Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

20 results about "Client-side encryption" patented technology

Client-side encryption is the cryptographic technique of encrypting data on the sender's side, before it is transmitted to a server such as a cloud storage service. Client-side encryption features an encryption key that is not available to the service provider, making it difficult or impossible for service providers to decrypt hosted data. Client-side encryption allows for the creation of applications whose providers cannot access the data its users have stored, thus offering a high level of privacy. Those applications are sometimes marketed under the misleading term "zero-knowledge".

Cryptographic mediation of communication channels for software applications

A method applies secure cryptographic communication between legacy applications and corresponding external services. A user device has one or more processors and memory, and runs a legacy application. The application receives input (e.g., from a user). In response to the input, the application initiates communication over a secure communication protocol to an external service not running on the user device. A client crypto-service encapsulates the communication and provides a secure encrypted tunnel to a server crypto-service, at a server system, in communication with the external service. The server system has one or more processors and memory. The server system receives the encapsulated communication at the server crypto-service and sends the communication to the external service. The server system then receives a response to the communication from the external service and returns the response, through the secure encrypted tunnel, to the user device.
Owner:SB TECH INC

Data transmission method in intelligent agent system, intelligent agent system, equipment and medium

One or more embodiments of the present disclosure provide a data transmission method in an agent system, an agent system, a device and a medium, the agent system comprising an agent application, a first client, a first server and a large model, the first client, the first server and the large model being deployed in a trusted execution environment, comprising the following steps: receiving a first user request in response to an agent application, encrypting the first user request by a first client, and transmitting first encrypted data to a large model; the first client receives second encrypted data transmitted by the large model; the first client obtains the reasoning result, encrypts at least one subtask, and transmits third encrypted data to the first server; the first client receives fourth encrypted data transmitted by the first server; and the first client obtains a task execution result, and the agent application outputs the task execution result. And deploying the first client, the first server and the large model in a trusted execution environment to realize security and credibility of data transmission in the intelligent agent system.
Owner:BEIJING ZITIAO NETWORK TECH CO LTD

A cloud-edge collaborative business process intelligent optimization method and device and storage medium

The application discloses a cloud-edge collaborative business process intelligent optimization method and device and a storage medium, and belongs to the field of business process optimization. The method comprises the following steps: step 1, a client preprocesses a local business process event log, and calculates the support, cost and average cost lower bound of a scenario with a length of m; step 2, the client encrypts the scenario and the calculation result and uploads them to a server; step 3, the server calculates the global confidence, global average cost and global average cost lower bound of the scenario, adds scenarios meeting high correlation and low cost to a result set and a candidate set, and adds scenarios meeting high correlation and potential low cost to the candidate set; step 4, the server generates a candidate scenario with a length of m+1 based on the candidate set, and encrypts and distributes the candidate scenario to the client; step 5, the client calculates the support, cost and average cost lower bound of the new candidate scenario; and step 6, steps 2-5 are circularly executed until there is no new candidate scenario, and a final result set is output.
Owner:HEBEI UNIV OF TECH

Cloud sharing multi-terminal real-time online document encryption device based on national secret

The application discloses a cloud sharing multi-terminal real-time online document encryption device based on a national secret, belongs to the technical field of cloud sharing and encryption, and aims to solve the technical problem of how to realize real-time collaborative editing of user sensitive data and avoid content leakage in a document editing process. The technical scheme is that the device comprises a server and a client, the client comprises an application terminal and a password module, the server comprises a key distribution service unit and a collaborative service unit, the key distribution service unit comprises a key management service module and a key distribution service module, the collaborative service unit comprises a service module and a collaborative processing service module, the key distribution service unit is used for key distribution and key management, the collaborative service unit completes key distribution by calling the key distribution service module, and the client-encrypted document is converted and stored in ciphertext through collaborative operation, and the ciphertext is retransmitted to other clients.
Owner:INSPUR QILU SOFTWARE IND

Design implementation method and system for simulating defense gateway

The invention discloses a design implementation method and system for simulating a defense gateway. The simulation defense gateway comprises a simulation gateway container management platform, generates a simulation gateway container with redundancy based on a simulation gateway image, and runs a heterogeneous gateway program in the container; the simulation agent is deployed between the client and the simulation gateway container, distributes request data of the client to the simulation gateway container and returns response data of the simulation gateway container to the client; the multi-mode voting device is used for performing multi-mode voting on the output processed by the analog gateway container; the negative feedback controller receives the multi-mode voting results, if the voting results are inconsistent, the simulation gateway container management platform is triggered to clean the current simulation gateway container, other heterogeneous simulation gateway containers are randomly selected from the simulation gateway mapping pool for recovery, and meanwhile, a negative feedback result is sent to the simulation agent; and closing the encrypted session of the client. According to the invention, the security defense capability of the gateway is effectively improved.
Owner:STATE GRID HENAN ELECTRIC POWER ELECTRIC POWER SCI RES INST +2

Distributed training method and apparatus, terminal device, and computer readable medium

The present application relates to the technical field of artificial intelligence, and in particular to a distributed training method and device, terminal equipment and computer readable medium. The present application encrypts local original graph data, sends the encrypted graph data to other clients and obtains encrypted graph data of other clients, performs private intersection on the local encrypted graph data and the obtained encrypted graph data of other clients, obtains target graph data, trains the local model according to the target graph data, sends the trained model parameters to the central server to update the global model parameters, and sends the updated global model parameters to each local client to update the local model. The present application encrypts the local client graph data by the private intersection technology, interacts with the encrypted graph data of other clients, obtains data for model training, can ensure the security in the data interaction process, and improves the accuracy of the distributed training parameters.
Owner:PING AN TECH (SHENZHEN) CO LTD

Stateless session recovery method, apparatus and device for tlcp protocol

ActiveCN121462217BImplementing a stateless session recovery methodImprove access speedUser identity/authority verificationProtocol for Carrying Authentication for Network AccessDistributed computing
This application provides a stateless session recovery method, apparatus, and device for the TLCP protocol. The method includes: determining a second client signature hash value based on a client signature certificate; determining a second client encryption hash value based on a client encryption certificate; determining a second server signature hash value based on a server signature certificate; determining a second server encryption hash value based on a server encryption certificate; if the first client signature hash value is the same as the second client signature hash value, the first client encryption hash value is the same as the second client encryption hash value, the first server signature hash value is the same as the second server signature hash value, and the first server encryption hash value is the same as the second server encryption hash value, then the client's session is recovered, and a TLCP connection is established with the client. The technical solution of this application can save network bandwidth resources, reduce the computing resource consumption of business servers, and significantly shorten the connection establishment time.
Owner:HANGZHOU HIKVISION DIGITAL TECHNOLOGY CO LTD

An information sharing method, system, device and storage medium

The application discloses an information sharing method, system, device and storage medium, relates to the field of cryptography, and comprises the following steps: an initialization module is used for distributing the signature private key and the signature public key corresponding to the current user group and the public parameter information to each layer client in the current user group after the signature private key and the signature public key corresponding to the current user group and the public parameter information are generated, initializing the identity key information of the first layer client, and recording by using a block chain; a key distribution module is used for obtaining corresponding identity key information by configuring corresponding next layer clients by taking each layer client as a key generation party; an information encryption and sharing module is used for obtaining target ciphertext by encrypting the first target layer client, calling a preset block chain by using the identity key information of the second target layer client as an information receiver, verifying the preset block chain, and obtaining target contract events including the ciphertext after the verification is passed; and an information decryption module is used for decrypting and signing when the second target layer client listens to the target contract events. The system management burden is reduced.
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

Client-side encryption with low-cost integrity check

An apparatus in an illustrative embodiment comprises a client device configured for communication with a storage system, with the client device comprising a processor coupled to a memory. The client device is further configured to generate a data encryption key for a data item by computing a function of at least the data item, to encrypt the data item using the data encryption key for the data item, to encrypt the data encryption key using a secret key of the client device, and to send the encrypted data item and the encrypted data encryption key to the storage system for storage in the storage system. The client device is still further configured to retrieve the encrypted data item and the encrypted data encryption key from the storage system, and to perform an integrity check on the retrieved encrypted data item using a result of decrypting the retrieved encrypted data encryption key.
Owner:DELL PROD LP

User interface

Systems and methods for interacting with smart documents are disclosed. The system includes a document user interface that receives access requests, communicates with the smart document, and displays the content of the document. Features include rendering layouts tailored to user roles and devices, authentication mechanisms, and security measures such as screenshot prevention and client-side encryption, among a variety of others. The interface may support multi-panel displays, dynamic configurations, and other functionality like scheduling reports, marketing actions, and due diligence processes. Various other methods, systems, and features are also disclosed.
Owner:FACTIFY TECHNOLOGIES INC

A homomorphic convolution acceleration method based on approximate fast fourier transform

The application provides a homomorphic convolution acceleration method based on approximate fast Fourier transform, and belongs to the technical field of algorithm optimization of privacy calculation.The method mainly comprises client encryption, server-side calculation and client decryption, uses the fault tolerance feature of homomorphic convolution to perform optimized calculation on the homomorphic convolution, replaces the number theory transform NTT with fast Fourier transform FFT, and introduces an approximate method to further reduce the bit width, so as to reduce the hardware cost of each operation; in the process of determining the approximate FFT bit width, a multi-objective design space exploration method is adopted, different bit widths are used in multiple stages of fast Fourier transform, a space evaluation method based on a lookup table is designed, and multi-objective space exploration is performed on the space evaluation method, so that a design balance between calculation accuracy and power consumption is realized. The application is suitable for any convolution layer, reduces the overall overhead of homomorphic convolution, improves the calculation efficiency, and has a wide application prospect.
Owner:PEKING UNIV

Information encryption and decryption device, information encryption method, and information decryption method

The application discloses an information encryption and decryption device, an information encryption method and an information decryption method. The device comprises an adaptation unit, a client encryption unit and a server decryption unit. The adaptation unit is used for determining a target encryption mode and informing the target encryption mode to the client encryption unit. The client encryption unit is used for encrypting to-be-transmitted information according to the target encryption mode to obtain information ciphertext, and sending the information ciphertext to the server decryption unit. The server decryption unit is used for receiving the information ciphertext sent by the client encryption unit, and decrypting the information ciphertext to obtain the to-be-transmitted information. The technical scheme of the embodiment of the application provides an information encryption and decryption device with rich encryption strategies, has strong portability, is isolated from business logic and page layout, well adapts to various application system platforms, and greatly reduces introduction cost.
Owner:AGRICULTURAL BANK OF CHINA

Secure cloud storage and retrieval of client-side encrypted files

A system and method for secure cloud storage of client-side encrypted data using a hierarchical encryption structure and a hierarchical storage structure to provide hierarchical key management and hierarchical data access.
Owner:KEYCRYPT TECHNOLOGIES PTY LTD

Stateless session recovery method, apparatus and device for TLCP protocol

The invention provides a stateless session recovery method, device and equipment for a TLCP protocol, and the method comprises the steps: determining a second client signature hash value based on a client signature certificate, and determining a second client encryption hash value based on a client encryption certificate; determining a second server-side signature hash value based on the server-side signature certificate, and determining a second server-side encryption hash value based on the server-side encryption certificate; if the signature hash value of the first client is the same as the signature hash value of the second client, the encrypted hash value of the first client is the same as the encrypted hash value of the second client, the signature hash value of the first server is the same as the signature hash value of the second server, and the encrypted hash value of the first server is the same as the encrypted hash value of the second server; and if not, recovering the session of the client, and establishing the TLCP connection with the client. According to the technical scheme, network bandwidth resources can be saved, computing resource consumption of the service server can be reduced, and connection establishment time is remarkably shortened.
Owner:HANGZHOU HIKVISION DIGITAL TECHNOLOGY CO LTD

Protein data encryption storage and operation method based on TEE server cluster

The invention relates to a protein data encryption storage and operation method based on a TEE server cluster. The method comprises the following steps: performing encryption processing on protein data through an encryption algorithm, and storing encrypted data fragments in a TEE server cluster by adopting a distributed storage strategy; after the cluster credibility is verified, an encryption operation request of a client is received; performing comparison operation among the cluster nodes based on the encrypted data to generate an encryption result; and an encryption operation result is returned to the client through an authorization mechanism. By adopting the method, the confidentiality and integrity protection of the protein data in the whole process of storage, transmission and operation is realized, and the technical problems that the data is easy to leak and the operation is not credible in the traditional scheme are effectively solved.
Owner:ZHEJIANG LAB

Hardware encryption-based large model cloud security inference chip architecture, cloud security inference method and application

The application discloses a large model cloud end security reasoning chip architecture based on hardware encryption, which comprises a client encryption terminal, a cloud end security reasoning chip and a key management service.The client encryption terminal is integrated with a hardware encryption module, adopts a hybrid encryption strategy, encrypts user input data through a symmetric encryption algorithm, and realizes the safe distribution of session keys through an asymmetric encryption algorithm.The cloud end security reasoning chip is a special ASIC chip, adopts a multi-stage pipeline architecture, and comprises a ciphertext input processing unit, a secure calculation area, a ciphertext output processing unit and a security control and root of trust.The secure calculation area is a physically isolated chip area, and the decrypted input data, model weights and intermediate calculation results are circulated between the secure on-chip cache and the calculation unit in the area.The security control and root of trust are integrated with a physically unclonable function to realize hardware identity authentication.The key management service is a distributed key management system based on a PKI system, and supports key rotation, revocation and update operations.
Owner:SHANGHAI QUSU CHAOWEI TECHNOLOGY CO LTD

User interface

Systems and methods for interacting with smart documents are disclosed. The system includes a document user interface that receives access requests, communicates with the smart document, and displays the content of the document. Features include rendering layouts tailored to user roles and devices, authentication mechanisms, and security measures such as screenshot prevention and client-side encryption, among a variety of others. The interface may support multi-panel displays, dynamic configurations, and other functionality like scheduling reports, marketing actions, and due diligence processes. Various other methods, systems, and features are also disclosed.
Owner:FACTIFY TECHNOLOGIES INC

User interface

Systems and methods for interacting with smart documents are disclosed. The system includes a document user interface that receives access requests, communicates with the smart document, and displays the content of the document. Features include rendering layouts tailored to user roles and devices, authentication mechanisms, and security measures such as screenshot prevention and client-side encryption, among a variety of others. The interface may support multi-panel displays, dynamic configurations, and other functionality like scheduling reports, marketing actions, and due diligence processes. Various other methods, systems, and features are also disclosed.
Owner:FACTIFY TECHNOLOGIES INC

Intelligent optimization method and device for business process of cloud edge collaboration, and storage medium

The invention discloses a cloud edge collaborative business process intelligent optimization method and device and a storage medium, and belongs to the field of business process optimization. The method comprises the following steps of: 1, preprocessing a local business process event log by a client, and calculating the support degree, the cost and the average cost lower bound of a plot with the length of m; 2, the client side encrypts the plot and uploads the plot and a calculation result to the server; 3, the server calculates the global confidence degree, the global average cost and the global average cost lower bound of the plots, the plots meeting the high correlation and low cost are added into a result set and a candidate set, and the plots meeting the high correlation and potential low cost are added into the candidate set; 4, the server generates m + 1 length candidate plots based on the candidate set, encrypts and distributes the m + 1 length candidate plots to the client; 5, the client side calculates the lower bound of the support degree, the cost and the average cost of the new candidate plot; and 6, circularly executing the steps 2-5 until no new candidate plot exists, and outputting a final result set.
Owner:HEBEI UNIV OF TECH