Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

204 results about "Certificate authority" patented technology

In cryptography, a certificate authority or certification authority (CA) is an entity that issues digital certificates. A digital certificate certifies the ownership of a public key by the named subject of the certificate. This allows others (relying parties) to rely upon signatures or on assertions made about the private key that corresponds to the certified public key. A CA acts as a trusted third party—trusted both by the subject (owner) of the certificate and by the party relying upon the certificate. The format of these certificates is specified by the X.509 standard.

Distributed node unified identity authentication method and system based on QUIC protocol

The invention relates to a QUIC protocol-based distributed node unified identity authentication method and system, belongs to the technical field of network security, is applied to a client, and comprises the following steps: registering a client domain name identity through a certificate authority, obtaining a client certificate, and pre-storing a server certificate chain; generating a QUIC initial data packet according to the target server domain name identifier and the client certificate, and sending the QUIC initial data packet to the server; receiving a QUIC handshake data packet returned by the server; verifying the legality of the server certificate based on the server certificate chain, and if the server certificate is legal, calculating a pre-master key according to the client DH private key and the server DH public key; deriving a 1-RTT session key based on the pre-master key; generating a signature verification message, and sending the client certificate and the signature verification message to a server; and synchronously using the 1-RTT session key to encrypt the application layer data with the server, and transmitting the data to the server in the 1-RTT encryption space of the QUIC protocol. According to the invention, the reliability of node identities and the confidentiality of data are ensured.
Owner:BEIJING LIUJINSUIYUE TECH CO LTD

Anti-quantum composite digital certificate implementation method and device, equipment and storage medium

The invention discloses an anti-quantum composite digital certificate implementation method. The method comprises the following steps: generating a classical cryptographic algorithm key pair and an anti-quantum cryptographic algorithm key pair; combining the classical key algorithm public key and the anti-quantum cryptography algorithm public key to obtain a public key algorithm identifier and a dual-algorithm public key combination; respectively performing signature processing on the certificate request by using a classical cryptographic algorithm private key and an anti-quantum cryptographic algorithm private key, and combining two signature results to obtain a signature algorithm identifier and a dual-algorithm signature value combination; submitting a composite digital certificate application request to a CA certificate authority; and verifying the dual-algorithm signature value combination by using the dual-algorithm public key combination in the composite digital certificate application request through the CA certificate authority, and issuing the digital certificate if the verification is passed. The invention also discloses a device for realizing the anti-quantum composite digital certificate realization method, computer equipment and a storage medium. According to the invention, dual security assurance under the threat of quantum computing is realized.
Owner:KOAL SOFTWARE CO LTD

Tamper protection for the clock of a field tool

Method (100) for operating a field device (1) comprising an adjustable clock (2), at least one non-volatile CA memory (3) containing a public key certificate (3a) of a trusted certification authority, CA, at least one non-volatile time memory (4) for recording a date and / or time (4a) and at least one interface (5), comprising the steps: • A current date and / or time (7a) is received via the interface (5) (170); • this current date or time (7a) is compared with the date or time (4a) in the time memory (4) (180); and • In response to the fact that the current date or time (7a) is later (190) than the date or time (4a) in the time memory (4), the adjustable clock (2) of the field device (1) is set to the current date or time (7a) (200).
Owner:VEGA GRIESHABER GMBH & CO

Attribute-based access control method for realizing puncture revocation and outsourcing decryption under multiple authorizations

InactiveCN120956419AKey distribution for secure communicationAccess structureEngineering
The invention discloses an attribute-based access control method for realizing puncture revocation and outsourcing decryption under multiple authorizations, which is characterized in that a certificate issuing mechanism is responsible for initialization of a system and registration of an attribute issuing mechanism and a user, and the attribute issuing mechanism manages part of attributes authorized by the attribute issuing mechanism and generates a conversion key of an agency for outsourcing decryption; the data owner encrypts the data by using attribute-based encryption according to the defined access structure and the label structure; and the proxy server converts the access strategy formulated by the data owner into a puncture strategy and then punctures the conversion key so as to cancel the specified user group. According to the method, puncture revocation and outsourcing decryption attribute-based access control under a multi-authorization mechanism can be realized, and a feasible method is provided for lightweight and fine-grained user revocation under the multi-authorization mechanism.
Owner:NANJING UNIV OF POSTS & TELECOMM

Anti-quantum certificate signature verification method and device, equipment and storage medium

The invention discloses an anti-quantum certificate signature verification method, which comprises the following steps: signing and issuing a traditional certificate to a certificate issuing mechanism, and carrying out abstract operation processing on a serial number of the traditional certificate to obtain an abstract of the traditional certificate; issuing an anti-quantum certificate to a certificate issuing mechanism, and adding the abstract of the traditional certificate into an extension item of the anti-quantum certificate, so that the anti-quantum certificate is bound with the traditional certificate; when the security of the certificate needs to be verified in the interaction process with other application systems, performing signature verification processing on the traditional certificate; and after the signature verification of the traditional certificate is passed, carrying out signature verification processing on the countermeasure quantum certificate, and if the verification is passed, considering the certificate as a trusted certificate. The invention further discloses a device for implementing the anti-quantum certificate signature verification method, computer equipment and a storage medium. According to the method, the potential risk that a traditional digital certificate is attacked by quantum during use can be well solved, and the security of the certificate is greatly improved.
Owner:KOAL SOFTWARE CO LTD

Remote attestation method and related device

This disclosure provides a remote attestation method and a related device, to verify a remote attestation report by using a symmetric key of a subscriber identity module (SIM), without depending on a digital certificate provided by a certificate authority (CA) server. This can improve reliability of a remote attestation report verification process. In the method, a first apparatus receives request information, where the request information is for requesting a remote attestation report, and the remote attestation report is for remote attestation of the first apparatus. The first apparatus sends first information based on the request information, where the first information includes the remote attestation report and verification information, the verification information is for verifying the remote attestation report, and the verification information is obtained by processing the remote attestation report based on a symmetric key of a SIM in the first apparatus.
Owner:HUAWEI TECH CO LTD

Distributed identity association and verification method and system combining alliance chain and trusted CA

The invention discloses a distributed identity association and verification method and system combining an alliance chain and a trusted CA (Certificate Authority). The method comprises the following steps: firstly, guiding a user to complete identity verification in a trusted third-party authentication center to obtain an authoritative verifiable certificate; based on the certificate, the back end of the system automatically applies for signing and issuing an operation certificate for on-chain interaction to the alliance chain. The system constructs a distributed identity document aggregating verifiable credentials and public key information for a user. A user imports an operation certificate and a private key into a block chain wallet, signs a transaction in person, and registers a DID and a document thereof into an on-chain smart contract, so that the problems that in an existing block chain identity system, an on-chain identity is separated from an entity identity, roots of trust are not uniform, and interoperability is poor are solved; unified and non-tampering on-chain association of a user entity identity, an on-chain operation identity and a standardized DID is realized, an identity system with a trusted CA as a root of trust is established, the sovereignty and security of the user are guaranteed while supervision requirements are met, and the identity interoperability is improved.
Owner:XI AN JIAOTONG UNIV

Distributing certificate bundles according to fault domains

Operations of a certificate bundle distribution service may include: detecting a trigger condition to distribute a certificate bundle that includes a set of certificate authority certificates; determining, for each of a plurality of network entities associated with a computer network, a fault domain representing at least one single point of failure; partitioning the plurality of network entities into a plurality of certificate distribution groups, based on a set of partitioning criteria that includes a fault domain of each particular network entity, in which each particular certificate distribution group includes a particular subset of network entities, and the particular subset of network entities are associated with a particular fault domain; selecting a particular certificate distribution group, of the plurality of certificate distribution groups, for distribution of the certificate bundle; and transmitting the certificate bundle to the particular subset of network entities in the particular certificate distribution group.
Owner:ORACLE INT CORP

Anti-quantum anonymity voucher generation method and device, equipment and medium

The invention discloses an anti-quantum anonymity voucher generation method and device, equipment and a medium, and the method comprises the steps: carrying out the improvement of a conventional original image sampling method based on an approximate trap door sampling and refusal sampling technology, constructing a more efficient anonymity voucher generation protocol, remarkably reducing the calculation complexity, and improving the practicality. The user sends an application to a certificate authority (CA) to obtain an anonymous certificate for a specific attribute; and the CA interacts with the user and returns the signed attribute, and the user calculates an anonymous certificate according to the attribute and locally stores the anonymous certificate. During identity authentication, a user interacts with a service provider (SP) by using a local certificate to dynamically generate a proof; and the SP verifies the certification and then outputs an authentication result. According to the method, the defects of traditional identity authentication and anonymous certificates are overcome, efficient authentication can be realized under limited equipment and a high-privacy scene, and a better scheme is provided for actual deployment of the anonymous certificates.
Owner:SOUTH CHINA AGRICULTURAL UNIVERSITY

Methods and apparatus for automatically securing communications between a mediation device and a law enforcement device

ActiveUS12500944B2Securing communicationLawful interceptionSecure communication
Methods and apparatus for automatically securing communications between a mediation device (MD) and a law enforcement device, such as an agent's terminal, to which intercepted communications, e.g., traffic, is sent are described. Based on a desired intercept request to be implemented, a Lawful Interception (LI) administration (admin) device (LID) identifies at least a first mediation device (MD) which will be involved in implementing the intercept request. The LID then proceeds to enable the use of a private certificate authority to automatically generate and provision the MD and a law enforcement device with certificates and private keys via an automated process. Each of the MD and law enforcement device automatically obtain a security certificate and corresponding private key. The security certificates and corresponding private keys are then used, in an automated manner, to establish a mutual TLS connection between the MD and the law enforcement device.
Owner:CHARTER COMM OPERATING LLC

System and method for using client-based login certificates for remote applications

A system and method for providing a single sign-on for connecting a client device to a virtual infrastructure. The virtual infrastructure includes a server, an enterprise connector and a certificate authority. The client device receives an identity provider (IdP) token obtained from an IdP on authenticating a user of the client device. On authentication of the user, a desktop client application on the client device sends a request through the enterprise authority for a login certificate. A login certificate generated by the certificate authority is received by the client device. The login certificate to the client device is sent to the virtual infrastructure to allow the client device a connection to a virtual machine of the virtual infrastructure.
Owner:WORKSPOT INC

Systems and methods for utilizing onboard vehicle hardware for secure ECU data communication

Aspects of the present application utilizes onboard vehicle hardware for secure ECU data communication. In some embodiments, a main ECU receives a private key from a certificate authority and stores it within a hardware security module (HSM). The main ECU may then generate a symmetric vehicle-specific key based on at least one vehicle parameter of the vehicle (e.g., the odometer) and store it in the HSM. An additional ECU may be detected by the main ECU on a vehicle communication network (e.g., ethernet). The additional ECU may be an FPGA that includes an unprovisioned vehicle control operation. The main ECU may generate an FPGA image for the additional ECU where the FPGA image has the symmetric vehicle-specific key. The main ECU may then cryptographically sign the FPGA image using the private key stored in the HSM and transmit the signed FPGA image to the additional ECU for installation.
Owner:ADEIA GUIDES INC

Cryptographic attestation of data object attributes in a distributed system

A request to provide a data object attestation authority certificate to a second cluster of secure environments is received at a first cluster of secure environments. The request comprises a cluster certificate of the second cluster issued by a cluster enrollment certificate authority (CA). The cluster certificate is validated using a public key of the enrollment CA. An encrypted message comprising the attestation authority certificate and a digital signature of the first cluster is generated. The encrypted message is encrypted using a public key indicated in the cluster certificate of the second cluster. The digital signature is associated with a cluster certificate of the first cluster issued by the enrollment CA. The encrypted message is provided to the second cluster to be decrypted using a private key associated with the cluster certificate of the second cluster, and to be validated using at least the public key of the enrollment CA.
Owner:FORTANIX INC

Electronic device for authentication and method of operation thereof

An operating method for an electronic device is disclosed. An operating method for an electronic device according to an embodiment of this disclosure may include the following operations: retrieving a certificate from a file stored in the electronic device; sending a verification request for the certificate to a certificate authority in response to recognizing that the certificate is a new certificate; determining whether the certificate's validity period has expired in response to receiving a response from the certificate authority confirming the certificate's validity; determining whether the certificate is included in an exception list when the certificate's validity period has expired; and storing the certificate in the memory of the electronic device in response to determining that the certificate is included in the exception list, wherein the exception list includes at least one certificate.
Owner:SAMSUNG ELECTRONICS CO LTD

Digital certificate management method, device, equipment, medium and program product

The invention provides a digital certificate management method. The method can be applied to the technical fields of big data and financial science and technology. The method is applied to a server for distributing a digital certificate in a distributed server cluster, and comprises the following steps: acquiring a digital certificate application element, and generating a digital certificate request file and a private key based on the digital certificate application element. Wherein the private key is a private key of an environment system which cannot carry out data transmission and is bound with a server used for distributing the digital certificate. And sending the digital certificate request file to a digital certificate issuing mechanism for generating a digital certificate. Wherein the digital certificate comprises a public key corresponding to the private key, and the private key is used for verifying the digital certificate. And acquiring the digital certificate, and distributing the digital certificate to a server for authenticating the digital certificate in a distributed server cluster. The invention further provides a digital certificate management device and equipment, a storage medium and a program product.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Anti-quantum-attack smart park data sharing method, device and medium

The invention discloses an anti-quantum-attack smart park data sharing method and device and a medium, and the method comprises the steps: generating a digital signature public key and a digital signature private key through a system administrator according to an anti-quantum digital signature scheme, and generating a homomorphic encryption and decryption public key and a homomorphic encryption and decryption private key according to an anti-quantum homomorphic encryption scheme, an anonymous signature public key and an anonymous signature private key are generated through a certificate authority according to the digital signature scheme for resisting anonymity of the quantum signer; sending an access request message of the user to a system administrator so as to sign the access request message by using a private key with a digital signature and sending the signed access request message to the user; verifying the identity of the administrator based on the digital signature, signing the access request information by using a private key of an anonymous signature, sending the access request information to a system administrator to verify the identity of the user, and allowing the user to access after the identity of the user passes verification; a system administrator selects plaintext data to encrypt and generate a ciphertext, and sends the ciphertext to a data requester, so that the data requester performs homomorphic operation on the ciphertext to complete data security sharing.
Owner:山东浪潮智慧建筑科技有限公司

Systems and methods for managing public key infrastructure certificates for components of a network

A device may determine that a network function of a network has been instantiated to facilitate communication via the network. The device may request a certificate authority to provide a certificate for the network function. The device may receive, from the certificate authority, the certificate. The device may generate a certificate profile to enable other network functions of the network to authenticate communications with the network function, wherein the certificate profile identifies: the certificate and a certification protocol. The device may provide, to the network function, the certificate profile to cause the network function to use the certificate to communicate with the other network functions.
Owner:VERIZON PATENT & LICENSING INC

Systems and methods for phone number certification and verification

Methods, systems, apparatuses, and computer-readable storage mediums are described for issuing digital certificates to phone numbers and verifying phone numbers based on the digital certificates. For instance, a client may request from a certificate authority a digital certificate to be associated with the client's phone number. The certificate authority issues a phone number challenge to the client to verify that the request did in fact come from the client. The certificate authority signs and issues the digital certificate to the client responsive to a successful challenge. The digital certificates are utilized to exchange messages between a caller and call recipient to determine whether a phone number provided via CLI is accurate or inaccurate. Embodiments described herein determine whether the phone number is accurate using a process referred herein as positive CLI verification and determines whether the phone number is inaccurate using a process referred herein as negative CLI verification.
Owner:JUST ONE TECH LLC

Device credential migration

PendingUS20260254807A1Internet privacyDevice migration
The present application relates to devices and components including apparatus, systems, and methods to migrate one or more credentials from a first device to a second device. The migration of the one or more credentials can include performing authentication procedures corresponding to the one or more credentials for determining whether migration of the one or more credentials is allowable, and utilizing certificate authority security domains of secure elements to bind the one or more credentials to the secure elements for migration.
Owner:APPLE INC

Anonymous credential generation system and method

The invention discloses an anonymous voucher generation system and method, and belongs to the technical field of computer security, and the anonymous voucher generation system comprises a certificate mechanism, a plurality of users and a server side. The certificate authority is used for sending the attribute, the credential value, the pseudonym and the accumulator evidence of the first user to the first user; the first user is configured to generate a blinded credential using the credential value, generate an accumulator auxiliary parameter based on the accumulator value and the accumulator evidence, generate a first zero knowledge proof based on the accumulator auxiliary parameter and a blinding auxiliary parameter in the blinded credential, the first zero knowledge proof is used for proving that the first user has the blinded certificate, the accumulator evidence, the accumulator auxiliary parameter and the blinding auxiliary parameter; and the server side is used for verifying the validity of the first zero knowledge proof, and verifying the correctness of the public attribute, the blinded certificate and the accumulator auxiliary parameters by adopting a bilinear pairing operation. The system can reduce the calculation overhead of the user in the anonymous credential technology.
Owner:WUHAN UNIV

Internal Certification Authority for Electronic Control Units

Example operations include providing, by a first electronic control unit (ECU), a fixed private key for the vehicle to a server; generating, by the first ECU, a finite-lifetime certificate based on the fixed private key, where the first ECU acts as a certificate authority; and providing the finite-lifetime certificate to a second ECU in the vehicle to enable the second ECU to securely communicate with the server.
Owner:TOYOTA MOTOR NORTH AMERICA INC

Dynamic attachment of secure properties to machine identity with digital certificates

Technology is shown for dynamically attaching secure properties to an identity certificate. Claims determining secure properties for an identity are signed and embedded in an identity certificate. Both the identity certificate and the signed claims in the certificate are verified. When a service request is received from the identity, the signed claims from the identity certificate are checked to determine if the request is permitted. If the request is permitted, then the service request is processed. Some examples involve creating claims determining the secure properties for the remote machine, signing the claims to create the signed claims, distributing the signed claims to a certificate authority, embedding the signed claims in the remote machine identity certificate, and distributing the remote machine identity certificate. The claims can be embedded in the certificate as X.509 properties.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Offline digital asset generation and provisioning

A system for offline generation of digital assets includes: a security credential management system (SCMS) that is operable to generate and conditionally transmit digital assets; and a certificate authority communicatively connected to the SCMS by a communication network, the certificate authority being operable to receive the digital assets from the SCMS. The certificate authority is operable to securely provision a plurality of computerized devices based on the received digital assets, the certificate authority intermittently connects to the SCMS to receive the digital assets, the certificate authority is operable to securely provision the plurality of computerized devices while disconnected from the SCMS, and the provisioning by the certificate authority while disconnected from the SCMS is limited by a policy associated with the certificate authority.
Owner:INTEGRITY SECURITY SERVICES LLC

Method and apparatus for automatic digital certificate validation

The public key can be recorded on the blockchain by the certificate authority in such a way that any third party can quickly and easily verify that the public key is certified by the certificate authority and that the certification has not been revoked. The certificate authority can revoke a certification almost instantaneously, and / or can certify a new key for the same entity at the same time as revoking the old key. The verification can be incorporated into a new transaction so that there is no gap between reliance on the certificate and verification of its validity. In some cases, each transaction in which a certificate is used can also serve as a certification transaction that links to update the certificate to enable subsequent use.
Owner:ENCHEN CHARTER CO LTD

Digital identity authentication method, device, equipment and medium

The invention discloses a digital identity authentication method and device, equipment and a medium. The method comprises the following steps: in response to a registration application sent by a user side, generating third identification information based on first identification information, second identification information and biological characteristic information acquired by a certificate authorization center; generating a user digital signature based on the third identification information and the user public key; in response to a login application sent by the user side, generating a first challenge value based on the generated first random number and the first timestamp; generating a user identity signature based on the first challenge value, the user digital signature and the user private key; when the user identity signature meets a preset identity condition, generating a first session key, and generating a second session key based on the first session key, the third identification information and the first timestamp; and when the second session key satisfies a preset communication condition, determining that the login application sent by the user side is passed. According to the invention, the bottleneck problems of centralization risk, security vulnerability, insufficient anti-counterfeiting property and the like of traditional identity authentication are solved.
Owner:CHINA MOBILE (XIONGAN) ICT CO LTD +3

Procedures for securely equipping systems with an individual certificate

The invention relates to a method for securely equipping systems (Sys) with an individual certificate, for secure communication with at least one communication partner, wherein a certification authority (CA) is established based on an asymmetric key pair (CARootPub, CARootPriv).It is characterized by the fact that at least one verification instance (PI) is established, wherein the verification instance (PI) is equipped with all the necessary means required for verifying certificates (Cert) issued by the certification authority (CA), and which include at least the implementation of a signature verification procedure for signatures created using the private key (CARootPriv) of the certification authority (CA) and the public key (CARootPub) of the certification authority (CA), wherein, for the purpose of carrying out the verification, the certificate (Cert) to be verified is transmitted from a requesting system (Sys) to the verification instance (PI), the verification instance (PI) performs the verification and communicates the result of the verification to the requesting system (Sys) in a suitable manner.
Owner:MERCEDES BENZ GROUP AG

Transitioning network entities associated with virtual cloud network by series of stages of certificate packet distribution processing

A network entity associated with the virtual cloud network is transitioned through a certificate packet distribution process for distributing a new certificate authority certificate to the network entity. The operations may include performing, with respect to each of the network entities, a first operation associated with a first stage of processing; for each particular network entity, obtaining individual entity information associated with the progress of the particular network entity with respect to the first phase; calculating an aggregation metric indicating an aggregation progress of the network entity with respect to the first phase based on the individual entity information; determining, based on the aggregation metric, that one or more transition criteria for transitioning the network entity from the first phase to a second phase of the processing are satisfied; and, with respect to each of the network entities, performing a second operation associated with the second stage of processing.
Owner:ORACLE INT CORP

A commercial cryptographic digital certificate generation method supporting quantum-resistant cryptography

The application relates to the technical field of information security, in particular to a commercial cipher digital certificate generation method supporting quantum-resistant cipher, which comprises the following steps: a certificate authority generates a hybrid signature self-signed certificate with quantum-resistant cipher signature and traditional public key cipher signature; a user generates a hybrid signature certificate request file and sends the file to the certificate authority; the certificate authority generates a hybrid signature user signature certificate; a key generation center generates a user traditional public key cipher encryption key pair and a user quantum-resistant cipher encryption key pair; the certificate authority generates a hybrid signature user encryption certificate; the certificate authority generates a hybrid encryption public key, a private key encryption ciphertext and a hybrid ciphertext; and the user extracts the hybrid signature signature certificate, the encryption certificate, the quantum-resistant cipher encryption private key and the traditional public key cipher encryption private key, and verifies the signature certificate and the encryption certificate. The application can resist quantum attacks and is compatible with existing digital certificates.
Owner:SHANDONG DUOFANG SEMICON CO LTD +1

Efficient, high-volume certificate chain validation

Techniques are disclosed for a certificate chain validation framework in which a validation service may validate a leaf certificate on behalf of an application service without traversing the rest of the certificate chain. The validation service maintains a database of validation information provided by a certificate authority. When the validation service receives a certificate chain validation request from an application service, the validation service may validate the leaf certificate by verifying signature and certificate data associated with other certificates in the certificate chain indicated by the leaf certificate using associated validation information from the database.
Owner:GOOGLE LLC

Intelligent campus certificate credit data management system based on artificial intelligence

The invention discloses an intelligent campus certificate credit data management system based on artificial intelligence, which relates to the technical field of artificial intelligence and comprises a multi-source data acquisition unit, a certificate verification unit, a credit progress monitoring unit and a credit supervision unit. The method comprises the following steps: acquiring a personal certificate data set, verifying the authenticity of an electronic seal and anti-counterfeiting watermark characteristics, marking the verified personal certificate data set as a target data set, extracting an issuing mechanism in a certificate, acquiring time and skill levels, carrying out assignment representation, and integrating into a certificate value data set; the credit conversion coefficient is calculated according to the authority, skill scarcity and industry acceptance degree of a certificate issuing mechanism, the certificate, the course score and the practice record of the same student are associated, and the student credit acquisition progress is predicted through time sequence analysis. And automatically generating a personalized repair scheme and sending the personalized repair scheme to the student terminal and the monitoring party associated with the student terminal.
Owner:HUNAN TECHN COLLEGE OF RAILWAY HIGH SPEED