Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

34 results about "Cryptographic hardware" patented technology

Solid state disk data encryption method and solid state disk

The invention relates to the technical field of electric digital data processing security, and discloses a solid state disk data encryption method and a solid state disk. According to the method, a national cryptographic algorithm hardware encryption and decryption co-processing module is serially arranged on a data bus between a main control chip and a flash memory particle array, so that transparent encryption of write-in data and transparent decryption of read-out data are realized; the module performs encryption and decryption based on an SM4 algorithm and an XTS advanced encryption standard mode in combination with a logic address as an adjustment value, and securely injects a root key through an out-of-band interface to derive a data key. The system comprises a main control chip, a flash memory array and the co-processing module, wherein the co-processing module is integrated with a hardware encryption and decryption engine, a key management unit and data flow control logic. On the premise that a general main control chip is not changed, high-performance, high-compatibility and high-security national cryptographic hardware-level full-disk encryption is realized.
Owner:深圳市彦胜科技有限公司

Recovery using an encrypted fallback key in metadata

A computer-implemented method (CIM), according to one approach, includes generating a primary cryptographic recovery key, and generating an alternate cryptographic recovery key, where the alternate cryptographic recovery key is generated and stored in a cryptographic Hardware Security Module (HSM). The method further includes storing an encrypted fallback key in metadata associated with a data set, where the encrypted fallback key is an operational key encrypted by the primary cryptographic recovery key, and storing a Recovery Key Verification Pattern (RKVP) in the metadata, where the RKVP is associated with the primary cryptographic recovery key and is stored for the primary cryptographic recovery key. In response to a determination that the operational key is unavailable, the encrypted fallback key is retrieved to perform a data decryption operation.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION +1

Method for configuring cryptographic hardware, confidential computing method for data, and related device

Provided in the embodiments of the present disclosure are a method for configuring cryptographic hardware, a confidential computing method for data, and a related device. The method for configuring cryptographic hardware comprises: maintaining a device state of cryptographic hardware bound to a plurality of simulation devices, which device state is an idle state or a busy state, wherein one simulation device corresponds to one virtual machine, and a plurality of simulation devices are bound to the cryptographic hardware, such that the plurality of virtual machines share the cryptographic hardware by means of the corresponding simulation devices; and on the basis of the device state of the cryptographic hardware, processing a use request of a virtual machine for the cryptographic hardware by means of the simulation device corresponding to the virtual machine, such that the virtual machine uses the cryptographic hardware, wherein the virtual machine is any one of the plurality of virtual machines. The embodiments of the present disclosure can improve the utilization rate of cryptographic hardware by virtual machines.
Owner:HYGON INFORMATION TECH CO LTD

Method and apparatus for device identifier composition engine certificate-based security and out-of-band temporary key generation for bluetooth pairing

An information handling system includes a hardware processor and a memory device to execute code instructions of an automatic peripheral device pairing management system pairing agent to receive, via a wireless interface adapter, a device identifier composition engine (DICE) certificate from a wireless peripheral device indicating the identity of the wireless peripheral device, the DICE certificate including a public key. The hardware processor executes computer readable program code of an out-of-band (OOB) temporary key generator agent to generate an OOB temporary key. The hardware processor executes the computer readable program code of the automatic peripheral device pairing management system pairing agent to encrypt the OOB temporary key using the public key. The hardware processor to sends the public key-encrypted OOB temporary key to the wireless peripheral device to be decrypted using a private key at the wireless peripheral device. The hardware processor executes a confirm value generation function to confirm that the OOB temporary key matches the decrypted OOB temporary key at the wireless peripheral device to automatically Bluetooth® (BT) pair the information handling system to the wireless peripheral device.
Owner:DELL PROD LP

A hardware implementation method and application of SM4 S-box based on redundant tower domain

The application discloses a kind of SM4 S box hardware implementation method and application based on redundant tower area, belong to information security technical field, including: using redundant tower area to express AES S box, and using little end order to express affine transformation;Give the conversion relationship between the S box of AES and SM4, and express affine transformation and constant offset using little end order;Based on step 1 and step 2, give the SM4 S box expression based on redundant tower area;Combined with the mask implementation of three-stage inverse of redundant tower area, complete the complete SM4 hardware design.The application first maps SM4 S box to the redundant tower area implementation framework of AES S box, by optimizing and merging multiple affine transformation layers and constant offset, realize high compact RTF-SM4.The S box is very easy to combine with mask class and double-track class and other gate-level side channel attack protection schemes, realize compact and anti-side channel attack SM4 hardware implementation, ensure the side channel security of encryption hardware.
Owner:NANJING UNIV OF SCI & TECH +2

Systems and methods for completing a self-executing cryptographic interaction protocol using a completion device

A computer-implemented method for completing self-executing cryptographic interaction protocols using a completion device is disclosed. The method comprises: establishing, by the completion device, a wireless connection with a source device; receiving, from the source device, a request for completion of a self-executing cryptographic interaction protocol; comparing the information that identifies the self-executing cryptographic interaction protocol or the source device to a configuration stored in the completion device; and based on the comparing resulting in a match: outputting, via an output component of the completion device, a first indication of the match between the information and the configuration; signing the self-executing cryptographic interaction protocol using a digital signature stored in a cryptographic hardware element of the completion device; and sending the signed self-executing cryptographic interaction protocol to the source device.
Owner:CAPITAL ONE SERVICES LLC

SM4 S box hardware implementation method based on redundant tower domain and application

The invention discloses an SM4 S box hardware implementation method and application based on a redundant tower domain, and belongs to the technical field of information security, and the method comprises the steps: employing the redundant tower domain to represent an AES S box, and employing a small end sequence to represent affine transformation; giving a transformation relation between the S boxes of the AES and the SM4, and representing affine transformation and constant offset by adopting a small end sequence; based on the step 1 and the step 2, SM4 S box representation based on the redundant tower domain is given; and in combination with mask implementation of three stages of redundancy tower domain inversion, complete SM4 hardware design is completed. According to the method, the SM4 S box is mapped into the redundant tower domain implementation framework of the AES S box for the first time, and the high-compactness RTF-SM4 is realized by optimizing and combining a plurality of affine transformation layers and constant offsets. The S box is very easily combined with gate-level side channel attack protection schemes such as a mask type and a double-track type, so that compact SM4 hardware capable of resisting side channel attack is realized, and the side channel security of encryption hardware is ensured.
Owner:NANJING UNIV OF SCI & TECH +2

A dual-mode reduction operation system and method for lattice-based cryptographic hardware acceleration

The application discloses a dual-mode reduction operation system and method for lattice-based cryptography hardware acceleration, and relates to the technical field of cryptography and information security. The system comprises a routing control unit, which is used for receiving intermediate result data generated in a lattice-based cryptography algorithm operation process, and generating corresponding routing control signals according to the operation type of the intermediate result data, and outputting the intermediate result data and the routing control signals to corresponding data output ends; a first modular reduction operation unit, which is used for executing Montgomery reduction operation based on a prime number condition on corresponding intermediate result data when receiving a routing control signal of modular multiplication operation; and a second modular reduction operation unit, which is used for executing Barrett reduction operation with 2 as a base on corresponding intermediate result data when receiving a routing control signal of modular addition operation. The application can optimize the implementation performance of the algorithm without affecting the security, and is suitable for various software and hardware environments.
Owner:BEIJING ELECTRONICS SCI & TECH INST

Parallel computing platform, method, system and equipment based on SM2 signature algorithm

The invention discloses a parallel computing platform, method, system and equipment based on an SM2 signature algorithm, and belongs to the technical field of data encryption. The system comprises a bus which reads and writes data stored in an external storage unit and obtains an encryption task or a decryption task; the working queue storage unit is used for sequentially storing the encryption tasks or the decryption tasks to obtain a task queue; a plurality of cryptographic hardware accelerators; and the command execution unit is used for obtaining the encryption tasks or the decryption tasks from the task queue in sequence, and distributing one or more of the password hardware accelerators to the corresponding encryption tasks or decryption tasks according to the task commands corresponding to the obtained multiple parallel encryption tasks or decryption tasks.
Owner:CCORE TECH CO LTD

Cooperative hardware security terminal architecture based on glass vacuum cavity

PendingCN121985329ADoes not affect game operationDoes not affect multimedia processingKey distribution for secure communicationSecurity arrangementAttackKey storage
The invention discloses a cooperative hardware security terminal architecture based on a glass vacuum cavity, which comprises an independently arranged glass vacuum cavity security module, can cooperatively work with an existing terminal main processor, and realizes hardware-level security upgrade on the premise of not influencing original performance and use experience. The glass vacuum cavity adopts two selectable sealing processes, so that both mass production and flexibility are considered; and a national security level hardware security unit is integrated in the cavity to realize key storage and encrypted transmission. An end-cloud collaborative architecture is adopted, sensitive data are not stored locally, and the security module can realize physical transplantation. The method is high in compatibility, does not depend on an advanced process, is high in physical attack resistance, can be widely applied to various smart phones and high-security-level terminals, and has high practicability and market value.
Owner:王成金

Cooperative noise masking secure communication method and system based on converter ripple communication

The application discloses a kind of based on converter ripple communication's collaborative noise masking secure communication method and system, applied to including at least two power electronic converters and the power transmission line connected to its power electronic system;Source converter superimposes information signal in power control loop, and forms information carrier in power transmission line by pulse width modulation;Sink converter synchronously superimposes collaborative noise signal in power control loop, and injects collaborative noise carrier with the same frequency as information carrier in power transmission line, so that information carrier and collaborative noise carrier are superimposed to form hybrid carrier on power transmission line;Sink converter constructs noise transfer characteristic estimation model using collaborative noise signal injected by itself, and carries out collaborative noise carrier component elimination processing to recover information carrier;The application does not need to add new communication line or special encryption hardware, and can realize the improvement of power electronic system communication security.
Owner:ZHEJIANG UNIV

Authorization license detection method and system applied to industrial host software

The invention relates to the technical field of industrial host software, and provides an authorization permission detection method applied to industrial host software, which comprises the following steps: S1, finishing authorization system deployment on a host running the industrial software; s2, when the industrial software is triggered to run according to a preset time interval, the industrial software calls an authorization SDK interface function to initiate an authorization state verification request and an authorization SDK packaging request and then transmits the authorization state verification request and the authorization SDK packaging request to a kernel layer drive program; s3, the driving program calls a process protection module to detect the safety of a software operation environment, initiates an encryption calling request to the safety encryption hardware through the USB bus after confirming that no abnormity exists, and then returns a result to the driving program; s4, the drive program transmits the encryption result to the authorization SDK in a transparent manner, the SDK decrypts the encryption result to obtain a plaintext result and feeds the plaintext result back to the industrial software for operation, and the industrial software modifies an internal authorization flag bit according to the result; and S5, safety monitoring and connection verification are maintained in the whole detection process. The problem that a traditional industrial software authorization mode is prone to being counterfeited or cracked is solved.
Owner:SUPCON TECH CO LTD

Hardware-Generated Key Encryption

Hardware-generated encryption keys are provided to enable per-file encryption of files to be stored in flash storage in a mobile device. Hardware-generated encryption keys are also used to decrypt encrypted files stored in the flash storage. A hardware key manager is configured to provide an unlimited number of child keys generated from one or more base keys. A nonce is applied to a base key to generate the child key. The hardware key manager communicates the child key to a host controller interface via a first bus. Software on the mobile device does not have access to the value of the child keys. A flash storage driver communicates commands to the host controller interface via a second bus. The host controller interface includes a cryptographic engine that utilizes the child keys to encrypt data to be written to the flash storage or decrypt data read from the flash storage.
Owner:GOOGLE LLC

A multi-modal scalable high-performance homomorphic encryption system

The application discloses a multi-modal scalable high-performance homomorphic encryption system, and relates to the technical field of computer systems, which comprises an upper-layer server software and a driving architecture in communication connection and a multi-modal homomorphic encryption hardware architecture realized based on FPGA; the upper-layer server software and the driving architecture comprise a multi-modal homomorphic encryption algorithm software library, a software memory scheduler, a modulo calculation module software driver and a floating-point calculation module software driver; the multi-modal homomorphic encryption hardware architecture realized based on FPGA comprises a communication data controller, a plurality of modulo calculation modules, a floating-point calculation module, a data read-write bus and a high-bandwidth memory; each modulo calculation module comprises a fast number theory transformation calculation unit. Through the design scheme of software and hardware cooperation, the application solves the problem of low scheduling efficiency of different-scale ciphertext calculation tasks under multi-modal homomorphic encryption in the design of hardware architecture, and significantly improves the calculation efficiency.
Owner:SUN YAT SEN UNIV

Payment terminal setup procedure, associated payment terminal

UndeterminedES3075794T3Third partyReliability engineering
Method for configuring a payment terminal and the associated payment terminal. The proposed technique relates to a method for configuring a payment terminal. The method comprises a step (11) of loading, into a secure memory of the payment terminal, firmware comprising several different cryptographic methods, each of which is designed to allow a third party possessing the appropriate cryptographic hardware for the method in question to subsequently perform operations to verify the authenticity and integrity of at least one application installed on the payment terminal.
Owner:BANKS & ACQUIRERS INT HLDG SAS

Support for additional cryptographic algorithms using an inline cryptographic hardware component

Systems and techniques are described herein for offloading cryptographic services. For example, a method may include receiving a request to provide a cryptographic service type and initiating a cryptographic algorithm in a cryptographic hardware component, where the cryptographic algorithm is associated with the cryptographic service type. The method may further include applying a cryptographic operation to data to obtain a cryptographic result. The cryptographic operation is associated with the cryptographic algorithm. The method may further include storing at least a portion of the cryptographic result in a hardware register of the cryptographic hardware component. The cryptographic result is configured for use for performing a cryptographic action.
Owner:QUALCOMM INC

A file encryption apparatus

This invention provides a file encryption device, comprising: a file input pool, a file formatter, a matrix multiplier, an inverse matrix unit, a file output pool, a user password manager, an encryption matrix generator, a universal DES encryptor, an encryption matrix array, and a universal DES decryptor. This invention can meet the needs of people's daily electronic data for low security and large data volumes, avoiding the use of expensive professional data encryption hardware or software, and preventing low-cost data cracking. It provides a low-computation, low-latency, and low-cost encryption device based on a matrix transformation algorithm.
Owner:ZHONGKE FANYU (WUHAN) TECH CO LTD

Cryptographic hardware accelerator with dummy block addressing for protection against side channel attacks

A hardware accelerator is disclosed for performing a computational operation in a cryptographic application comprises one or more addressable computational blocks and a plurality of addressable register blocks. A bus is used for data exchange between the blocks in the form of read-from-bus operations and write-to-bus operations in the course of performing the computational operation. A controller for controlling the data exchange performs a block addressing operation using a respective pre-assigned first address of the blocks for addressing the one or more of the blocks involved in a write-to-bus operation in the data exchange. The controller performs a dummy-addressing selection operation to select one or more of the blocks for a dummy addressing operation and a dummy-addressing operation of the selected one or more of the blocks for dummy-addressing the one or more of the selected blocks in the write-to-bus operation.
Owner:IHP GMBH INNOVATIONS FOR HIGH PERFORMANCE MICROELECTRONICS LEIBNIZ INSTITUT FÜR INNOVATIVE MIKROELEKTRONIK

An offline billing method and apparatus

This specification provides an offline bill generation method and apparatus. The method includes: a terminal device comprising a Trusted Execution Environment (TEE) and a secure element based on encrypted hardware; when the terminal device detects a transaction by a target account in an offline scenario, obtaining basic transaction information and the target account's identity information in the TEE; sending the basic transaction information and the identity information to the secure element; in the secure element, signing the basic transaction information and the identity information using a stored first private key to obtain a first signature; and in the TEE, combining the basic transaction information, the identity information, and the first signature to generate an offline bill corresponding to the transaction and storing the offline bill.
Owner:ALIPAY (HANGZHOU) INFORMATION TECH CO LTD

Method for carrying out security upgrading on vehicle-mounted security element and application thereof

The invention discloses a method and a system for carrying out security upgrading on a vehicle-mounted security element, and relates to the technical field of vehicle-mounted network security. According to the method, a traditional local upgrading program is decoupled into a local client side and a cloud server side, wherein the client side is only responsible for SE hardware interaction and process control; the server side carries out centralized processing on all security key operations such as firmware management, key management, authentication authorization, encryption and decryption and the like, and provides services for the client side through an API. According to the method, sensitive data and operation are placed in the protected cloud, safety specifications such as GP are followed, safety risks in the upgrading process are effectively avoided, meanwhile, dependence on local encryption hardware is reduced, unification of safety and economical efficiency is achieved, and the method is particularly suitable for production of vehicle-mounted electronic products and OTA upgrading scenes.
Owner:LINKSCI

Method for creating commodity assets from unrefined commodity reserves utilizing blockchain and distributed ledger technology

A token system and method, employing a token representing an interest in a smart contract, comprising: a distributed ledger, storing parameters of a smart contract, the smart contract representing an agreement, secured by a security interest in property, to execute the security interest unless a token is returned within a period; a communication port configured to interface with an automated communication network for communications between a plurality of cryptographic hardware processors; and an automated distributed virtual state machine, hosted by the plurality of cryptographic hardware processors, employing a distributed consensus model for transaction validation, the automated distributed virtual state machine being configured to: communicate distributed consensus messages through the automated communication network; communicate the token; execute the smart contract defined by the parameters, receiving inputs and producing outputs on a blockchain; and communicate an immutable message for exercise of the security interest.
Owner:IP OVERSIGHT CORPORATION

Hardware-generated key encryption

PCT designated stageWO2025230516A1Key distribution for secure communicationMultiple keys/algorithms usageComputer hardwareHost controller interface
Hardware-generated encryption keys are provided to enable per-file encryption of files to be stored in flash storage in a mobile device. Hardware-generated encryption keys are also used to decrypt encrypted files stored in the flash storage. A hardware key manager is configured to provide an unlimited number of child keys generated from one or more base keys. A nonce is applied to a base key to generate the child key. The hardware key manager communicates the child key to a host controller interface via a first bus. Software on the mobile device does not have access to the value of the child keys. A flash storage driver communicates commands to the host controller interface via a second bus. The host controller interface includes a cryptographic engine that utilizes the child keys to encrypt data to be written to the flash storage or decrypt data read from the flash storage.
Owner:GOOGLE LLC

Post-quantum cryptography algorithm security implementation method and system for resisting side channel attack

The invention provides a side channel attack resistant post-quantum cryptographic algorithm security implementation method and system, and belongs to the technical field of cryptographic hardware security. In password hardware, a hardware-algorithm collaborative abstraction layer is used as a core control hub, and the method comprises the following steps of: constructing a logically isolated security execution environment supported by protected hardware; loading a security algorithm image subjected to side channel reconstruction resistance; in the process of executing the algorithm mapping, the abstraction layer dynamically schedules hardware resources and synchronously injects randomized disturbance; meanwhile, physical side channel signals are collected in real time through a safety monitoring unit; and when the signal is judged to be abnormal, feeding back to the abstraction layer to dynamically adjust a disturbance strategy or switch a standby execution path. Through cooperation and dynamic adjustment of software and hardware resources, the problems of protection design lagging, resource static splitting and lack of adaptive ability in the prior art are solved, efficient active security defense is achieved, and the protection ability of post quantum cryptography hardware for resisting side channel attacks is improved.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

Cryptographic hardware sharing systems and methods

Various techniques are provided to implement cryptographic hardware sharing systems and methods. In one example, a programmable logic device (PLD) includes a configuration engine configured to provide configuration data for processing using a first set of security functions. The PLD further includes a PLD fabric including an array of memory cells configured to operate upon being programmed using the configuration data and provide user data for processing using a second set of security functions. The PLD further includes a security engine including a cryptographic circuit and an interface integration logic circuit. The logic circuit is configured to selectively couple, based on an indicator, the configuration engine or PLD fabric to the cryptographic circuit. The cryptographic circuit is configured to perform the first set or second set of security functions when coupled to the configuration engine or PLD fabric, respectively, by the logic circuit. Related systems and methods are provided.
Owner:LATTICE SEMICON CORP

Field programmable gate array configuration method and device, edge gateway and storage medium

The application discloses a field programmable gate array configuration method and device, an edge gateway and a storage medium. A target encryption algorithm of a target blockchain needing interaction is identified. A target hardware logic corresponding to the target encryption algorithm is selected from a pre-stored encryption hardware logic library. A field programmable gate array is configured according to the target hardware logic. An encryption algorithm associated with the target blockchain in the field programmable gate array is updated, so that the field programmable gate array performs a signature verification operation associated with the target blockchain through the encryption algorithm associated with the target blockchain. According to the application, the field programmable gate array is reconstructed according to the encryption algorithm of the target blockchain, so that the hardware device can support the signature verification operation of multiple blockchains across platforms by using the reconstructed field programmable gate array, the occupation of the computing resources of the hardware device is reduced, the device throughput is improved, and the access of different blockchains is facilitated.
Owner:CHINA MOBILE SHANGHAI ICT CO LTD +2

Data transmission method and device based on virtual network card multi-queue mode

The invention discloses a data transmission method and device based on a virtual network card multi-queue mode. The method comprises the following steps: determining the number of a plurality of virtual network cards; creating a plurality of virtual operation threads in the server according to the number of the plurality of virtual network cards, and creating a plurality of candidate password operation threads according to the performance of the password hardware and the performance of the central processing unit; under the condition that the data packet reaches a target virtual network card in the plurality of virtual network cards, reading the data packet through the reading thread, and determining a target tunnel by analyzing the data packet; applying for an idle target cryptographic operation thread from the plurality of candidate cryptographic operation threads, and performing encryption processing on the data packet through the target cryptographic operation thread to obtain encrypted data; and transmitting the encrypted data to the client through the target tunnel. Through the data transmission method and device, the problems of low data transmission speed and low efficiency in related technologies are solved.
Owner:Fisherman Information Technology Co Ltd

Intelligent dynamic data encryption adjustment system

The invention discloses an intelligent dynamic data encryption adjustment system, which comprises a context sensing module, a core decision module and a security execution module, the context sensing module collects external environment indexes, equipment computing resource use conditions and to-be-encrypted data characteristics, the core decision-making module dynamically generates encryption configuration based on a preprocessing result, and the security execution module adaptively calls a bottom layer encryption hardware or software library. Through multi-dimensional data collaboration and dynamic decision making, the problem that an existing static encryption mode lacks adaptability is solved, accurate matching between an encryption scheme and environment, resource and data characteristics is achieved, and balance between encryption safety and system operation efficiency is guaranteed.
Owner:ORDOS DIGITAL ECONOMY DEVELOPMENT INVESTMENT CO LTD

Recovery using an encrypted fallback key in metadata

A computer-implemented method (CIM), according to one approach, includes generating a primary cryptographic recovery key, and generating an alternate cryptographic recovery key, where the alternate cryptographic recovery key is generated and stored in a cryptographic Hardware Security Module (HSM). The method further includes storing an encrypted fallback key in metadata associated with a data set, where the encrypted fallback key is an operational key encrypted by the primary cryptographic recovery key, and storing a Recovery Key Verification Pattern (RKVP) in the metadata, where the RKVP is associated with the primary cryptographic recovery key and is stored for the primary cryptographic recovery key. In response to a determination that the operational key is unavailable, the encrypted fallback key is retrieved to perform a data decryption operation.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Differential control of aggregated cryptographic hardware assets

A method includes: receiving, through a user interface at a computer system, information indicating a change to one or more aggregate operational parameters for cryptographic hardware assets remote from the computer system and communicatively coupled to the computer system through one or more networks; obtaining one or more hardware parameters for one or more of the cryptographic hardware assets; based on the one or more hardware parameters, identifying a subset of the cryptographic hardware assets to receive one or more adjustments to one or more computing parameters to cause the change to the one or more aggregate operational parameters; and sending instructions to the subset of the cryptographic hardware assets to effect the adjustment to the one or more computing parameters.
Owner:AURADINE INC