Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

114 results about "Cryptographic key generation" patented technology

Automated rule-based smart contract approval via blockchain cybersecurity authentication services

In one embodiment, a method includes accessing transaction data associated with a protected first function of a first blockchain transaction protocol by a cybersecurity authentication service of a blockchain cybersecurity platform, accessing a transaction protocol runbook comprising preconfigured conditions associated with the protected first function, determining that the protected first function is eligible to be analyzed by an automated decisional logic module based on the transaction protocol runbook, determining each preconfigured condition is satisfied based on the transaction data by the automated decisional logic module, generating an authentication object for the protected first function, generating signed transaction data based on the accessed transaction data and a private encryption key, wherein the signed transaction data is configured to update a second blockchain transaction protocol to indicate that the protected first function is authenticated, and transmitting a transaction bundle comprising the accessed transaction data and the signed transaction data.
Owner:HALBORN INC

Key establishment and secure communications using satellite-provided random number values

Systems and techniques for secure communications and distribution of random values for cryptographic key generation, coordinated with the use of specific key generation parameters, are described. An example method includes: receiving a first random value and a second random value generated from at least one quantum random number generator (QRNG), with at least one of the first random value and the second random value being provided from a satellite communication; obtaining key generation parameters associated with cryptographic key generation, where the key generation parameters specify a specific combination of the first random value and the second random value; and generating a cryptographic key, using the specific combination of the first random value and the second random value, as a seed to a cryptographic function.
Owner:WELLS FARGO BANK NA

Verification system for proving authenticity and ownership of digital assets

Methods and systems described herein may implement blockchain asset authentication. A verification system may generate an encryption key associated with a digital asset, wherein the digital asset is associated with a first entity. The verification system may sign the digital asset using the encryption key. The verification system may generate a first key and a second key based on the encryption key, wherein the first key and the second key are part of a set of multi-party secret keys. The verification system may send the first key to the first entity and store the second key on the verification system. The verification system may receive a request to authenticate the digital asset. The verification system may in response to the request to authenticate, generate the encryption key based on the first key and the second key. The verification system may authenticate the digital asset based on the recreated first secret.
Owner:PAYPAL INC

Encryption and decryption method, system and device, equipment and storage medium

The invention discloses an encryption and decryption method, system, device and equipment and a storage medium, and relates to the technical field of data security of a storage system.The encryption and decryption method comprises the steps that a system password is received through an RAID controller, a derived password is generated in combination with a pre-stored random number salt value and an encryption key, and the derived password is sent to the RAID controller; and converting the password into a readable password conforming to the password rule of the self-encryption disk, and encrypting and storing the readable password so as to control the locking or unlocking of the self-encryption disk. According to the method, the salt value and the encryption key are stored in advance, so that the exposure of a plaintext password is avoided, the problems of performance bottleneck and key storage security risk caused by centralized encryption of a traditional RAID controller are solved, meanwhile, the encryption characteristic of the self-encryption disk is utilized, automatic encryption during data storage and automatic locking after power failure are realized, and the security of data storage is improved. The technical effects of reducing the calculation load, improving the key security and guaranteeing the end-to-end encryption of the data storage are achieved, so that RAID redundancy and the security mechanism of the self-encryption disk are deeply combined, and the data protection capability of the whole system is enhanced.
Owner:SHANDONG YUNHAI GUOCHUANG CLOUD COMPUTING EQUIP IND INNOVATION CENT CO LTD

Data encryption storage method and device of mobile storage terminal and storage medium

The invention discloses a data encryption storage method and device of a mobile storage terminal and a storage medium, and relates to the technical field of mobile terminal data encryption storage, and the method comprises the following steps: obtaining to-be-encrypted data, and generating a unique encryption key based on the to-be-encrypted data; performing encryption operation on the text data through the encryption key; performing encryption operation on the image data through the encryption key; generating a key ID based on the storage ciphertext and the encryption key; when a user needs to access the storage ciphertext in the mobile storage terminal, the identity of the user is verified firstly, and after verification is passed, the encryption key is restored through the key ID and the storage ciphertext, and the storage ciphertext is decrypted; the method and the device are used for solving the problems that the encryption key is easy to leak and the encrypted data is further leaked due to insufficient generation and protection means of the encryption key in the existing mobile terminal data encryption storage technology.
Owner:SHENZHEN SHUAIHONGYU TECHNOLOGY CO LTD

Full-link data security protection method and system

A full-link data security protection method and a system are provided. The method includes: at a data creation and collection stage: building a data security identification; at a data transmission and storage stage: dividing the ciphertext file into blocks to generate ciphertext components; calculating a virtual index and a data label; transmitting the ciphertext components to a distributed hash table (DHT) network; uploading a tuple including the virtual index, the data block, and the data label to a cloud server; at a data processing and exchange stage: applying re-encryption based on a re-encryption key generation algorithm; performing decryption to obtain the signed identifier and a secret value; acquiring a tuple having a ciphertext component associated with the virtual index. Attribute-based proxy re-encryption is used to achieve fine-grained access control for the cloud storage. In the data destruction stage, the DHT network automatic updating utility is leveraged to realize data self-destructing.
Owner:JINAN UNIVERSITY

Mutual authentication and encryption key generation in wireless ambient power (AMP) devices

A method for receiving, by an ambient power (AMP) device that harvests environmental energy, an identification (ID) request frame from a powered wireless device. The ID request frame includes one or more frame-exchange parameters and an authentication and key management (AKM) method. The method includes retrieving, from memory, a secret that is shared with the powered wireless device, determining, using the secret, one or more first AKM parameters, and transmitting, to the powered wireless device, by the AMP device, an ID response frame including an ID of the AMP device, at least one of the one or more frame-exchange parameters and the one or more AKM parameters with which the powered wireless device is to be mutually authenticated with the AMP device and to generate an encryption key to initiate an encrypted wireless communication session.
Owner:INFINEON TECHNOLOGIES AMERICAS CORP

Wireless audio transmission protocol optimization algorithm for low-delay dynamic password

The invention discloses a wireless audio transmission protocol optimization algorithm for a low-delay dynamic password, which comprises the following steps of: generating an initial encryption key: before audio data transmission starts, generating the initial encryption key according to a current network environment, equipment computing power and audio transmission requirements; the encryption key can be generated based on a timestamp, a random number or a key exchange protocol, the randomness and the safety of the encryption key are ensured, and a proper encryption algorithm is selected: according to equipment computing resources and network conditions, a proper low-delay encryption algorithm is selected. By selecting a low-delay encryption algorithm and dynamically adjusting the encryption complexity, the influence of the encryption process on transmission delay is remarkably reduced, the real-time performance of audio transmission is optimized, the reliability of key synchronization in a wireless network is ensured through a redundant synchronous data packet and a regular key synchronization mechanism, and even if signal loss or interference occurs, the reliability of key synchronization in the wireless network is ensured. And synchronization can be recovered in time, so that decryption failure caused by asynchronous keys is avoided.
Owner:同辉佳视(北京)信息技术股份有限公司

Data access method and device, electronic equipment and storage medium

The invention discloses a data access method and device, electronic equipment and a storage medium, and is applied to an object storage service protocol client, the method comprises the following steps: obtaining a data processing request, the data processing request carrying a data processing type and a target object key identifier; when the data processing type is a write processing type, encrypting the written to-be-encrypted data according to a target preset data key corresponding to the target object key identifier to obtain a first data ciphertext, and encrypting the target preset data key according to the target object key identifier to obtain a first encryption key; and generating target data according to the first data ciphertext and the first encryption key, and transmitting the target data to a data cache region of an object storage service protocol client, so as to write the target data in the data cache region into a server through an object storage service protocol. According to the embodiment of the invention, the data of the user can be locally encrypted, so that the data owner can completely control the data on the cloud.
Owner:PENG CHENG LAB

Privacy-preserving authenticated key rotation

Certain aspects of the disclosure provide a method for performing data verification. The method includes generating a MAC by applying a tagging algorithm indicated by a shared verification key to a data item; appending the MAC to the data item; generating an encrypted dataset comprising an encrypted data item and encrypted message authentication; generating a re-encryption key based on a homomorphic secret key corresponding to the homomorphic public key and a new public key; generating a re-encrypted dataset comprising a re-encrypted data item and a re-encrypted MAC; transmitting the re-encrypted dataset to a first external system configured to perform data verification; receiving, from the first external system, an encrypted verification result based on the shared verification key; and taking an action based on receiving the verification result indicating that the data item is authentic.
Owner:INTUIT INC

Wireless communication system and communication method

To provide a radio communication system and a communication method capable of safely relaying communication between a radio station connected to the Internet network and a radio station connected to a closed network.SOLUTION: The closed area system 11 and the cloud system 21 included in the wireless communication system 1 include a closed area side gateway server 13 and a cloud side gateway server 22. When receiving an authentication request from a radio station 41,42, a closed area side gateway server 13 and a cloud side gateway server 22 store activation information including unique information of the radio station 41,42 and generation information of an encryption key in a storage device 27. Regardless of whether the wireless station 41,42 is connected to the closed network 10 or the Internet network 20, the communication between the wireless station 41,42 and the closed system 11 or the cloud system 21 is protected by the encryption key generated based on the generation information included in the activation information.SELECTED DRAWING: Figure 1
Owner:ICOM INC

Information encryption processing method and device, equipment, medium and program product

The embodiment of the invention provides an information encryption processing method and device, equipment, a medium and a program product, and the method comprises the steps: carrying out the Hash calculation of the obtained user registration information in an information encryption process, obtaining a Hash value, extracting an encryption key and an authentication key from the Hash value, and performing encryption calculation on the user registration information according to a key stream generated based on the initial encryption parameter and the encryption key to obtain ciphertext information, performing encryption calculation based on the ciphertext information and the authentication key to obtain an encryption authentication tag, and storing the ciphertext information and the encryption authentication tag in a preset storage address. And the storage security of the user registration information is improved.
Owner:CHINA MOBILE (XIONGAN) ICT CO LTD +3

SM2-based proxy re-encryption algorithm implementation and file authorization sharing system

The invention discloses a system for realizing file authorization sharing based on an SM2 proxy re-encryption algorithm, and the system comprises a client module which is used for file encryption, key generation and key exchange between users; the server module is used for storing a file ciphertext and a Capsule and carrying out key conversion; and the encryption algorithm module is used for realizing secret key generation based on SM2, file encryption based on SM4 and Hash calculation of SHA3. The method has the beneficial effects that national commercial password standard algorithms such as SM2, SM4 and the like are fully fused, and data encryption and proxy re-encryption functions in a domestic algorithm environment are realized on the basis of ensuring the system security. As an elliptic curve public key cryptographic algorithm autonomously designed in China, the SM2 algorithm has the characteristics of public algorithm structure, high security, excellent calculation efficiency and the like.
Owner:内江数循数字科技有限公司

Model file distribution method and device, storage medium and processor

The invention discloses a model file distribution method and device, a storage medium and a processor. In the scheme, a key generation center generates key data of a model owner based on an identifier of the model owner, and generates key data of a model user based on an identifier of the model user; the model owner encrypts the original model file based on the encryption element and the main public key, generates a re-encryption key, and sends the encryption element, the re-encryption key and the encrypted model file to the key agent center; the key agent center generates a re-encryption ciphertext based on the encryption element and the re-encryption key, and sends the re-encryption ciphertext and the encrypted model file to a model user; and the model user decrypts the encrypted model file based on the key data of the model user, the re-encrypted ciphertext and the main public key to obtain an original model file. Compared with the problems of poor security and low encryption and decryption efficiency in the model file distribution process, the method has obvious advantages.
Owner:太保科技有限公司

Microcontroller unit (MCU) secure boot

A method includes building a firmware image to execute on a bootloader of a system on chip (SoC), the firmware image including first encryption public and private keys, and digitally signing the firmware image with a second encryption private key. The signed firmware image is encrypted with a symmetric encryption key, which in turn is encrypted with a second encryption public key. The encrypted signed firmware image and the encrypted symmetric encryption key are sent to the SoC to cause the SoC to (1) decrypt the encrypted symmetric encryption key to produce the symmetric encryption key using a third encryption private key from a first asymmetric key pair, (2) decrypt the encrypted signed firmware image to produce the signed firmware image using the symmetric encryption key, and (3) verify a digital signature of the signed firmware image using a third encryption public key from a second asymmetric key pair.
Owner:VERKADA INC

An authenticatable client-side watermarking method based on thumbnail encrypted images

The application discloses a kind of based on thumbnail encryption image's authenticatable user end watermark method, belong to computer security technical field. Including: image pre-processing, image encryption, key generation and distribution, decryption and watermark embedding, tamper detection and positioning, tamper content recovery, extract watermark lock user identity.The present application is based on the holographic redundancy embedding of thumbnail and the fine authentication based on parity check, with very strong anti-shearing and self-healing ability;Using the disturbance of pair of pixel difference value, all image pixels can be embedded watermark, and the security blind area is eliminated;Encrypted image has clear identifiable thumbnail, and is highly similar to plaintext, which is convenient for cloud management, and the details privacy is effectively protected through high-frequency information confusion;Encryption and watermark embedding are fused in bottom algebra operation, and the calculation efficiency is high.
Owner:HENAN NORMAL UNIV

Data protection

Data Protection The present description relates to a method comprising:a) receiving, by an electronic device, a software module of a first application, the software module comprising a public key associated with the first application;b) generating, by a cryptographic circuit of the electronic device, an encryption key based on a secret key of the electronic device and one of: the public key and an identification value derived from the public key;c) generating one or more protected data by applying a cryptographic operation, by the cryptographic circuit, to one or more first data associated with the first application and based on the encryption key; andd) storing the one or more protected data in a first part of a memory of the electronic device. Figure for abstract: Fig. 3
Owner:STMICROELECTRONICS INT NV

Signal transmission apparatus, signal reception apparatus, signal transmission method, and signal reception method in autoencoder-based encryption key generation system

The present invention relates to an autoencoder-based encryption key generation technique, and more particularly, to a signal transmission apparatus, a signal reception apparatus, a signal transmission method, and a signal reception method in an autoencoder-based encryption key generation system, wherein an encryption key with enhanced security may be generated on the basis of an autoencoder.
Owner:GWANGJU INST OF SCI & TECH

Enhanced encryption for face-related data

A method includes obtaining a plurality of representative vectors associated with face-related data. The method includes determining an encryption key based on a parameter stored in a record, generating an encrypted vector set by, for each respective vector of the plurality of representative vectors, encrypting the respective vector with a homomorphic encryption operation based on the encryption key, where the encrypted vector set includes a first encrypted vector that is linked to a subset of the face-related data associated with the first plurality of face vectors. The method further includes obtaining an encrypted face search vector using the encryption key to perform homomorphic encryption. The method further includes selecting a first encrypted vector based on the encrypted face search vector and retrieving the subset of the face-related data based on the first encrypted vector.
Owner:VERKADA INC

Point-to-point network interconnect with application level interface supporting provenance nodes

The invention relates to peer-to-peer network interconnects with application level interfaces for supporting provenance attestation nodes. Secure peer-to-peer networks are implemented with computing devices through non-secure network connections. Each computing device may include provenance attestation hardware or be coupled with provenance attestation hardware. The provenance attestation hardware may be validated by public available data, such as a trusted server. Furthermore, provenance attestation hardware may facilitate encryption key generation to facilitate encryption of communications at the computing device to ensure security of such communications over the non-secure network connection. The provenance proof hardware may include hardware acceleration circuitry to provide network services, such as cryptocurrency transactions, blockchain verification computations, even blockchain services integrating smart contracts, token exchange, survey services utilizing provenance proof data, distributed data backup, distributed computations, etc.
Owner:CROSSBAR INC

Secure element, encryption key generation method, computer program, encryption key management system, and encryption key management method

To easily implement CRYSTALS Dilithium, which is one quantum-resistant encryption, even in a secure element with a poor capacity of a storage memory.SOLUTION: A secure element 1 comprises: a storage memory 11 for storing a secret seed ζ, and a cryptographic key generation unit 10 for generating a secret key sk based on the secret seed ζ stored in the storage memory 11, according to a key generation algorithm that generates the secret key sk for quantum-safe encryption (CRYSTALS Dilithium) from a polynomial ring matrix A based on the secret seed ζ.SELECTED DRAWING: Figure 1
Owner:DAI NIPPON PRINTING CO LTD

Secure storage and integrity check of secrets

Disclosed embodiments relate to systems and methods for securely storing a secret. Techniques include accessing a secret associated with a network identity and generating a primary encryption key for encrypting the secret. Generating the primary encryption key includes: accessing a first encryption key associated with the network identity, accessing a second encryption key stored in a process memory location associated with a machine of the network identity, and applying a primary key hash function to the first encryption key and the second encryption key to generate the primary encryption key. Techniques further include encrypting the secret using the primary encryption key to generate an encrypted secret; obfuscating the encrypted secret to generate an obfuscated encrypted secret; and storing the obfuscated encrypted secret in a secured storage location associated with the machine of network identity.
Owner:CYBER ARK SOFTWARE LTD

Mutual authentication and encryption key generation in wireless ambient power (AMP) devices

A method for receiving, by an ambient power (AMP) device that harvests ambient energy, an identification (ID) request frame from a powered wireless device. The ID request frame includes one or more frame exchange parameters and an authentication and key management (AKM) method.The method includes retrieving, from a memory, a secret shared with the powered wireless device, determining, using the secret, one or more first AKM parameters and transmitting, by the AMP device, to the powered wireless device, an ID response frame comprising an ID of the AMP device, at least one of the one or more frame exchange parameters, and the one or more AKM parameters with which the powered wireless device and the AMP device are to be authenticated to each other, and generating an encryption key to initiate an encrypted wireless communication session.
Owner:INFINEON TECHNOLOGIES AMERICAS CORP

Communication devices, communication systems, communication methods, and programs

This technology provides a way to suppress the decrease in the remaining number of encryption keys, even if the generation of encryption keys does not proceed normally. [Solution] The communication device includes a generation means for generating an encryption key to be consumed in encrypted communication, a determination means for determining whether the generation of the encryption key by the generation means is performed correctly, and a selection means for selecting either a first communication process using a first authentication key which is an authentication key generated from the encryption key, or a second communication process which does not consume the encryption key, according to the determination result by the determination means.
Owner:NEC CORP

Lattice-based inner product function encryption method supporting fine-grained revocation, storage medium and equipment

The invention discloses a lattice-based inner product function encryption method supporting fine-grained revocation, a storage medium and equipment. Comprising a system initialization stage, a group administrator initialization stage, a user key generation stage, a function key generation stage, an encryption stage, a decryption stage, a group updating stage, a re-encryption key generation stage, a re-encryption stage, a function updating stage and a key updating stage. And meanwhile, the method disclosed by the invention can resist quantum computer attacks and collusion attacks and realize forward security at the same time.
Owner:SOUTHEAST UNIV

QUANDLE-based cryptographic framework

The invention relates to a QUANDLE based cryptographic framework. Systems and methodologies are described for secure communication to facilitate encrypted transmission of data between a transmitting device (encoder) and a receiving device (decoder) with a query algebra. An example system includes an encoder, a decoder, and a communication channel. The encoder may generate a ciphertext (c) based on the message (x), the encoding variable (y), and the common encryption key (e), where the ciphertext (c) is then sent to the decoder via the communication channel. The decoder may receive the ciphertext (c) via the communication channel and generate a decrypted form (x ') of the message (x) based on the ciphertext (c), the encoding variable (y) and the private encryption key (f), where the sum is a binary operation that satisfies the Quandle and / or rack axiom.
Owner:MELLANOX TECHNOLOGIES LTD(IL) +1

A quantum key replenishment method, device, system, storage medium and computer program product

The quantum key charging method disclosed in the application comprises the following steps: if an allowed charging message including an authorization token sent by a charging service terminal is received, a first encryption key is obtained; a second encryption key corresponding to an identity recognition module is generated; the second encryption key is encrypted by using the first encryption key to obtain first encrypted information; the first token verification information and the first encrypted information are sent to the charging service terminal; the second token verification information and the second encryption key verification information sent by the charging service terminal are received; after the second token verification information and the second encryption key verification information are verified, m quantum keys allocated to the identity recognition module are determined; the m quantum keys are encrypted by using the second encryption key to obtain second encrypted information; and the first token verification information and the second encrypted information are sent to the charging service terminal. The application also discloses a quantum key charging device, a quantum key charging system, a storage medium and a computer program product.
Owner:CHINA MOBILE COMM LTD RES INST +1

A Method for Secure Data Flow Based on Access Control Encryption in a Cloud-Edge Environment

The present invention discloses a method for secure data flow based on access control encryption in a cloud-edge environment, belonging to the field of secure data circulation; specifically: First, a cloud-edge environment simulation scenario is built; the receiving domain authorization agency outputs the receiving domain public key and private key. Then, n sending domain authorization agencies jointly execute an algorithm to obtain the sending domain public key and their respective authorization keys. Each sending domain authorization agency independently runs a partial encryption key generation algorithm to obtain its respective partial encryption key, and the sender runs an encryption key aggregation algorithm to obtain the aggregated encryption key. Next, the receiving domain authorization agency obtains the decryption key and returns it to the receiver. The sender uses the aggregated encryption key to encrypt the plaintext data m and uploads it to the edge node, and a purification algorithm generates a purified ciphertext and uploads it to the cloud server. Finally, after the user retrieves the purified ciphertext, it is decrypted with the decryption key to obtain the message m. The present invention meets the requirements for secure circulation of private data in a cloud-edge environment.
Owner:BEIJING UNIV OF POSTS & TELECOMM

System and method for encrypted NFC communication

A method for authenticating a message from a near field communications (NFC) tag having a corresponding encryption key includes receiving a message from the NFC tag, the message comprising: an NFC tag identifier uniquely corresponding to the NFC tag; an item of variable data generated by the NFC tag; and an authentication code generated by the NFC tag from the tag identifier, and item of variable data, and the encryption key; and reading the authentication code from the message, said authentication code being an extracted authentication code; and authenticating that the message is from the NFC tag by determining that the authentication code is from the NFC tag, without decrypting any portion of the received message. Illustrative embodiments determine that the authentication code is from the NFC tag by checking the authentication code against a pre-determined list of authentication codes uniquely associated with that NFC tag.
Owner:LEGITIMATE INC

Privacy protection-oriented NCA-Arnold secure transmission method

The invention discloses an NCA-Arnold secure transmission method for privacy protection, and the method comprises the steps: carrying out the position scrambling of image pixel positions, and obtaining an image after the pixel positions are changed; randomly selecting plaintext information and a user given key, generating a hash value by using an SHA-512 function, and determining a control parameter and an initial value of the NCA according to the hash value; generating a scrambling matrix according to the generated encryption key, determining a new scrambling matrix through the scrambling matrix, a position function pos () and a direction function dir (), and performing scrambling operation on image positions and pixel values by using a folding algorithm; and carrying out diffusion operation on the scrambled image by using a chaos diffusion formula to obtain a chaos vector, then carrying out XOR operation to obtain an encryption result, and after encryption is completed, carrying out data transmission for a receiving end to carry out decryption processing. According to the method, the complex dynamic characteristics of the NCA and the pixel scrambling capability of Arnold mapping are combined, so that efficient encryption and privacy protection of the digital image are realized.
Owner:CHANGCHUN UNIV OF SCI & TECH