Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

46 results about "Cryptographic key generation" patented technology

Verification system for proving authenticity and ownership of digital assets

Methods and systems described herein may implement blockchain asset authentication. A verification system may generate an encryption key associated with a digital asset, wherein the digital asset is associated with a first entity. The verification system may sign the digital asset using the encryption key. The verification system may generate a first key and a second key based on the encryption key, wherein the first key and the second key are part of a set of multi-party secret keys. The verification system may send the first key to the first entity and store the second key on the verification system. The verification system may receive a request to authenticate the digital asset. The verification system may in response to the request to authenticate, generate the encryption key based on the first key and the second key. The verification system may authenticate the digital asset based on the recreated first secret.
Owner:PAYPAL INC

Wireless communication system and communication method

PendingJP2026017880AWireless commuication servicesCoding/ciphering apparatusCryptographic key generationCloud systems
To provide a radio communication system and a communication method capable of safely relaying communication between a radio station connected to the Internet network and a radio station connected to a closed network.SOLUTION: The closed area system 11 and the cloud system 21 included in the wireless communication system 1 include a closed area side gateway server 13 and a cloud side gateway server 22. When receiving an authentication request from a radio station 41,42, a closed area side gateway server 13 and a cloud side gateway server 22 store activation information including unique information of the radio station 41,42 and generation information of an encryption key in a storage device 27. Regardless of whether the wireless station 41,42 is connected to the closed network 10 or the Internet network 20, the communication between the wireless station 41,42 and the closed system 11 or the cloud system 21 is protected by the encryption key generated based on the generation information included in the activation information.SELECTED DRAWING: Figure 1
Owner:ICOM INC

SM2-based proxy re-encryption algorithm implementation and file authorization sharing system

The invention discloses a system for realizing file authorization sharing based on an SM2 proxy re-encryption algorithm, and the system comprises a client module which is used for file encryption, key generation and key exchange between users; the server module is used for storing a file ciphertext and a Capsule and carrying out key conversion; and the encryption algorithm module is used for realizing secret key generation based on SM2, file encryption based on SM4 and Hash calculation of SHA3. The method has the beneficial effects that national commercial password standard algorithms such as SM2, SM4 and the like are fully fused, and data encryption and proxy re-encryption functions in a domestic algorithm environment are realized on the basis of ensuring the system security. As an elliptic curve public key cryptographic algorithm autonomously designed in China, the SM2 algorithm has the characteristics of public algorithm structure, high security, excellent calculation efficiency and the like.
Owner:内江数循数字科技有限公司

Microcontroller unit (MCU) secure boot

A method includes building a firmware image to execute on a bootloader of a system on chip (SoC), the firmware image including first encryption public and private keys, and digitally signing the firmware image with a second encryption private key. The signed firmware image is encrypted with a symmetric encryption key, which in turn is encrypted with a second encryption public key. The encrypted signed firmware image and the encrypted symmetric encryption key are sent to the SoC to cause the SoC to (1) decrypt the encrypted symmetric encryption key to produce the symmetric encryption key using a third encryption private key from a first asymmetric key pair, (2) decrypt the encrypted signed firmware image to produce the signed firmware image using the symmetric encryption key, and (3) verify a digital signature of the signed firmware image using a third encryption public key from a second asymmetric key pair.
Owner:VERKADA INC

An authenticatable client-side watermarking method based on thumbnail encrypted images

The application discloses a kind of based on thumbnail encryption image's authenticatable user end watermark method, belong to computer security technical field. Including: image pre-processing, image encryption, key generation and distribution, decryption and watermark embedding, tamper detection and positioning, tamper content recovery, extract watermark lock user identity.The present application is based on the holographic redundancy embedding of thumbnail and the fine authentication based on parity check, with very strong anti-shearing and self-healing ability;Using the disturbance of pair of pixel difference value, all image pixels can be embedded watermark, and the security blind area is eliminated;Encrypted image has clear identifiable thumbnail, and is highly similar to plaintext, which is convenient for cloud management, and the details privacy is effectively protected through high-frequency information confusion;Encryption and watermark embedding are fused in bottom algebra operation, and the calculation efficiency is high.
Owner:HENAN NORMAL UNIV

Enhanced encryption for face-related data

A method includes obtaining a plurality of representative vectors associated with face-related data. The method includes determining an encryption key based on a parameter stored in a record, generating an encrypted vector set by, for each respective vector of the plurality of representative vectors, encrypting the respective vector with a homomorphic encryption operation based on the encryption key, where the encrypted vector set includes a first encrypted vector that is linked to a subset of the face-related data associated with the first plurality of face vectors. The method further includes obtaining an encrypted face search vector using the encryption key to perform homomorphic encryption. The method further includes selecting a first encrypted vector based on the encrypted face search vector and retrieving the subset of the face-related data based on the first encrypted vector.
Owner:VERKADA INC

Point-to-point network interconnect with application level interface supporting provenance nodes

The invention relates to peer-to-peer network interconnects with application level interfaces for supporting provenance attestation nodes. Secure peer-to-peer networks are implemented with computing devices through non-secure network connections. Each computing device may include provenance attestation hardware or be coupled with provenance attestation hardware. The provenance attestation hardware may be validated by public available data, such as a trusted server. Furthermore, provenance attestation hardware may facilitate encryption key generation to facilitate encryption of communications at the computing device to ensure security of such communications over the non-secure network connection. The provenance proof hardware may include hardware acceleration circuitry to provide network services, such as cryptocurrency transactions, blockchain verification computations, even blockchain services integrating smart contracts, token exchange, survey services utilizing provenance proof data, distributed data backup, distributed computations, etc.
Owner:CROSSBAR INC

Secure storage and integrity check of secrets

Disclosed embodiments relate to systems and methods for securely storing a secret. Techniques include accessing a secret associated with a network identity and generating a primary encryption key for encrypting the secret. Generating the primary encryption key includes: accessing a first encryption key associated with the network identity, accessing a second encryption key stored in a process memory location associated with a machine of the network identity, and applying a primary key hash function to the first encryption key and the second encryption key to generate the primary encryption key. Techniques further include encrypting the secret using the primary encryption key to generate an encrypted secret; obfuscating the encrypted secret to generate an obfuscated encrypted secret; and storing the obfuscated encrypted secret in a secured storage location associated with the machine of network identity.
Owner:CYBER ARK SOFTWARE LTD

Communication devices, communication systems, communication methods, and programs

This technology provides a way to suppress the decrease in the remaining number of encryption keys, even if the generation of encryption keys does not proceed normally. [Solution] The communication device includes a generation means for generating an encryption key to be consumed in encrypted communication, a determination means for determining whether the generation of the encryption key by the generation means is performed correctly, and a selection means for selecting either a first communication process using a first authentication key which is an authentication key generated from the encryption key, or a second communication process which does not consume the encryption key, according to the determination result by the determination means.
Owner:NEC CORP

A quantum key replenishment method, device, system, storage medium and computer program product

The quantum key charging method disclosed in the application comprises the following steps: if an allowed charging message including an authorization token sent by a charging service terminal is received, a first encryption key is obtained; a second encryption key corresponding to an identity recognition module is generated; the second encryption key is encrypted by using the first encryption key to obtain first encrypted information; the first token verification information and the first encrypted information are sent to the charging service terminal; the second token verification information and the second encryption key verification information sent by the charging service terminal are received; after the second token verification information and the second encryption key verification information are verified, m quantum keys allocated to the identity recognition module are determined; the m quantum keys are encrypted by using the second encryption key to obtain second encrypted information; and the first token verification information and the second encrypted information are sent to the charging service terminal. The application also discloses a quantum key charging device, a quantum key charging system, a storage medium and a computer program product.
Owner:CHINA MOBILE COMM LTD RES INST +1

Systems and devices configured to generate and utilize short-range communication-based authentication tokens, and methods of use thereof

PendingUS20260128903A1User identity/authority verificationCryptographic key generationUser equipment
Systems and methods of the present disclosure enable improved cryptographic security using an integrated circuit of a short range wireless card. The integrated circuit receives, via a short range wireless signal, from a user device, a bearer token request including an identifier that identifies a user, the user device or both. The integrated circuit determines a cryptographic key and uses a time keeping circuit to generate a time value indicative of a window of time for which a bearer token is to be valid. The integrated circuit uses a cryptographic hash to produce the bearer token based on: the identifier, the time value and the cryptographic key. The integrated circuit transmits, via a return short range wireless signal to the user device, the bearer token to enable authentication of the user upon the bearer token being equivalent to a comparison token within the time window.
Owner:CAPITAL ONE SERVICES LLC

Cryptographic system, cryptographic method, and cryptographic program

PendingCN121729860AMultiple keys/algorithms usageCryptographic key generationPlaintext
The encryption device (400) doubly encrypts a plaintext using the first internal public key and the first external public key and generates a ciphertext. A re-encryption key generation device (500) generates a randomized internal private key using the second random number and the first internal private key, generates a second encrypted random number using the second internal public key, generates a randomized external private key using the first random number and the first external private key, and generates a first encrypted random number using the second external public key. The re-encryption device (600) generates a re-encrypted text using the randomized external private key, the randomized internal private key, the second internal public key, the second external public key, and the ciphertext. The decryption device (700) calculates a plaintext using the second internal private key, the second encrypted random number, the second external private key, the first encrypted random number, and the re-encrypted text.
Owner:MITSUBISHI ELECTRIC CORP

Encryption system, encryption method and encryption program

PendingDE112023006562T5Multiple keys/algorithms usagePlaintextCryptographic key generation
An encryption device (400) generates a ciphertext by double-encrypting a plaintext using a first internal public key and a first external public key. A re-encryption key generation device (500) generates a randomized internal secret key using a second random number and a first internal secret key, generates a second encrypted random number using a second internal public key, generates a randomized external secret key using a first random number and a first external secret key, and generates a first encrypted random number using a second external public key.A re-encryption unit (600) generates a newly encrypted text using the randomized external secret key, the randomized internal secret key, the second internal public key, the second external public key, and the ciphertext. A decryption unit (700) computes the plaintext using the second internal secret key, the second encrypted random number, the second external secret key, the first encrypted random number, and the newly encrypted text.
Owner:MITSUBISHI ELECTRIC CORP

Systems and methods for secure data transmission using cryptographic engine

PCT designated stageWO2026043553A1Key distribution for secure communicationUser identity/authority verificationCryptographic key generationUser device
A method and system for secure data transmission between user devices using a cryptographic engine are disclosed. The method includes obtaining plaintext data for encryption as indicated by an encryption request, generating encrypted data using an encrypting key, and generating a unique encryption identifier associated with the encrypted data. The encryption identifier may be used for referencing one or more cryptographic keys, including the encrypting key, and is used to retrieve key material during decryption. An authentication request including the encryption identifier and access credentials is received and validated. Upon successful validation, the encrypted data is decrypted using a decrypting key and the plaintext data is provided to a user interface. In some embodiments, cryptographic operations are performed locally on the client device. Embodiments may implement symmetric and / or asymmetric encryption for various operations.
Owner:CRITTORA LLC

Modular firmware security upgrade method and system for intelligent monitoring terminal

PendingCN122152335AVersion controlProgram/content distribution protectionCryptographic key generationTimestamp
The application relates to the technical field of Internet of Things security, and discloses a modularized firmware security upgrade method and system for an intelligent monitoring terminal, which comprises the following steps: dividing firmware into four independent modules of a boot loader, a kernel, a file system and an application program, and calculating a check value; generating a security package by using a device unique identifier to derive an encryption key; generating an asymmetric key pair based on a hardware fingerprint to perform digital signature verification; creating a dual-system partition mapping table after verifying the integrity of running firmware and the security state of a system; performing module decryption verification and atomized update of a partition pointer in a fixed sequence; and generating a hash chain containing data such as a timestamp and a version number for storage evidence. The system comprises five modules of an upgrade package construction, security authentication, environment verification, upgrade execution and storage evidence tracing. Through modularized security encapsulation, hardware fingerprint authentication and an atomized upgrade mechanism, the security and reliability problems in the firmware upgrade process are solved.
Owner:DONGGUAN QIAOAN ZHILIAN TECHNOLOGY CO LTD

A puncturable key-policy attribute-based proxy re-encryption method based on lattice cryptography

ActiveCN121508821BKey distribution for secure communicationChosen-plaintext attackCryptographic key generation
The present application relates to the technical field of password security protection, and discloses a puncturable key policy attribute proxy re-encryption method based on lattice cryptography, which comprises an initialization step, an initial key generation step, an encryption step, a puncturable key update step, a decryption step, a re-encryption key generation step and a re-encryption step. The present application allows a receiver to perform a puncturing operation on a specific label locally, thereby autonomously revoking the decryption capability under the corresponding label without the intervention of a data owner or triggering global re-encryption. The receiver-driven revocation mechanism not only realizes fine-grained access control differentiated by labels, but also reduces system overhead while maintaining ciphertext reusability. The present scheme can securely support proxy re-encryption of ciphertext without exposing plaintext or master keys. Based on the security constructed on the LWE assumption, the present method supports multi-bit encryption and can provide effective security protection under quantum attack and chosen plaintext attack models.
Owner:BEIJING ELECTRONICS SCI & TECH INST

Cryptographic secret generation and provisioning

A system includes a memory device and a processor, operatively coupled with the memory device, to perform operations including receiving, from a device via a brokering agent, a request to provide an encrypted version of a set of secrets data corresponding to a target state of the device, determining whether to authorize the request in view of the brokering agent, and in response to authorizing the request, providing the encrypted version of the set of secrets data and permission to transition to the target state.
Owner:BLOCKFRAME INC

Generation of cryptographic keys

There is provided mechanisms for generating a cryptographic key for a user. The method is performed by a cryptographic key generator device. The method comprises authenticating the user using biometrics data read from the user using a biometrics reader. The method comprises obtaining, only when having authenticated the user, a PUF response from a PUF entity by providing a challenge based on biometrics response data to the PUF entity. The biometrics response data is a function of the biometrics data. The method comprises generating the cryptographic key using a cryptographic function and by seeding the cryptographic function with the PUF response.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Data security encryption method based on smart campus cloud platform

The present application relates to the technical field of data security encryption, in particular to a data security encryption method based on a smart campus cloud platform, which comprises the following steps: receiving a data processing request carrying an original data file and preset metadata tags thereof; matching a target encryption security level and encryption control parameters based on a tag query security policy library; starting a multi-channel encryption key generation engine to generate a core working key, a data integrity check key and an access session key after verifying that a user identity attribute meets an access condition; using the core working key to block and obfuscate encode the original file to form a timestamped intermediate encrypted data block; using the integrity check key to calculate an overall hash value and generate a to-be-encapsulated ciphertext package; and finally using the access session key to perform secondary encapsulation to form a final ciphertext stream. The present application realizes dynamic adaptation of encryption strength according to data attributes, and completes integrated security processing of encryption, integrity protection and session control through multi-key cooperation.
Owner:CHINA TELECOM CONSTR 4TH ENG

Microcontroller having wireless communication module for use with a system

ActiveUS12621663B2Computer security arrangementsSecurity arrangementCryptographic key generationMicrocontroller
Systems, apparatuses, and methods that provide for a wireless communication microcontroller for use with a system microcontroller. A first microcontroller is configured to control aspects of a system in which the device can be embedded. A second microcontroller is operatively connected to the first microcontroller, with the second microcontroller including a wireless communication module for wireless communication. A secure element is operatively connected to the second microcontroller, with a cryptographic key being stored in the secure element. The second microcontroller is configured to receive instructions for programming the first microcontroller through the wireless communication module and request a session key from the secure element. The secure element is configured to generate the session key using the cryptographic key. The second microcontroller is further configured validate the instructions using the session key and send the validated instructions to the first microcontroller.
Owner:DENTSPLY SIRONA INC

Techniques for establishing trust in a cluster of edge devices

Techniques are disclosed to establish trust in a cluster of edge devices. A new cloud-computing edge device can be connected to a cluster of cloud-computing edge devices. The new cloud-computing edge device can store a fleet encryption key and a plurality of public encryption keys corresponding to the cluster of cloud-computing edge devices. The new cloud-computing edge device can use the fleet encryption key to generate encrypted message data including a new public encryption key and send the encrypted message data to the cluster. If the encrypted message data is successfully decrypted by the cluster of cloud-computing edge devices, the new cloud-computing edge device can send a request for a session token to the cluster of cloud-computing edge devices. If a signature of the request is verified, the new cloud-computing edge device can receive the session token and establish a communication session with the cluster of cloud-computing edge devices.
Owner:ORACLE INT CORP

Puncture key strategy attribute proxy re-encryption method based on lattice password

ActiveCN121508821AKey distribution for secure communicationChosen-plaintext attackCryptographic key generation
The invention relates to the technical field of password security protection, and discloses a puncturable key strategy attribute proxy re-encryption method based on a lattice password, which comprises an initialization step, an initial key generation step, an encryption step, a puncture key updating step, a decryption step, a re-encryption key generation step and a re-encryption step. According to the method, the receiver is allowed to perform puncture operation on the specific label locally, so that the decryption capability under the corresponding label is autonomously revoked, a data owner does not need to intervene or trigger global re-encryption, and the revocation mechanism driven by the receiver not only realizes fine-grained access control distinguished according to the label, but also realizes the decryption capability under the corresponding label. And system overhead is reduced while reusability of the ciphertext is maintained. According to the scheme, proxy re-encryption of the ciphertext can be safely supported on the premise that the plaintext or the master key is not exposed. Based on the security of LWE hypothesis construction, the method supports multi-bit encryption, and can provide effective security protection under a quantum attack and selection plaintext attack model.
Owner:BEIJING ELECTRONICS SCI & TECH INST

System and method for encrypting and decrypting data

A method of encrypting data, performed by a computer system includes: dividing transmission target data into an arbitrary number of blocks; selecting an encryption key generation target block to be used for extracting an encryption key from among the plurality of divided blocks; generating an encryption key based on the encryption key generation target block; selecting an encryption target block from among remaining blocks excluding the encryption key generation target block; and encrypting the encryption target block based on the generated encryption key.
Owner:ICERTI

Method and system for ongoing spectral feedback and control during quantum key distribution using data analysis

The present invention provides a quantum communication system and associated methods for securely establishing a cryptographic key between two or more transmitters and a receiver. Each transmitter emits qubit signals from a light source within defined time windows, characterized by specific bases and modes controlled by a transmitter controller. The receiver utilizes an interference device with multiple inputs to receive qubit signals and outputs to generate an interference signal, which is detected by multiple detectors. A receiver controller sends information on detected outputs to transmitters and provides feedback based on spectral characteristics. Simultaneously, the system adjusts subsequent qubit signal characteristics based on this spectral feedback, enabling the establishment of a cryptographic key between transmitters using the detected signals. This adjustment optimizes the cryptographic key rate, enhancing security and efficiency in quantum communication protocols.
Owner:QUANTIZED TECHNOLOGIES INC

Key establishment and secure communications using satellite-provided random number values

PendingUS20260095316A1Key distribution for secure communicationCryptographic key generationSecure communication
Systems and techniques for secure communications and distribution of random values for cryptographic key generation, coordinated with the use of specific key generation parameters, are described. An example method includes: receiving a first random value and a second random value generated from at least one quantum random number generator (QRNG), with at least one of the first random value and the second random value being provided from a satellite communication; obtaining key generation parameters associated with cryptographic key generation, where the key generation parameters specify a specific combination of the first random value and the second random value; and generating a cryptographic key, using the specific combination of the first random value and the second random value, as a seed to a cryptographic function.
Owner:WELLS FARGO BANK NA

Protecting near field communication (NFC)

PendingUS20260039656A1Near-field transmissionSecuring communicationCryptographic key generationCommunication device
Methods, systems, and apparatus, including computer programs encoded on computer storage media, for protecting near field communication (NFC). One of the methods includes obtaining, using a first Near Field Communication (NFC) device, an embedded encrypted key from a second NFC device; generating, using the embedded encrypted key from the second NFC device, a resource request including the embedded encrypted key from the second NFC device; transmitting the resource request to a verifying component; in response to transmitting the resource request, obtaining response data from the verifying component configured to cause a device coupled to the first NFC device to perform an action.
Owner:THE NINTH LLC

A symmetric key distribution visual dynamic design method

ActiveCN115913549BKey distribution for secure communicationCryptographic key generationSoftware engineering
This invention discloses a visual dynamic design method for symmetric key distribution, implemented based on a database storing key component information and a drag-and-drop interface. The visual dynamic design method specifically includes the following steps: S1. Establishing a database storing key component information, including encryption keys and business keys; S2. Creating a visual symmetric key distribution operation interface on the operation interface; S3. Performing drag-and-drop operations on the symmetric key distribution operation interface generated in step S2 according to the business scenario to establish a node architecture and assign protection encryption keys; S4. Generating and displaying a key relationship topology structure specific to the business scenario. This invention adopts a modular and visual design, enabling dynamic generation of key protection strategies for different businesses, achieving the goal of one-time development and applicability across multiple business scenarios, further reducing the workload of developers and improving the efficiency of key protection distribution.
Owner:HEBEI PRIME NUMBER INFORMATION SECURITY CO LTD

Encryption method using fixed-base comb method

An elliptic curve encryption method includes determining a window size indicating a number of groups for performing scalar multiplication in parallel, generating, based on a first encryption key, a second encryption key, the generating the second encryption key including changing a value of the first encryption key, the first encryption key being a random number, generating a third encryption key based on the second encryption key, the generating the third encryption key including changing a total number of bits of the second encryption key to be a multiple of the window size by applying a binary number-based value conversion method, and performing, in parallel, a scalar multiplication operation with the third encryption key and a vector on an elliptic curve based on the window size, wherein the second encryption key has a value conforming to the binary number-based value conversion method.
Owner:SAMSUNG ELECTRONICS CO LTD

System for secure key generation using chaotic oscillator-based entropy units

ActiveDE202025107853U1Random number generatorsInternal/peripheral component protectionCryptographic key generationKey size
A system for secure cryptographic key generation using chaotic oscillator-based entropy units, wherein the system comprises the following: a housing designed for integration into a machine or electronic device; one or more chaotic oscillator units physically arranged within the housing, each chaotic oscillator unit comprising a nonlinear electronic circuit configured to operate in a chaotic dynamic regime to generate an aperiodic analog signal sensitive to initial conditions and intrinsic circuit noise; a signal acquisition unit electrically connected to one or more chaotic oscillator units and configured to receive the aperiodic analog signal, wherein the signal acquisition unit includes an analog conditioning circuit configured to normalize the signal amplitude and limit the signal bandwidth to a predefined operating range; a converter unit that is electrically coupled to the signal acquisition unit and is configured to sample the processed analog signal at time-varying sampling intervals to generate a digital entropy data stream; a processing unit comprising one or more processors operationally linked to a non-volatile memory, wherein the processing unit is configured to perform entropy conditioning operations on the digital entropy data stream to suppress distortions and reduce temporal correlation; a key generation unit that is operationally coupled with the processing unit and configured to convert conditional entropy data into cryptographic key material of a predefined key length; and a secure storage unit that is operationally connected to the key generation unit and is configured to store the cryptographic key material while preventing unauthorized external access, wherein the system is configured to generate cryptographic keys from physically chaotic behavior without relying on deterministic, purely software-based entropy sources.
Owner:PALRAJ VIMAL KUMAR VIRUDHUNAGAR +2

Cryptographic Key Generation Device

ActiveGB6512168SComputer hardwareCryptographic key generation
Owner:LAXMAN MAJHI +1