Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

27 results about "Certificate signing request" patented technology

In public key infrastructure (PKI) systems, a certificate signing request (also CSR or certification request) is a message sent from an applicant to a certificate authority in order to apply for a digital identity certificate. It usually contains the public key for which the certificate should be issued, identifying information (such as a domain name) and integrity protection (e.g., a digital signature). The most common format for CSRs is the PKCS #10 specification and another is the Signed Public Key and Challenge SPKAC format generated by some web browsers.

Real estate full life cycle intelligent management method and system based on Internet of Things perception

The invention provides a real estate full life cycle intelligent management method and system based on Internet of Things perception, and the method comprises the steps: distributing a unique hardware identifier of equipment, combining a lightweight digital certificate with a pre-shared key to achieve two-factor authentication, and storing a root certificate in a cloud end; an access authentication process is optimized, an identity label and a certificate signature request need to be submitted when a node accesses for the first time, a temporary session key is generated after the gateway verifies, and abnormal access is immediately isolated and reported; data integrity verification is implemented, and after a sensor collects data, an abstract is generated and data encryption transmission is carried out; after decryption, the receiving end recalculates the abstract for comparison, and if not, the abstract is discarded and nodes are marked to be abnormal; a data anomaly detection model is constructed, energy consumption fluctuation is determined based on historical data, a frequency baseline is collected, data reasonability is monitored in real time, secondary authentication is triggered when the data is abnormal, and node data access is suspended if the data fails; a hierarchical key system is established, hardware is solidified by a root key, session keys are alternated for 24 hours, and data encryption keys are dynamically derived and distributed through encryption channels.
Owner:LERUAN CENTURY (BEIJING) INFORMATION TECHNOLOGY CO LTD

Method for verifying the origin of an electronic unit for a control device using a verification system, computer program product and verification system

The invention relates to a method for verifying the origin of an electronic unit (1) for a control device (2) using a verification system (3), comprising the steps of: receiving a certificate signing request (7) for digitally certifying the control device (2) with the electronic unit (1) from a requesting instance using a receiving device (4) of the verification system (3), wherein the certificate signing request (7) is signed with a wrapper signature (8) of the electronic unit (1); generating a verification request (9) with a manufacturer of the electronic unit (1) based on the received wrapper signature (8) using an electronic computing device (6) of the verification system (3); transmitting the verification request (9) to the manufacturer using a sending device (5) of the verification system (3);Receiving a verification message (11) for verifying the electronic unit (1) from the manufacturer using the receiving device (4); and verifying the origin of the electronic unit (1) depending on the verification message (11) using the electronic computing device (6). The invention further relates to a computer program product and a verification system (3).
Owner:AUDI AG +1

Secure programming system, operating method thereof and computer readable recording medium using such operating method

A method for operating a secure programming system is provided. Firstly, a first verification code is calculated according to a payload extracted from a job control package. Then, a second verification code is calculated according to the payload burnt into a programmable device. If the first verification code and the second verification code are verified successfully, a burning task is performed. Then, an OEM certificate signing request is generated according to an identifiable information and a programmable device public key. If the OEM certificate signing request is verified successfully, an OEM device certificate is generated and signed with an OEM private key. A third verification code is calculated according to the OEM device certificate. Then, a fourth verification code is calculated according to the OEM device certificate burnt into the programmable device.
Owner:DEDIPROG TECH

Hierarchical certificate issuing system, method, device and equipment

PendingCN121864327AUser identity/authority verificationRoot certificateCertificate signing request
The invention provides a hierarchical certificate issuing system, method, device and equipment, and the system comprises root CA equipment, strategy CA equipment and certificate issuing CA equipment: the root CA equipment is used for generating a self-signature root CA certificate based on a root CA key pair, and carrying out the signature of a strategy CA certificate signature request of the strategy CA equipment through employing a root CA private key, and obtaining the strategy CA certificate; the policy CA equipment is used for acquiring a policy CA certificate from the root CA equipment and signing a certificate issuing CA certificate signature request of the certificate issuing CA equipment by adopting a policy CA private key to obtain the certificate issuing CA certificate; the certificate issuing CA equipment is used for acquiring a certificate issuing CA certificate from the policy CA equipment and signing a terminal certificate signature request of the terminal equipment by adopting a certificate issuing CA private key to obtain a terminal entity certificate; and the certificate issuing CA equipment is also used for sending a certificate chain to the terminal equipment, and the certificate chain comprises a self-signature root CA certificate, a policy CA certificate, a certificate issuing CA certificate and a terminal entity certificate.
Owner:BEIJING CHUANGRUI HONGKE TECHNOLOGY CO LTD

Cryptographic algorithm identity (CAI) certificate selection system and method

Systems and methods for cryptographic algorithm identity certificate selection in an Information Handling System (IHS) are described. In one embodiment, an IHS includes a processor, and a memory coupled to the processor. The memory stores program instructions that, upon execution, cause the processor to receive a Certificate Signing Request (CSR) from a server, sign the CSR with a first Cryptographic Algorithm Identity (CAI) key stored in the memory, and send the signed CSR to the server. The server is configured to identify a geographical region that is associated with the first CAI key, identify an approved cryptographic algorithm that is approved for use in the identified region, and send a second CAI key associated with the identified approved cryptographic algorithm. When the IHS receives the second CAI key from the server, it may perform a cryptographic operation using a cryptographic algorithm associated with the second CAI key.
Owner:DELL PROD LP

Authentication method, authentication system and communication method

PendingCN121585376AUser identity/authority verificationCertificate signing requestEngineering
The invention discloses an authentication method, an authentication system and a communication method, a complex three-level architecture under a PKI (Public Key Infrastructure) framework is abandoned, a two-layer architecture of a main controller and nodes is adopted, hierarchical interaction overhead is reduced, a certificate signature request is firstly sent through the nodes, a trust chain between the two layers is established by adopting a signature verification mode, and a certificate signature request is sent through the nodes. And then, within a preset time, based on encryption, decryption, signature and signature verification of the secret key, strict identity authentication of a request-response-confirmation mechanism is completed, so that the security of data interaction during communication can be ensured.
Owner:JIANGSU XCMG STATE KEY LAB TECH CO LTD

Method of updating device certificate and device for driving the method

ActiveUS12621167B2User identity/authority verificationInternet privacyCertificate signing request
A device may include processing circuitry configured to, generate a device identifier associated with the device, and generate a unique endorsement identity (ID) associated with the device identifier, a first layer sub-circuit configured to, receive the device identifier, and generate a first certificate and a second certificate based on the device identifier and the unique endorsement ID, the first certificate and the second certificate including information to authenticate the device, and the processing circuitry is further configured to, receive the first certificate and the second certificate, and verify whether the device has been modified based on the first certificate and the second certificate, wherein, in response to the first layer sub-circuit being modified, the first layer sub-circuit is further configured to, generate an endorsement key based on a new unique endorsement ID, and generate a certificate signing request for the new unique endorsement ID based on the endorsement key.
Owner:SAMSUNG ELECTRONICS CO LTD

Method for verifying the origin of an electronic unit for a control device using a verification system, computer program product, and verification system

The invention relates to a method for verifying the origin of an electronic unit (1) for a control device (2) using a verification system (3), having the steps of: receiving a certificate signing request (7) for digitally certifying the control device (2) with the electronic unit (1) from a query entity by means of a receiving device (4) of the verification system (3), wherein the certificate signing request (7) is signed with a wrapper signature (8) of the electronic unit (1); generating a verification query (9) for a manufacturer of the electronic unit (1) on the basis of the received wrapper signature (8) by means of an electronic computing device (6) of the verification system (3); transmitting the verification query (9) to the manufacturer by means of a transmitting device (5) of the verification system (3); receiving a verification message (11) for verifying the electronic unit (1) from the manufacturer by means of the receiving device (4); and verifying the origin of the electronic unit (1) on the basis of the verification message (11) by means of the electronic computing device (6). The invention also relates to a computer program product and to a verification system (3).
Owner:VOLKSWAGEN AG +1

Trusted digital identity management method and device, equipment, medium and product

The invention discloses a trusted digital identity management method, device, equipment, medium and product, a super SIM card receives a key generation instruction sent by a user terminal, generates a key comprising a public key and a private key, generates a certificate signature request file according to the public key and an identity identification code of the user terminal, and sends the certificate signature request file to the user terminal; the user terminal carries a certificate signature request file and user identity information and initiates a digital identity creation request to the trusted identity platform; and when the SIM card receives encrypted data returned after the trusted identity platform adopts the public key to encrypt, the SIM card adopts the private key to decrypt to obtain the digital identity certificate, the user identity information and the biological characteristic identification information signed by adopting the digital identity certificate in the encrypted data, and returns a digital identity creation result to the user terminal. According to the invention, the management processes such as creation and authentication of the digital identity certificate are realized through the super SIM card, and the security of the digital identity certificate in the storage and authentication process is improved.
Owner:CHINA MOBILE INTERNET CO LTD +1

Certificate signature request file synchronization method and device, electronic equipment and storage medium

PendingCN121940391AUser identity/authority verificationFile synchronizationStation
The invention relates to a certificate signature request file synchronization method and device, electronic equipment and a storage medium, and the method comprises the steps: automatically sending a generated CSR file to a first server located in the same local area network as the electronic equipment in response to the availability of network connection, forwarding the received CSR file by the first server, and sending the CSR file to the electronic equipment; and the CSR file sent by the electronic equipment can be uniformly forwarded to the second server only by configuring the first server which can be connected with the same local area network as the electronic equipment and also can be connected with the external network without configuring a special network which can be connected with the external network for writing on the electronic equipment. In this way, additional manual sites can be omitted, network and after-sales costs are saved, the data reliability is further improved, and the risk of file leakage is avoided; and meanwhile, the automation and intellectualization of the automatic generation, sending and forwarding processes of the whole CSR file are realized, the production efficiency is remarkably improved, and the electronic equipment of which the CSR file is not successfully forwarded is prevented from flowing into the market.
Owner:SHENZHEN SKYWORTH RGB ELECTRONICS CO LTD

Interim root-of-trust enrolment and device-bound public key registration

ActiveUS12695631B2Certificate signing requestEngineering
Methods, apparatuses, devices and computer readable media are provided in relation to enrolment. In one example, an electronic device is provided. The electronic device comprises a security module having a physical unclonable function (PUF). The security module is configured to establish an enrolment key pair (EPK,ESK) based on a first challenge and response to the PUF, the enrolment key pair comprising an enrolment public key (EPK) and an enrolment secret key (ESK). The electronic device further comprises one or more memories. The electronic device further comprises one or more processors configured to, over a secure connection, transmit a certificate signing request (CSR) comprising a device identifier and the EPK to a server for a certificate certifying that the EPK is associated with the device identifier, wherein the CSR is signed using the ESK, and wherein the device identifier is based on a function of the EPK. The one or more processors are further configured to, over the secure connection, receive a temporary enrolment device certificate certifying that the EPK is associated with the device identifier and including a validity period. The one or more processors are further configured to install the temporary enrolment device certificate in memory.
Owner:CRYPTO QUANTIQUE LTD

Digital certificate full life cycle management method and system based on PKI system

The invention provides a digital certificate full life cycle management method and system based on a PKI system, and relates to the technical field of information security, and the method comprises the steps: receiving a certificate signature request sent by an unmanned platform end through a user datagram protocol UDP; if the validity verification of the certificate signature request is passed, signing and issuing an unmanned platform end certificate by using a private key of the intermediate CA; a complete certificate chain containing an unmanned platform end certificate is assembled, and the complete certificate chain is issued to the unmanned platform end at a time through a UDP; monitoring the state information of the certificate managed by the intermediate CA through a certificate life cycle management engine integrated in the intermediate CA; and when the residual validity period of the certificate is determined to be insufficient based on the state information, a certificate updating process is automatically triggered, and the unmanned platform end is notified to send a new certificate signature request through a UDP (User Datagram Protocol). According to the method, security risks are isolated through hierarchical CA design, automatic processing of certificate application, signing and issuing, updating and revoking is realized, and the security of a PKI system is improved.
Owner:天津(滨海)人工智能创新中心

Communication certificate secure canning method, device and equipment of vehicle-mounted terminal and medium

The invention provides a communication certificate security canning method, device and equipment of a vehicle-mounted terminal and a medium, and effectively solves the problem that a large number of security risks and uncontrollable factors occur due to the fact that a communication certificate does not exist between an existing vehicle-mounted terminal and a vehicle factory. The method comprises the following steps: a production line module sends a certificate generation instruction to a vehicle-mounted terminal, and a vehicle-mounted host receives the certificate generation instruction through a vehicle body bus and forwards the certificate generation instruction to a key generation module of the vehicle-mounted terminal; the key generation module calls the vehicle factory encryption module, locally generates an asymmetric key pair at the vehicle-mounted terminal through the vehicle factory encryption module, and generates a certificate signature request based on the asymmetric key pair; the vehicle factory encryption module binds the certificate signature request with a vehicle-mounted terminal identifier pre-acquired by the key generation module to generate a communication certificate; and the key generation module generates a processing result and feeds back the processing result to the production line module through the vehicle body bus so as to complete safe canning.
Owner:JIANGSU BDSTAR AUTOMOTIVE ELECTRONICS CO LTD

Signature request verification method and system, certificate generation method and system and electronic equipment

The invention discloses a signature request verification method and system, a certificate generation method and system and electronic equipment, which are applied to a verification terminal, the verification terminal is respectively connected with a terminal to be verified and a registration terminal, and the method comprises the following steps: establishing a connection with an operator UKEY through dual verification; obtaining verification information from the operator UKEY, and establishing a secure channel with the registration terminal through the verification information; a first device serial number is obtained, a generation instruction and the first device serial number are sent to the to-be-verified terminal, and the generation instruction is used for driving the to-be-verified terminal to generate a certificate signature request; a certificate signature request is received, the first device serial number, the certificate signature request and a verification instruction are sent to the registration terminal through the secure channel, and the verification instruction is used for driving the registration terminal to verify the first device serial number and the certificate signature request to obtain a verification result; and receiving a verification result. The registration terminal can identify the certificate signature request of a legal source, and the authentication efficiency and security are improved.
Owner:FUJIAN LANDI COMMERCIAL EQUIPMENT CO LTD

Dynamic generation of digital certificate requests

ActiveUS12598077B2User identity/authority verificationCertificate signing requestEngineering
A method in a server, the method comprising: storing, in a memory of the server, a certificate signing request (CSR) input template comprising: (i) a dynamic first field definition including an attribute name, and (ii) a second field definition including a second field value; transmitting respective CSR instructions to a plurality of client devices, each instruction including the CSR input template; in response to transmitting the instructions, receiving, from each client device, a CSR comprising: (i) a first field value including an attribute value inserted by the client device in place of the attribute name, and (ii) the second field value; installing respective digital certificates at each of the client devices in response to receiving the CSRs.
Owner:ZEBRA TECHNOLOGIES CORP

Managing hygiene of key pairs between certificate authorities using FHE

A method of issuing a digital certificate includes receiving a certificate signing request (CSR) from an entity; determining a public key of the entity from the CSR; applying encryption to the public key; checking whether a result of the encryption is in a database to determine whether the public key has been previously used; and responsive to the public key not having been previously used, issuing a certificate to the entity based on the public key and the CSR. The method can further include, responsive to the public key having been previously used, alerting the entity to resubmit the CSR with a public key that has not been previously used or inquiring from the entity whether to proceed to issuing the certificate despite previous use. The encryption can be fully homomorphic encryption (FHE).
Owner:DIGICERT INC

Digital certificate issuing method based on double certificate system and related device

ActiveCN120110678BQuantum algorithmCertificate signing request
Embodiments of the application disclose a digital certificate issuing method and related device based on a double-certificate system, a user terminal generates a first and a second public-private key pair according to an asymmetric encryption algorithm and a post-quantum key signature algorithm respectively; the first and the second public key are taken as a hybrid public key to generate a certificate signature request together with user identification information, and the certificate signature request is sent to a certificate authority terminal; the certificate authority terminal generates a hybrid key signature certificate, a hybrid key encapsulation certificate, an encrypted hybrid key encapsulation private key and an encrypted symmetric key according to the certificate signature request; the user terminal decrypts the encrypted hybrid key encapsulation private key and the symmetric key according to the first private key to obtain the hybrid key encapsulation private key; the hybrid key signature certificate and the hybrid key encapsulation certificate are installed and bound with the corresponding private key, so that the hybrid key signature certificate and the hybrid key encapsulation certificate are issued, the legal use of the certificate in a quantum algorithm resistant scenario is ensured, and the information security is improved.
Owner:ORIGIN QUANTUM COMPUTING TECH (HEFEI) CO LTD

Secure communications between edge clusters and cluster management system

An apparatus comprises at least one processing device configured to establish a first secure communication channel between at least one edge computing site and a management system, and to send a certificate signing request over the first secure communication channel from the at least one edge computing site to the management system. The processing device is further configured to receive, over the first secure communication channel from the management system in response to the certificate signing request, a digitally signed certificate for the at least one edge computing site and a certificate authority certificate. The processing device is still further configured to establish a second secure communication channel between the at least one edge computing site and the management system. The second secure communication channel utilizes a mutual authentication protocol. The certificate authority certificate and the digitally signed certificate are used to establish the second secure communication channel.
Owner:DELL PROD LP

Certificate update method and certificate update system of device driving the same

ActiveUS12664282B2User identity/authority verificationDigital data protectionOriginal equipment manufacturerCertificate signing request
A method of updating a certificate for device identification of at least one example embodiment includes generating a device identifier comprising unique information of the device, generating a device identity (ID) certificate signing request (CSR) based on the device identifier, updating the bootloader, the updating including updating a certificate of the device based on the device ID CSR using firmware of the device in response to a request of a host device, and in response to the bootloader being changed, authenticating the updating of the bootloader based on a second certificate generated by an original equipment manufacturer (OEM) of the device in response to authentication of the bootloader failing based on a first certificate generated by a manufacturer of the device.
Owner:SAMSUNG ELECTRONICS CO LTD

Method for verifying the origin of an electronic unit for a control device using a verification system, computer program product and verification system

The invention relates to a method for verifying the origin of an electronic unit (1) for a control device (2) using a verification system (3), comprising the steps of: receiving a certificate signing request (7) for digitally certifying the control device (2) with the electronic unit (1) from a requesting instance using a receiving device (4) of the verification system (3), wherein the certificate signing request (7) is signed with a wrapper signature (8) of the electronic unit (1); generating a verification request (9) with a manufacturer of the electronic unit (1) based on the received wrapper signature (8) using an electronic computing device (6) of the verification system (3); transmitting the verification request (9) to the manufacturer using a sending device (5) of the verification system (3);Receiving a verification message (11) for verifying the electronic unit (1) from the manufacturer using the receiving device (4); and verifying the origin of the electronic unit (1) depending on the verification message (11) using the electronic computing device (6). The invention further relates to a computer program product and a verification system (3).
Owner:AUDI AG +1

Fine time measurement location configuration information protection

PendingUS20260136189A1User identity/authority verificationSecurity arrangementStationCertificate signing request
Fine Time Measurement (FTM) Location Configuration Information (LCI) protection and, specifically, FTM LCI protection with authentication and selective client enablement may be provided. To perform FTM LCI protection, a controller may first obtain a key-pair including a public key and a private key from a Certificate Authority (CA). The controller my determine a venue location where an Access Point (AP) is located. The controller may send a Certificate Signing Request (CSR) with the venue location to the CA. In response to sending the CSR, the controller may receive a public key certificate from the CA, wherein the public key certificate includes the venue location. The AP may receive a request for Location Configuration Information (LCI) from a Station (STA), wherein the LCI includes an AP location. The AP creates a hash of LCI of the AP using the private key and sends the LCI and the hash to the STA.
Owner:CISCO TECHNOLOGY INC

Registration authority

PCT designated stageWO2026084998A1Securing communicationRegistration authorityInternet privacy
A method of updating a certificate at an end-point of a network is disclosed. The method comprises: verifying, by a registration authority, an authenticity of a head-end system in the network; verifying, by the registration authority, an authenticity of at least one end-point communicatively coupled to the head-end system; receiving, by the registration authority and after verification of the authenticity of the head-end system and the at least one end-point, at least one certificate signing request from the at least one end-point, via the head-end system; brokering, by the registration authority, a new certificate from a certificate authority for each at least one end-point based on the respective at least one certificate signing request; and providing, by the registration authority, each new certificate to the head-end system for transmission to the respective at least one end-point.
Owner:LANDIS GYR TECH INC

Method of acquiring an operational certificate

A method of acquiring an operational certificate for an application (140) running on an authorized and / or authenticated host node (130) in a network (100), the method comprising: transmitting, by the application, a request comprising a Certificate Signing Request to a proxy engine (145) running on the authorized and / or authenticated host node; receiving, by the proxy engine, the request, and submitting the Certificate Signing Request to a Certificate Authority (155); signing, by the Certificate Authority, the operational certificate and transmitting a response comprising the signed operational certificate to the proxy engine; and forwarding, by the proxy engine, the signed operational certificate to the application.
Owner:LANDIS GYR TECH INC

Equipment authentication method and device, computer equipment and storage medium

PendingCN121690649AUser identity/authority verificationDigital rights managementSecurity validation
The invention discloses an equipment authentication method and device, computer equipment and a storage medium, a request file containing a unique serial number and a certificate signature is generated at an equipment end, the request file is converted into a two-dimensional code by using an image coding algorithm, and data is acquired at an upper computer in an optical scanning mode, so that cross-equipment off-line secure transmission is realized, and the security of equipment authentication is improved. And the leakage risk of the plaintext file in the open network is avoided. And meanwhile, symmetric encryption, digital signature and integrity verification mechanisms are adopted in the whole process of acquisition, decoding, encryption and transmission of authentication data, so that tampering and replay attacks are effectively prevented. According to the method and the device, the device registration process in the production stage is simplified, the method and the device are suitable for a batch and automatic authentication environment, and particularly in a Google TV and other systems needing strict digital rights management and security verification, rapid and reliable device identity establishment and certificate registration can be realized, so that the security and the traceability of the device authentication system are integrally improved.
Owner:彩迅工业(中山)有限公司

Systems and methods for securing interconnecting directories

Systems and methods are provided for deploying keys in connection with proxy resolution. One example computer-implemented method includes distributing, by a service core computing device, a root certificate signed by a certificate authority and an intermediate certificate, which is signed by a root private key associated with the root certificate, and receiving, from a participant, a signing request for a participant certificate including a participant public key. The method also includes assessing, by the service core computing device, the signing request for the participant certificate and signing, by the service core computing device, the participant certificate with an intermediate public key included in the intermediate certificate. The method then includes disseminating the signed participant certificate to the participant and another participant, whereby the participants on the participant certificate based on the participant certificate being signed by the intermediate public key.
Owner:VOCALINK INT LTD

Certificate enrollment system and method for non-virtual machine based network element

ActiveUS12556919B2Security arrangementSecuring communicationCertificate signing requestEngineering
A system for performing full-automated enrollment of certificates in a mobile communications network, includes: a network element configured to request a certificate; at least one server configured to authenticate the network element and provide certificate authority (CA) information to the network element; and a certificate manager configured to obtain a preconfigured policy for the requested certificate, obtain the certificate based on the preconfigured policy, and issue the certificate to the network element, wherein the network element is configured to: send, to the at least one server, a request for obtaining information on the certificate manager; obtain, from the at least one server, the information on the certificate manager; send, to the certificate manager based on the obtained information on the certificate manager, a certificate signing request (CSR) for requesting the certificate; and receive, from the certificate manager, the requested certificate generated by a CA server of the certificate manager.
Owner:RAKUTEN MOBILE INC

Digital certificate issuing method based on post-quantum hybrid algorithm and related device

The embodiment of the application discloses a digital certificate issuing method based on a post-quantum hybrid algorithm and a related device, a user terminal generates three pairs of public and private keys according to an asymmetric encryption algorithm, a post-quantum key signature algorithm and a post-quantum key packaging algorithm; generates a certificate signature request according to a hybrid public key including a first and a second public key and user identification information; and sends the same to a CA terminal together with a third public key; the CA terminal generates a hybrid key signature and a packaging certificate, key packaging ciphertext and encrypted hybrid key packaging private key according to the two; the user terminal decrypts the key packaging ciphertext and the encrypted hybrid key packaging private key according to the first and the third private keys to obtain the hybrid key packaging private key; installs the hybrid key signature and the packaging certificate and binds the same with the corresponding private key, so that the issuing of the hybrid key signature and the packaging certificate can be realized, the legal use of the certificate in the anti-quantum algorithm scene is ensured, and the information security is improved.
Owner:ORIGIN QUANTUM COMPUTING TECH (HEFEI) CO LTD