Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

12 results about "Attribute-based encryption" patented technology

Attribute-based encryption is a type of public-key encryption in which the secret key of a user and the ciphertext are dependent upon attributes (e.g. the country in which he lives, or the kind of subscription he has). In such a system, the decryption of a ciphertext is possible only if the set of attributes of the user key matches the attributes of the ciphertext.

A method for access control with distinguished permissions based on attribute-based encryption

The application relates to a kind of attribute-based encryption-based differentiated permission access control methods, and belongs to the field of attribute cryptography and access control technology.The application adopts hybrid encryption mechanism, encrypts shared data using symmetric encryption system, and encrypts symmetric key using attribute-based encryption system, and only when the key associated attributes of a user meet the access control policy, the user can decrypt to obtain the symmetric key, and then decrypt to obtain the shared data plaintext using the symmetric key.In order to ensure the integrity and non-repudiation of shared data, the private key of the data owner is used for signing while the data owner generates the ciphertext.By using symmetric encryption mechanism and attribute-based encryption system, attribute-based, fine-grained permission control is realized, and the encryption and decryption efficiency of data is ensured.
Owner:BEIJING INST OF COMP TECH & APPL

Data distribution system, data distribution method, and data distribution program

PendingUS20260067074A1Key distribution for secure communicationAttribute-based encryptionDistribution method
A data distribution system that distributes an encrypted data from a transmitting device to a receiving device via a relay device with support by a key issuing device, wherein the key issuing device is configured to generate public parameters for ElGamal encryption and a secret key for attribute-based encryption, send the public parameters to the transmitting device and keep the secret key; and the transmitting device is configured to encrypt data by the public parameters, create a user defined policy for each data ID, attach the defined policy for the corresponding data ID to the encrypted data and send the encrypted data with the user defined policy to the relay device.
Owner:NEC CORP

Data distribution system, data distribution method, and data distribution program

PendingJP2026044418AKey distribution for secure communicationAttribute-based encryptionDistribution method
The workload on the data transmission device is reduced. [Solution] A data distribution system that distributes encrypted data from a transmitting device to a receiving device via a relay device with the support of a key issuing device, wherein the key issuing device is configured to generate public parameters for ElGamal encryption and a private key for attribute-based encryption, transmit the public parameters to the transmitting device, and retain the private key, and the transmitting device is configured to encrypt data using the public parameters, create a user-defined policy for each data ID, attach the policy defined for the corresponding data ID to the encrypted data, and transmit the encrypted data together with the user-defined policy to the relay device.
Owner:NEC CORP

Data sovereignty gateway for telemetry signals

PCT designated stageWO2026069060A1Multiple keys/algorithms usageUser identity/authority verificationAttribute-based encryptionCiphertext
A method, system, and computer program product are configured to: receive a telemetry message in a telemetry pipeline; determine a classification of the telemetry message; select, based on the classification of the telemetry message, an attribute-based encryption (ABE) ciphertext from plural different ABE ciphertexts, wherein each respective one of the plural different ABE ciphertexts is encoded with a respective data sovereignty policy; attach the ABE ciphertext to the telemetry message; and forward the telemetry message with the ABE ciphertext to a data sovereignty gateway.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION +2

Access control and protection of telemetry signals using attribute-based encryption

A system, method and computer program product are configured to: receive, at a telemetry backend, a request for telemetry data from a user, the request including an attribute-based encryption (ABE) ciphertext associated with the user; attempt to decrypt the ABE ciphertext using plural different ABE decryption keys; successfully decrypt the ABE ciphertext using a respective one of the plural different ABE decryption keys; and based on the successfully decrypting the ABE ciphertext using the respective one of the plural different ABE decryption keys, provide the user with access to telemetry data stored in a respective one of plural storage partitions associated with the respective one of the plural different ABE decryption keys, wherein the telemetry data stored in the respective one of plural storage partitions includes the telemetry data requested by the user.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Cross-chain data transmission method and system

The application discloses a cross-chain data transmission method and system, relates to the technical field of blockchains, and applies to a data possession end. The method comprises the following steps: generating a corresponding linear key matrix according to an access strategy of each attribute; encrypting to-be-transmitted data according to a security vector set and the linear key matrix to obtain target encrypted ciphertext; sending the target encrypted ciphertext to a main chain, and storing the target encrypted ciphertext to a target storage position through the main chain, so that a data user end obtains the target encrypted ciphertext through a relay chain and a parallel chain. The blockchains in the data transmission system are divided into the main chain, the parallel chain and the relay chain. Then, data is stored on a distributed storage network. Finally, an attribute-based encryption algorithm is used to resist quantum attacks and ensure the safety of data in the transmission process, so that the overall execution efficiency, the computing performance and the system safety of the blockchain network data transmission are improved.
Owner:CHINA MOBILE ZIJIN INNOVATION INST CO LTD +2

Data sovereignty gateway for telemetry signals

PendingUS20260088991A1Key distribution for secure communicationAttribute-based encryptionCiphertext
A method, system, and computer program product are configured to: receive a telemetry message in a telemetry pipeline; determine a classification of the telemetry message; select, based on the classification of the telemetry message, an attribute-based encryption (ABE) ciphertext from plural different ABE ciphertexts, wherein each respective one of the plural different ABE ciphertexts is encoded with a respective data sovereignty policy; attach the ABE ciphertext to the telemetry message; and forward the telemetry message with the ABE ciphertext to a data sovereignty gateway.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Attribute based encryption with bounded collusion resistance

An attribute based encryption system includes a key generator configured to generate a cyclic group (G) having a prime order q; generate an attribute key matrix (M); generate a master public key (MPK) based, at least in part, on the group (G) and (M); generate a master secret key (MSK) based on a first vector s and a second vector t that represent an encryption policy; generate a user secret key based, at least in part, on the MSK and on a set of one or more user attributes; and send the user secret key to a user device, wherein a ciphertext message can be successfully decrypted if a vector y associated with attributes of the user associated with the user secret key is orthogonal to each row of a set of rows of M selected according to a set of authorization attributes used to encrypt the ciphertext message.
Owner:SRI INTERNATIONAL

Defense system for information security of trusted data space

The invention relates to the technical field of information security defense, in particular to a defense system for information security of a trusted data space. The system comprises a data encryption module, an environment verification module, a response execution module, a data use monitoring module and a block chain evidence storage module. According to the data sensitivity and the real-time network delay, the bit number of the security key is dynamically selected, the attribute-based encryption or proxy re-encryption technology is adopted, the data and the executable strategy are packaged into the trusted data unit, when the data reach the edge node, the credibility of the node environment is strictly verified through integrity measurement and remote certification, and the reliability of the node environment is improved. And after the verification is passed, dynamic authorization is performed in combination with a real-time context, the data is decrypted for use, whether to increase or decrease the security key bit is intelligently decided based on the violation frequency and the performance index so as to seek the optimal balance between the security and the performance, and low time delay and high availability can be maintained while the integrity and confidentiality of the data are guaranteed on the whole.
Owner:GUANGZHOU YUANFENG INTELLIGENT TECH CO LTD

Access control and protection of telemetry signals using attribute-based encryption

PCT designated stageWO2026069059A1Multiple keys/algorithms usageDigital data protectionAttribute-based encryptionCiphertext
A system, method and computer program product are configured to: receive, at a telemetry backend, a request for telemetry data from a user, the request including an attribute-based encryption (ABE) ciphertext associated with the user; attempt to decrypt the ABE ciphertext using plural different ABE decryption keys; successfully decrypt the ABE ciphertext using a respective one of the plural different ABE decryption keys; and based on the successfully decrypting the ABE ciphertext using the respective one of the plural different ABE decryption keys, provide the user with access to telemetry data stored in a respective one of plural storage partitions associated with the respective one of the plural different ABE decryption keys, wherein the telemetry data stored in the respective one of plural storage partitions includes the telemetry data requested by the user.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION +2

A searchable registration attribute base encryption method

A searchable registration attribute-based encryption method includes: generating a public reference string using a public reference string generator; users generating their own public and private keys; a key manager collecting and aggregating the public keys of all registered users to generate a unified master public key and auxiliary decryption keys; the data owner encrypting the original data while generating a searchable ciphertext index, uploading it to a cloud server for storage, thus achieving data encryption and searchability; the user generating a search trapdoor based on the keywords to be searched, sending it to the cloud server through a secure channel, with the trapdoor bound to the user's own attributes to ensure fine-grained search permissions; the cloud server verifying whether the user's attributes meet the access policy without decrypting the data, then performing keyword matching and returning the successfully matched ciphertext; the user using their private key, the ciphertext returned by the cloud server, and the search component to decrypt the ciphertext and recover the original data.
Owner:SHAANXI NORMAL UNIV

Encryption device, decryption device, decryption-possible verification device, cryptosystem, encryption method and encryption program

Encryption device (400), comprising: an encryption unit (403) that is set up when a user secret SKΓ is generated using a secret key MSK of attribute-based encryption and a set of attributes Γ according to a decryption-possible condition L, to generate a key K and a ciphertext P corresponding to key K by encrypting the decryption-possible condition L using attribute-based encryption, where a key PK is used as an encryption key of the attribute-based encryption, consisting of a public key MPK corresponding to the secret key MSK and a public key PQCPK of post-quantum cryptography, to consider a part of the ciphertext P in which the decryption-possible condition L is encrypted on the basis of a secret value as PD and to consider a part of the ciphertext P in which the secret value being shared is encrypted as P-SS, K' and P'-D are generated by randomizing the key K and the PD using a random number R, and to generate a ciphertext C by encrypting data consisting of the PD and the random number R using post-quantum cryptography with the public key PQCPK, wherein The P-SS, P'-D and K' decryption-possible verification parameters correspond to the secret user key SKΓ.
Owner:MITSUBISHI ELECTRIC CORP