Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

5037 results about "Common key" patented technology

Safety control method and system for remote control of Internet of Things

The invention relates to the technical field of management of the Internet of Things, and discloses a security control method and system for remote control of the Internet of Things, and the system comprises a security remote control platform, a zero-trust gateway, an authentication module, a security policy engine, edge proxy equipment and an encryption communication module. And the authentication module is used for performing identity authentication on the equipment and the user. The security policy engine dynamic access control table comprises access rule entries and associated signature information, and is issued to the edge proxy device through the zero-trust gateway. And the edge proxy device stores the dynamic access control table, verifies the signature information based on the platform public key, and performs matching and verification according to the access rule entry when receiving the control instruction. And the encryption communication module is used for performing encryption transmission on the access control table, the control instruction and the execution result. According to the invention, the whole process of remote control of the Internet of Things is dynamic, secure and credible, and the anti-attack capability and operation reliability of the system are effectively improved.
Owner:JINLANCHEN (BEIJING) TECHNOLOGY CO LTD

Driving vehicle road cloud cooperative safety control method and system based on trusted computing

The invention discloses a driving vehicle road cloud collaborative safety management and control method and system based on trusted computing, and the method comprises the steps: generating an HMAC-SM3 data fingerprint through employing an SM3 Hash algorithm engine, and proposing an LSTM lightweight dynamic trust evaluation model based on a TinyML framework; through a step-by-step Hash verification and rollback mechanism, through Geohash coding and SM3 Hash joint calculation, based on an aggregation signature of a BLS12-381 curve and public key aggregation, the communication overhead during multi-RSU collaborative signature is reduced; distributed private key fragmentation decryption is realized by adding a homomorphic aggregation ciphertext; aggregating and delaying the compressed ciphertext; dynamically evaluating the credibility of the nodes by a Krum dynamic defense mechanism; the system comprises a vehicle side credible sensing layer, a roadside credible broadcast layer and a cloud credible decision-making layer. According to the invention, through layered credibility verification, dynamic trust chain extension and a data privacy protection mechanism, the security and credibility problems of multi-node cooperation in an automatic driving scene are solved.
Owner:BEIJING INST OF TECH

Vehicle-mounted ad hoc network security communication system and method based on NTRU lattice cryptosystem

The invention belongs to the technical field of digital information transmission, and relates to a vehicle-mounted ad hoc network security communication system and method based on an NTRU lattice cryptosystem, and the system comprises a message signature module, a message encryption module, a message decryption module, an identity authentication module, and a key exchange module. The message signature module carries out signature by utilizing a private key and a random polynomial dynamically generated by a pseudo-random number generator based on an NTRU lattice cryptosystem; the message encryption module encrypts a to-be-sent message by randomly selecting a temporary polynomial and combining a public key of a receiver; the message decryption module is used for decrypting the received ciphertext # imgabs1 # by using a private key and an inverse element # imgabs0 # of a module p of the private key; the identity authentication module is used for performing identity authentication; the key exchange module realizes secure key exchange between communication nodes in the vehicle-mounted ad hoc network through an improved Blom key distribution protocol. The system improves the security and communication efficiency of the vehicle-mounted network.
Owner:CHANGCHUN UNIV OF TECH

Bidirectional authentication security mobile communication method and system based on public key digital fingerprint

The invention discloses a bidirectional authentication secure mobile communication method and system based on a public key digital fingerprint, and belongs to the technical field of communication security. The method specifically comprises the following steps: S1, digital certificate application and issuing: a mobile terminal and a service server respectively use an encryption algorithm to generate an asymmetric key pair which comprises a public key and a private key, an entity submits a CSR file which comprises a public key, entity identity information and an extension field to a CA, and the CA strictly audits the entity identity and issues a digital certificate; and performing digital signature on the public key and the entity information by using a CA private key after the auditing is passed. Two-way identity authentication is achieved, communication safety is improved, a traditional scheme only supports one-way authentication of a client to a server and is prone to phishing attack and identity false use, digital certificates are exchanged before communication between a mobile terminal and a service server, the legality of the certificates is verified through a public key of a CA root certificate, and the authenticity of the identities of the two parties is ensured. A bidirectional authentication mechanism effectively prevents man-in-the-middle attack and identity counterfeiting problems, and the security risk is greatly reduced.
Owner:HAINAN SOFTWARE VOCATIONAL & TECH COLLEGE

Electronic data storage verification method and system based on hierarchical hash and smart contract

The invention provides an electronic data evidence storage verification method and system based on hierarchical hash and an intelligent contract, and relates to the technical field of block chains and data security, and the method comprises the steps: obtaining to-be-stored electronic data; to-be-stored electronic data is divided into data blocks according to a preset rule, a unique identifier and a timestamp are added to each data block, and a standardized data unit is generated; performing hierarchical hash calculation on the standardized data unit, generating a leaf node hash value by each data block, aggregating the leaf node hash values layer by layer according to a Merkle tree structure, and generating root hash; calling a block chain smart contract, submitting the tree structure hash, the timestamp and the public key encrypted signature to a block chain network, after verification of a consensus node, writing the evidence information into the block chain, analyzing a hash path submitted by a user by the smart contract to perform data verification, if the hash path is consistent with the data verification, returning verification success, otherwise, triggering an exception handling contract; through the dynamic partitioning algorithm and the layered hash structure, the calculation overhead of large file processing is reduced.
Owner:SHANDONG UNIV OF POLITICAL SCI & LAW

Computer network data secure transmission system and method

The invention discloses a computer network data secure transmission system and method, and particularly relates to the technical field of network data secure transmission, and the system comprises a dynamic key management module which generates a key seed through a quantum random number generator, generates a dynamic key bound with a data packet in combination with a timestamp, and transmits the dynamic key to a server; after being encrypted by a receiving end public key, the data are transmitted through an independent verification channel; the dual-path transmission control module is used for establishing dual channels of a main path and a shadow path, a data packet of the main path is embedded into a random camouflage protocol header to simulate a non-sensitive protocol, and a blank data packet is filled in the shadow path to maintain traffic characteristics; according to the real-time verification engine, a receiving end constructs an encrypted hash tree to achieve fragment-level integrity verification, and meanwhile, requests key state three-state verification from the key management module. Through key dynamic generation and separation transmission, dual-path adaptive fragmentation distribution, fragmentation hash tree reconstruction and key linkage verification, and abnormal triggering fragmentation level retransmission, the problems of long-term effectiveness of a static key, predictable transmission path and verification lag are solved.
Owner:陈俊奕

Securing secrets and their operation

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for providing secure protection of secrets. In some implementations, a passphrase and data corresponding to an authenticatable entity are received. An entropy extender is generated based at least on the data associated with the authenticatable entity. A key pair is generated using the passphrase and the entropy extender, the key pair comprising a public key and a private key. An identifier is generated using data from the public key, wherein the identifier maps to a file for storing content related to the authenticatable entity.
Owner:CHANG MINGTAI +1

Maintaining authentication integrity of signals from backscattering-based communications devices

A first wireless device may be configured to transmit a first public key, an unsigned transmission, and a signed transmission to a backscattering-based communications device. The signed transmission may be signed based on a first private key. The backscattering-based communications device may be configured to receive the first public key, the unsigned transmission, and the signed transmission from the first wireless device. The backscattering-based communications device may be configured to process the unsigned transmission in response to verifying the signed transmission based on the first public key. The backscattering-based communications device may be configured to transmit a verification of the signed transmission in response to verifying the signed transmission based on the first public key.
Owner:QUALCOMM INC

Anti-quantum security identity authentication method, system, medium and equipment

The invention discloses an anti-quantum security identity authentication method and system, a medium and equipment. The method comprises the following steps: S1, a client, a service server and a key distribution center perform key configuration by adopting a digital signature algorithm; s2, the client sends an authentication request to the authentication server, and receives an authentication response with a bill granted bill returned by the authentication server; s3, the client sends a bill request to the bill issuing server, and receives a bill response with the service bill returned by the bill issuing server; s4, the client generates a client key exchange public key by adopting a first key exchange algorithm and sends an access request, the service server calculates a shared key and a ciphertext after receiving the public key, generates an access response comprising the ciphertext and identity information encrypted by using the shared key, and returns the access response to the client; and S5, the client receives the access response and obtains the shared key, and performs encrypted communication with the service server by using the shared key. The method has forward safe quantum attack resistance and strong identity authentication.
Owner:HAINAN HUAMI TECHNOLOGY CO LTD

Interface authentication method, system and equipment based on national cryptographic algorithm and medium

The invention discloses an interface authentication method, system and device based on a national cryptographic algorithm and a medium, belongs to the technical field of computer security, and aims to solve the technical problem of how to realize identity authentication, data encryption, integrity verification and replay attack protection of interface interaction and meet the security requirement of a key information system. According to the technical scheme, the method comprises the following steps: system initialization: a server and a client respectively generate SM2 key pairs, the client and the server exchange public keys through a secure channel, and a mapping relation between the public key of the opposite side and an identity label is stored; session key negotiation: exchanging a temporary public key based on an SM2-ECDH algorithm, calculating a shared secret value, and deriving an SM4 session key through a KDF; the client side carries out SM3 hash and SM2 signature on request parameters, and the server side verifies the signature and verifies a timestamp and a random number to resist replay attacks; and session key updating: triggering key updating according to a preset condition, and encrypting the new key negotiation message by using the original session key.
Owner:SHANDONG INSPUR DIGITAL BUSINESS TECHNOLOGY CO LTD

Methods, architectures, apparatuses, and systems for decentralized data control and access management

Procedures, methods, architectures, apparatuses, systems, devices, and computer program products for decentralized data control and access management. For example, a data owner may perform a subscription procedure to obtain verification credentials and an index (e.g., address, identifier) to public data control and access information. The data owner may perform a registration procedure to register ownership of data using the public data control and access information. The public data control and access information may include a public key. The public key is paired with a private trapdoor key to form a key pair. The data owner and a data consumer may perform an access procedure to grant access to registered data. For example, the registration procedure may verify collisions between a token hash, a data hash, and a data owner hash based on use of the key pair.
Owner:INTERDIGITAL PATENT HOLDINGS INC

Secure device attestation using entitlement tokens

Apparatuses, systems, and techniques for issuing entitlement tokens to a root of trust allowing the root of trust to take certain action(s) with respect to a component that it secures, for example, to affect a change in the software and / or features available to the component it secures. In some embodiments, the entitlement token issuance process may involve receiving an attestation report corresponding to a root of trust of a computing system, wherein the attestation report is cryptographically signed using a private key unique to the root of trust, verifying the attestation report using a public key corresponding to the private key, and based at least upon successful verification of the attestation report, issuing an entitlement token for the root of trust allowing the root of trust to take one or more actions with respect to a system component secured by the root of trust.
Owner:NVIDIA CORP

Distributed node unified identity authentication method and system based on QUIC protocol

The invention relates to a QUIC protocol-based distributed node unified identity authentication method and system, belongs to the technical field of network security, is applied to a client, and comprises the following steps: registering a client domain name identity through a certificate authority, obtaining a client certificate, and pre-storing a server certificate chain; generating a QUIC initial data packet according to the target server domain name identifier and the client certificate, and sending the QUIC initial data packet to the server; receiving a QUIC handshake data packet returned by the server; verifying the legality of the server certificate based on the server certificate chain, and if the server certificate is legal, calculating a pre-master key according to the client DH private key and the server DH public key; deriving a 1-RTT session key based on the pre-master key; generating a signature verification message, and sending the client certificate and the signature verification message to a server; and synchronously using the 1-RTT session key to encrypt the application layer data with the server, and transmitting the data to the server in the 1-RTT encryption space of the QUIC protocol. According to the invention, the reliability of node identities and the confidentiality of data are ensured.
Owner:BEIJING LIUJINSUIYUE TECH CO LTD

Food production traceability management system based on block chain

The invention discloses a food production traceability management system based on a block chain, which belongs to the field of food management systems, and is characterized in that a unique identifier ID of an inheritor is generated based on an SHA-256 Hash algorithm, a Merkle tree root Hash value of food production data is dynamically associated, a non-tampering digital identity file is constructed, a data island of traditional decentralized management is broken through, and the traceability of food production is improved. According to the technical scheme, full-chain credible association between the non-abandoned technology and the production process is ensured, validity of an electronic signature is automatically verified by means of an intelligent contract, data tampering or identity failure risks are recognized in real time by comparing a public key decryption result with a signature hash value, JSON format alarms are pushed by means of Apache Kafka message middleware, cross-department collaborative response is achieved, and the security and reliability of the electronic signature are improved. The risk prevention and control efficiency is remarkably improved, encryption signature is performed in combination with an ECDSA key pair of a hardware security module, strong binding of an inheritor identifier, a production batch and equipment is ensured, identity fraudulent use or qualification counterfeiting is prevented, and traceability of the whole life cycle of non-abandoned skill inheritance is achieved.
Owner:BEIJING KAIWU DIGITAL TECH CO LTD

Identity authentication unloading method and system based on intelligent network card

The invention relates to the field of network security, and discloses an identity authentication unloading method and system based on an intelligent network card. The method comprises the following steps: presetting a master key in an intelligent network card; presetting a master key in the intelligent network card; receiving client request data forwarded by the application layer and extracting a service identifier; generating a private key of the corresponding service through the service identifier and the master key; acquiring a local authentication message, signing the local authentication message by using the private key, generating a server signature value, and sending the server signature value to the client through the application layer to trigger a client authentication process; receiving client certificate data forwarded by the application layer and extracting a certificate signature value; and verifying the certificate signature value by using a preset certificate issuing mechanism public key and generating a verification result, and outputting feedback information based on the verification result. According to the method, a hardware-level unloading function in an identity authentication process is realized through the intelligent network card, and the problems of high calculation overhead and poor expansibility of traditional TLS bidirectional authentication are solved.
Owner:JIHUA LAB

NTRU-based efficient and compact key packaging, encryption and decryption method

The invention discloses an efficient and compact key packaging, encryption and decryption method based on NTRU. The invention belongs to the technical field of lattice passwords, and particularly relates to an NTRU-based secret key packaging, encrypting and decrypting method with scalable ciphertext compression and balanced performance. According to the method, a public key compression and scaling ciphertext compression technology is provided for an NTRU password system, only one polynomial is needed in the encryption and decryption process, and the technology is also suitable for other password schemes based on NTRU. The method has the advantages of being shorter in ciphertext size, more flexible in parameter selection, capable of proving security under classical and quantum random oracle models, tighter in theoretical security protocol advantage, higher in known attack resistance, efficient in implementation, negligible in error rate and the like.
Owner:FUDAN UNIVERSITY

Systems and methods for threshold cryptography for cloud-based software-implemented hardware security modules

Disclosed herein are systems and methods for threshold cryptography for cloud-based software-implemented hardware security modules. In an embodiment, an encryption system collects at least a decryption-threshold number of private-key shares from a secure store, where the private-key shares correspond to a public key generated in a first secure enclave as part of a secret key set, which also includes a first plural quantity of the private-key shares. The encryption system obtains an ephemeral-hardware-security-module-(eHSM)-encryption key by decrypting the collected private-key shares. The encryption system initializes, in a second secure enclave, a second instance of a first eHSM. The initialized second instance of the first eHSM is encrypted with the obtained eHSM-encryption key.
Owner:ASSA ABLOY AB

Multi-party collaborative anti-quantum signature method and system based on homomorphic hash

The invention provides a multi-party collaborative anti-quantum signature method and system based on homomorphic Hash, and relates to the technical field of digital signatures, the system comprises a plurality of participants and a verification party, and the method is specifically as follows: each participant generates a pair of public and private keys, the public key is composed of a total public key, a total signature matrix and a total Hash matrix of all participants; based on the public and private keys, all participants perform multi-party signature on the target message through a homomorphic hash function, and a generated signature is composed of total hash challenge values of all participants, total response vectors of all participants and commitment value high-order difference values of all participants; according to the signature, the verifier recovers the high order of the total commitment value, further calculates the total hash challenge value, and verifies the validity of the signature through comparison of the total hash challenge value; according to the method, multi-user collaborative signature is realized, and the security of resisting malicious opponents under a quantum computer is obtained.
Owner:SHANDONG NORMAL UNIV

Law compliance examination verification method and system based on deep learning and block chain

The invention relates to the technical field of block chains and artificial intelligence, and discloses a legal compliance examination and verification method and system based on deep learning and block chains, and the method comprises the steps: building a mapping relation based on the public key information of an enterprise and a registration database, and marking the identity features of the enterprise; constructing a block chain interaction map according to the enterprise identity features, classifying enterprise nodes in the block chain interaction map, and identifying whether a potential transverse protocol group with a high polymerization degree exists or not; if yes, acquiring historical transaction information recorded in the block chain system by the enterprise, and analyzing the historical transaction information into a feature vector; analyzing time sequence characteristics of interaction behaviors between enterprises, and outputting risk behavior tags; and generating an exception report according to the risk behavior tag, and encrypting and storing the exception report in the supervision side block chain. According to the invention, potential collusion groups with strong connection features are identified, and compliance identification accuracy and report credibility in a block chain environment are improved.
Owner:ZHEJIANG DAGU TECH CO LTD

Improved AES (Advanced Encryption Standard) encryption method and system with side channel attack resistance attribute

The invention discloses an improved AES (Advanced Encryption Standard) encryption method and an improved AES encryption system with a side channel attack resistance attribute, namely, an encryption key is used for carrying out AES encryption on the same plaintext data for multiple times, and a ciphertext generated by each time of encryption is randomly changed and has a certain side channel attack resistance attribute. According to the principle, a variable-length random number mechanism is introduced on the basis of a standard AES encryption algorithm, so that time and power consumed by each AES encryption have certain variability, and the capability of resisting time side channel attack and power consumption side channel attack is improved; a random number matrix and an S-box intermediate matrix are introduced to obtain a reinforced round key, and finally, the round key is used for carrying out round key addition operation on an AES standard ciphertext, so that when the same encryption key is used for carrying out AES encryption on the same data, the ciphertext result after each encryption is randomized, the effect similar to that of RSA public key encryption is achieved, and the encryption efficiency is improved. The security of the data ciphertext is improved, and the encryption and decryption performance is far faster than that of the RSA algorithm.
Owner:SICHUAN VOCATIONAL & TECHN COLLEGE OF COMM

Anti-quantum computing public key cryptography method and system

The invention relates to the technical field of information security, in particular to an anti-quantum computing public key cryptography method and system. The method comprises the following steps: acquiring a large prime number p and constructing a multivariable polynomial ring; randomly generating a group of polynomial coefficients, generating a polynomial embedding rule public key, and generating a multivariable polynomial ring embedding public key; the method comprises the following steps: acquiring a quantum computer message, performing polynomial space mapping conversion and message public key encryption, and meanwhile, generating a quantum message public key encrypted ciphertext by introducing a polynomial perturbation term and a transcendental coding term; the quantum message public key encryption ciphertext and the corresponding polynomial ring embedded public key are transmitted to a quantum message decryption party for inversion decryption processing, and a quantum computer message decryption plaintext is generated; and performing anti-quantum computing security analysis on the encryption and decryption processes, and regenerating a multivariable polynomial ring dynamic public key. According to the method, the attack of quantum computing can be effectively resisted, so that the security of quantum information transmission is guaranteed.
Owner:QINGDAO HUITIANXIA BIG DATA TECHNOLOGY SERVICE CO LTD

Tokenized structured exchange tracking

A method includes receiving a protection request for an exchange and generating a metadata object including a plurality of outputting attributes for outputting. The method further includes generating a protected NFT including a link with the metadata object. The protected NFT is encapsulated within a control structure that restricts an output of the metadata object. The method further includes signing the protected NFT using at least one of a first private key or a second public key. The method further includes transmitting the signed protected NFT to the remote device and continuously monitoring the exchange. The method further includes detecting, by the control structure, at least one outputting attribute of the plurality of outputting attributes is satisfied and, in response to detecting the at least one outputting attribute is satisfied, outputting at least a portion of the output.
Owner:WELLS FARGO BANK NA

Server, terminal and security system

Provided in the present application are a server, a terminal and a security system. The server comprises an authentication and key management module, a secure multi-party computation engine and a secure-channel management module, wherein the authentication and key management module is used for performing identity verification on a terminal, generating a first private key corresponding to the terminal and a first public key corresponding to the first private key, and generating a first session key on the basis of a second public key of the terminal and the first private key; the secure multi-party computation engine is used for verifying fingerprint information of the terminal and cooperating with a plurality of terminals to perform identity verification on a server; and the secure-channel management module is used for establishing a secure channel with the terminal, encrypting communication data on the basis of the first session key, and using the secure channel to send the encrypted communication data to the terminal. The solution of the present application can effectively solve the security problem of communication between a terminal and a server, and has the advantages of high flexibility and a low cost.
Owner:TSINGHUA SHENZHEN INTERNATIONAL GRADUATE SCHOOL +1

File fragmentation encryption transmission method and device based on B / S (Browser / Server) architecture

The invention discloses a file fragment encryption transmission method and device based on a B / S architecture, and belongs to the field of information security. The problem of systematic contradiction among file transmission efficiency, safety and reliability is solved. The method comprises the following steps: determining a fragmentation threshold value, and carrying out self-adaptive fragmentation processing on an original file; respectively performing RSA public key encryption and AES random key secondary encryption on each fragment file to generate a double-encrypted file; writing the SHA-3 hash value of each fragment file and the timestamp information into a block chain network to generate a non-tampering meta-file; a multiplexing transmission channel is established, a meta-file and an encrypted file set are downloaded at the same time, and each fragment adopts an independent transmission thread; verifying the consistency of the Hash value of the downloaded file and the blockchain evidence, and executing an exponential backoff retransmission strategy on the fragments which fail in verification; and performing streaming decryption recombination on the verified fragments to generate a temporary file with a digital watermark. The method is mainly used in data transmission field.
Owner:BEIJING SENYI INTELLIGENT TECHNOLOGY CO LTD

Anti-quantum signature method and system used between two terminals, and electronic equipment

The invention relates to the technical field of quantum computers, in particular to an anti-quantum signature method and system used between two terminals and electronic equipment. The initial to-be-verified commitment value of each terminal is obtained by homomorphic Hash commitment operation of the signature calculation result of the public key information stored in the terminal private key and encryption based on the commitment key, so that the confidentiality and randomness of the public commitment value are effectively ensured, and only two terminals need to interact and share the initial to-be-verified commitment value in the process. Compared with conventional data encryption, transmission and decryption operations, the data transmission frequency is reduced, and the signature verification effect is improved.
Owner:ORIGIN QUANTUM COMPUTING TECH (HEFEI) CO LTD

Revocable attribute-based encryption method with strategy hiding

The invention discloses a revocable attribute-based encryption method with strategy hiding, which is based on ciphertext strategy attribute encryption, solves the problem that user privacy is leaked due to disclosure of an access strategy, realizes revocation of fine-grained user attribute access authority, and is proved to be completely safe. In a system establishment stage, system parameters are disclosed, a public key and a master key are generated, an authoritative authority authorizes a data user, distributes a private key and generates an AGK tree and an attribute group key, a data owner generates a ciphertext according to the public key, an access structure set by the data owner and a selected secret value, and the ciphertext is transmitted to the data owner. And then hiding the mapping function by using a cuckoo filter, positioning the attribute by a data user through the cuckoo filter, updating a private key by using an attribute group key, and finally decrypting the ciphertext to obtain the wanted information.
Owner:HUAIYIN INSTITUTE OF TECHNOLOGY

Anonymous Internet of Things identity authentication method and device based on anti-quantum computing password

The invention provides an anonymous Internet of Things identity authentication method and device based on an anti-quantum computing password. A key generation device sends a public key to a message sending end and a message receiving end, and sends a private key to an authentication server; the authentication server generates a blind parameter based on the private key, and sends the blind parameter to the message sending end; the message sending end performs blind operation based on the blind parameter, the public key and the to-be-transmitted message to obtain a blind message, and sends the blind message to the authentication server; the authentication server performs post-quantum signature on the blind message based on the private key to obtain a to-be-solved blind signature, and sends the to-be-solved blind signature to the message sending end; the message sending end carries out blind resolution operation on the to-be-resolved blind signature to obtain a target signature; the message sending end sends the to-be-transmitted message and the target signature to a message receiving end; and the message receiving end performs post-quantum verification on the target signature based on the public key, and if verification succeeds, processing is performed based on the to-be-transmitted message. Through the scheme of the invention, the user data security can be improved.
Owner:HANGZHOU HIKVISION DIGITAL TECHNOLOGY CO LTD

System and Method for Direct, Structured, and Versioned Data Storage and Retrieval on a Blockchain Network

The present embodiment discloses a novel process and system for storing versioned data on the Bitcoin blockchain network. This process involves generating derived public keys linked to specific versions and data parts using a key tweaking method, and storing each data part on the blockchain using its associated derived public key. Information about versions and parts are stored in root transactions. An API is provided for managing the stored data, with options for encryption, checksums, data anchoring, timestamping, segmentation, and digital signatures. AIDIOS, a data protocol designed for direct storage and retrieval on the Bitcoin blockchain, is also included. This system allows for significant amounts of data to be stored directly on the blockchain.
Owner:DATAFAIR INC

Device-bound, replay-protected applications for a root of trust

A method for provisioning a device-bound, replay-protected software image may include obtaining, from a provisioning system, a software image and a digital signature associated with the software image. The method may include applying a hash function to the software image and a hash message authentication code (HMAC) to generate a hash of the software image. The HMAC may include an authentication code derived from first data provided by a root of trust (RoT). The first data may include a nonce generated by the RoT or system information associated with the RoT. The method may include verifying, using a public key of the provisioning system, the digital signature. The method may include, responsive to the verification of the digital signature, causing the software image to execute.
Owner:CRYPTOGRAPHY RESEARCH INC

Medical data circulation and storage method based on block chain

The invention relates to the technical field of medical data circulation and storage, in particular to a block chain-based medical data circulation and storage method, which comprises the following steps of data storage, data circulation and data auditing. The medical data storage security is remarkably improved, the blockchain storage performance bottleneck is avoided, the non-tampering property of the blockchain ensures that the data operation record is traceable in the whole process, the malicious tampering risk of internal personnel is completely eradicated, a mixed encryption mechanism is adopted, a session key is chained after being encrypted by a public key of a patient, a private key is only held by the patient, the cracking difficulty is extremely high, and the safety is high. According to the method, high-efficiency and de-intermediary data circulation is achieved, patient privacy control and compliance are enhanced, fragmented PBFT consensus is adopted, the medical transaction throughput can reach 2000 + TPS, clinical real-time requirements are met, breakthrough is achieved in the aspects of safety, efficiency and privacy protection, and a trusted infrastructure is provided for medical data value circulation.
Owner:JIANGSU CHUANGYI CLOUD TECHNOLOGY CO LTD