Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

19 results about "Cryptographic hardware" patented technology

Method for configuring cryptographic hardware, confidential computing method for data, and related device

Provided in the embodiments of the present disclosure are a method for configuring cryptographic hardware, a confidential computing method for data, and a related device. The method for configuring cryptographic hardware comprises: maintaining a device state of cryptographic hardware bound to a plurality of simulation devices, which device state is an idle state or a busy state, wherein one simulation device corresponds to one virtual machine, and a plurality of simulation devices are bound to the cryptographic hardware, such that the plurality of virtual machines share the cryptographic hardware by means of the corresponding simulation devices; and on the basis of the device state of the cryptographic hardware, processing a use request of a virtual machine for the cryptographic hardware by means of the simulation device corresponding to the virtual machine, such that the virtual machine uses the cryptographic hardware, wherein the virtual machine is any one of the plurality of virtual machines. The embodiments of the present disclosure can improve the utilization rate of cryptographic hardware by virtual machines.
Owner:HYGON INFORMATION TECH CO LTD

Method and apparatus for device identifier composition engine certificate-based security and out-of-band temporary key generation for bluetooth pairing

An information handling system includes a hardware processor and a memory device to execute code instructions of an automatic peripheral device pairing management system pairing agent to receive, via a wireless interface adapter, a device identifier composition engine (DICE) certificate from a wireless peripheral device indicating the identity of the wireless peripheral device, the DICE certificate including a public key. The hardware processor executes computer readable program code of an out-of-band (OOB) temporary key generator agent to generate an OOB temporary key. The hardware processor executes the computer readable program code of the automatic peripheral device pairing management system pairing agent to encrypt the OOB temporary key using the public key. The hardware processor to sends the public key-encrypted OOB temporary key to the wireless peripheral device to be decrypted using a private key at the wireless peripheral device. The hardware processor executes a confirm value generation function to confirm that the OOB temporary key matches the decrypted OOB temporary key at the wireless peripheral device to automatically Bluetooth® (BT) pair the information handling system to the wireless peripheral device.
Owner:DELL PROD LP

Systems and methods for completing a self-executing cryptographic interaction protocol using a completion device

A computer-implemented method for completing self-executing cryptographic interaction protocols using a completion device is disclosed. The method comprises: establishing, by the completion device, a wireless connection with a source device; receiving, from the source device, a request for completion of a self-executing cryptographic interaction protocol; comparing the information that identifies the self-executing cryptographic interaction protocol or the source device to a configuration stored in the completion device; and based on the comparing resulting in a match: outputting, via an output component of the completion device, a first indication of the match between the information and the configuration; signing the self-executing cryptographic interaction protocol using a digital signature stored in a cryptographic hardware element of the completion device; and sending the signed self-executing cryptographic interaction protocol to the source device.
Owner:CAPITAL ONE SERVICES LLC

A dual-mode reduction operation system and method for lattice-based cryptographic hardware acceleration

The application discloses a dual-mode reduction operation system and method for lattice-based cryptography hardware acceleration, and relates to the technical field of cryptography and information security. The system comprises a routing control unit, which is used for receiving intermediate result data generated in a lattice-based cryptography algorithm operation process, and generating corresponding routing control signals according to the operation type of the intermediate result data, and outputting the intermediate result data and the routing control signals to corresponding data output ends; a first modular reduction operation unit, which is used for executing Montgomery reduction operation based on a prime number condition on corresponding intermediate result data when receiving a routing control signal of modular multiplication operation; and a second modular reduction operation unit, which is used for executing Barrett reduction operation with 2 as a base on corresponding intermediate result data when receiving a routing control signal of modular addition operation. The application can optimize the implementation performance of the algorithm without affecting the security, and is suitable for various software and hardware environments.
Owner:BEIJING ELECTRONICS SCI & TECH INST

Parallel computing platform, method, system and equipment based on SM2 signature algorithm

The invention discloses a parallel computing platform, method, system and equipment based on an SM2 signature algorithm, and belongs to the technical field of data encryption. The system comprises a bus which reads and writes data stored in an external storage unit and obtains an encryption task or a decryption task; the working queue storage unit is used for sequentially storing the encryption tasks or the decryption tasks to obtain a task queue; a plurality of cryptographic hardware accelerators; and the command execution unit is used for obtaining the encryption tasks or the decryption tasks from the task queue in sequence, and distributing one or more of the password hardware accelerators to the corresponding encryption tasks or decryption tasks according to the task commands corresponding to the obtained multiple parallel encryption tasks or decryption tasks.
Owner:CCORE TECH CO LTD

Cooperative hardware security terminal architecture based on glass vacuum cavity

PendingCN121985329ADoes not affect game operationDoes not affect multimedia processingKey distribution for secure communicationSecurity arrangementAttackKey storage
The invention discloses a cooperative hardware security terminal architecture based on a glass vacuum cavity, which comprises an independently arranged glass vacuum cavity security module, can cooperatively work with an existing terminal main processor, and realizes hardware-level security upgrade on the premise of not influencing original performance and use experience. The glass vacuum cavity adopts two selectable sealing processes, so that both mass production and flexibility are considered; and a national security level hardware security unit is integrated in the cavity to realize key storage and encrypted transmission. An end-cloud collaborative architecture is adopted, sensitive data are not stored locally, and the security module can realize physical transplantation. The method is high in compatibility, does not depend on an advanced process, is high in physical attack resistance, can be widely applied to various smart phones and high-security-level terminals, and has high practicability and market value.
Owner:王成金

Cooperative noise masking secure communication method and system based on converter ripple communication

The application discloses a kind of based on converter ripple communication's collaborative noise masking secure communication method and system, applied to including at least two power electronic converters and the power transmission line connected to its power electronic system;Source converter superimposes information signal in power control loop, and forms information carrier in power transmission line by pulse width modulation;Sink converter synchronously superimposes collaborative noise signal in power control loop, and injects collaborative noise carrier with the same frequency as information carrier in power transmission line, so that information carrier and collaborative noise carrier are superimposed to form hybrid carrier on power transmission line;Sink converter constructs noise transfer characteristic estimation model using collaborative noise signal injected by itself, and carries out collaborative noise carrier component elimination processing to recover information carrier;The application does not need to add new communication line or special encryption hardware, and can realize the improvement of power electronic system communication security.
Owner:ZHEJIANG UNIV

Authorization license detection method and system applied to industrial host software

The invention relates to the technical field of industrial host software, and provides an authorization permission detection method applied to industrial host software, which comprises the following steps: S1, finishing authorization system deployment on a host running the industrial software; s2, when the industrial software is triggered to run according to a preset time interval, the industrial software calls an authorization SDK interface function to initiate an authorization state verification request and an authorization SDK packaging request and then transmits the authorization state verification request and the authorization SDK packaging request to a kernel layer drive program; s3, the driving program calls a process protection module to detect the safety of a software operation environment, initiates an encryption calling request to the safety encryption hardware through the USB bus after confirming that no abnormity exists, and then returns a result to the driving program; s4, the drive program transmits the encryption result to the authorization SDK in a transparent manner, the SDK decrypts the encryption result to obtain a plaintext result and feeds the plaintext result back to the industrial software for operation, and the industrial software modifies an internal authorization flag bit according to the result; and S5, safety monitoring and connection verification are maintained in the whole detection process. The problem that a traditional industrial software authorization mode is prone to being counterfeited or cracked is solved.
Owner:SUPCON TECH CO LTD

Payment terminal setup procedure, associated payment terminal

UndeterminedES3075794T3Third partyReliability engineering
Method for configuring a payment terminal and the associated payment terminal. The proposed technique relates to a method for configuring a payment terminal. The method comprises a step (11) of loading, into a secure memory of the payment terminal, firmware comprising several different cryptographic methods, each of which is designed to allow a third party possessing the appropriate cryptographic hardware for the method in question to subsequently perform operations to verify the authenticity and integrity of at least one application installed on the payment terminal.
Owner:BANKS & ACQUIRERS INT HLDG SAS

Support for additional cryptographic algorithms using an inline cryptographic hardware component

Systems and techniques are described herein for offloading cryptographic services. For example, a method may include receiving a request to provide a cryptographic service type and initiating a cryptographic algorithm in a cryptographic hardware component, where the cryptographic algorithm is associated with the cryptographic service type. The method may further include applying a cryptographic operation to data to obtain a cryptographic result. The cryptographic operation is associated with the cryptographic algorithm. The method may further include storing at least a portion of the cryptographic result in a hardware register of the cryptographic hardware component. The cryptographic result is configured for use for performing a cryptographic action.
Owner:QUALCOMM INC

A file encryption apparatus

This invention provides a file encryption device, comprising: a file input pool, a file formatter, a matrix multiplier, an inverse matrix unit, a file output pool, a user password manager, an encryption matrix generator, a universal DES encryptor, an encryption matrix array, and a universal DES decryptor. This invention can meet the needs of people's daily electronic data for low security and large data volumes, avoiding the use of expensive professional data encryption hardware or software, and preventing low-cost data cracking. It provides a low-computation, low-latency, and low-cost encryption device based on a matrix transformation algorithm.
Owner:ZHONGKE FANYU (WUHAN) TECH CO LTD

Cryptographic hardware accelerator with dummy block addressing for protection against side channel attacks

A hardware accelerator is disclosed for performing a computational operation in a cryptographic application comprises one or more addressable computational blocks and a plurality of addressable register blocks. A bus is used for data exchange between the blocks in the form of read-from-bus operations and write-to-bus operations in the course of performing the computational operation. A controller for controlling the data exchange performs a block addressing operation using a respective pre-assigned first address of the blocks for addressing the one or more of the blocks involved in a write-to-bus operation in the data exchange. The controller performs a dummy-addressing selection operation to select one or more of the blocks for a dummy addressing operation and a dummy-addressing operation of the selected one or more of the blocks for dummy-addressing the one or more of the selected blocks in the write-to-bus operation.
Owner:IHP GMBH INNOVATIONS FOR HIGH PERFORMANCE MICROELECTRONICS LEIBNIZ INSTITUT FÜR INNOVATIVE MIKROELEKTRONIK

An offline billing method and apparatus

This specification provides an offline bill generation method and apparatus. The method includes: a terminal device comprising a Trusted Execution Environment (TEE) and a secure element based on encrypted hardware; when the terminal device detects a transaction by a target account in an offline scenario, obtaining basic transaction information and the target account's identity information in the TEE; sending the basic transaction information and the identity information to the secure element; in the secure element, signing the basic transaction information and the identity information using a stored first private key to obtain a first signature; and in the TEE, combining the basic transaction information, the identity information, and the first signature to generate an offline bill corresponding to the transaction and storing the offline bill.
Owner:ALIPAY (HANGZHOU) INFORMATION TECH CO LTD

Post-quantum cryptography algorithm security implementation method and system for resisting side channel attack

The invention provides a side channel attack resistant post-quantum cryptographic algorithm security implementation method and system, and belongs to the technical field of cryptographic hardware security. In password hardware, a hardware-algorithm collaborative abstraction layer is used as a core control hub, and the method comprises the following steps of: constructing a logically isolated security execution environment supported by protected hardware; loading a security algorithm image subjected to side channel reconstruction resistance; in the process of executing the algorithm mapping, the abstraction layer dynamically schedules hardware resources and synchronously injects randomized disturbance; meanwhile, physical side channel signals are collected in real time through a safety monitoring unit; and when the signal is judged to be abnormal, feeding back to the abstraction layer to dynamically adjust a disturbance strategy or switch a standby execution path. Through cooperation and dynamic adjustment of software and hardware resources, the problems of protection design lagging, resource static splitting and lack of adaptive ability in the prior art are solved, efficient active security defense is achieved, and the protection ability of post quantum cryptography hardware for resisting side channel attacks is improved.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

Field programmable gate array configuration method and device, edge gateway and storage medium

The application discloses a field programmable gate array configuration method and device, an edge gateway and a storage medium. A target encryption algorithm of a target blockchain needing interaction is identified. A target hardware logic corresponding to the target encryption algorithm is selected from a pre-stored encryption hardware logic library. A field programmable gate array is configured according to the target hardware logic. An encryption algorithm associated with the target blockchain in the field programmable gate array is updated, so that the field programmable gate array performs a signature verification operation associated with the target blockchain through the encryption algorithm associated with the target blockchain. According to the application, the field programmable gate array is reconstructed according to the encryption algorithm of the target blockchain, so that the hardware device can support the signature verification operation of multiple blockchains across platforms by using the reconstructed field programmable gate array, the occupation of the computing resources of the hardware device is reduced, the device throughput is improved, and the access of different blockchains is facilitated.
Owner:CHINA MOBILE SHANGHAI ICT CO LTD +2

Data transmission method and device based on virtual network card multi-queue mode

The invention discloses a data transmission method and device based on a virtual network card multi-queue mode. The method comprises the following steps: determining the number of a plurality of virtual network cards; creating a plurality of virtual operation threads in the server according to the number of the plurality of virtual network cards, and creating a plurality of candidate password operation threads according to the performance of the password hardware and the performance of the central processing unit; under the condition that the data packet reaches a target virtual network card in the plurality of virtual network cards, reading the data packet through the reading thread, and determining a target tunnel by analyzing the data packet; applying for an idle target cryptographic operation thread from the plurality of candidate cryptographic operation threads, and performing encryption processing on the data packet through the target cryptographic operation thread to obtain encrypted data; and transmitting the encrypted data to the client through the target tunnel. Through the data transmission method and device, the problems of low data transmission speed and low efficiency in related technologies are solved.
Owner:Fisherman Information Technology Co Ltd

Password hardware side channel leakage point positioning method, system and related equipment

The invention provides a password hardware side channel leakage point positioning method and system and related equipment.The positioning method comprises the following steps that in response to the fact that password hardware is determined to conduct password operation, signal data of the password hardware in operation are obtained; determining an abnormal area of the password hardware based on the signal data, and determining a password hardware side channel leakage point based on the abnormal area of the password hardware; wherein the signal data at least comprises temperature data on the surface of the password hardware. The positioning method is not easily influenced by environmental noise, and the positioning accuracy of the password hardware leakage point is improved.
Owner:CASIC DEFENSE TECH RES & TEST CENT

Method for improving internal key operation performance of cryptographic card

PendingCN122372193AOperational systemCiphertext
This application relates to the fields of information security and cryptographic hardware technology, and discloses a method for improving the performance of internal key operations in a cryptographic card. This method is executed by a cryptographic card driver deployed in the operating system kernel: a key ciphertext buffer is established within the driver to store a copy of the key ciphertext identical to that in the cryptographic card's main control chip; service instructions are received from the host and the instruction code type is detected; when an internal key operation instruction is detected, the corresponding key ciphertext is read from the buffer according to the key index in the instruction, the instruction code is modified to an external key operation instruction code, and the key ciphertext is filled in; the correspondence between internal and external instructions is recorded; the external instruction is sent to the cryptographic card, allowing the FPGA to parse it and directly send it to the operation chip for computation; after receiving the response message, the response code is restored according to the correspondence and sent to the host. This invention significantly improves the performance of internal key operations while saving FPGA resources.
Owner:BEIJING JN TASS TECH