Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

128 results about "Certificate authority" patented technology

In cryptography, a certificate authority or certification authority (CA) is an entity that issues digital certificates. A digital certificate certifies the ownership of a public key by the named subject of the certificate. This allows others (relying parties) to rely upon signatures or on assertions made about the private key that corresponds to the certified public key. A CA acts as a trusted third party—trusted both by the subject (owner) of the certificate and by the party relying upon the certificate. The format of these certificates is specified by the X.509 standard.

Tamper protection for the clock of a field tool

PendingDE102024122454A1Programme controlTime-division multiplexTamper resistancePublic key certificate
Method (100) for operating a field device (1) comprising an adjustable clock (2), at least one non-volatile CA memory (3) containing a public key certificate (3a) of a trusted certification authority, CA, at least one non-volatile time memory (4) for recording a date and / or time (4a) and at least one interface (5), comprising the steps: • A current date and / or time (7a) is received via the interface (5) (170); • this current date or time (7a) is compared with the date or time (4a) in the time memory (4) (180); and • In response to the fact that the current date or time (7a) is later (190) than the date or time (4a) in the time memory (4), the adjustable clock (2) of the field device (1) is set to the current date or time (7a) (200).
Owner:VEGA GRIESHABER GMBH & CO

Remote attestation method and related device

This disclosure provides a remote attestation method and a related device, to verify a remote attestation report by using a symmetric key of a subscriber identity module (SIM), without depending on a digital certificate provided by a certificate authority (CA) server. This can improve reliability of a remote attestation report verification process. In the method, a first apparatus receives request information, where the request information is for requesting a remote attestation report, and the remote attestation report is for remote attestation of the first apparatus. The first apparatus sends first information based on the request information, where the first information includes the remote attestation report and verification information, the verification information is for verifying the remote attestation report, and the verification information is obtained by processing the remote attestation report based on a symmetric key of a SIM in the first apparatus.
Owner:HUAWEI TECH CO LTD

Distributed identity association and verification method and system combining alliance chain and trusted CA

The invention discloses a distributed identity association and verification method and system combining an alliance chain and a trusted CA (Certificate Authority). The method comprises the following steps: firstly, guiding a user to complete identity verification in a trusted third-party authentication center to obtain an authoritative verifiable certificate; based on the certificate, the back end of the system automatically applies for signing and issuing an operation certificate for on-chain interaction to the alliance chain. The system constructs a distributed identity document aggregating verifiable credentials and public key information for a user. A user imports an operation certificate and a private key into a block chain wallet, signs a transaction in person, and registers a DID and a document thereof into an on-chain smart contract, so that the problems that in an existing block chain identity system, an on-chain identity is separated from an entity identity, roots of trust are not uniform, and interoperability is poor are solved; unified and non-tampering on-chain association of a user entity identity, an on-chain operation identity and a standardized DID is realized, an identity system with a trusted CA as a root of trust is established, the sovereignty and security of the user are guaranteed while supervision requirements are met, and the identity interoperability is improved.
Owner:XI AN JIAOTONG UNIV

Anti-quantum anonymity voucher generation method and device, equipment and medium

The invention discloses an anti-quantum anonymity voucher generation method and device, equipment and a medium, and the method comprises the steps: carrying out the improvement of a conventional original image sampling method based on an approximate trap door sampling and refusal sampling technology, constructing a more efficient anonymity voucher generation protocol, remarkably reducing the calculation complexity, and improving the practicality. The user sends an application to a certificate authority (CA) to obtain an anonymous certificate for a specific attribute; and the CA interacts with the user and returns the signed attribute, and the user calculates an anonymous certificate according to the attribute and locally stores the anonymous certificate. During identity authentication, a user interacts with a service provider (SP) by using a local certificate to dynamically generate a proof; and the SP verifies the certification and then outputs an authentication result. According to the method, the defects of traditional identity authentication and anonymous certificates are overcome, efficient authentication can be realized under limited equipment and a high-privacy scene, and a better scheme is provided for actual deployment of the anonymous certificates.
Owner:SOUTH CHINA AGRICULTURAL UNIVERSITY

System and method for using client-based login certificates for remote applications

A system and method for providing a single sign-on for connecting a client device to a virtual infrastructure. The virtual infrastructure includes a server, an enterprise connector and a certificate authority. The client device receives an identity provider (IdP) token obtained from an IdP on authenticating a user of the client device. On authentication of the user, a desktop client application on the client device sends a request through the enterprise authority for a login certificate. A login certificate generated by the certificate authority is received by the client device. The login certificate to the client device is sent to the virtual infrastructure to allow the client device a connection to a virtual machine of the virtual infrastructure.
Owner:WORKSPOT INC

Systems and methods for utilizing onboard vehicle hardware for secure ECU data communication

Aspects of the present application utilizes onboard vehicle hardware for secure ECU data communication. In some embodiments, a main ECU receives a private key from a certificate authority and stores it within a hardware security module (HSM). The main ECU may then generate a symmetric vehicle-specific key based on at least one vehicle parameter of the vehicle (e.g., the odometer) and store it in the HSM. An additional ECU may be detected by the main ECU on a vehicle communication network (e.g., ethernet). The additional ECU may be an FPGA that includes an unprovisioned vehicle control operation. The main ECU may generate an FPGA image for the additional ECU where the FPGA image has the symmetric vehicle-specific key. The main ECU may then cryptographically sign the FPGA image using the private key stored in the HSM and transmit the signed FPGA image to the additional ECU for installation.
Owner:ADEIA GUIDES INC

Cryptographic attestation of data object attributes in a distributed system

A request to provide a data object attestation authority certificate to a second cluster of secure environments is received at a first cluster of secure environments. The request comprises a cluster certificate of the second cluster issued by a cluster enrollment certificate authority (CA). The cluster certificate is validated using a public key of the enrollment CA. An encrypted message comprising the attestation authority certificate and a digital signature of the first cluster is generated. The encrypted message is encrypted using a public key indicated in the cluster certificate of the second cluster. The digital signature is associated with a cluster certificate of the first cluster issued by the enrollment CA. The encrypted message is provided to the second cluster to be decrypted using a private key associated with the cluster certificate of the second cluster, and to be validated using at least the public key of the enrollment CA.
Owner:FORTANIX INC

Electronic device for authentication and method of operation thereof

An operating method for an electronic device is disclosed. An operating method for an electronic device according to an embodiment of this disclosure may include the following operations: retrieving a certificate from a file stored in the electronic device; sending a verification request for the certificate to a certificate authority in response to recognizing that the certificate is a new certificate; determining whether the certificate's validity period has expired in response to receiving a response from the certificate authority confirming the certificate's validity; determining whether the certificate is included in an exception list when the certificate's validity period has expired; and storing the certificate in the memory of the electronic device in response to determining that the certificate is included in the exception list, wherein the exception list includes at least one certificate.
Owner:SAMSUNG ELECTRONICS CO LTD

Anti-quantum-attack smart park data sharing method, device and medium

The invention discloses an anti-quantum-attack smart park data sharing method and device and a medium, and the method comprises the steps: generating a digital signature public key and a digital signature private key through a system administrator according to an anti-quantum digital signature scheme, and generating a homomorphic encryption and decryption public key and a homomorphic encryption and decryption private key according to an anti-quantum homomorphic encryption scheme, an anonymous signature public key and an anonymous signature private key are generated through a certificate authority according to the digital signature scheme for resisting anonymity of the quantum signer; sending an access request message of the user to a system administrator so as to sign the access request message by using a private key with a digital signature and sending the signed access request message to the user; verifying the identity of the administrator based on the digital signature, signing the access request information by using a private key of an anonymous signature, sending the access request information to a system administrator to verify the identity of the user, and allowing the user to access after the identity of the user passes verification; a system administrator selects plaintext data to encrypt and generate a ciphertext, and sends the ciphertext to a data requester, so that the data requester performs homomorphic operation on the ciphertext to complete data security sharing.
Owner:山东浪潮智慧建筑科技有限公司

Device credential migration

PendingUS20260254807A1Internet privacyDevice migration
The present application relates to devices and components including apparatus, systems, and methods to migrate one or more credentials from a first device to a second device. The migration of the one or more credentials can include performing authentication procedures corresponding to the one or more credentials for determining whether migration of the one or more credentials is allowable, and utilizing certificate authority security domains of secure elements to bind the one or more credentials to the secure elements for migration.
Owner:APPLE INC

Dynamic attachment of secure properties to machine identity with digital certificates

Technology is shown for dynamically attaching secure properties to an identity certificate. Claims determining secure properties for an identity are signed and embedded in an identity certificate. Both the identity certificate and the signed claims in the certificate are verified. When a service request is received from the identity, the signed claims from the identity certificate are checked to determine if the request is permitted. If the request is permitted, then the service request is processed. Some examples involve creating claims determining the secure properties for the remote machine, signing the claims to create the signed claims, distributing the signed claims to a certificate authority, embedding the signed claims in the remote machine identity certificate, and distributing the remote machine identity certificate. The claims can be embedded in the certificate as X.509 properties.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Offline digital asset generation and provisioning

A system for offline generation of digital assets includes: a security credential management system (SCMS) that is operable to generate and conditionally transmit digital assets; and a certificate authority communicatively connected to the SCMS by a communication network, the certificate authority being operable to receive the digital assets from the SCMS. The certificate authority is operable to securely provision a plurality of computerized devices based on the received digital assets, the certificate authority intermittently connects to the SCMS to receive the digital assets, the certificate authority is operable to securely provision the plurality of computerized devices while disconnected from the SCMS, and the provisioning by the certificate authority while disconnected from the SCMS is limited by a policy associated with the certificate authority.
Owner:INTEGRITY SECURITY SERVICES LLC

A commercial cryptographic digital certificate generation method supporting quantum-resistant cryptography

The application relates to the technical field of information security, in particular to a commercial cipher digital certificate generation method supporting quantum-resistant cipher, which comprises the following steps: a certificate authority generates a hybrid signature self-signed certificate with quantum-resistant cipher signature and traditional public key cipher signature; a user generates a hybrid signature certificate request file and sends the file to the certificate authority; the certificate authority generates a hybrid signature user signature certificate; a key generation center generates a user traditional public key cipher encryption key pair and a user quantum-resistant cipher encryption key pair; the certificate authority generates a hybrid signature user encryption certificate; the certificate authority generates a hybrid encryption public key, a private key encryption ciphertext and a hybrid ciphertext; and the user extracts the hybrid signature signature certificate, the encryption certificate, the quantum-resistant cipher encryption private key and the traditional public key cipher encryption private key, and verifies the signature certificate and the encryption certificate. The application can resist quantum attacks and is compatible with existing digital certificates.
Owner:SHANDONG DUOFANG SEMICON CO LTD +1

Efficient, high-volume certificate chain validation

Techniques are disclosed for a certificate chain validation framework in which a validation service may validate a leaf certificate on behalf of an application service without traversing the rest of the certificate chain. The validation service maintains a database of validation information provided by a certificate authority. When the validation service receives a certificate chain validation request from an application service, the validation service may validate the leaf certificate by verifying signature and certificate data associated with other certificates in the certificate chain indicated by the leaf certificate using associated validation information from the database.
Owner:GOOGLE LLC

Intelligent campus certificate credit data management system based on artificial intelligence

The invention discloses an intelligent campus certificate credit data management system based on artificial intelligence, which relates to the technical field of artificial intelligence and comprises a multi-source data acquisition unit, a certificate verification unit, a credit progress monitoring unit and a credit supervision unit. The method comprises the following steps: acquiring a personal certificate data set, verifying the authenticity of an electronic seal and anti-counterfeiting watermark characteristics, marking the verified personal certificate data set as a target data set, extracting an issuing mechanism in a certificate, acquiring time and skill levels, carrying out assignment representation, and integrating into a certificate value data set; the credit conversion coefficient is calculated according to the authority, skill scarcity and industry acceptance degree of a certificate issuing mechanism, the certificate, the course score and the practice record of the same student are associated, and the student credit acquisition progress is predicted through time sequence analysis. And automatically generating a personalized repair scheme and sending the personalized repair scheme to the student terminal and the monitoring party associated with the student terminal.
Owner:HUNAN TECHN COLLEGE OF RAILWAY HIGH SPEED

Handwritten signature method based on collaborative signature technology

The application discloses a handwritten signature method based on a collaborative signature technology, and is carried out according to the following steps: S1, identity information and biological characteristics of a user are collected through a client; S2, the client initializes a random number generator, generates a client SM2 collaborative signature key component d1 and a public key negotiation parameter P1, and sends them to a server; S3, the server generates a server SM2 collaborative signature key component d2, negotiates a public key P with the client public key negotiation parameter P1, and applies for an event certificate to a certificate authority; S4, the server generates an electronic seal based on a handwritten signature track picture, combines a to-be-signed original text, a time stamp and the event certificate, and assembles to-be-electronic signature data; S5, the server and the client complete SM2 collaborative signature of the to-be-electronic signature data through single interaction, generate a signature value, and assemble electronic signature data; and S6, the client and the server destroy the generated data. The application has better operation convenience and higher key security.
Owner:杭州脉讯科技有限公司

Authentication system, authentication method, and program

An authentication system includes: a certificate authority; a central control system; a group including an unmanned vehicle that is a master vehicle and an unmanned vehicle that is a slave vehicle; a management system; and an external system. The central control system includes a first authentication information transmitting unit that transmits, to the master vehicle, first authentication information received from the certificate authority. The master vehicle includes an authentication unit that executes authentication with the slave vehicle belonging to the same group, and a second authentication information transmitting unit that transmits second authentication information including a first token with an expiration date and the first authentication information to the authenticated slave vehicle. The management system includes an authentication unit that executes authentication with the external system; and a third authentication information transmitting unit that transmits, to the authenticated external system, third authentication information including a second token and the first authentication information received from the certificate authority. The slave vehicle and the external system each include an authentication unit that executes authentication based on the second authentication information and the third authentication information.
Owner:NT T INC

Block chain network access control method and device, equipment and storage medium

The invention provides a block chain network access control method and device, equipment and a storage medium, and relates to the technical field of access control. The method comprises the steps of firstly obtaining a user certificate issued by a certificate issuing mechanism in a block chain system; the method comprises the steps of obtaining a TLS certificate issued by a TLS certificate issuing mechanism, carrying out integrity verification on the TLS certificate issued by the TLS certificate issuing mechanism, ensuring communication security between a user and a block chain system, obtaining a data signature certificate issued by a signature issuing mechanism after the integrity verification is passed, and signing target transaction data information and a user certificate by using the data signature certificate. And sending the signed target transaction data information and the user credential to a target institution, and applying for data access, and after the target institution verifies that the data access permission of the user is passed, the user can access the target transaction data. According to the method and the system, the security of the system is enhanced by implementing access permission control on different levels of the block chain system through the multi-level certificate structure.
Owner:CHENGDU PRIME STARK TECH CO LTD

Systems and methods for providing trusted user interface layouts

A point-of-sale system may include a customer-facing device including a customer-facing display, one or more first processors, and a first non-transitory, computer-readable medium including first instructions, a merchant-facing device including a merchant-facing display, one or more second processors, a second non-transitory, computer-readable medium including second instructions which cause the one or more second processors to, receive a signed data structure from a certificate authority trusted by the customer-facing device, transmit the signed data structure to the customer-facing device, the data structure defining a user interface for display on the customer-facing display for performance of a transaction, wherein the first instructions cause the one or more first processors to authenticate the signed data structure, render the user interface defined in the signed data structure on the customer-facing display, and receive user input via the user interface related to the transaction.
Owner:FISERV INC

A data processing method and apparatus

The data processing method and device provided in the embodiments of the present application comprise the following steps: a block link receives a first request message sent by a first electronic device; the first request message carries identification information of the first electronic device, information of data to be sent by the first electronic device, and identification information of a second electronic device; the encryption mode of the first electronic device is determined according to the first request message; the encryption mode of the first electronic device is sent to a certificate authority (CA), so that the CA determines the encryption key and the decryption key corresponding to the encryption mode according to the encryption mode of the first electronic device, and sends the encryption key to the first electronic device. In this way, the dynamic change of the encryption mode can be realized, and the security of data transmission is improved.
Owner:CHINA MOBILE GROUP SHANDONG +1

Certificate management system, method and device for eSIM card and electronic equipment

The invention relates to the technical field of intelligent cards, and discloses a certificate management system, method and device for an eSIM card and electronic equipment, and the certificate management system comprises a secure storage area which is used for storing a plurality of sets of certificate chains; each set of certificate chain corresponds to a certificate authority, a certificate authority node is used as a head node, and hierarchical certificates are stored through a longitudinal certificate chain table; each certificate authority node stores a certificate of a current certificate issuing mechanism, an eSIM identifier and an activation state label, and the eSIM identifier of only one certificate authority node is in an activation state; all certificate mechanism nodes are connected through a transverse index linked list; the transverse index chain table is used for realizing positioning of multiple sets of certificate chains. According to the technical scheme, certificate chain positioning is achieved through the transverse index chain table, the eSIM identifier of the certificate mechanism node corresponding to the certificate chain is set to be in the activated state, certificate switching in different markets is achieved, and then the adaptability and flexibility of the eSIM card used in the different markets are improved.
Owner:BEIJING TSINGTENG MICROSYSTEM CO LTD

An internet of things identity authentication method based on lightweight Falcon signature

The application discloses an Internet of Things identity authentication method based on a lightweight Falcon signature, and the Internet of Things comprises a device, an edge gateway and a cloud platform, and comprises the following steps: initializing the device to generate a Falcon-512 key pair, performing sparse compression on the Falcon-512 key pair, and performing fragmented encryption storage; the Falcon-512 key pair comprises a private key sk and a public key pk; sending a registration request CSR to a cloud certificate authority CA through the device to obtain a device certificate Cert; collecting communication data Data through the device, calculating a hash value H(Data||Timestamp) of the communication data Data, wherein Timestamp is a time stamp; inputting the hash value H into an iterative FFT, mapping and storing the hash value H through a plurality of butterfly operations in the iterative FFT to obtain an intermediate result C in the FFT; wherein, based on the independence of the butterfly operation in the iterative FFT, a plurality of butterfly operations are processed in parallel through the SIMD instruction of the ARM Cortex-M processor; and a random integer z conforming to a discrete Gaussian distribution is generated through Gaussian sampling.
Owner:CHENGDU UNIVERSITY OF TECHNOLOGY

Certificate signing scheme based on SM9 signature algorithm

ActiveCN115589296BID-based encryptionKey (cryptography)
The application is suitable for the field of information security technology, and provides a certificate signature scheme based on an SM9 signature algorithm, which comprises the following steps: S100, system initialization calculation, a certificate authority generates a random number as a private key and calculates a public key, then randomly selects a signer private key and performs public key calculation to produce a signer private key pair; S200, certificate authorization, a signer provides identity information to the certificate authority, the certificate authority verifies the information according to the information and the key information, and calculates and generates a certificate after the information passes, and feeds back the certificate to the signer; and S300, signature calculation and the like. The application is based on the signature structure of the SM9 national secret algorithm, combines the advantages of traditional public key cryptography and identity-based encryption technology, and solves the problems of complex certificate management and key escrow. The scheme can resist attacks of Type 1 and Type 2 enemies at the same time.
Owner:SHANGHAI MATRIXELEMENTS TECH CO LTD +1

Verification method, electronic device, storage medium and computer program product

The invention provides a verification method, electronic equipment, a storage medium and a computer program product. The method comprises one of the following steps that a server side sends first information containing identification information of a remote certificate (RA) agent and related information of a trusted platform module (TPM) device to a certificate authority (CA), and the first information is provided for the CA to a client side; the binding relation is used for verifying the RA agency and the TPM equipment corresponding to the server side. The RA agency and the TPM equipment are used for verifying the RA agency and the TPM equipment corresponding to the server side. And the server receives a remote attestation request which is sent by the client and at least comprises the random number, and sends a remote attestation report which is generated based on the random number and the identification information of the RA agent corresponding to the server to the client, so that the client verifies the RA agent corresponding to the server and the TPM equipment based on the remote attestation report. According to the invention, the client can accurately verify the credible state of the server.
Owner:CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1

Certificate hijacking defense method and device for terminal application, and terminal

PendingCN121814327ASolve the problem of data leakageUser identity/authority verificationDomain nameTransport layer
The invention discloses a terminal application-oriented certificate hijacking defense method and device, and a terminal, and the method comprises the steps: enabling a terminal application client to access a target server according to a domain name of the target server, and obtaining a service certificate returned by the target server; the terminal application client verifies the service certificate; when the verification is passed, the terminal application client submits a target server domain name and a target certificate issuing mechanism issuing a service certificate to the terminal system for verification; and when the terminal application client acquires a connection instruction issued by the terminal system, the terminal application client and the target server complete handshake connection based on the transport layer secure connection protocol to perform data transmission. According to the invention, during connection, the service certificate, the target server domain name, the target certificate issuing mechanism and the like are verified, so that the problem of user data leakage caused by the fact that an application program is possibly maliciously guided to a forged transport layer secure connection protocol server in the prior art can be effectively solved.
Owner:深圳开鸿数字产业发展有限公司

Limiting power of untrusted certificate authorities

ActiveUS12689527B2Internet privacyEngineering
Limiting power of untrusted certificate authorities is disclosed. An unstructured list of certificate authorities associated with an application may be augmented with a limiting database that includes a per target certificate authority list. For targets identified in the limiting database, the certificate of an entity may be trusted only when the certificate authority is in the target's list, even if the certificate authority is present in the unstructured list of certificate authorities.
Owner:DELL PROD LP

Serial number generation for stateless cloud certificate authority

A system associated with a public key infrastructure certificate framework in a cloud computing environment may include a certificate authority data store that contains information about a plurality of certificate authority instances (with each certificate authority instance being associated with an instance index and an instance deployment time). A certificate authority server, coupled to the certificate authority data store, may retrieve an instance index and instance deployment time from the certificate authority data store. The certificate authority server may then determine a current certificate identifier generation timestamp. A unique certificate identifier for a public key certificate is generated by the certificate authority server based on a deterministic creation algorithm, the instance index, the instance deployment time, and the certificate identifier generation timestamp. The public key certificate can then be issued using the unique certificate identifier.
Owner:SAP SE

Method for installing electronic certificate and system for installing electronic certificate

A method for installing electronic certificates includes: issuing, by a server of a certificate authority, the electronic certificates for authenticating a single terminal in chronological order for each of a plurality of users in a case where the plurality of users use the single terminal at different time points; and when one user of the plurality of users uses the single terminal, using prescribed software which runs on the single terminal to: confirm whether an immediately preceding electronic certificate issued by the server exists on the single terminal; and install a next electronic certificate issued by the server on the single terminal if the immediately preceding electronic certificate exists on the single terminal.
Owner:CONTROL SYST LAB LTD

Privacy-preserving digital signature system and method using hash and signature operations in a distributed trusted rich execution environment

Disclosed is a distributed trusted computing system consisting of a cluster of Trusted Rich Execution Environments (T-REEs) instantiated on a network of computers, information processing methods executed within these T-REEs, and information exchange methods used by these T-REEs to communicate with each other to perform privacy-preserving digital signature operations on electronic files. According to the present disclosure, a trusted party called a certification authority (also called a signer) can authenticate the content integrity and origin authenticity of a file submitted by a file owner (called a customer) by performing a hash operation on a T-REE instantiated on a customer computer and performing a private key signing operation on the hash value on a T-REE instantiated on the signer computer, thereby allowing the certification authority to authenticate the integrity and authenticity of the file without accessing the file's content.
Owner:FIDUCIAEDGE TECH CO LTD +2