Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

312 results about "Encryption decryption" patented technology

Definition of Decryption. Decryption inverts the encryption process in order to convert the message back to its real form. The receiver uses a decryption algorithm and a key to transform the ciphertext back to original plaintext, it is also known as deciphering.

Techniques for efficient encryption and decryption during file system cross-region replication

Techniques are described for a hierarchical caching mechanism enabling efficient cross-region replications. In some embodiments, replication-related information (e.g., key-value pairs) is stored in a particular layout in a binary tree (B-tree) of a file system for replication processing. A hierarchy of caches storing a first type of information (e.g., crypto keys associated with iNodes) may be arranged to match the particular layout in the B-tree to enable efficient parallel processing of a second type of information (e.g., files, file data, or symbolic links), where the replication-related information in the B-tree is partitioned into multiple key ranges for parallel processing. In some embodiments, the caches in different hierarchies may be shared by different parallel-processing key ranges and replication jobs in a file system.
Owner:ORACLE INT CORP

Method, device, and system for physical channel encryption in wireless networks

This disclosure above describes a method, a device, and a system for encrypting / decrypting physical channels in a wireless communication network. Among various embodiments are: pre-allocating a key, dynamically granting a key, encrypting the physical channel based on key in various levels, dividing the spectrum into two categories, or dividing a network into an initial access network and a private network. In one embodiment, a method for physical channel encryption is disclosed. Performed by a UE, the method may include obtaining a first key for decrypting a first physical channel, the first physical channel being encrypted; and decrypting the first physical channel based on the first key to obtain a signal or data transmitted by a first network element, the signal or the data being carried in the first physical channel.
Owner:ZTE CORP

SM2 collaborative signature, encryption and decryption system and method fusing anti-quantum characteristics

The invention discloses an SM2 collaborative signature and encryption and decryption system and method fusing anti-quantum characteristics, and relates to the field of cryptography and information security. According to the method, an anti-quantum cryptographic algorithm and a national cryptographic SM2 cooperative computing framework are deeply integrated, and a key security system is constructed: SM2 sub-private keys, anti-quantum key pairs and public keys are acquired and generated through an anti-quantum algorithm software and hardware enhancement module, and the private keys are encrypted and stored and are regularly alternated; on the basis of anti-quantum collaborative signature, encryption and decryption modules, an anti-quantum verification mechanism is embedded, and data is transmitted in combination with a national secret TLCP protocol, so that signature, encryption and decryption operations are completed; the equipment integration and dynamic security control unit monitors a security state, calculates a threat index to generate a protection strategy, and dynamically switches a security mode, so that the problems of insufficient security, vulnerability to attacks and data tampering of a traditional SM2 algorithm under the threat of quantum computing are effectively solved; and the long-term anti-attack capability and the operation reliability of the equipment in a high-security demand scene are remarkably improved.
Owner:ZHEJIANG ICINFO TECH

Encryption-decryption scheme for detecting linear spoofing attack in cyber-physical system

The invention discloses a novel encryption-decryption scheme, and aims to detect and defend linear spoofing attacks on a cyber-physical system (CPS). With the wide application of CPS in key infrastructures such as industrial automation, smart power grids and automobile systems, it is particularly important to ensure the safety and integrity of CPS. Linear spoofing attacks are malicious behaviors, normal operation of the linear spoofing attacks is interfered by controlling input or output of a system, and a traditional security mechanism is often difficult to effectively cope with the type of attacks. According to the invention, an encryption algorithm is designed to protect data transmission of the CPS, and the encryption algorithm is combined to recover original data and identify potential attack signs at the same time. According to the scheme, the combination of the cryptography technology and the signal processing method is utilized, the data stream can be monitored in real time, and the possible linear attack is identified by analyzing the change of the data before and after encryption. In addition, according to the scheme, calculation efficiency and implementation feasibility are considered, and it is ensured that necessary safety guarantee is provided on the premise that system performance is not affected. Experimental results show that the proposed encryption-decryption scheme can effectively detect linear spoofing attacks in the cyber-physical system, and has relatively low false alarm rate and missing report rate. In addition, the scheme shows good adaptability and robustness in practical application, and provides a new thought and technical support for the security protection of the CPS in the future.
Owner:QINGDAO UNIV

Methods, systems and computer program products for secure encryption of data for transmission via an untrusted intermediary

The invention is directed toward systems, methods and computer program products that enable end to end user authentication along with encryption to mitigate the risks posed by untrusted or unsecure intermediary entities. The invention (i) enables full end to end encryption of sensitive data that has been input by a user on a terminal device at one end, and the intended or authorized recipient at the other end, (ii) ensures that data entered by the user on the terminal device is not readable by any intermediary entity including a partner application or other software application implemented within the terminal device, and (iii) eliminates the risk of successful local attacks on the terminal device to unauthorizedly access user data, or to unauthorizedly obtain access to encryption / decryption keys that can be used to unauthorizedly access encrypted user data.
Owner:EPIFI TECH PTE LTD

Method for realizing java source code file security encryption based on C + + dynamic library

The invention provides a method for realizing secure encryption of a java source code file based on a C + + dynamic library, which relates to the technical field of secure encryption, and comprises the following steps of: partitioning the java source code file, and processing by adopting a dual encryption mechanism through an encryption module in the C + + dynamic library: firstly, generating a dynamic key and a static key XOR to obtain a mixed key, performing AES encryption by utilizing the mixed key, and then, performing encryption by utilizing the mixed key; carrying out secondary encryption by adopting an elliptic curve cryptographic algorithm; the environment is monitored in real time during decryption, and debugging protection is prevented; and if the environment is normal, executing reverse decryption to recover the source code. According to the method, the source code protection intensity is improved, and reverse engineering and debugging attacks are effectively prevented.
Owner:ZHEJIANG SHUXIN NETWORK CO LTD

Security coprocessor hybrid encryption method and system based on SM2 / 3 / 4 domestic cryptographic algorithm

According to the safety coprocessor hybrid encryption method based on the SM2 / 3 / 4 domestic cryptographic algorithm, a novel hybrid encryption system based on the SM2 / 3 / 4 and considering encryption safety, efficiency and key management convenience is constructed on the basis of the characteristics of the SM2 algorithm, the SM3 algorithm and the SM4 algorithm, and the encryption / decryption and signature / verification process is achieved. And aiming at the efficiency problem of a domestic SM algorithm, an encryption / decryption and signature / verification scheme is designed and realized through pure software analysis and software and hardware (SW / HW) collaboration, so that optimal division of software and hardware is realized, and the algorithm efficiency is greatly improved.
Owner:ANHUI NORMAL UNIV

Encryption communication method and system used between EtherCAT slave station nodes

The invention is suitable for the field of communication technology improvement, and provides an encryption communication method and system used between EtherCAT slave station nodes, an OTP / nonvolatile storage, an encryption scrambling unit and a decryption descrambling unit are integrated in an EtherCAT slave station chip of a coupler and an I / O module, and encryption / decryption of an EtherCAT message is achieved on the hardware level; xOR operation or an AES algorithm is adopted for encryption, and a secret key is stored in an unmodifiable storage unit; and meanwhile, a parallel architecture of an encrypted network and a standard network is constructed, so that the standard interaction between the slave station node and the master station is not influenced by encrypted communication. The system solves the contradiction of poor real-time performance of a private protocol and easy plaintext communication plagiarism in the prior art, realizes the effects of no real-time performance loss, strong communication exclusiveness and flexible compatibility, and is suitable for an EtherCAT high-speed backplane bus system under industrial 4.0.
Owner:ANXIN MICRO SEMICON TECH (SHENZHEN) CO LTD

Shared encryption and decryption method and device

The present invention discloses a shared encryption and decryption method and device, and relates to the field of network security technology, wherein the shared encryption method comprises: receiving a data encryption request sent by a first system; obtaining a first ZMK ciphertext and a ZPK ciphertext from the first system, encrypting the first ZMK ciphertext with the LMK of a shared encryption machine cluster, and then encrypting it with the first SPK of a first encryption machine associated with the first system; decrypting the first ZMK ciphertext with the first SPK to obtain a second ZMK ciphertext; sending the ZPK ciphertext, the second ZMK ciphertext and data to be encrypted to the shared encryption machine cluster, the shared encryption machine cluster encrypts the data to be encrypted, and obtains an encrypted data ciphertext; receiving the encrypted data ciphertext provided by the shared encryption machine cluster; and sending the encrypted data ciphertext to a second key server associated with the second system. The present invention can ensure the security between various systems when shared encryption is implemented.
Owner:BANK OF CHINA

Multi-image encryption algorithm based on hyperchaotic system and computer-generated holography

The invention relates to the technical field of chaotic cryptography, image encryption and information security, in particular to a multi-image encryption algorithm based on a hyper-chaotic system and computer-generated holography, which comprises the following steps: S1, generating a pseudo-random sequence for encryption by using the hyper-chaotic system; s2, preprocessing the original image based on computer-generated holography; s3, combining the generated pseudo-random sequence with the preprocessed image to realize image encryption; s4, through decryption operation corresponding to the encryption process, the original image is restored after the correct secret key is input; and S5, the decryption operation comprises inverse transformation and reconstruction operation on the encrypted image. The algorithm comprises an image preprocessing module, a hyperchaotic system module, a compressed sensing coding module, a computer-generated holographic encryption module, a decryption module and a post-processing module, the security of sensitive image data in the transmission and storage process can be ensured, and efficient and reliable guarantee is provided for sensitive image encryption in various fields.
Owner:KUNMING UNIV OF SCI & TECH

Data encryption and decryption method and related equipment

The invention discloses a data encryption method, a data decryption method and related equipment, and relates to the technical field of artificial intelligence. In the encryption method of the scheme, after to-be-encrypted original plaintext data is determined, encryption environment perception data is firstly obtained; the original plaintext data and the encryption environment perception data are input into an encryption strategy generation model by calling an encryption agent, and the encryption strategy generation model outputs an encryption algorithm selection result, key information and a key distribution path matched with the current original plaintext data and the encryption environment; and finally, encrypting the original plaintext data by using the encryption strategy to obtain ciphertext data. Based on the scheme, the dynamic determination of the encryption algorithm, the key information and the key distribution path can be realized, and by combining with the corresponding decryption scheme, the scheme can adapt to the data encryption and decryption requirements under different scenes and different situations.
Owner:IFLYTEK CO LTD

Unmanned aerial vehicle identity authentication and key negotiation system and method

The invention discloses an unmanned aerial vehicle identity authentication and key negotiation system and method. The system comprises a trusted registration mechanism, an unmanned aerial vehicle, a cloud server and a mobile terminal, in a system initialization stage, a trusted registration mechanism publicly releases a single hash function and a symmetric encryption / decryption algorithm; in a mobile terminal registration stage, a trusted registration mechanism verifies a registration request of a user; in the unmanned aerial vehicle registration stage, the unmanned aerial vehicle sends its identity ID to the trusted registration mechanism to request registration, and the trusted registration mechanism distributes a unique challenge and random number to the unmanned aerial vehicle after receiving the identity ID; in the user login stage, a user ID, a password and biological characteristics are input into the mobile terminal, and the mobile terminal verifies the user identity through pre-stored parameters; in the identity authentication and key negotiation stage, mutual authentication is carried out among the mobile terminal, the cloud server and the unmanned aerial vehicle, and a session key for future encrypted communication is negotiated.
Owner:JIANGSU SECOND NORMAL UNIVERSITY

System and method for providing multiple key encryption

Systems and methods for providing multiple key encryption may generate a private key encryption key (KEK) and a corresponding public KEK in a trusted execution environment (TEE); provide the public KEK to a key generator; generate, by the key generator, a data encryption key (DEK) and encrypt the DEK with the public KEK; obtain, by a key processor, an ephemeral public key and the encrypted DEK, and send the ephemeral public key and the encrypted DEK to the TEE; decrypt, by the TEE, the encrypted DEK using the private KEK, and re-encrypt the decrypted DEK with the ephemeral public key; obtain, by the key processor, the re-encrypted DEK from the TEE and pass the re-encrypted DEK to a signing service; decrypt, by the signing service, the re-encrypted DEK using a corresponding ephemeral private key; and encrypt, by the signing service, data using the DEK.
Owner:THE BANK OF NEW YORK MELLON

Timestamp-based association of identifiers

Systems and methods for associating sessions of encrypted identifiers are provided. A collection of data packets received during one or more sessions within a time period may be retrieved. Each packet in the collection may be associated with a unique identifier of a respective session. An epoch time may be calculated for each of the retrieved data packets based on the determined skew and respective timestamp information of the data packet. It may be identified as to whether each of the calculated epoch times matches a previously calculated epoch time for a packet associated with a previous session or a session that has previously been associated with a selected session. The timestamp information may be associated with a browser identifier and subject to encryption / decryption by an identifier server or authorized parties.
Owner:PARRABLE

Image encryption and decryption system, method and device and medium

The invention relates to the technical field of image encryption, and discloses an image encryption and decryption system, method and device and a medium. The system comprises a secret key module used for transmitting initial information to an algorithm module; the initial information comprises key information and an initial vector; the initial vector represents an auxiliary parameter in encryption; the algorithm module is used for detecting the to-be-processed image data and converting the initial information into a target key stream with a corresponding length based on the data length of the to-be-processed image data; and the data processing module is used for encrypting / decrypting the to-be-processed image data according to the target key stream to obtain an encrypted / decrypted image. According to the invention, the security of image data transmission can be improved.
Owner:SHANDONG YUNHAI GUOCHUANG CLOUD COMPUTING EQUIP IND INNOVATION CENT CO LTD

Hardware security module and controller

The present invention provides an HSM and a controller. The HSM includes an HSM bus matrix and, connected to the HSM bus matrix, a plurality of HSM master modules, an HSM external bus port, an HSM SRAM and a plurality of HSM slave modules. The HSM master modules include an HSM CPU core and an HSM DMA. The HSM slave modules include at least one encryption / decryption engine module. The HSM of the present invention complies with the Evita standard, and through storing sensitive information in the HSM SRAM or the like, provides secure execution and storage. Not only data isolation between the HSM and an external host, and hence protection of sensitive information, can be provided, the use of the HSM DMA allows the HSM CPU core to be offloaded from heavy data movement, thereby enhancing operating efficiency of the HSM CPU core.
Owner:GIGADEVICE SEMICON (BEIJING) INC

Encryption and decryption system and method for user privacy data

The invention relates to the technical field of user privacy data encryption and decryption, and discloses a user privacy data encryption and decryption system which comprises a user privacy data encryption and decryption system body. The user privacy data encryption and decryption system body comprises a data sovereignty layer, a strategy engine, a key management layer, a dynamic encryption layer, an intelligent decryption layer and a security audit and traceability layer. According to the user privacy data encryption and decryption system and method, user data privacy is guaranteed through cooperation of all the layers and the whole process from data authority management to encryption and decryption, data is prevented from being accessed and used without authorization, all the layers are clear in division of labor, the data sovereignty layer determines data attribution and access authority, the strategy engine formulates an access strategy, and the user privacy data encryption and decryption efficiency is improved. The key management layer is responsible for key full-life-cycle management, the dynamic encryption layer implements encryption operation, the intelligent decryption layer processes decryption requests, and the architecture enables each function module of the system to perform own functions and is convenient to develop, maintain and manage.
Owner:WUXI YIZHI INFORMATION TECHNOLOGY CO LTD

5G session message encryption and decryption method, sending end, receiving end and transmission system

The embodiment of the invention discloses a 5G session message encryption method, a 5G session message decryption method, a sending end, a receiving end and a transmission system, which are used for improving the security of a 5G session message. The scheme comprises the following steps: acquiring a to-be-sent 5G session message, a receiving end public key of the 5G session message and a session key of the 5G session message; performing encryption on the 5G session message by using the session key; encrypting the session key by using the receiving end public key; generating a message digest of the 5G session message, and encrypting the message digest by using a sending end private key to obtain a digital signature; and packaging the encrypted 5G session message, the encrypted session key and the digital signature into an encrypted message, wherein the encrypted message is sent to a receiving end of the 5G session message through a 5G session message platform.
Owner:CHINA MOBILE COMM GRP TERMINAL +1

Encryption and decryption strategy driven memristor neural network multi-index state estimation method for security assurance

The invention discloses a security guarantee-oriented encryption and decryption strategy-driven memristor neural network multi-index state estimation method. The method comprises the following steps of: 1, establishing a memristor neural network dynamic model with H infinity performance constraint and hybrid attack; 2, performing state estimation on the memristor neural network dynamic model under the driving of an encryption and decryption strategy; 3, calculating an error covariance matrix upper bound and an H infinity performance constraint condition of the memristor neural network; and 4, solving a value of an estimator gain matrix, and realizing memristor neural network state estimation with hybrid network attacks. The method solves the problem that the existing state estimation method cannot process the multi-index state estimation of the memristive neural network with H infinity performance constraint and variance constraint under the driving of encryption and decryption strategies at the same time, so that the estimation accuracy is low, and under the condition that information exists under the encryption and decryption strategies and information at other moments cannot be received, the estimation accuracy is low. And the accuracy of the estimation performance is low.
Owner:HARBIN UNIV OF SCI & TECH

Dynamic key-based underground UWB positioning system hybrid encryption method

The invention relates to an underground UWB positioning system hybrid encryption method based on a dynamic key, and belongs to the technical field of UWB positioning, and the method comprises the following steps: a positioning terminal randomly generates an RSA key pair before network access, and sends an RSA public key to a positioning base station through broadcasting a network access application frame; after receiving the RSA public key, the base station randomly generates an AES secret key exclusive to the terminal, performs RSA encryption on the AES secret key by using the RSA public key provided by the terminal to form an encrypted AES secret key, and then embeds the encrypted AES secret key into a network access response frame and returns the network access response frame to the terminal; the terminal decrypts the encrypted field in the network access response frame by using a self RSA private key to obtain an original AES key; bidirectional time-of-flight ranging TW-TOF is carried out, and all data are subjected to end-to-end protection through an AES encryption and decryption mechanism.
Owner:CHINA COAL TECH & ENG GRP CHONGQING RES INST CO LTD

Security and protection monitoring system information signature encryption device based on national cryptographic algorithm

The invention discloses a security and protection monitoring system information signature encryption device based on a national cryptographic algorithm, and the device comprises an IPC end module which collects video stream data in real time; the video stream signature module based on the national cryptographic algorithm is used for signing the input video stream data and storing the signed video stream data into a user-defined SEI of the video stream data; the video encryption and decryption module based on the national cryptographic algorithm is used for carrying out encryption processing on an I frame and filling data in the video stream data, storing the encrypted I frame in an original region of the I frame, storing the encrypted filling data in a user-defined SEI, and inserting the user-defined SEI in front of the I frame; and the NVR end module is used for storing the signed and encrypted video stream data. Before the video stream is transmitted, a series of onvif control signaling interaction is carried out, the integrity and confidentiality of the signaling are controlled, and the integrity and confidentiality of video data transmission are protected.
Owner:TOEC ANCHEN INFORMATION TECH

Data encryption device, memory encryption and decryption system and chip

The invention relates to the technical field of data encryption, and discloses a data encryption device, a memory encryption and decryption system and a chip. A password root output end; the key generation circuit is used for generating an n-bit first key and an n-bit second key; the data encryption logic circuit comprises a four-round encryption module, a four-round encryption unit in the four-round encryption module comprises an n-bit interleaver, four columns of 64-bit round function components correspondingly arranged on the two sides of the interleaver and two sub-circuits for encrypting residual data and residual keys, and the four-round encryption unit is connected with an address input end, a password root output end and a key generation circuit. And the four-round encryption module is used for performing alignment processing on the memory access address, performing interleaving encryption processing based on the four-round encryption module according to the n-bit alignment address obtained by the alignment processing, the first key and the second key, and generating an n-bit password root, so that the encryption device encrypts the write data according to the password root, and the decryption device decrypts the read data according to the password root.
Owner:SUZHOU SASAMAI SEMICON CO LTD +2

Binary Encryption / Decryption Method for Secure Audio / Video Broadcast and Communication and for Data Transmission / Storage

PendingUS20250181731A1Digital data protectionSelective content distributionEngineeringCommutative encryption
An encryption / decryption method is disclosed, where an input data string is described in term of a reference set of unique processing strings of number of bits between minimum and maximum, with these being organized in classes of members of same number of bits, where one or more classes are modified by permutating their members such obtaining a modified set, where directional correspondence reference-to-modified of a member is the encryption / decryption of that member, described in an encryption / decryption key with such keys being stored to be specific to every encryption / decryption enabled device, where such enabled devices exchange encrypted data using such key that is dedicated to a pair of devices only, without sharing such key on the communication channel, and where a central switchboard connects such communicating devices to enable exchanging encrypted data, concealing the communicating devices.
Owner:SECAREANU RADU MIRCEA

Block cipher implementation method, device and equipment based on lightweight algorithm structure

The invention provides a block cipher implementation method, device and equipment based on a lightweight algorithm structure. The method comprises the steps that cache equipment or a data interface obtains a plaintext needing cipher implementation; loading plaintexts by the register or the cache, and grouping the plaintexts into four branches for parallel processing by using the SIMD register; generating a round key by designing a key scheduling algorithm, and storing the round key in a special register; designing a lightweight algorithm structure for performing password implementation on the four branches stored in the SIMD register; and performing I-round encryption / decryption iteration on four branches of initial input of the plaintext / ciphertext by using a lightweight algorithm structure to generate the ciphertext / plaintext. According to the method disclosed by the invention, the cryptographic algorithm based on the lightweight algorithm structure is designed to encrypt and decrypt the data transmitted by the network or the communication, so that the software and hardware implementation cost in the application process is reduced while the requirement of easily implementing the lightweight password application is met, and the security is good.
Owner:KAIYUAN INTERNATIONAL MATHEMATICS RESEARCH INSTITUTE

Systems, and methods for secure remote multi-user LAN access

The disclosure relates to systems, methods and computer readable media for enabling distributed secure remote access from a device via a wide area network (WAN), to a designated physical site covered by local area network (LAN). Specifically, the disclosure relates to a computerized systems, methods and computer-readable media using hardware-based, virtual private network pairs having preshared encryption / decryption keys, operable to transmit data over WAN from a physical computing device to an exclusively designated site in a physical area covered by a LAN.
Owner:MOBULUSNET LTD

Memory encryption and decryption module and method, chip, program product and readable storage medium

The invention provides a memory encryption and decryption module and method, a chip, a program product and a readable storage medium. The memory encryption and decryption module comprises a memory array; a ciphertext array; the row control unit is used for gate and read-write control of rows; the first column of control units are used for gating the corresponding bit lines and shifting the bit lines when secret key data are generated; the second column control unit is used for controlling column gating and read-write of the ciphertext array; the storage control unit and the encryption and decryption control unit are used for providing row and column control signals; and a data input / output unit. The key is generated through the storage unit array and the peripheral amplifier circuit, encryption and decryption are carried out through XOR calculation in the key calculation process, localized encryption and decryption are achieved in the storage unit array, and the problems that in the prior art, an encryption and decryption module is large in area, high in energy consumption, large in delay and the like are effectively solved; and the efficiency and the flexibility of localized encryption, decryption and storage of the memory data of the existing edge end equipment are effectively improved.
Owner:VERISILICON MICROELECTRONICS (SHANGHAI) CO LTD

Secure communication method suitable for confidential virtual machine and PCIe device, computing device and medium

The invention relates to the technical field of confidential computing, in particular to a secure communication method suitable for a confidential virtual machine and PCIe equipment, computing equipment and a medium. The method is applied to a computing device, the computing device comprises a confidential virtual machine, a PCIe device and a control bridge, the control bridge achieves a security fence for the PCIe device, the PCIe device communicates with the confidential virtual machine through the control bridge, and the method comprises the steps that the control bridge obtains target data between the PCIe device and the confidential virtual machine; and the control bridge encrypts / decrypts the target data, so that the target data is transmitted between the PCIe equipment and the confidential virtual machine in a ciphertext form. According to the method and the device, the control bridge used for realizing the security fence of the PCIe equipment is arranged, and the encrypted transmission is carried out through the control bridge and the confidential virtual machine, so that the PCIe equipment can be combined with the confidential virtual machine for use, and the secure and trusted computing capability is realized through the encrypted transmission between the control bridge and the confidential virtual machine.
Owner:SHENZHEN CONFIDENTIAL COMPUTING TECH CO LTD

Spatial domain self-decoding of encrypted communication

Various embodiments of the present disclosure provide for a method and apparatuses that perform spatial encoding in a multipath environment such that transmissions on different beams are separately encrypted with complex codes such that when the transmissions on the different beams are received at the receiver, the separate encryptions are cancelled out. The transmissions can also have time delay, gain, and phase modifications made to the transmissions such that the automatic self-decryption is performed within a predefined distance of where the receiver is determined to be. In this way, encryption / decryption keys do not have to be sent to the receiver, and unauthorized devices that intercept the beams at a location other than the receiver location will not be able to decrypt the communication.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Data efficient circulation system based on data capsule and trusted controlled execution environment

The invention belongs to the technical field of data security, and particularly relates to an efficient data circulation system based on a data capsule and a trusted controlled execution environment. The invention aims to cooperatively construct an efficient data element safe circulation architecture based on software and hardware technologies such as attribute-based encryption, a distributed account book and a credible controlled execution environment depending on a data capsule, and innovatively realize management and control of a full life cycle of data; the data capsule is used as a core component, ciphertext packaging and strategy packaging modes are adopted, and a strategy covers five dimensions of an access main body, access time, a use position, access content and a use mode; the production component completes data encryption and capsule generation in a trusted controlled execution environment, and the consumption component can access data only when conditions are met through double-layer attribute encryption and decryption, identity verification and strategy check; besides, the system architecture has wide universality and is suitable for various data circulation scenes, and a safe and efficient circulation mode of data elements is provided.
Owner:NANKAI UNIV

Thermal migration for confidential computing environments

The invention relates to thermal migration for confidential computing environments. The system and method are directed to migration operations associated with a confidential computing environment, such as thermal migration operations. In response to a request to migrate data, the security hypervisor may establish a secure communication channel to the network interface controller to communicate one or more keys for accessing the securely stored data. The security hypervisor may generate a descriptor associated with the memory location of the data and then communicate the descriptor to the network interface controller. Thus, encryption / decryption operations may be offloaded to the network interface controller, which may use the descriptor and the key to migrate data from the source location to the destination location.
Owner:MELLANOX TECHNOLOGIES LTD(IL)