Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

63 results about "Authorization certificate" patented technology

In computer security, an attribute certificate, or authorization certificate (AC) is a digital document containing attributes associated to the holder by the issuer. When the associated attributes are mainly used for the purpose of authorization, AC is called authorization certificate. AC is standardized in X.509. RFC 5755 further specifies the usage for authorization purpose in the Internet.

Distributed data use control method and system based on DID and verifiable certificate

The invention discloses a distributed data use control method and system based on a DID and a verifiable credential, a storage medium and an electronic device, and the method comprises the steps: carrying out the identity verification of a data user based on a DID, carrying out the authentication of the identity through a verifiable credential issued by an authority, and carrying out the verification of the identity through the verifiable credential; the privacy information range is controlled by adopting a selective disclosure mechanism; generating data authorization information based on the verifiable certificate, establishing an encrypted point-to-point data transmission channel in combination with the DID identifiers of the authorizer and the authorized person, and executing encrypted transmission and encrypted storage of data; and verifying the identity of a data user based on a DID signature mechanism, carrying out tamper-proof verification on a use strategy in the authorization certificate, and carrying out compliance judgment on an authorization range, strategy content and a decryption condition. According to the method provided by the invention, identity credibility right confirmation in a distributed environment is realized, the security and compliance of data exchange are improved, and security autonomy and verifiable control in a data use stage are realized.
Owner:AISINO CORPORATION

Data processing method and system for multi-factor authentication and block chain evidence storage

The invention relates to the technical field of data management, and discloses a multi-factor authentication and blockchain evidence storage data processing method and system, and the system comprises an identity authentication module which is used for carrying out the multi-factor identity verification, and writing a verification result and an authentication serial number into an authorization certificate; the authorization contract module is used for generating a block chain authorization contract according to user authorization and setting a state version number; the government affair data access module is used for reading government affair data through the government affair network integrated public data platform and adding a request signature generated based on an SM3 algorithm into a request; the block chain evidence storage module is used for performing same-rule uplink evidence storage on the authorization certificate and the calling log, generating an authorization abstract, calling the log and generating a log abstract; the consistency verification module is used for matching the authorization voucher with the call log; and the user authority management module is used for displaying an authorization state and executing modification or revocation operation. According to the invention, credible verification and dynamic management and control of the whole authorization process are realized, and the security of data sharing is improved.
Owner:温州市数安港管理服务中心

Unmanned aerial vehicle cross-domain service function link accessing method based on alliance chain

The invention discloses an alliance chain-based unmanned aerial vehicle cross-domain service function link accessing method, which comprises the following steps of: 1, initializing a system and configuring an alliance chain, generating a global password parameter and a root key by a trusted mechanism, and finishing domain registration and certificate chain storage by each management domain edge server; 2, blockchain-driven identity management is carried out, and the unmanned aerial vehicle completes chain registration and anti-counterfeiting registration certificate acquisition through a domain edge server to which the unmanned aerial vehicle belongs; 3, deploying a flexible threshold signature algorithm to realize multi-domain joint signature and Byzantine fault tolerance; 4, executing a cross-domain SFC security authentication protocol, including SFC pre-verification and security authorization certificate issuing, first node verification starting, hop-by-hop key negotiation and handover certificate transmission, and on-chain auditing; and 5, based on the topology centrality and the path coverage, dynamically electing an orchestrator to realize load balancing. According to the invention, safe access and identity authentication of the cross-domain service function chain of the unmanned aerial vehicle are realized, safety, efficiency and expandability are balanced, and reliable guarantee is provided for cross-domain cooperation of the unmanned aerial vehicle.
Owner:NANJING UNIV OF AERONAUTICS & ASTRONAUTICS

Controlling application access to sensitive data

Some embodiments control access by applications to resources in a computing environment. An embodiment notes a request from an application to access a resource, determines a compliance status of the application based on access control policy compliance criteria, ascertains an authorization status of the request based on an authorization credential of the request and an authorization requirement of the resource, and responds to the request based on the compliance status and also based on the authorization status, thereby providing fine-grained access control. Access may also be controlled based on a request's beneficiary. An access request response may allow access, deny access, or ask for additional authorization. A compliance classifier reduces risk by dynamically updating compliance status after compliance criteria changes or attribute changes. An identity service access control architecture uses a compliance attribute to improve efficiency. Applications may be access control grouped according to resource sensitivity labels.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Controlling application access to sensitive data

Some embodiments control access by applications to resources in a computing environment. An embodiment notes a request from an application to access a resource, determines a compliance status of the application based on access control policy compliance criteria, ascertains an authorization status of the request based on an authorization credential of the request and an authorization requirement of the resource, and responds to the request based on the compliance status and also based on the authorization status, thereby providing fine-grained access control. Access may also be controlled based on a request's beneficiary. An access request response may allow access, deny access, or ask for additional authorization. A compliance classifier reduces risk by dynamically updating compliance status after compliance criteria changes or attribute changes. An identity service access control architecture uses a compliance attribute to improve efficiency. Applications may be access control grouped according to resource sensitivity labels.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Legal service project three-party agent pre-auditing arrangement and double-threshold gating method and system based on large language model, and storage medium

The invention relates to the field of legal science and technology and generative artificial intelligence, and discloses a legal service project three-party agent pre-auditing arrangement and double-threshold gating method and system based on a large language model, and a storage medium. A platform, party and law institution three-party agent collaborative architecture is constructed, and role recognition, evidence structuring, law mapping, intelligent evaluation and document generation are completed through a chat mechanism. The method comprises the following steps: judging a party role based on LLM and generating an authorization certificate; demand fingerprints and evidence maps are extracted under platform arrangement, and legal mapping and reference chains are generated; hierarchical visible control is realized through a double-threshold scoring function; generating a neutral summary, a strategy tree and a document first draft through combination; and finally, outputting a desensitization packaging result and completing auditing anchoring. According to the method, the compliance, comparability and auditing performance of the project establishment stage are effectively improved, and the method is suitable for multiple types of legal service pre-docking scenes.
Owner:GUANGDONG OPERATOR WIRE INTELLIGENT TECHNOLOGY CO LTD

Supervisable privacy information retrieval method and device, storage medium and program product

The invention discloses a supervisible privacy information retrieval method and device, a storage medium and a program product, and relates to the technical field of cryptography and privacy computing. The method comprises the following steps: a data holder completes a publicly verifiable cryptographic commitment for a database version in a system initialization stage and records the database version commitment to an evidence storage chain, and a supervision committee establishes a threshold signature system; the supervision committee performs compliance check on the external authorization certificate and the authorization message provided by the query party, generates a threshold signature when the check is passed, and records an authorization event to the certificate storage chain; the query party assembles an authorization query packet based on the threshold signature and submits the authorization query packet to the data holder; and generating a response ciphertext under the condition that the data holder passes verification of the threshold signature and the authorization query packet, confirms that authorization is legal and is consistent with the committed binding of the database version. According to the method, authorization decision making and post responsibility asking for encrypted query are realized, and trust hypothesis for a single-point approval subject is reduced.
Owner:SICHUAN POLICE COLLEGE

Data desensitization method based on trusted data space

The invention relates to the technical field of data security, and discloses a trusted data space-based data desensitization method, which comprises the following steps of: in a trusted execution environment, analyzing data source metadata to obtain field semantic relevance and data consanguinity topology of the data source metadata; taking real-time context features of the data source metadata as nodes, taking the data consanguinity topology and the field semantic relevance as connection weight edges, and constructing a self-adaptive desensitization rule tree of the data source metadata; in the trusted execution environment, based on an authorization certificate of a user of the data source metadata and a data processing purpose, constructing a multi-party security computing protocol of the data source metadata; segmenting the desensitization rule set into distributed policy fragments based on the multi-party security computing protocol; performing parallel desensitization on a to-be-processed data source based on the distributed strategy fragment; according to the method, the adaptability and the accuracy of the desensitization rule are improved.
Owner:BEIJING ZHONGAN NEBULA SOFTWARE TECH CO LTD

Distributed data authorization method and system based on wearable device

The embodiment of the invention provides a distributed data authorization method and system based on wearable equipment, and relates to the technical field of intelligent wearable equipment. According to the method, original data can be obtained through the wearable device, forced end-to-end encryption and desensitization are executed on the original data, and authorizable data are generated. And uploading the authorizable data to the decentralized storage network so as to cast an ownership certificate of the authorizable data through the decentralized storage network. When the data authorization is performed, a data authorization credential for the authorizable data may be casted based on the ownership credential, thereby transferring the data authorization credential in accordance with the authorization request. Through forced encryption and desensitization, privacy calculation is carried out on the premise that original data is not leaked, privacy security is guaranteed to the maximum extent, and it is ensured that a user has ownership to the data through an ownership certificate. Moreover, by casting a data authorization certificate, key authorization and on-chain recording of authorization are realized, and transparency and traceability of data authorization can be improved.
Owner:XIAOCHE DIGITAL TECHNOLOGY CO LTD

USE OF UNIT-BOUND AUTHORIZATION CERTIFICATES FOR IMPROVED AUTHORIZATION SECURITY IN NATIVE APPLICATIONS

Procedure that includes: Received by an authorization server (201) and by a native application (202) on a unit, an initial authorization grant, a public key of a private / public key pair generated on the unit, and an acknowledgment of the authenticity of the native application (202); Received by the authorization server (201) and by the native application (202) on the unit, an update token and a digital signature of the update token created with the private key, wherein the authorization server (201) recognizes the update token only when the update token is verified with the public key that was previously registered; Validate, by the authorization server (201), the digital signature of the update token; In response to the validation of the update token from the native application (202) on the unit, the authorization server (201) transmits a new access token and a new update token from the authorization server (201) to the native application (202) on the unit, the new access token enabling the native application (202) on the unit to access the computer resource; Input into a neural network (757) the initial authorization, the public key, the confirmation of the authenticity of the native application (202), the update token, and the digital signature of the update token, wherein the neural network (757) is trained to generate an access token generated by the neural network (757) and an update token generated by the neural network (757); and Compare, by one or more processors, the new access token and the new update token generated by the authorization server (201) with the access token and the update token generated by the neural network (757) to validate the new access token and the new update token generated by the authorization server (201).
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Internet of Things equipment management method and system based on MQTT protocol

The invention provides an Internet of Things equipment management method and system based on an MQTT protocol. The method comprises the following steps: sending an equipment discovery request carrying an equipment unique identifier to a cloud platform; receiving an authorization certificate and MQTT server connection information sent by the cloud platform; the authorization certificate and the MQTT server connection information are generated by the cloud platform according to the unique identifier of the equipment; according to the connection information of the MQTT server, establishing encrypted connection with the MQTT server, and performing identity authentication by using the authorization certificate during connection; a downlink management message sent by the cloud platform is received and analyzed, and the downlink management message is in a predefined JSON format and comprises a message type field used for defining behavior operation and an authorization certificate used for session verification; and verifying the authorization voucher in the downlink management message, and executing a corresponding management operation according to the message type field after the verification is passed. Through the technical scheme of the invention, the security of the remote management process can be improved.
Owner:TRANSCEND COMM BEIJING

A method, system and device for inter-application data encryption communication based on a dbus bus

The application discloses an inter-application data encryption communication method based on a dbus bus, an inter-application data encryption communication system based on the dbus bus, an inter-application data encryption communication device based on the dbus bus, an electronic device, a storage medium and a vehicle, and comprises the following steps: a session is created between a server and a client, and a communication session process is executed; a communication daemon process is executed to perform communication authentication processing on the communication session process; the communication authentication processing comprises communication encryption through an authorization certificate and an authorization key, and authentication of a session data unit is performed according to the certificate and the key; if the authentication result is true, the session data unit is retained in the communication session process; and if the authentication result is false, the session data unit in the communication session process is blocked. Through the above scheme, the authorization certificate and the authorization key are double-authenticated, and the security level of the communication connection is improved relative to the original encryption mode of the digital certificate or the digital key alone.
Owner:CHINA FAW CO LTD

Aviation satellite communication dynamic authorization method based on multi-source device fingerprints

The invention relates to an aeronautical satellite communication dynamic authorization method based on multi-source equipment fingerprints, and belongs to the technical field of aeronautical communication security. The method comprises the following steps: dynamically collecting and integrating fingerprint data of multi-source equipment to form a multi-source fingerprint set; based on stability and communication relevance, performing two-dimensional grading, differential purification and weight fusion on the fingerprint features to generate a unique device fingerprint identifier; in combination with geography and link security level division results, introducing real-time risk assessment parameters to dynamically adjust authorization strategy weights; and verifying the identity of the equipment based on a dynamic strategy, generating an authorization voucher with time efficiency, and embedding the authorization voucher into a communication link establishment process, so as to realize dynamic authorization and abnormal linkage handling with a session as a period. According to the invention, the accurate authentication of the device identity and the dynamic adaptation of the authorization strategy are realized, and the security and reliability of aviation satellite communication are effectively improved.
Owner:AIRLAND INTERNET TECH CO LTD

Method, device, storage medium and program product for retrievable privacy information

The application discloses a kind of private information retrieval method, equipment, storage medium and program product of supervision, it is related to cryptography and privacy computing technical field.The method comprises: by data holder, public verifiable cryptography commitment is completed in system initialization phase to database version, and database version commitment is recorded to evidence chain by supervision committee, and threshold signature system is established;By supervision committee, the compliance audit is carried out to external authorization certificate and authorization message provided by inquirer, threshold signature is generated when audit passes, and authorization event is recorded to evidence chain;By inquirer, authorization query package is assembled based on threshold signature and is submitted to data holder;In the case where data holder is verified to threshold signature and authorization query package and confirms that authorization is legal and is consistent with database version commitment binding, response ciphertext is generated.The application realizes the authorization decision and after-the-fact accountability of encrypted query, reduces the trust assumption to single-point approval subject.
Owner:SICHUAN POLICE COLLEGE

Vehicle temporary authorization control method and system, electronic equipment and storage medium

The invention provides a vehicle temporary authorization control method and system, electronic equipment and a storage medium, and the method comprises the steps: obtaining the multi-dimensional credit data of a corresponding user at the current moment under the condition that a temporary authorization request initiated by a user terminal for a target vehicle is received; the multi-dimensional credit data is used for representing at least one of the operation credibility, the riding danger level and the performance risk state of the user; determining a short-term credit weight of the user at the current moment based on the multi-dimensional credit data; and under the condition that the short-term credit weight is greater than or equal to the access threshold, generating a temporary authorization certificate and issuing the temporary authorization certificate to the target vehicle, the temporary authorization certificate being used for indicating the target vehicle to open the use permission after the verification is passed. According to the method and the system, the dynamically generated temporary authorization certificate is used as an authority carrier, so that convenient key-free vehicle borrowing is realized, and high-risk users are prevented from obtaining the vehicle use right through multi-dimensional real-time risk interception, and therefore, the safety and the flexibility of vehicle management are greatly improved.
Owner:XIAOAN KEJI

Electronic device

The application discloses an electronic device and belongs to the technical field of electronic devices. In the case that the kernel initialization of the real-time operating system of the electronic device is completed, an authorization certificate stored in the electronic device is acquired; the authorization certificate is parsed to confirm current identity information corresponding to the real-time operating system; in the case that the current identity information matches first identity information, a first service associated with the first identity information is started, wherein the first identity information comprises a user; in the case that the current identity information matches second identity information, a second service associated with the second identity information is started, wherein the second identity information comprises an after-sales personnel or a research and development personnel.
Owner:VIVO MOBILE COMM CO LTD

A multi-factor authentication and blockchain storage data processing method and system

The application relates to the technical field of data management, and discloses a data processing method and system for multi-factor authentication and block chain storage, which comprises the following modules: an identity authentication module for multi-factor identity verification, writing the verification result and an authentication serial number into an authorization voucher; an authorization contract module for generating a block chain authorization contract according to user authorization and setting a state version number; a government affair data access module for reading government affair data through a government affair network integrated public data platform and adding a request signature generated based on an SM3 algorithm into the request; a block chain storage module for storing the authorization voucher and a call log in the same rule, generating an authorization digest, a call log and a log digest; a consistency checking module for matching the authorization voucher and the call log; and a user authority management module for displaying an authorization state and executing a modification or revocation operation. The application realizes trusted verification and dynamic management and control of the whole authorization process, and improves the security of data sharing.
Owner:温州市数安港管理服务中心

Service request processing method and device for realizing network penetration

The invention provides a service request processing method and device for realizing network penetration, and relates to the technical field of data transmission, and the method comprises the steps: obtaining a service request of an Internet terminal; sending the service request to a firewall for preprocessing, and forwarding the service request to a front-end server for judgment based on the preprocessed service request and a first gateway to obtain a judgment result about whether a back-end server needs to be called for interaction; if the judgment result is that a back-end server needs to be called for interaction, sequentially sending a preset authorization certificate and the service request to a second gateway for processing, and forwarding the authorization certificate and the service request to a security platform for authentication through the second gateway to obtain an authenticated service request; and sending the authenticated service request to a third gateway, and sending the authenticated service request to a back-end server through the third gateway for service request processing to obtain a service request processing result. According to the invention, the operation and maintenance cost and resource waste are reduced, and unauthorized external access and potential data leakage risks are prevented.
Owner:INST OF SCI & TECH INFORMATION OF CHINA ACAD OF RAILWAY SCI GRP CO LTD +2

Blockchain-based digital economy e-commerce management methods and systems

This invention relates to the field of blockchain technology, specifically to a blockchain-based digital economy e-commerce management method and system, comprising the following steps: acquiring order data, extracting product codes, transaction amounts, and addresses of buyers and sellers; concatenating and executing SHA-256 to generate an order digest and constructing associated data of transaction participants; extracting the digest, inputting elliptic curve signature to generate a transaction authorization certificate; collecting inventory changes, logistics status, and payment time series data to construct an e-commerce transaction state chain; encapsulating the blockchain, writing new block records, and executing the path to generate on-chain transaction record certificates; calling the certificate to read the state chain, verifying the consistency of signatures and data, and outputting an e-commerce transaction integrity certificate. In this invention, by hashing and elliptic curve signing key order data, identity encryption verification and data confirmation are achieved. On-chain records of the transaction state chain are constructed based on signatures and time series data, ensuring consistency between inventory, payment, and logistics. On-chain certificates support traceability verification, improving the traceability, security, and consistency of e-commerce transactions.
Owner:HANGZHOU WENLUN MOUNTAIN TECHNOLOGY CO LTD

Authorization information reverse authentication method, device, equipment, medium and product

The embodiment of the invention provides an authorization information reverse authentication method and device, equipment, a medium and a product. The method comprises the steps that authorization information of second terminal equipment is acquired, and the authorization information comprises a mobile phone number and authorization data of the second terminal equipment; carrying out desensitization processing on the mobile phone number to obtain a user unique identifier; generating an authorization report request according to the user unique identifier and the authorization data; the authorization report request is sent to the authorization evidence storage platform, so that the authorization evidence storage platform generates authorization certificate information according to the authorization report request, the authorization certificate information is uploaded to the block chain, and the authorization certificate information is used for the authorization evidence storage platform to respond to an authorization certificate query request sent by the supervisor. The security of an authorization information authentication mode is improved.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD +1

An authentication method and system for secure data transmission

This invention relates to the field of secure data transmission, and more particularly to an authentication method and system for secure data transmission. The method includes receiving commitment information from a communication node and associating and storing the commitment information with the communication node's identity identifier. Upon meeting preset trigger conditions, the method receives verification information from the communication node, which corresponds to the commitment information. The commitment information is verified based on the verification information; upon successful verification, an identity credential for the communication node is generated. The method also receives an authorization request from the communication node, which includes attribute information of the data to be transmitted. An authorization credential bound to the data to be transmitted is generated based on the authorization request. Finally, the method receives the data to be transmitted, the identity credential, and the authorization credential from the communication node. The validity of the identity credential and the authorization credential is verified; if both are valid, the data to be transmitted is received. By coupling authentication and authorization, this invention achieves fine-grained access control and can adapt to complex network environments such as high latency and intermittent connections.
Owner:SHENZHEN GLOBALBRANDS TECH CO LTD

Service access method, terminal device, server, and routing node

Provided in the present application are a service access method, a terminal device, a server, and a routing node. The solution comprises: a service authorization server receiving a service authorization request, which is sent by a terminal device, for a target application; on the basis of an access regulation and control policy, which is locally configured for the target application, the service authorization server determining whether to allow the terminal device to perform service access on the target application; after service authorization verification is passed, the service authorization server configuring, for the terminal device, a service authorization certificate and a time limit of the service authorization certificate, such that the terminal device sends, to a routing node, a service access request for the target application; and after the service authorization credibility verification is passed, forwarding the service access request to an application server of the target application.
Owner:ZTE CORP

An iCloud data decryption and extraction system and method

An iCloud data decryption and extraction system and method, relating to the field of data security technology, includes: verifying user compliance authorization and initializing the decryption environment; obtaining the user's root key based on a temporary access token and the user's iCloud account compliance authorization credentials; deriving session keys based on the user's root key and iCloud data storage structure information to obtain temporary session keys for various data types; performing parallel multi-threaded scheduling on the data to be extracted; matching decryption algorithms for various types of data downloaded to the decryption end and performing data decryption operations based on the temporary session keys; performing data download integrity verification and data decryption integrity verification; when both verifications pass, performing data reconstruction operations and reconstructed integrity verification; and outputting and securely destroying the extracted complete data types, significantly improving data extraction efficiency and data decryption compatibility and integrity.
Owner:深圳市乐数科技有限责任公司

Wireless local area network authorized traffic identification and quality of service guarantee method and device, wireless access point, terminal chip, terminal chip module and terminal equipment

This application relates to the field of network management and optimization technology, and provides a method, apparatus, wireless access point, terminal chip, terminal chip module, and terminal device for identifying authorized traffic and ensuring quality of service (QoS) in a wireless local area network (WLAN). The method includes: a wireless access point on the network side receiving authorization credentials and QoS information sent by a terminal chip; obtaining target network element information based on the authorization credentials; verifying whether the target network element is a trusted network element based on the target network element information and a first authentication public key; if the target network element is a trusted network element, obtaining a second authentication public key from the target network element and verifying whether the authorization credentials are trusted credentials; if the authorization credentials are trusted credentials, determining that the traffic corresponding to the QoS information in the dedicated traffic transmission channel is authorized traffic, and providing QoS assurance for the authorized traffic according to the QoS information. This method can ensure that the QoS assurance for authorized traffic is reliable and controllable, and can improve the transmission quality of authorized traffic.
Owner:SPREADTRUM SEMICON(CHENGDU) CO LTD

Method and system for secure control of virtual machine cloning in a cloud server cryptomachine environment

The present application relates to the technical field of virtualization security, in particular to a virtual machine cloning security control method and system in a cloud server cryptomachine environment, comprising the following steps: a physical cryptomachine generates a hardware root key pair, a management platform generates an authorization certificate by signing with a root key pair public key, extracts a source marker to construct a unique identifier in combination with a time stamp, calls a private key to encrypt a data block to generate a signature and construct a credential, the cryptomachine decrypts and compares a hash digest by using a public key, divides an independent storage area when consistent, establishes a mapping relationship and returns a resource access handle to a cloned virtual machine. In the present application, a trusted authorization system is established through a hardware root key, a unique identity credential containing a source marker is dynamically constructed, the identity authenticity is ensured through digital signature and hardware level verification, after verification, an independent storage area is forcibly divided, hardware resource physical isolation of cloning and source instance is realized, the risk of unauthorized access is blocked, and the security of cryptographic operation is ensured.
Owner:数盾信息科技股份有限公司

A network disk proxy access method and system based on digital certificate and virtual IP

This invention discloses a method and system for proxy access to cloud storage based on digital certificates and virtual IPs, which can be used in user-built cloud storage systems. The method includes: establishing a platform service unit and applying for a domain name certificate to serve as the trusted root node of the entire system; establishing an encrypted communication channel between the cloud storage service unit and the platform service unit based on the domain name certificate; applying for user accounts on the platform service unit, binding them to the cloud storage service unit, and issuing cloud storage certificates; establishing an encrypted communication channel between the proxy service unit and the cloud storage service unit based on the cloud storage certificate; applying for an authorization certificate from the cloud storage service unit; creating a virtual IP and providing proxy cloud storage services to other applications based on the virtual IP, forwarding cloud storage service requests from other applications to the cloud storage service unit, and the cloud storage service unit responding after confirming permissions. This method can ensure the information security of self-built cloud storage systems and improve compatibility with network restrictions.
Owner:林景涛

Equipment authorization method and device, computer equipment and storage medium

The invention relates to an equipment authorization method and device, computer equipment and a storage medium. The method comprises the following steps: acquiring an authorization request sent by a device end; the authorization request comprises a device verification code and an authorization repetition identifier corresponding to the device end; under the condition that fusing is not triggered between the server side and the equipment side, determining a service verification code of the equipment side according to equipment information of the equipment side in the authorization request; performing authorization verification on the equipment end according to the authorization repetition identifier, the service verification code and the equipment verification code; and under the condition that the authorization verification is passed, feeding back an authorization voucher to the equipment end so as to complete the authorization of the equipment end. By adopting the method, the equipment authorization security can be improved.
Owner:ZHEJIANG DAHUA TECH CO LTD

Cross-chain medical data transaction method, transmission protocol and system

The present application relates to the technical field of medical data transaction, in particular to a cross-chain medical data transaction method, a transmission protocol and a system, comprising compliance preprocessing and quality characterization of medical data to form a transaction data offer; and registering the transaction data offer as an on-chain queryable offer record, outputting an offer fingerprint and an offer constraint set; initiating a transaction request and giving a use commitment and a compliance qualification declaration; a cross-chain coordination mechanism performs consistency verification, generates a cross-chain authorization credential, and outputs an authorization status record; a data provider executes controlled delivery according to the cross-chain authorization credential and the authorization status record, and generates a use audit event stream; when a revocation condition, out-of-range access or regulatory audit request is triggered, the cross-chain coordination mechanism executes freezing, revocation or accountability treatment according to the authorization status record and the use audit event stream, and completes the closed loop of the transaction. The present application improves the data credibility, controllability and automatic matching ability under multi-chain collaboration.
Owner:EDGE INTELLIGENCE RES INST NANJING CO LTD

Security system and method for strongly binding program and hardware identifier

The invention relates to a security system and method for strongly binding a program and a hardware identifier, and belongs to the technical field of software protection and equipment authentication. According to the invention, an'authorization certificate 'uniquely bound with specific equipment is generated through a scheme of'encrypting a hardware identifier by a secret key derived from the hardware identifier'. The credential cannot be correctly decrypted and verified on any other hardware. When a protected program and an authorization certificate thereof are completely copied to another non-authorized device, due to different local hardware identifications of a new device, a correct decryption key cannot be generated when a program verification preamble module of the new device performs self-inspection, so that decryption fails and program operation is forcibly stopped, and therefore, pirate behaviors are effectively prevented.
Owner:SOUTH WEST INST OF TECHN PHYSICS