Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

91 results about "End-to-end encryption" patented technology

End-to-end encryption (E2EE) is a system of communication where only the communicating users can read the messages. In principle, it prevents potential eavesdroppers – including telecom providers, Internet providers, and even the provider of the communication service – from being able to access the cryptographic keys needed to decrypt the conversation.

QR-Code-Based Authentication for Closed Mesh Networks

A method for secure onboarding to a closed mesh network in which a camera-equipped device scans a QR code embedded in a durable physical carrier (e.g., adhesive bandages, photographs, ID cards) to extract an access credential, configuration profile, or secure URL that automatically configures the device for network access, authenticates the device to the mesh without manual credential entry or transmission of plaintext credentials over insecure channels, and establishes end-to-end encrypted communications between network nodes; the method supports cryptographically random, single-use or time-limited credentials with periodic refresh to prevent replay, encoding of VPN / WireGuard or proprietary configuration profiles, substantially real-time onboarding (e.g., under five seconds), optional multi-factor verification (biometric or PIN), immediate initiation of secure messaging, voice / video or data sessions upon onboarding, audit logging for compliance and revocation based on detected unauthorized activity, and covert or overt embedding of QR codes in environment-resistant carriers for emergency, disaster response, first responder, or covert deployment, with the QR code rendered unreadable or deactivated after successful onboarding to prevent credential reuse.
Owner:DURYA SARA +2

Hardware-level identity authentication and end-to-end encryption near-field data interaction method and system for electric red-in secure connection terminal

The invention relates to the technical field of near-field communication security, in particular to a hardware-level identity authentication and end-to-end encryption near-field data interaction method and system for an electric red-connected terminal, and the method comprises the steps: a first electric red-connected terminal and a second electric red-connected terminal initiate pairing based on a Bluetooth secure connection pairing protocol, and negotiate to generate a long-term key through an ECDH algorithm; performing bidirectional identity verification by adopting an application layer authentication protocol; activating AES-CCM encryption by using a session key derived from a long-term key; bluetooth signal strength and a connection state are monitored in real time, and a negotiation key is automatically paired again when abnormity occurs; generating an interaction log, digitally signing the log by using a locally stored private key, and securely storing the signed log in a local secure storage area of the terminal; the digital signature of the latest log is verified, and if interaction abnormity is found, the local security module of the terminal recovers the local data to the pre-interaction state according to the last credible log record. The problem that traditional Bluetooth communication is prone to eavesdropping and tampering can be solved.
Owner:ELECTRIC POWER RES INST OF GUANGXI POWER GRID CO LTD

Agricultural heterogeneous sensing and intelligent network scheduling method and system

The invention relates to the technical field of network scheduling, and discloses an agricultural heterogeneous perception and intelligent network scheduling method and system, and the method comprises the following steps: S01, a system initialization stage; step S02, a resource scheduling and strategy learning stage; step S03, a sensing data fusion and processing stage; s04, a security mechanism and life cycle management stage: adopting an end-to-end encryption and identity authentication mechanism in a data transmission process, and collecting feedback parameters for updating a scheduling strategy and releasing resources after a task is completed; the system comprises a multi-mode agricultural sensing terminal, intelligent gateway equipment, a 5G and LPWAN hybrid access network, a resource scheduling module and a scheduling strategy learning engine. According to the method, the multi-dimensional state characteristics such as the network congestion level, the edge node load, the data timeliness and the task priority are sensed in real time through the deep reinforcement learning model, and the optimal allocation decision of communication and computing resources is dynamically generated.
Owner:DAOJIANYOUXING (CHONGQING) TECH CO LTD +2

Data sharing method and system for metabolic acidosis patients

The invention relates to the technical field of computers, discloses a data sharing method and system for patients suffering from metabolic acidosis, and aims to solve the problem of out-of-control safety caused by extensive authority, bare transmission and traceless behaviors in cross-institution medical data circulation. A dynamic authority strategy based on roles and scenes is constructed by extracting and standardizing patient diagnosis and treatment data from a hospital system; end-to-end encrypted transmission is realized through bidirectional authentication and a temporary session key; establishing a three-layer block chain type audit log tracking access, a secret key and a data flow direction; dynamic desensitization, quality verification, cache acceleration and intelligent contract extension mechanisms are integrated, and a visual authority topology monitoring and credit scoring system is supplemented. According to the technical scheme, data field-level accurate authorization, encryption and anti-theft in the whole transmission process, traceability in the whole operation period and use compliance self-feedback are achieved, and the scientific research value of clinical data is released to the maximum extent while the privacy safety of a patient is effectively guaranteed.
Owner:THE FIRST MEDICAL CENT CHINESE PLA GENERAL HOSPITAL

Server system, instance creation method and cloud management platform

Disclosed are a server system based on public cloud technology, an instance creation method and a cloud management platform, and belong to the technical field of cloud services. The server system comprises a first server and a second server connected by a connection channel. A first instance of the first server is provided with a first business module and a first security module; a second instance of the second server is provided with a second business module and a second security module; the first business module is used for sending an access request for the second business module, and the access request is used for requesting the second business module to provide a second tenant service; the first security module is used for obtaining the access request, encrypting the access request, and sending the encrypted access request to the connection channel; and the second security module is used for obtaining the encrypted access request from the connection channel, decrypting the encrypted access request, and sending the decrypted access request to the second business module. The application realizes end-to-end encryption protection of the access request.
Owner:HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD

Server system, instance creation method and cloud management platform

Disclosed are a server system based on public cloud technology, an instance creation method and a cloud management platform, belonging to the technical field of cloud services. The server system comprises a first server and a second server, between which connection channels are established. A first service module and a first security module are provided in a first instance of the first server; a second service module and a second security module are provided in a second instance of the second server; the first service module is configured to send an access request for the second service module, the access request being used for requesting the second service module to provide a second tenant service; the first security module is configured to acquire the access request, encrypt the access request, and send the encrypted access request to the connection channel; and the second security module is configured to acquire the encrypted access request from the connection channel, decrypt the encrypted access request, and send the decrypted access request to the second service module. The present application implements end-to-end encryption protection of access requests.
Owner:HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD

Systems and methods for end to end encryption utilizing a commerce platform for card not present transactions

A method and apparatus for processing a transaction between a merchant system and a customer system, the customer system associated with a customer of the merchant are described. The method may include receiving, at a commerce platform, a transaction request from the merchant system, wherein the transaction request is generated by the merchant system and comprises a card identifier and encrypted payment card data, wherein the card identifier is determined from card data for a payment card used in the transaction and the encrypted payment card data comprises at least an encryption of a payment account number. The method may also include decrypting, by the commerce platform, the encrypted payment card data using an encryption key selected based on the card identifier, the encryption key associated with the commerce platform. Furthermore, the method may include authorizing, by the commerce platform in communication with one or more authorization systems, the transaction using the decrypted payment card data.
Owner:STRIPE LLC

Health status system, platform, and method

A health status platform includes a receiving component that receives a test result a test of a biological sample collected from a human patient. The test result includes an indication of a presence of an infectious disease in the patient, and an identification and a verification of the patient. The platform includes a certificate component that issues a certificate of origin of the biological sample; and a data merging component that cooperates with a venue access manager that controls access to a venue. The data merging component implements a distributed ledger system that stores encrypted test results of the patient and the identification and verification of the patient, and an end-to-end encryption system that receives an encrypted venue access request from a venue access manager, decrypts the access request, determines if an access request is valid, and if valid, provides an encrypted certificate of origin to the venue access manager.
Owner:TENSORX INC

Performing deduplication on multi-tenancy dataset

End-to-end encryption in a storage system with multi-tenancy, includes: performing deduplication on a first tenant dataset, the first tenant dataset including data encrypted using a first storage system encryption key; and performing deduplication on a second tenant dataset, the second tenant dataset including data encrypted using a second storage system encryption key, where deduplication is not performed between the first and second tenant datasets.
Owner:PURE STORAGE INC

A privacy protection type intelligent camera system

This invention discloses a privacy-preserving smart camera system, comprising: an image sensor for acquiring raw image signals of a scene; a target recognition module, based on a deep learning model, for real-time detection of faces, bodies, or user-specified specific object regions in the scene; a privacy region processing module, for performing at least one privacy protection operation among blurring, pixelation, or occlusion on non-target regions detected by the target recognition module; and a data encryption module, employing an end-to-end encryption algorithm to locally encrypt the privacy-preserving video stream, ensuring data transmission and storage security. This invention, through real-time target recognition at the device side, retains only the target region image needed by the user, while non-target regions undergo irreversible processing using various adjustable privacy methods, eliminating the risk of redundant acquisition and leakage of sensitive information from the source, and solving the problem of uncontrollable image acquisition range in existing cameras.
Owner:ANHUI KAIXIN ELECTRONIC TECHNOLOGY CO LTD

Intranet security operation and maintenance method and device based on bastion host, medium and program product

ActiveCN121619154ASecuring communicationEnd-to-end encryptionTrusted system
The embodiment of the invention provides an intranet security operation and maintenance method and device based on a bastion host, a medium and a program product, and relates to the technical field of operation and maintenance management. The method comprises the following steps: in response to a connection request actively initiated by a zero-trust proxy client, establishing an end-to-end encrypted application layer tunnel between a zero-trust proxy server and the zero-trust proxy client under the condition that bidirectional authentication is passed; acquiring context information corresponding to the operation and maintenance terminal, and determining a dynamic authorization strategy based on the context information; and performing operation and maintenance management and control on the operation and maintenance operation of the operation and maintenance terminal based on the dynamic authorization strategy, and transmitting operation and maintenance traffic generated between the operation and maintenance terminal and the intranet resource side through the application layer tunnel. According to the embodiment of the invention, the zero-trust system model taking the internal resource side as the active connection end is constructed, and the dynamic authorization strategy is generated by acquiring the related context information in real time, so that the security of internal network operation and maintenance is greatly improved.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

End-to-end encrypted video conferences

Techniques for implementing end-to-end encrypted video conferences are disclosed. In an example method, a client device generates a first key. The client device outputs a request to initiate a locked, end-to-end encrypted video conference encrypted based on the first key. The client device encrypts the first key using public keys of each participant. The client device distributes the encrypted first key to the participants. The client device receives a request to admit an additional participant to the end-to-end encrypted video conference. The client device rejects the request.The client device generates a second key. The client device encrypts the second key using the public keys. The client device distributes the encrypted second key to the participants and the additional participant. The client device outputs a request to restart the end-to-end encrypted video conference for the participants and the additional participant that will be encrypted based on the second key.
Owner:ZOOM COMMUNICATIONS INC

Community Governed End to End Encrypted Multi-Tenancy System to Perform Tactical and Permanent Database Operations and Microservices

Multi-tenancy system to perform tactical and permanent database and communication operations including secure handling of personally identifiable and / or health information (PII / PHI), data collection, data management, reporting, data analytics, secure communications, document sharing and microservices (e.g., capturing biomarkers, determining presence of certain conditions by comparing captured biomarkers to biometrics associated with condition). System includes security platform meeting stringent data protection mandates including firewall with extensive security protocols, encrypting communications between components of system (in transit) and information within each of the components (at rest). PII / PHI information is further encrypted and only visible with appropriate decryption key. System utilizes low code / no code database platform to address increasing demand for rapid, iterative and collaborative application development. System includes form builder to easily add dynamic fields. System includes a collaborative database development with a community structure approach of “who” data is needed from rather than “what” data is needed. Community structure controls operation thereof.
Owner:ARDIAN TECH

A method for end-to-end encryption of location sharing for PDT / DMR intercom

PendingCN122340458AEnd-to-end encryptionLocation sharing
This invention discloses an end-to-end encrypted location sharing method for PDT / DMR walkie-talkies, solving the problems of low positioning data accuracy, insecure transmission, and unreliable encryption during walkie-talkie location sharing. The method includes: a dispatch terminal / authorized walkie-talkie sending a location sharing control signaling POS_CMD, which, according to the CSBK signaling definition in the extended PDT / DMR standard, initiates / dissolves a sharing event and determines the sharing event mode; the called walkie-talkie sends an end-to-end shared location information data frame POS_INF, which uses Data Type=0xF, multiplexes the physical layer encoding format of a 3 / 4 coding rate data frame to carry encrypted location information, and employs a 0-180° latitude / 0-360° longitude mapping, with the KeyFrame field sharing the ciphertext; and the dispatch terminal / member walkie-talkie decrypts the POS_INF data frame and reconstructs the location information. This method achieves encrypted control information sharing with the ciphertext, with the entire encryption / decryption process completed on the walkie-talkie / dispatch terminal side, improving data security and preventing location information exposure.
Owner:SICHUAN HAIGE HENGTONG PRIVATE NETWORK TECH CO LTD

Medical voice commerce system with artificial intelligence for healthcare integration and universal accessibility

The invention discloses a multilingual medical voice commerce system enabling secure, voice-activated transactions for healthcare products, services, and prescriptions. Utilizing AI-driven speech recognition optimized for medical terminology, the system integrates natural language processing and context-aware recommendation engines. Secure features include HIPAA-compliant authentication, patient consent management, and end-to-end encryption. The platform interfaces with electronic health records, pharmacy networks, insurance verification systems, and wearable health monitors for real-time medical data access and transaction execution. Designed for hospital procurement, surgical environments, telehealth, and home healthcare, the system incorporates universal accessibility, including adaptations for visual, motor, cognitive, and speech impairments. Multilingual capabilities ensure cultural and linguistic inclusivity. AI analytics track usage patterns, optimize recommendations, detect health trends, and support population health initiatives. Operable across smart speakers, medical devices, and connected platforms, the system delivers a unified, monetized, secure, and inclusive medical voice commerce ecosystem for patients, providers, and healthcare organizations worldwide.
Owner:BYRD STEPHEN M

ROAX: universal interoperable medical record system using blockchain technology

ROAX is a universal healthcare system build on top of blockchain technology, a platform designed to empower both doctors and patients by providing a secure, compliant, and privacy- preserving system for storing verifiable proofs and signatures of medical records. Utilizing blockchain technology, ROAX ensures the integrity, security, and interoperability of medical data, transferring data ownership directly to the record owner. For the first time, the platform incentivizes doctors to collaborate, fostering a cooperative medical ecosystem. By decentralizing verifiable data, ROAX significantly enhances data security, protecting against breaches and unauthorized alterations. This immutable and verifiable record system not only safe-guards patient information but also assures the credibility of medical records. ROAX introduces a universal interoperable framework, the idea was inspired from the end-to- end encryption from WhatsApp and incorporates blockchain technologies as well as recent trends of cryptography to complete an entire infrastructure that can facilitate the development of Decentralized Medical (DeMed) applications, thereby broadening the scope and accessibility of healthcare services. The platform supports a new economy for medical data and insurance, promoting efficient data availability and utilization across the medical industry. A medical entity / doctor would carry out its usual creation of medical record to a centralised database. After which he will also generate a proof / signature and submit it it as a transaction onto the blockchain. Validators of the network verify the transaction. Anyone that holds the raw medical records can now verify the data on-chain. Authorised individual with the medical record can share the medical records via a data availability layer encrypted through the receiver's public key. And the intended receiver could decrypt it via their own private key. In the previous step, the medical entity communicates with the patient's hardware device via an end to end encryption communication.
Owner:GOH ZHEN HAO

Server Inaccessible End-to-End Encrypted Data Protection

System and method for a data environment using linked chains of data packages and logical packages to allow for identification of server data from a local machine without allowing access to unencrypted data by the server. The local machine may identify all data packages and all logical packages in the data environment without downloading all data packages and logical packages providing for faster remote data use with improved security. Data packages and logical packages may be organized by their unique checksums. Header information contained within the data packages and logical packages allows a local machine to identify all data packages in the data environment while only downloading and decrypting a minimal number of data packages or logical packages and data.
Owner:BOUTWELL JOSHUA JOSEPH

Electronic device for transmitting and receiving end-to-end encrypted data based on attestation of electronic device and thereof operation method in wireless communication system

A method of a first electronic device which is connected to a fabric network supporting end-to-end encryption (E2EE) in a wireless communication system is provided. The method includes generating a fabric key based on a pre-stored first device key and a second member key received from a second electronic device, transmitting the fabric key to the second electronic device through a fabric server, which manages the fabric network, and a service server, which manages service data, encrypting service data based on the fabric key, and transmitting the encrypted data to the second electronic device through the service server, wherein the fabric key is shared with the fabric server, which is a member entity of the fabric network, and the second electronic device, wherein the encrypted data is decryptable at a member entity of the fabric network that shares the fabric key.
Owner:SAMSUNG ELECTRONICS CO LTD

Pregeneration of one-time pads for end-to-end encryption

A processing system implementing end-to-end encryption includes a number of nodes each connected to a network and including a respective processor. Further, at least one node connected to the network includes a one-time pad (OTP) pregeneration circuitry configured to select an OTP pregeneration operating mode based on the number of nodes connected to the network. Further, the pregeneration circuitry of the node is configured to generate an OTP associated with another node connected to the network based on the selected OTP pregeneration operating mode before a packet is received from that node.
Owner:ADVANCED MICRO DEVICES INC

Charging pile Internet of Things communication security protection system with charging protocol encryption

The invention discloses a charging-protocol-encrypted charging pile Internet of Things communication security protection system, and relates to the field of new energy charging infrastructure and Internet of Things security. In order to solve the problems that an existing charging pile communication protocol is insufficient in encryption and prone to attack and information leakage, the system integrates the functions of charging protocol end-to-end encryption, two-way security authentication, key dynamic management, abnormal communication detection and a security operation and maintenance platform, and whole-process security guarantee of communication is achieved. Through trial verification, the communication data stealing and tampering event is zero, the attack detection blocking success rate reaches 98%, the operation and maintenance response time is shortened by 40%, and the user complaint rate is reduced by 35%. The system meets compliance requirements, has been popularized in multiple operating enterprises, significantly improves communication security and reliability, prevents network attack risks, and has significant security benefits.
Owner:SHAANXI KANGFU ELECTRONIC TECH CO LTD

Systems and methods using emulation for end to end encryption

Methods and system implement solutions for integrating encryption and emulation into native database formats and / or architectures. “Native” database is used to describe a database that has not been designed for end to end encryption, an off the shelf database deployment, and / or a commercially available database. According to some embodiments, various encryption systems and methods employ emulation operations to enable a native database and native database functions to leverage full encryption primitives. Various aspects integrate emulation operations into standard database implementations, where the emulation enables native database functions to operate on entirely encrypted data.
Owner:MONGODB INC

Efficient functional bootstrapping for homomorphic encryption

End-to-end cryptographic communication to securely exchange data to / from a homomorphic cryptography circuit. The homomorphic cryptography circuit may perform homomorphic operations on ciphertext(s) of plaintext message(s) that evaluate non-linear operation(s) over the encryption of the plaintext message(s) using lookup table(s) under a functional bootstrapping scheme. The functional bootstrapping executes the lookup table(s) using Nth-order trigonometric Hermite interpolation with derivative constraints set to reduce noise for (p) interpolation points, thereby achieving the desired noise refreshing effect of bootstrapping. The homomorphic cryptography circuit may use a vector data structure to amortize the functional bootstrapping by performing the trigonometric Hermite interpolation over a vector of a plurality of the ciphertexts in parallel, e.g., using SIMD instructions, thereby improving the functional bootstrapping efficiency. The circuit output(s) may be decrypted by an external device to generate unencrypted result(s) of the homomorphic operation(s) on the plaintext message(s) with no access to the unencrypted plaintext message(s) themselves.
Owner:DUALITY TECHNOLOGIES INC

Lightning arrester intelligent monitoring terminal, system and method based on power gap OS

The invention discloses a lightning arrester intelligent monitoring terminal, system and method based on an electric power gap OS, and the terminal, system and method achieve a remarkable technical effect by deeply integrating the electric power gap OS in the lightning arrester monitoring terminal and implementing the end-to-end encryption communication of the whole life cycle. The potential safety hazard of data transmission of a traditional monitoring device in a public network is fundamentally solved, and the safety of the whole process of data access to a power grid Internet of Things platform is ensured through a multi-encryption technology. Secondly, according to the method, a unified framework of an electric power gap OS is utilized, standardized and plug-and-play access of the monitoring terminal is realized, the problem of data islands among devices of different manufacturers is effectively solved, and efficient fusion of monitoring data and a power grid master station system is promoted. The invention provides a safe, unified, efficient and low-operation-and-maintenance-cost intelligent monitoring solution for the lightning arrester, and has remarkable practical value for improving the real-time performance and accuracy of sensing the operation state of a power grid and supporting lightning protection of a power transmission line and intelligent operation and maintenance of the power grid.
Owner:YUXI POWER SUPPLY BUREAU OF YUNNAN POWER GRID

Containerized, decentralized, and distributed web applications with end-to-end encryption

A method performed by a relay server for facilitating communications between a web application executing in a web browser and one or more client computing devices. The method includes receiving a selected domain name under which the web application is to be registered, verifying that the web application is allowed to be registered under the selected domain name based on accessing a record associated with the selected domain name in a domain name system (DNS) database, registering the web application under the selected domain name, relaying messages associated with the selected domain name that are received from the one or more client computing devices to the web application over a first bidirectional communication connection established between the web application and the relay server, and relaying messages received from the web application over the first bidirectional communication connection to respective ones of the one or more client computing devices.
Owner:SHORE LABS ZBIGNIEW ZEMLA

Intelligent health early warning system based on cloud processing

The invention discloses an intelligent health early warning system based on cloud processing, and relates to the field of intelligent early warning, and the system comprises the steps: comprehensively collecting the physiological, environment and behavior data of a user through a multi-mode collection module, and dynamically adjusting the collection frequency; after preprocessing and end-to-end encryption are completed on the user side edge equipment, the data are uploaded to the cloud for mixed storage and life cycle management; performing fusion analysis on the data by the system, mining internal association and extracting key feature vectors, and constructing a personalized dynamic health assessment model according to the internal association and the key feature vectors; the system calculates a comprehensive health risk score and a specific disease incidence probability based on a model, realizes graded early warning, and bidirectionally interacts and feeds back to a user and medical staff through an intelligent terminal. The method has the advantages that safety and high efficiency of data are guaranteed through edge-cloud cooperative processing and end-to-end encryption, accurate risk assessment and graded early warning are realized based on a personalized health model, and the method has early warning accuracy, use convenience and medical specialty.
Owner:深圳市英得尔实业有限公司

Cat.1 module-based virtual private network and networking method thereof

This invention discloses a virtual private network (VPN) based on Cat.1 modules and its networking method, aiming to solve the technical bottlenecks of existing LTE VPN solutions, such as high cost, narrow equipment compatibility, insufficient security, and poor deployment flexibility. This invention deeply integrates L2TP and VPN protocol stacks into the Cat.1 module hardware and firmware, constructing a "VPN server - Cat.1 module - client device" networking architecture. First, system initialization is completed, and L2TP dialing parameters are set through either batch configuration using AT commands or visual configuration via a web page. Then, the Cat.1 module actively initiates dialing to the VPN server, establishing an end-to-end encrypted L2TP tunnel through dual verification of device IMEI and user identity. Finally, relying on interfaces such as USB, WIFI, and RJ45, the virtual network is shared with various types of clients, including embedded devices and sensors. This invention does not rely on operator private network APN resources, reduces equipment hardware costs, shortens deployment cycles, and improves the economy, adaptability, and security of virtual networking.
Owner:ZHEJIANG LIERDA INTERNET OF THINGS TECH