprising detecting a loss of communication between the hardware token and the sharing device during the sharing process of a digital key; attempting to restore the communication and retrying the failed sub-sequence of commands; continuing the sharing process once the communication is successfully re-established. The invention also relates to a system for carrying out this method and to a hardware token.
Owner:BAYERISCHE MOTOREN WERKE AG

Computational function transformation (CFT) in computer implemented cryptography

Data is processed by cryptographic operations selected from encryption, decryption, hashing, and public key exchange (PKI). Data elements are processed as n-state data elements with n an integer at least greater than 3 based on an n-state reversible n-state inverter. The n-state reversible inverter is a self-propagating n-state inverter generating different other n-state reversible inverters. The n-state reversible inverter is derived from a sequence of n n-state data elements with at least a first n-state data element occurring at least twice in different positions in the sequence and a second n-state data element not occurring. The n-state reversible inverter is created from the sequence of n-state data elements. A sequence of n n-state elements is created from a set of k n-state elements with k smaller than n. The k n-state elements are provided by a public key exchange method.
Owner:LABLANS PETER MR

Advanced authentication techniques and applications

A system, apparatus, method, and machine-readable medium are described for performing advanced authentication techniques and associated applications. For example, one embodiment of a method comprises: receiving a policy identifying a set of acceptable authentication capabilities; determining a set of client authentication capabilities; and filtering the set of acceptable authentication capabilities based on the determined set of client authentication capabilities to arrive at a filtered set of one or more authentication capabilities for authenticating a user of the client.
Owner:NOK NOK LABS INC

PKI smart-card threat detection and endpoint use visibility

Provided is a Middleware comprising an Event Generator to generate events related to access and usage of the authenticator device by one or more apps executing on an end-point; an Event Viewer that makes visible events related to certificate based PKI authenticator device interactions by the one or more apps; and an Event Uploader to upload the events. An Analytics Engine on a server side identifies an application usage status of the authenticator device in view of event and application correlations, builds analytics on usage patterns from the application usage status on PKI authenticator device interactions by the one or more apps, and reports anomalies and potential attacks on the authenticator device in view of the analytics based on an event threat analysis.
Owner:THALES DIS CPL USA INC