Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

16 results about "Cryptography protocols" patented technology

A cryptographic protocol is a protocol executed by several distant agents through a network where the messages or part of the messages are produced using cryptographic functions (encryption, hashing, etc.).

Verified physical access of telecommunications network subscribers at third-party events or venues

The verification of individuals entering controlled locations such as events and venues is improved by using wireless devices as the entry tickets themselves, verifiable by a telecommunications network. The wireless device provides a network subscriber's identification information (e.g., a phone number) to an access point terminal, in response to an identification / authentication request from the access point terminal. In order to obtain the identification information to provide to the terminal, the wireless device verifies itself via the telecommunications network, which is capable of verifying the device's subscriber identity module (SIM) via cryptographic protocols. Thus, by verifying the device's SIM, the telecommunications network verifies the identity of the network subscriber operating the device, for purposes of sharing a phone number as an entry ticket. Because entry is controlled according to the device's own network-verifiable identity, third-parties that operate events or venues need not distribute entry tickets (e.g., physical or electronic) to individuals.
Owner:T MOBILE US INC

Public verifiable data service method for instrument control system

PendingCN121923921AUser identity/authority verificationCryptography protocolsCloud storage
The invention belongs to the technical field of information security, relates to zero-knowledge proof and block chain technologies, and particularly provides a public verifiable data service method for an instrument control system, so as to solve the technical problem of huge calculation overhead caused by the fact that commitment consistency check of large-scale data needs to be executed in a circuit in an existing zk-SNARK-based scheme. According to the invention, a hybrid proving system based on a cryptographic protocol Plonk and Groth16 is designed, the promise adaptive to the system is designed, and the consistency check of the promise of the database is transferred from the inside of an arithmetic circuit to the outside of the circuit, so that the huge calculation overhead introduced into a zk-SNARK circuit by the promise consistency check of a large-scale database is avoided; and finally, the verifiable execution of safe calling and operation on the data subset from the third-party cloud storage is realized, the accuracy and integrity of industrial data are ensured, and the problem of trust missing in a cross-domain scene is solved.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

A general two-party oblivious signature method and system

This invention discloses a general two-party unintentional signature method and system, belonging to the field of cryptographic protocol technology. The method includes: participants P1 and P2 jointly generating a signature public key; participants P1 and P2 jointly calculating a signature of the message, wherein the signature is known only to participant P1, and participant P1 uses the signature public key to verify the signature. This invention can both distribute key storage to avoid the risk of key leakage and prevent additional participants from obtaining the final signature content.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI

Light-weight transmission encryption method based on commercial cryptographic algorithm

The invention relates to the technical field of information security, and discloses a lightweight transmission encryption method based on a commercial cryptographic algorithm, which comprises the following steps: two communication parties establish an initial session through a lightweight handshake protocol; collecting a feature vector of the data to be sent and an equipment operation state containing CPU, memory and energy limited parameters; calculating a comprehensive load index according to the acquired parameters, comparing a threshold according to a preset decision function, determining a simplified strength mode when the equipment is in a high-load state and processes non-critical data, and otherwise, determining a standard strength mode; and writing the encryption mode into a message header, and performing block encryption and packaging transmission on the data load by using the session key. According to the method, through a parallel key exchange process, compact key storage and a self-adaptive encryption decision mechanism, the problems of large calculation overhead, high handshake delay and large storage occupation of a commercial cryptographic protocol in a resource-constrained environment are effectively solved, and the equipment energy consumption and the communication delay are reduced while the security of key data is guaranteed.
Owner:CSG EHV POWER TRANSMISSION

Verified physical access of telecommunications network subscribers at third-party events or venues

The verification of individuals entering controlled locations such as events and venues is improved by using wireless devices as the entry tickets themselves, verifiable by a telecommunications network. The wireless device provides a network subscriber's identification information (e.g., a phone number) to an access point terminal, in response to an identification / authentication request from the access point terminal. In order to obtain the identification information to provide to the terminal, the wireless device verifies itself via the telecommunications network, which is capable of verifying the device's subscriber identity module (SIM) via cryptographic protocols. Thus, by verifying the device's SIM, the telecommunications network verifies the identity of the network subscriber operating the device, for purposes of sharing a phone number as an entry ticket. Because entry is controlled according to the device's own network-verifiable identity, third-parties that operate events or venues need not distribute entry tickets (e.g., physical or electronic) to individuals.
Owner:T MOBILE US INC

Key migration method, cryptographic module and live migration method thereof, and related equipment

The embodiment of the invention provides a key migration method, a cryptographic module and a live migration method thereof, and related equipment, the key migration method is applied to a target cryptographic module coupled to a key mirror image import interface, and the key mirror image import interface is an interface which is preset by a target physical host and is only used for transmitting a key mirror image ciphertext. Comprising the following steps: sending a public key certificate and first cryptographic protocol information when a cryptographic module is thermally migrated; receiving a key mirror image ciphertext and second cryptographic protocol information based on the key mirror image import interface, the second cryptographic protocol information being generated by the source cryptographic module; and generating a decryption key for decrypting the key mirror image ciphertext according to the second cryptographic protocol information to obtain a key mirror image, and after the integrity of the key mirror image is verified, outputting an import result, thereby realizing the thermal migration of the cryptographic module.
Owner:HYGON YUNXIN INTEGRATED CIRCUIT DESIGN (SHANGHAI) CO LTD

Unmanned aerial vehicle authentication and key negotiation system and method based on PUF and chaotic mapping

The invention discloses an unmanned aerial vehicle authentication and key negotiation system and method based on PUF and chaotic mapping, and relates to the field of information security and cryptographic protocol security. The system generates a unique challenge-response pair through an unmanned aerial vehicle terminal PUF module to complete registration, a four-way handshake mechanism is adopted in the authentication stage, a session key is dynamically generated in combination with Henon chaotic mapping, the number of chaotic iterations is hidden through XOR operation, and identity legality is guaranteed through multi-layer MAC verification. According to the method, secret keys do not need to be pre-stored, the PUF physical unclonability and the chaotic mapping sensitivity are utilized, anonymous authentication and forward security are achieved, lightweight computing adapts to unmanned aerial vehicle resource constraints, various attacks are effectively resisted, and communication security is guaranteed.
Owner:JINLING INST OF TECH

Updating vehicle electronic control unit software

Aspects of the present invention relate to a control system (100) for use in updating software in a plurality of electronic control units, ECUs (112, 114, 116), of a vehicle (200). The control system receives software data (104) comprising software update information (134) associated with one or more of the ECUs (112, 114, 116), verifies the software update information (134) using a cryptographic protocol, and, responsive to successful verification of the software update information (134) according to the cryptographic protocol, outputs a software update (106, 108, 110) for each of the one or more ECUs (112, 114, 116), each software update (106, 108, 10 110) being based on the software update information (134) for the associated ECU (112, 114, 116).
Owner:JAGUAR LAND ROVER LTD

Secure Communications Among Multiple Entities Using Quantum Entanglement

Systems and techniques may generally be adapted for establishing secure communications with use of quantum entanglement, including via the use of mesh networks and multiple satellite communication locations. An example technique may include generating a stream of quantum entangled particles, and transmitting at least part of the stream of the quantum entangled particles to at least a first node, a second node, and an intermediate node connected via a satellite communication network. In this context, the intermediate node is located between the first node and the second node, and a secure trusted mesh of entities can be established among the first, second, and intermediate nodes. The stream of the quantum entangled particles can used to derive a quantum entangled value, such as for use with a cryptographic protocol of secure communications between the first node and the second node via the satellite communication network.
Owner:WELLS FARGO BANK NA

An information data operation processing system based on a secure isolation gateway

The application discloses an information data operation processing system based on a security isolation gateway, and relates to the technical field of data communication.The system comprises a security isolation gateway, a global side subsystem and N participant side subsystems, wherein N is a positive integer; the security isolation gateway is connected between the global side subsystem and each participant side subsystem and is configured to establish a controlled one-way data transfer channel between the two; the global side subsystem comprises a global coordination module, a trusted verification module and a security aggregation module; and each participant side subsystem comprises a trusted execution module.The application solves the technical problem that the privacy protection of the existing information data processing process depends on a complex cryptography protocol, is inefficient and is difficult to exclude malicious or low-quality updates, and affects the security and efficiency of cross-domain information processing, and achieves the technical effects of simplifying privacy protection, efficiently excluding malicious updates and improving the security and efficiency of cross-domain information processing by using the security isolation gateway.
Owner:TIANJIN XINSHITONG TECHNOLOGY CO LTD

Handling of sensitive data in a network having multiple security zones

A computer-implemented method is disclosed for handling sensitive data in a network comprising multiple security zones. The method includes sharing a data cleansing ruleset among a plurality of servers that are each within a respective security zone and using a multi-party cryptographic protocol that each of the plurality of servers participates in, to obtain a shared secret. Each server individually cleanses a respective dataset containing sensitive data using the data cleansing ruleset and then hashes the resulting cleansed dataset with a hash function using the shared secret as a salt. This produces a resultant dataset containing hashed representations of the original sensitive data, meaning that the dataset produced by each server can be collated to form a composite dataset without breaching data security requirements. A data operation can then be performed on the composite dataset.
Owner:MASTERCARD INT INC

Information data operation processing system based on security isolation gatekeeper

The invention discloses an information data operation processing system based on a security isolation gatekeeper, and relates to the technical field of data communication, the system comprises the security isolation gatekeeper, a global side subsystem and N participant side subsystems, and N is a positive integer; the security isolation gatekeeper is connected between the global side subsystem and each participant side subsystem, and is configured to establish a controlled one-way data ferry channel between the global side subsystem and each participant side subsystem; the global side subsystem comprises a global coordination module, a credible verification module and a security aggregation module, and each participant side subsystem comprises a credible execution module. The technical problems that privacy protection in an existing information data processing process depends on a complex cryptographic protocol, efficiency is low, malicious or low-quality updating is difficult to eliminate, and the safety and efficiency of cross-domain information processing are affected are solved, and the purposes that privacy protection is simplified through a safety isolation gatekeeper, malicious updating is efficiently eliminated, and the safety and efficiency of cross-domain information processing are improved are achieved. And the safety and efficiency of cross-domain information processing are improved.
Owner:TIANJIN XINSHITONG TECHNOLOGY CO LTD

Systems and methods for the automated integration of cryptographic protocols

The present technology relates to techniques for integrating centralized custodial services and DeFi services. In one aspect of the technology, a platform stores a cryptographic key associated with a user of the platform. The user instructs the platform of a first digital asset to transfer from a centralized custodial service to a DeFi service in exchange for a second digital asset. Based on these instructions, the platform causes the centralized custodial service to transmit the first digital asset to a self-executing computer program of the platform. The platform then transmits the cryptographic key, as well as the instructions, to the self-executing computer program. Upon receipt of the cryptographic key, the instructions, and the first digital asset, the self-executing computer program executes, transmitting the first digital asset to the DeFi service and causing the DeFi service to transmit the second digital asset to the centralized custodial service.
Owner:ROCKO INC

Privacy protection identity registration and authentication method and system compatible with standard sim card

This invention discloses a privacy-preserving identity registration and authentication method and system compatible with standard SIM cards, belonging to the field of cryptographic protocol technology. The system includes three participants: a user terminal, an operator, and an application. It is based on the SIM card issued by the mobile operator and owned by all mobile phone users. The user and the operator collaborate to complete the application's authentication of the user's identity. This invention features high security and efficiency; even if an adversary compromises the operator, they cannot obtain the user's login behavior. It also protects user authentication from man-in-the-middle attacks, is compatible with existing SIM cards, requires no replacement of existing hardware, and is easy to deploy. This invention further enhances privacy protection, ensuring that user access behavior is not tracked, has excellent interoperability, and is suitable for large-scale 5G application deployment.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI

Unknown network secret sharing and broadcasting method and system with low communication overhead

The invention discloses an unknown network secret sharing and broadcasting method and system with low communication overhead, and aims to solve the problem of high communication overhead of broadcasting and secret sharing under an unknown network model based on various distributed computing technologies and cryptographic protocols, such as threshold signature, polynomial commitment, erasure code and the like. A broadcast protocol and a secret sharing protocol with linear communication complexity are respectively designed, the protocol efficiency is remarkably improved, communication overhead close to the linear communication complexity is realized, and the method has wide application scenes in the fields of distributed consensus, secure multi-party computing and the like. An erasure code technology in traditional asynchronous consensus, a threshold signature technology in synchronous consensus and a polynomial commitment and Packed technology in asynchronous secret sharing are combined, and a commitment consistency verification protocol is designed, so that the overall communication overhead is optimized, and an important breakthrough is brought to the field of secure multi-party computing.
Owner:WUHAN UNIV