Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

80 results about "Cryptographic key generation" patented technology

Automated rule-based smart contract approval via blockchain cybersecurity authentication services

In one embodiment, a method includes accessing transaction data associated with a protected first function of a first blockchain transaction protocol by a cybersecurity authentication service of a blockchain cybersecurity platform, accessing a transaction protocol runbook comprising preconfigured conditions associated with the protected first function, determining that the protected first function is eligible to be analyzed by an automated decisional logic module based on the transaction protocol runbook, determining each preconfigured condition is satisfied based on the transaction data by the automated decisional logic module, generating an authentication object for the protected first function, generating signed transaction data based on the accessed transaction data and a private encryption key, wherein the signed transaction data is configured to update a second blockchain transaction protocol to indicate that the protected first function is authenticated, and transmitting a transaction bundle comprising the accessed transaction data and the signed transaction data.
Owner:HALBORN INC

Verification system for proving authenticity and ownership of digital assets

Methods and systems described herein may implement blockchain asset authentication. A verification system may generate an encryption key associated with a digital asset, wherein the digital asset is associated with a first entity. The verification system may sign the digital asset using the encryption key. The verification system may generate a first key and a second key based on the encryption key, wherein the first key and the second key are part of a set of multi-party secret keys. The verification system may send the first key to the first entity and store the second key on the verification system. The verification system may receive a request to authenticate the digital asset. The verification system may in response to the request to authenticate, generate the encryption key based on the first key and the second key. The verification system may authenticate the digital asset based on the recreated first secret.
Owner:PAYPAL INC

Privacy-preserving authenticated key rotation

Certain aspects of the disclosure provide a method for performing data verification. The method includes generating a MAC by applying a tagging algorithm indicated by a shared verification key to a data item; appending the MAC to the data item; generating an encrypted dataset comprising an encrypted data item and encrypted message authentication; generating a re-encryption key based on a homomorphic secret key corresponding to the homomorphic public key and a new public key; generating a re-encrypted dataset comprising a re-encrypted data item and a re-encrypted MAC; transmitting the re-encrypted dataset to a first external system configured to perform data verification; receiving, from the first external system, an encrypted verification result based on the shared verification key; and taking an action based on receiving the verification result indicating that the data item is authentic.
Owner:INTUIT INC

Wireless communication system and communication method

To provide a radio communication system and a communication method capable of safely relaying communication between a radio station connected to the Internet network and a radio station connected to a closed network.SOLUTION: The closed area system 11 and the cloud system 21 included in the wireless communication system 1 include a closed area side gateway server 13 and a cloud side gateway server 22. When receiving an authentication request from a radio station 41,42, a closed area side gateway server 13 and a cloud side gateway server 22 store activation information including unique information of the radio station 41,42 and generation information of an encryption key in a storage device 27. Regardless of whether the wireless station 41,42 is connected to the closed network 10 or the Internet network 20, the communication between the wireless station 41,42 and the closed system 11 or the cloud system 21 is protected by the encryption key generated based on the generation information included in the activation information.SELECTED DRAWING: Figure 1
Owner:ICOM INC

Information encryption processing method and device, equipment, medium and program product

The embodiment of the invention provides an information encryption processing method and device, equipment, a medium and a program product, and the method comprises the steps: carrying out the Hash calculation of the obtained user registration information in an information encryption process, obtaining a Hash value, extracting an encryption key and an authentication key from the Hash value, and performing encryption calculation on the user registration information according to a key stream generated based on the initial encryption parameter and the encryption key to obtain ciphertext information, performing encryption calculation based on the ciphertext information and the authentication key to obtain an encryption authentication tag, and storing the ciphertext information and the encryption authentication tag in a preset storage address. And the storage security of the user registration information is improved.
Owner:CHINA MOBILE (XIONGAN) ICT CO LTD +3

SM2-based proxy re-encryption algorithm implementation and file authorization sharing system

The invention discloses a system for realizing file authorization sharing based on an SM2 proxy re-encryption algorithm, and the system comprises a client module which is used for file encryption, key generation and key exchange between users; the server module is used for storing a file ciphertext and a Capsule and carrying out key conversion; and the encryption algorithm module is used for realizing secret key generation based on SM2, file encryption based on SM4 and Hash calculation of SHA3. The method has the beneficial effects that national commercial password standard algorithms such as SM2, SM4 and the like are fully fused, and data encryption and proxy re-encryption functions in a domestic algorithm environment are realized on the basis of ensuring the system security. As an elliptic curve public key cryptographic algorithm autonomously designed in China, the SM2 algorithm has the characteristics of public algorithm structure, high security, excellent calculation efficiency and the like.
Owner:内江数循数字科技有限公司

Microcontroller unit (MCU) secure boot

A method includes building a firmware image to execute on a bootloader of a system on chip (SoC), the firmware image including first encryption public and private keys, and digitally signing the firmware image with a second encryption private key. The signed firmware image is encrypted with a symmetric encryption key, which in turn is encrypted with a second encryption public key. The encrypted signed firmware image and the encrypted symmetric encryption key are sent to the SoC to cause the SoC to (1) decrypt the encrypted symmetric encryption key to produce the symmetric encryption key using a third encryption private key from a first asymmetric key pair, (2) decrypt the encrypted signed firmware image to produce the signed firmware image using the symmetric encryption key, and (3) verify a digital signature of the signed firmware image using a third encryption public key from a second asymmetric key pair.
Owner:VERKADA INC

An authenticatable client-side watermarking method based on thumbnail encrypted images

The application discloses a kind of based on thumbnail encryption image's authenticatable user end watermark method, belong to computer security technical field. Including: image pre-processing, image encryption, key generation and distribution, decryption and watermark embedding, tamper detection and positioning, tamper content recovery, extract watermark lock user identity.The present application is based on the holographic redundancy embedding of thumbnail and the fine authentication based on parity check, with very strong anti-shearing and self-healing ability;Using the disturbance of pair of pixel difference value, all image pixels can be embedded watermark, and the security blind area is eliminated;Encrypted image has clear identifiable thumbnail, and is highly similar to plaintext, which is convenient for cloud management, and the details privacy is effectively protected through high-frequency information confusion;Encryption and watermark embedding are fused in bottom algebra operation, and the calculation efficiency is high.
Owner:HENAN NORMAL UNIV

Enhanced encryption for face-related data

A method includes obtaining a plurality of representative vectors associated with face-related data. The method includes determining an encryption key based on a parameter stored in a record, generating an encrypted vector set by, for each respective vector of the plurality of representative vectors, encrypting the respective vector with a homomorphic encryption operation based on the encryption key, where the encrypted vector set includes a first encrypted vector that is linked to a subset of the face-related data associated with the first plurality of face vectors. The method further includes obtaining an encrypted face search vector using the encryption key to perform homomorphic encryption. The method further includes selecting a first encrypted vector based on the encrypted face search vector and retrieving the subset of the face-related data based on the first encrypted vector.
Owner:VERKADA INC

Point-to-point network interconnect with application level interface supporting provenance nodes

The invention relates to peer-to-peer network interconnects with application level interfaces for supporting provenance attestation nodes. Secure peer-to-peer networks are implemented with computing devices through non-secure network connections. Each computing device may include provenance attestation hardware or be coupled with provenance attestation hardware. The provenance attestation hardware may be validated by public available data, such as a trusted server. Furthermore, provenance attestation hardware may facilitate encryption key generation to facilitate encryption of communications at the computing device to ensure security of such communications over the non-secure network connection. The provenance proof hardware may include hardware acceleration circuitry to provide network services, such as cryptocurrency transactions, blockchain verification computations, even blockchain services integrating smart contracts, token exchange, survey services utilizing provenance proof data, distributed data backup, distributed computations, etc.
Owner:CROSSBAR INC

Secure element, encryption key generation method, computer program, encryption key management system, and encryption key management method

To easily implement CRYSTALS Dilithium, which is one quantum-resistant encryption, even in a secure element with a poor capacity of a storage memory.SOLUTION: A secure element 1 comprises: a storage memory 11 for storing a secret seed ζ, and a cryptographic key generation unit 10 for generating a secret key sk based on the secret seed ζ stored in the storage memory 11, according to a key generation algorithm that generates the secret key sk for quantum-safe encryption (CRYSTALS Dilithium) from a polynomial ring matrix A based on the secret seed ζ.SELECTED DRAWING: Figure 1
Owner:DAI NIPPON PRINTING CO LTD

Secure storage and integrity check of secrets

Disclosed embodiments relate to systems and methods for securely storing a secret. Techniques include accessing a secret associated with a network identity and generating a primary encryption key for encrypting the secret. Generating the primary encryption key includes: accessing a first encryption key associated with the network identity, accessing a second encryption key stored in a process memory location associated with a machine of the network identity, and applying a primary key hash function to the first encryption key and the second encryption key to generate the primary encryption key. Techniques further include encrypting the secret using the primary encryption key to generate an encrypted secret; obfuscating the encrypted secret to generate an obfuscated encrypted secret; and storing the obfuscated encrypted secret in a secured storage location associated with the machine of network identity.
Owner:CYBER ARK SOFTWARE LTD

Communication devices, communication systems, communication methods, and programs

This technology provides a way to suppress the decrease in the remaining number of encryption keys, even if the generation of encryption keys does not proceed normally. [Solution] The communication device includes a generation means for generating an encryption key to be consumed in encrypted communication, a determination means for determining whether the generation of the encryption key by the generation means is performed correctly, and a selection means for selecting either a first communication process using a first authentication key which is an authentication key generated from the encryption key, or a second communication process which does not consume the encryption key, according to the determination result by the determination means.
Owner:NEC CORP

QUANDLE-based cryptographic framework

The invention relates to a QUANDLE based cryptographic framework. Systems and methodologies are described for secure communication to facilitate encrypted transmission of data between a transmitting device (encoder) and a receiving device (decoder) with a query algebra. An example system includes an encoder, a decoder, and a communication channel. The encoder may generate a ciphertext (c) based on the message (x), the encoding variable (y), and the common encryption key (e), where the ciphertext (c) is then sent to the decoder via the communication channel. The decoder may receive the ciphertext (c) via the communication channel and generate a decrypted form (x ') of the message (x) based on the ciphertext (c), the encoding variable (y) and the private encryption key (f), where the sum is a binary operation that satisfies the Quandle and / or rack axiom.
Owner:MELLANOX TECHNOLOGIES LTD(IL) +1

A quantum key replenishment method, device, system, storage medium and computer program product

The quantum key charging method disclosed in the application comprises the following steps: if an allowed charging message including an authorization token sent by a charging service terminal is received, a first encryption key is obtained; a second encryption key corresponding to an identity recognition module is generated; the second encryption key is encrypted by using the first encryption key to obtain first encrypted information; the first token verification information and the first encrypted information are sent to the charging service terminal; the second token verification information and the second encryption key verification information sent by the charging service terminal are received; after the second token verification information and the second encryption key verification information are verified, m quantum keys allocated to the identity recognition module are determined; the m quantum keys are encrypted by using the second encryption key to obtain second encrypted information; and the first token verification information and the second encrypted information are sent to the charging service terminal. The application also discloses a quantum key charging device, a quantum key charging system, a storage medium and a computer program product.
Owner:CHINA MOBILE COMM LTD RES INST +1

System and method for encrypted NFC communication

A method for authenticating a message from a near field communications (NFC) tag having a corresponding encryption key includes receiving a message from the NFC tag, the message comprising: an NFC tag identifier uniquely corresponding to the NFC tag; an item of variable data generated by the NFC tag; and an authentication code generated by the NFC tag from the tag identifier, and item of variable data, and the encryption key; and reading the authentication code from the message, said authentication code being an extracted authentication code; and authenticating that the message is from the NFC tag by determining that the authentication code is from the NFC tag, without decrypting any portion of the received message. Illustrative embodiments determine that the authentication code is from the NFC tag by checking the authentication code against a pre-determined list of authentication codes uniquely associated with that NFC tag.
Owner:LEGITIMATE INC

Privacy protection-oriented NCA-Arnold secure transmission method

The invention discloses an NCA-Arnold secure transmission method for privacy protection, and the method comprises the steps: carrying out the position scrambling of image pixel positions, and obtaining an image after the pixel positions are changed; randomly selecting plaintext information and a user given key, generating a hash value by using an SHA-512 function, and determining a control parameter and an initial value of the NCA according to the hash value; generating a scrambling matrix according to the generated encryption key, determining a new scrambling matrix through the scrambling matrix, a position function pos () and a direction function dir (), and performing scrambling operation on image positions and pixel values by using a folding algorithm; and carrying out diffusion operation on the scrambled image by using a chaos diffusion formula to obtain a chaos vector, then carrying out XOR operation to obtain an encryption result, and after encryption is completed, carrying out data transmission for a receiving end to carry out decryption processing. According to the method, the complex dynamic characteristics of the NCA and the pixel scrambling capability of Arnold mapping are combined, so that efficient encryption and privacy protection of the digital image are realized.
Owner:CHANGCHUN UNIV OF SCI & TECH

SM4 encryption and decryption key generation hardware design method based on shared state machine

The invention discloses an SM4 encryption and decryption key generation hardware design method based on a shared state machine, the encryption key generation process and the decryption key generation process are combined, all data paths are shared, a part of the state machine is shared, the state machine takes K0, K1, K2 and K3 as main key input during encryption, and takes K35, K34, K33 and K32 as main key input during decryption, so that the encryption key generation process and the decryption key generation process are integrated. The generation of the decryption key can be completed by only 32 cycles when the key does not need to be updated, so that the number of cycles required by the generation of the decryption round key is reduced. The customized state machine optimizes the decryption key generation process through state jump, and ensures the correctness of the generated encryption round key and decryption round key through control of a control signal. The method is used for generating an SM4 encryption and decryption key, and the period number of generation of the decryption key is reduced by 50% when the key is not changed. And the number of registers and combinatorial logics required by generation of encryption and decryption keys is reduced.
Owner:NANJING UNIV OF SCI & TECH +1

Re-encryption key generation device, re-encryption device, ciphertext conversion system, re-encryption method, and re-encryption program

A re-encryption key generation device (500) comprises a re-encryption key generation unit (503) that generates a randomized secret key by randomizing a first secret key of public key encryption using a random number, and generates an encrypted random number by encrypting a random number by homomorphic encryption using a second public key of the homomorphic encryption. Each of the randomized secret key and the encrypted random number is an element of a re-encryption key for re-encrypting original ciphertext generated by encrypting plaintext using a first public key corresponding to the first secret key.
Owner:MITSUBISHI ELECTRIC CORP

Systems and devices configured to generate and utilize short-range communication-based authentication tokens, and methods of use thereof

Systems and methods of the present disclosure enable improved cryptographic security using an integrated circuit of a short range wireless card. The integrated circuit receives, via a short range wireless signal, from a user device, a bearer token request including an identifier that identifies a user, the user device or both. The integrated circuit determines a cryptographic key and uses a time keeping circuit to generate a time value indicative of a window of time for which a bearer token is to be valid. The integrated circuit uses a cryptographic hash to produce the bearer token based on: the identifier, the time value and the cryptographic key. The integrated circuit transmits, via a return short range wireless signal to the user device, the bearer token to enable authentication of the user upon the bearer token being equivalent to a comparison token within the time window.
Owner:CAPITAL ONE SERVICES LLC

Cryptographic system, cryptographic method, and cryptographic program

The encryption device (400) doubly encrypts a plaintext using the first internal public key and the first external public key and generates a ciphertext. A re-encryption key generation device (500) generates a randomized internal private key using the second random number and the first internal private key, generates a second encrypted random number using the second internal public key, generates a randomized external private key using the first random number and the first external private key, and generates a first encrypted random number using the second external public key. The re-encryption device (600) generates a re-encrypted text using the randomized external private key, the randomized internal private key, the second internal public key, the second external public key, and the ciphertext. The decryption device (700) calculates a plaintext using the second internal private key, the second encrypted random number, the second external private key, the first encrypted random number, and the re-encrypted text.
Owner:MITSUBISHI ELECTRIC CORP

Ciphertext conversion system, re-encryption verification method, and re-encryption verification program

This re-encryption verification device (700) comprises a verification unit (703) that verifies, on the basis of a re-encrypted ciphertext and a re-encryption key, whether or not the re-encrypted ciphertext has been generated by using the re-encryption key. The re-encrypted ciphertext is formed from: a randomized plaintext generated by using a randomized secret key generated by randomizing a first secret key of public key encryption using a random number to decrypt an original ciphertext generated by encrypting a plaintext using a first public key; and an encrypted random number generated by encrypting a random number using a second public key of the public key encryption. The re-encryption key is formed from the encrypted random number and the randomized secret key.
Owner:MITSUBISHI ELECTRIC CORP

Encryption system, encryption method and encryption program

An encryption device (400) generates a ciphertext by double-encrypting a plaintext using a first internal public key and a first external public key. A re-encryption key generation device (500) generates a randomized internal secret key using a second random number and a first internal secret key, generates a second encrypted random number using a second internal public key, generates a randomized external secret key using a first random number and a first external secret key, and generates a first encrypted random number using a second external public key.A re-encryption unit (600) generates a newly encrypted text using the randomized external secret key, the randomized internal secret key, the second internal public key, the second external public key, and the ciphertext. A decryption unit (700) computes the plaintext using the second internal secret key, the second encrypted random number, the second external secret key, the first encrypted random number, and the newly encrypted text.
Owner:MITSUBISHI ELECTRIC CORP

Systems and methods for secure data transmission using cryptographic engine

A method and system for secure data transmission between user devices using a cryptographic engine are disclosed. The method includes obtaining plaintext data for encryption as indicated by an encryption request, generating encrypted data using an encrypting key, and generating a unique encryption identifier associated with the encrypted data. The encryption identifier may be used for referencing one or more cryptographic keys, including the encrypting key, and is used to retrieve key material during decryption. An authentication request including the encryption identifier and access credentials is received and validated. Upon successful validation, the encrypted data is decrypted using a decrypting key and the plaintext data is provided to a user interface. In some embodiments, cryptographic operations are performed locally on the client device. Embodiments may implement symmetric and / or asymmetric encryption for various operations.
Owner:CRITTORA LLC

Modular firmware security upgrade method and system for intelligent monitoring terminal

The application relates to the technical field of Internet of Things security, and discloses a modularized firmware security upgrade method and system for an intelligent monitoring terminal, which comprises the following steps: dividing firmware into four independent modules of a boot loader, a kernel, a file system and an application program, and calculating a check value; generating a security package by using a device unique identifier to derive an encryption key; generating an asymmetric key pair based on a hardware fingerprint to perform digital signature verification; creating a dual-system partition mapping table after verifying the integrity of running firmware and the security state of a system; performing module decryption verification and atomized update of a partition pointer in a fixed sequence; and generating a hash chain containing data such as a timestamp and a version number for storage evidence. The system comprises five modules of an upgrade package construction, security authentication, environment verification, upgrade execution and storage evidence tracing. Through modularized security encapsulation, hardware fingerprint authentication and an atomized upgrade mechanism, the security and reliability problems in the firmware upgrade process are solved.
Owner:DONGGUAN QIAOAN ZHILIAN TECHNOLOGY CO LTD

A puncturable key-policy attribute-based proxy re-encryption method based on lattice cryptography

The present application relates to the technical field of password security protection, and discloses a puncturable key policy attribute proxy re-encryption method based on lattice cryptography, which comprises an initialization step, an initial key generation step, an encryption step, a puncturable key update step, a decryption step, a re-encryption key generation step and a re-encryption step. The present application allows a receiver to perform a puncturing operation on a specific label locally, thereby autonomously revoking the decryption capability under the corresponding label without the intervention of a data owner or triggering global re-encryption. The receiver-driven revocation mechanism not only realizes fine-grained access control differentiated by labels, but also reduces system overhead while maintaining ciphertext reusability. The present scheme can securely support proxy re-encryption of ciphertext without exposing plaintext or master keys. Based on the security constructed on the LWE assumption, the present method supports multi-bit encryption and can provide effective security protection under quantum attack and chosen plaintext attack models.
Owner:BEIJING ELECTRONICS SCI & TECH INST

Cryptographic secret generation and provisioning

A system includes a memory device and a processor, operatively coupled with the memory device, to perform operations including receiving, from a device via a brokering agent, a request to provide an encrypted version of a set of secrets data corresponding to a target state of the device, determining whether to authorize the request in view of the brokering agent, and in response to authorizing the request, providing the encrypted version of the set of secrets data and permission to transition to the target state.
Owner:BLOCKFRAME INC

Generation of cryptographic keys

There is provided mechanisms for generating a cryptographic key for a user. The method is performed by a cryptographic key generator device. The method comprises authenticating the user using biometrics data read from the user using a biometrics reader. The method comprises obtaining, only when having authenticated the user, a PUF response from a PUF entity by providing a challenge based on biometrics response data to the PUF entity. The biometrics response data is a function of the biometrics data. The method comprises generating the cryptographic key using a cryptographic function and by seeding the cryptographic function with the PUF response.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Data security encryption method based on smart campus cloud platform

The present application relates to the technical field of data security encryption, in particular to a data security encryption method based on a smart campus cloud platform, which comprises the following steps: receiving a data processing request carrying an original data file and preset metadata tags thereof; matching a target encryption security level and encryption control parameters based on a tag query security policy library; starting a multi-channel encryption key generation engine to generate a core working key, a data integrity check key and an access session key after verifying that a user identity attribute meets an access condition; using the core working key to block and obfuscate encode the original file to form a timestamped intermediate encrypted data block; using the integrity check key to calculate an overall hash value and generate a to-be-encapsulated ciphertext package; and finally using the access session key to perform secondary encapsulation to form a final ciphertext stream. The present application realizes dynamic adaptation of encryption strength according to data attributes, and completes integrated security processing of encryption, integrity protection and session control through multi-key cooperation.
Owner:CHINA TELECOM CONSTR 4TH ENG

Microcontroller having wireless communication module for use with a system

Systems, apparatuses, and methods that provide for a wireless communication microcontroller for use with a system microcontroller. A first microcontroller is configured to control aspects of a system in which the device can be embedded. A second microcontroller is operatively connected to the first microcontroller, with the second microcontroller including a wireless communication module for wireless communication. A secure element is operatively connected to the second microcontroller, with a cryptographic key being stored in the secure element. The second microcontroller is configured to receive instructions for programming the first microcontroller through the wireless communication module and request a session key from the secure element. The secure element is configured to generate the session key using the cryptographic key. The second microcontroller is further configured validate the instructions using the session key and send the validated instructions to the first microcontroller.
Owner:DENTSPLY SIRONA INC