Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

49 results about "End to end security" patented technology

Defining "End". The traditional definition of an endpoint is a client or server. In this definition end-to-end security starts on the client and ends on the server. Given the multitude of applications running in parallel on an operating system, and given increasing virtualization, this definition is usually no longer precise enough.

Secure key injection method and system

The invention discloses a secure key injection method and system, which are applied to electronic equipment with a rich execution environment and a secure virtual machine environment, and the method comprises the following steps: receiving a key injection request in the rich execution environment, and loading and starting the secure virtual machine environment; forwarding the key injection request to a secure virtual machine environment; generating a key pair in the secure virtual machine environment, and sending a public key certificate and an identity certificate of the key pair to a key management background through a rich execution environment; the key management background returns response data after verification is passed, and the response data is forwarded to the secure virtual machine environment through the rich execution environment; verifying the response data in the secure virtual machine environment; and after the verification is passed, storing the to-be-injected key material in the response data in the secure virtual machine environment. According to the invention, end-to-end security protection of the key material is realized through dual-environment cooperation, and the anti-attack capability and the data confidentiality of the injection process are effectively improved.
Owner:FUJIAN WISBO DIGITAL TECHNOLOGY CO LTD

Methods and related devices for secure transmission of messages

ActiveCN119232523BNetworks interconnectionSecuring communicationWide areaEnd to end security
This application provides a method for secure message transmission, a method for negotiating IPsec SAs, and related apparatus, applicable to wide area networks (WANs). In scenarios spanning multiple tunnel segments, by extending BGP routing and based on VRF granularity, an IPsec SA for end-to-end security protection is negotiated between a first edge and a second edge. After the first edge securely protects VPN service messages based on the IPsec SA, it sends the messages through the overlay end-to-end tunnel between the first and second edges. The second edge processes the messages based on the IPsec SA to obtain the VPN service messages. In this application, security protection only needs to be performed once at the first edge; intermediate nodes do not require encryption / decryption processing, thus ensuring secure message transmission while improving transmission efficiency and reducing transmission latency.
Owner:HUAWEI TECH CO LTD

Solid state disk controller circuit and solid state disk

The invention relates to the technical field of electric digital data processing, and discloses a solid state disk controller circuit and a solid state disk. The controller circuit comprises a physical unclonable function unit based on an SRAM (Static Random Access Memory), which is used for dynamically generating a stable hardware trust root key during power-on; the secure boot and firmware decryption engine is used for deriving a firmware decryption authentication key and a data key packaging key by using the key, and carrying out decryption and integrity verification on the encrypted firmware; the runtime firmware execution monitoring unit is used for detecting illegal jump in real time and triggering safe shutdown through a hardware-level control flow diagram; and the dynamic data encryption key management unit recovers the plaintext data key and sends the plaintext data key to the encryption engine only during operation, and power failure disappears. By means of the scheme, end-to-end security protection of firmware and data is achieved, and the risks of static key leakage and firmware tampering are eradicated.
Owner:深圳市彦胜科技有限公司

IoT safe zero touch provisioning

PendingUS20260074951A1TransmissionSecurity arrangementThird partyEnd to end security
Systems and methods are provided for bootstrapping Internet of Things (IoT) device provisioning from the IoT subscriber identity module (SIM) for End-to-end (IoT SAFE) communication-based authentication of a IoT device's subscriber identity module (SIM). In other words, IoT device provisioning can piggyback off of SIM authentication (performed on the SIM itself via IoT SAFE) resulting in true zero touch provisioning, where no “manual” or third party intervention is needed. In particular, an IoT device may include the SIM, communications componentry, and the functional IoT componentry (e.g., IoT sensors). While traditional attempts at zero touch provisioning fail to account for these different aspects of an IoT device, the proposed bootstrapping allows for each aspect of the IoT device to be provisioned beginning with / deriving from the authentication of the IoT device's SIM.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Dynamic data secure transmission and processing channel construction device and method based on zero trust

ActiveCN121644169AMultiple keys/algorithms usageEnd to end securityData stream
The invention provides a zero-trust-based dynamic data secure transmission and processing channel construction device and method, and the method comprises the steps: S1, collecting to-be-transmitted data, and classifying the data to obtain a data classification result; s2, based on the data classification result, the user identity information and the environmental risk information, a dynamic security policy is generated, and the dynamic security policy comprises an encryption algorithm selection rule, a trust evaluation threshold and a data operation authority policy; according to the invention, the fine-grained security policy is generated and continuously adjusted by dynamically sensing the data sensitivity and the real-time trust state, so that the full-link self-adaptive security protection from transmission to processing is realized; according to the method, the security multi-party calculation is seamlessly integrated in a high-sensitivity scene, so that the end-to-end security and privacy protection level of data in a cross-domain and multi-participant environment are remarkably improved while the data mobility is guaranteed, and the problem that a traditional static security mechanism is difficult to adapt to dynamic risks is effectively solved.
Owner:姚远

Micro-service security isolation method and system for multi-tenant SaaS platform

The invention provides a micro-service security isolation method and system for a multi-tenant SaaS platform, and the method comprises the steps: collecting tenant identity information, equipment terminal data and access environment parameters for the multi-tenant SaaS platform, and generating tenant credible baseline data; based on a zero-trust architecture, performing dynamic comparison and risk assessment on the tenant trusted baseline data and the real-time access request data, generating a tenant real-time trust score, and distributing a tenant minimum necessary permission set according to the tenant real-time trust score; and transparent encryption and isolation are carried out on the micro-service interaction flow among the tenants, a verification rule corresponding to the minimum necessary permission set of the tenants is configured for the API gateway, identity verification and flow limiting processing are carried out on real-time access requests of the tenants, and full-link security management and control are formed. According to the method and the device, the defect that the end-to-end security control from the access entry to the service interaction is difficult to realize due to insufficient isolation precision among micro-services of the current multi-tenant SaaS platform is overcome.
Owner:BEIJING NORTH LATITUDE 30 DEGREE NETWORK TECH CO LTD

Time-sensitive network end-to-end secure communication method

The invention relates to a time-sensitive network end-to-end secure communication method, and belongs to the technical field of communication. According to the method, a TSN terminal system of Linux is used for realizing bidirectional identity authentication and key agreement based on an SM2 cryptographic algorithm, and an SM4-CCM algorithm is used for realizing time-sensitive network security communication and data integrity verification; the SM2 national secret algorithm is an asymmetric encryption algorithm, a signature pair is generated based on an elliptic curve discrete logarithm problem, the two parties negotiate a shared key through elliptic curve point operation, a public key of a receiver is used for encryption, and only a private key can be used for decryption; sM4-CCM is a combination of an SM4 block cipher algorithm and a CCM mode, and is used for providing confidentiality, integrity and authenticity of data; according to the CCM mode, through combination of CTR encryption and CBC-MAC authentication, efficient authentication encryption is realized. The method can be used for real-time secure communication in a high-reliability industrial scene.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Fast joins and low memory usage for end-to-end (E2E)-secure applications using light MLS clients

ActiveUS12641081B2Securing communicationEnd to end securityParallel computing
A user device joins a communication session between the user device and a plurality of devices. The user device and the plurality of devices use a Message Layer Security (MLS) protocol for end-to-end security. The user device identifies a first device of the plurality of devices and obtains a portion of authentication tree information associated with the communication session. The portion being associated with the first device. The user device authenticates the first device based on obtaining the portion of the authentication tree information.
Owner:CISCO TECHNOLOGY INC

Method for establishing end-to-end secure communication of unmanned aerial vehicle under cloud network architecture

ActiveCN117376911Breduce overheadReasonable allocation of resourcesSecure communicationEnd to end security
The application discloses a method for establishing end-to-end secure communication of unmanned aerial vehicle under cloud network architecture, and takes cloud server as a security service center to provide full-process authentication service for unmanned aerial vehicle end system; the cloud server only issues public authentication materials to unmanned aerial vehicles, and session key negotiation and establishment of end-to-end secure communication are realized between unmanned aerial vehicles; the unmanned aerial vehicle end system does not need to store authentication materials of other unmanned aerial vehicles in advance, the cloud server is driven by specific tasks, and specific authentication materials required for key negotiation are issued to unmanned aerial vehicles which need to be securely cooperated according to task requirements. The application only requires that the cloud server and any one of the unmanned aerial vehicles for key negotiation establish a communication connection, and the authentication materials issued by the cloud server can make the unmanned aerial vehicles realize key negotiation and establish an end-to-end secure channel in a specific range; different temporary public keys are used for each request message, which can effectively prevent the harm caused by long-term and short-term secret leakage.
Owner:XIDIAN UNIV

Method, apparatus and computer program

PCT designated stageWO2025209829A1Security arrangementSecuring communicationDomain nameEnd to end security
There is provided apparatus, method(s) and computer program(s) for providing notifications indicating whether an end-to-end security mechanism is applied on domain name system (DNS) messages associated with a DNS query.
Owner:NOKIA TECHNOLOGIES OY

Secure connection method and system for accessing credential mobile terminal through USB

The invention relates to the technical field of computers, in particular to a secure connection method and system for accessing a credential mobile terminal through a USB, and the method comprises the steps: reading a preset device root key of a security module, generating a pre-authentication factor in combination with a unique identifier of an external hardware certificate, and generating a pre-authentication passing signal after the verification is passed; based on the pre-authentication passing signal, Beidou positioning information and a unique equipment UID of the credential mobile terminal are obtained, a unique equipment identifier is generated in combination with the pre-authentication factor, and based on a management and control result of the USB access permission, a security module is triggered regularly to perform integrity verification on an operating system mirror image of the credential mobile terminal. And determining to maintain or terminate the USB secure connection. The method has the advantage of improving the end-to-end security.
Owner:HANGZHOU BYTE INFORMATION TECH CO LTD

System for providing end-to-end security service using portable security unit based on intelligent home network

ActiveUS12719930B2End to end securityThe Internet
Provided is a system for providing an end-to-end security service using a portable security unit (PSU) based on an intelligent home network. The system includes a PSU connected to a home network, a user terminal configured to access the PSU using a QR code and then connected to the Internet according to a security policy prestored in the PSU by uploading PSU information of the PSU and user information, and a security-service-providing server including a registration part configured to register, when the user terminal accesses the security-service-providing server using the QR code and uploads the PSU information and the user information, the user terminal, the PSU, the user information, and the PSU information, a security connection part configured to connect the user terminal to the Internet through the PSU according to the prestored security policy when the user terminal attempts to access the Internet, and a threat prevention part configured to block access by a threatening terminal which has not been authenticated by the PSU, through the PSU.
Owner:U CUBE CO LTD

A judicial system secret data safe flow method based on blockchain technology

ActiveCN120567451BEnd to end securityXACML
The application relates to the technical field of judicial data security, and discloses a method for safely transferring classified data in a judicial system based on a blockchain technology. Multi-source judicial data is collected, sensitive information is identified through a large language model, and differential privacy desensitization processing is adopted; an SM4 encryption and a TLS 1.3 end-to-end security channel are constructed, data hash fingerprints are generated, and the data are written into a consortium chain for storage based on a PBFT consensus mechanism; a multi-modal classification engine is designed to extract features and intelligently classify; a hybrid permission model is established to integrate XACML policies and Kafka queues, and a dynamic permission control is implemented in combination with an RBAC / ABAC mechanism; a hierarchical encryption storage architecture is constructed, homomorphic encryption retrieval and erasure code distributed storage are adopted; a judicial knowledge graph is constructed based on a BERT model; a blockchain audit system is deployed in combination with an LSTM anomaly detection and a DREAD risk assessment model to form a closed-loop risk control system. The application solves the problems of security risks and privacy leakage in the cross-departmental transfer of judicial data.
Owner:UESTC (SHENZHEN) ADVANCED RES INST +1

Data processing device and communication method based on open-source honk and star flash communication protocol

PendingCN122372996AEnd to end securityCarrier signal
This invention discloses a data processing device and communication method based on the open-source HarmonyOS and the StarScan communication protocol. The device employs the StarScan protocol, combining physical layer hybrid modulation adaptive switching, improved time-division multiplexing and carrier sense hybrid access, and a simplified protocol stack to achieve microsecond-level end-to-end latency and high anti-interference capability. An end-to-end security system is constructed through device pre-registration, elliptic curve key negotiation, AES-256-GCM encryption, and two-way certificate authentication. Standardized interfaces for multiple types of terminals are implemented with dynamic resource allocation, supporting hot-swapping and improving scalability. The D-S evidence theory is used to fuse verification results from multiple terminals, improving identification accuracy and anti-spoofing capabilities, while reserving emergency bandwidth and implementing priority scheduling to ensure anomaly handling. Automatic device discovery is achieved based on enhanced beacon broadcasting and sliding window detection, combined with improved on-demand distance vector routing for topology optimization, supporting dynamic networking and self-maintenance, reducing deployment and maintenance complexity.
Owner:BEIJING ANSHIHUAYE TECH CO LTD

Security service implementation method and apparatus, security service system, device, and medium

The present disclosure relates to a security service implementation method and device, a security service system, an electronic device and a readable storage medium, and is applied to the technical field of mobile communication. The method comprises the following steps: a MEC server converts a received security service demand instruction and a corresponding security policy from a core network into a security service parameter suitable for a MEC platform, and sends the security service parameter. A MEC host pre-constructs an end-to-end security information for storing the correspondence among authorized user terminals, authorized business applications and security policies; after the MEC host is configured based on the security service parameter, the MEC host provides a matching security service for an authorized initiator based on an end-to-end security list. The present disclosure can realize a security service suitable for a 5G network while taking into account the network security performance and network quality requirements.
Owner:CETC CYBERSPACE SECURITY TECH CO LTD

Micro-service security isolation method and system for multi-tenant saas platform

The application provides a micro-service security isolation method and system for a multi-tenant SaaS platform, comprising: collecting tenant identity information, device terminal data and access environment parameters of the multi-tenant SaaS platform to generate tenant trusted baseline data; based on a zero-trust architecture, dynamically comparing and risk evaluating the tenant trusted baseline data and real-time access request data to generate a tenant real-time trust score, and distributing a tenant minimum necessary permission set according to the tenant real-time trust score; transparently encrypting and isolating micro-service interaction traffic between tenants, configuring a verification rule corresponding to the tenant minimum necessary permission set for an API gateway, and performing identity verification and traffic throttling processing on real-time access requests of the tenant to form full-link security management and control. In the application, the defects of insufficient isolation precision between micro-services of the current multi-tenant SaaS platform and the difficulty in realizing end-to-end security management and control from an access entrance to service interaction are overcome.
Owner:BEIJING NORTH LATITUDE 30 DEGREE NETWORK TECH CO LTD

Secured proxy data distribution

PendingUS20260052129A1Securing communicationSoftware deploymentEnd to end securityElectrical battery
The disclosure describes techniques for distributing large amounts of data to networked devices. A utility company server sends data to proxy device(s) (e.g., a plurality of data collecting / distributing devices), each of which sends the data to a number of proxied devices (e.g., smart utility meters). Accordingly, the utility company server utilizes a plurality of proxy devices to lessen device workload and network bandwidth consumption. The proxy devices each “manage” a plurality of proxied devices. Advantageously, the techniques provide end-to-end security of the data, avoid devotion of significant network bandwidth to repetitive transmissions, and in some installations reduce battery power consumption. The systems, devices, and techniques for distributing large amounts of data to networked devices may be configured to include: software defined on central office server(s); a plurality of proxy devices associated with each server; and a plurality of proxied devices (e.g., smart metering devices) associated with each proxy device.
Owner:ITRON INC

A bluetooth identity-oriented end-to-end secure communication method and system

The application discloses a kind of end-to-end security communication methods and systems for bluetooth identity identification, method includes the following steps: S1, initialization stage, using LE Secure Connections protocol establishes trusted key negotiation channel, and core key is derived;S2, daily identification stage, through dynamic resolvable private address RPA and encryption verification, prevent replay attack and relay attack;S3, storage stage, utilize hardware encryption engine and partition protection, ensure the physical security of key.The application uses the above-mentioned end-to-end security communication method and system for bluetooth identity identification, realizes end-to-end security coverage, from the initial pairing of mobile phone and equipment, to the dynamic verification of daily communication, to the hardware level protection of core key, forms whole-link closed-loop security system, effectively resists various malicious attacks, adapts high-risk scene such as finance, security, improves the security and reliability of bluetooth identity identification.
Owner:GUIZHOU HUOYANSHAN ELECTRICAL CORP

Digital financial data sharing method

The invention discloses a digital financial data sharing method, which comprises the following steps that S1, a data provider performs field grading and encryption processing on to-be-shared digital financial data, so that each field is endowed with an accurate security level by comprehensively calculating a field leakage risk, association importance and compliance requirements; on the basis, encryption strategies of different security levels and different secret keys are implemented, the balance of data security and data sharing is fundamentally realized, the minimum necessary data unit is allowed to be shared on the premise of meeting the security requirement, the principle of separation of the secret keys and the tokens is followed, and the authorization server is allowed to perform authentication after verification is passed. According to the method, the decryption private key is dynamically encrypted by the public key of the data receiver and then issued, so that an attacker cannot decrypt the data even if the token is leaked, the absolute security of the key in the transmission process is ensured, and an end-to-end security closed loop from authorization to decryption is constructed.
Owner:YONGZHOU OPEN UNIV

Semantic packet-based end-to-end secure communication method and system for Internet of Things

The invention discloses an Internet of Things end-to-end secure communication method and system based on a semantic packet, and belongs to the technical field of communication security, and the method comprises the steps: constructing a unified USP semantic packet to package to-be-sent service data; wherein the USP semantic packet comprises an authentication field used for bearing security authentication information; based on the authentication field of the USP semantic packet, the sending end and the receiving end perform initial bidirectional identity authentication, and negotiate to generate a session key; in a data communication stage, the sending end generates a dynamic security parameter for each USP semantic packet, performs security processing on each USP semantic packet by using the session key, fills a security processing result and the dynamic security parameter into an authentication field of the USP, and then sends the complete USP semantic packet to a receiving end; and the receiving end performs security verification on the USP semantic packet according to the dynamic security parameter and the session key carried in the USP semantic packet. According to the invention, high-performance, high-security and extensible end-to-end security communication is realized.
Owner:CHINA TOWER CO LTD

Secure packet transmission method and related apparatus

This disclosure provides a secure packet transmission method, a method for negotiating an internet protocol security security association (IPsec SA), and a related apparatus, and is applied to a wide area network. In a scenario of crossing a plurality of segments of tunnels, an IPsec SA used for end-to-end security protection is negotiated between a first site edge and a second site edge based on a virtual routing and forwarding (VRF) granularity by extending a border gateway protocol (BGP) route. After performing security protection on a virtual private network (VPN) service packet based on the IPsec SA, the first site edge sends the packet through an overlay end-to-end tunnel between the first site edge and the second site edge, and the second site edge processes the packet based on the IPsec SA, to obtain the VPN service packet.
Owner:HUAWEI TECH CO LTD

Data security systems and methods on controlled devices

ActiveUS12500937B2Securing communicationEnd to end securityDual core
A blockchain network architecture of an infrastructure for creating end-to-end security between all public network blockchain nodes includes administrator nodes configured to control corresponding blockchain nodes by reading logs, testing and configuration; blockchain nodes configured to communicate with each other through open, unsecured channels connected to a public network, and at least one blockchain core embedded in blockchain nodes of electronic smart IoT devices that includes a transaction module, module of blockchain specific applications and the secure memory; a dual core switching access control module combined hardware and software components; a controlled switch or connector; an in-device administrator module for configuration update and route of trust for all module of blockchain nodes. Information is transmitted between the dual core switching access control module through the blockchain nodes to the controlled switch or connector.
Owner:RATINER MICHAEL +1

Intelligent agent development and safe operation method and system based on private cloud

PendingCN121711148ASecuring communicationEnd to end securityDynamic load balancing algorithm
The invention discloses an agent development and safe operation method and system based on a private cloud. The method comprises the following steps: firstly, constructing a multi-level security virtual private cloud architecture; secondly, deploying a containerized agent platform in each security domain, creating an application through a micro-service architecture, binding an exclusive knowledge base, and establishing an application-knowledge base one-to-one security channel based on digital signature; thirdly, implementing a fine-grained permission management and control mechanism, dynamically verifying a data security level label by adopting an access control model, and guaranteeing the security of sensitive information in combination with a privacy technology; then integrating a cue word optimization engine to improve the interaction performance of an agent, and applying a dynamic load balancing algorithm to realize efficient scheduling of a large model cluster; and finally, constructing an end-to-end security protection chain through an AK / SK authentication system. According to the method, the secret-related intelligent agent is managed and controlled from multiple angles, safe development and efficient operation of the intelligent agent in the secret-related environment are achieved, and it is guaranteed that secret-related knowledge information is safe and controllable.
Owner:AVICIT CO LTD

A verifiable change access control method and system based on SET and two atomic locks

PendingCN122093104AImprove auditabilityImprove certaintyUser identity/authority verificationEnd to end securityClosed loop
This invention relates to the field of computer security technology, specifically to a verifiable change access control method and system based on SET and dual atomic locks. The method includes generating a unique hash identifier for the request intent: intent_hash; constructing and issuing a certificate, which at least includes a secure execution type (SET), an expiration date, a replay protection field, a root of evidence, and a signature; binding the certificate to the intent_hash; performing expiration date checks through fast gating; and performing atomic occupancy operations based on the replay protection key. This verifiable change access control method and system based on SET and dual atomic locks achieves an end-to-end security closed loop, eliminating the possibility of execution bypass; providing industrial-grade consistency and replay protection guarantees through dual atomic operations and dual-channel consistency gating; constructing a self-verifying and tamper-proof chain of evidence, greatly improving auditability; forming a tiered defense-in-depth system, enhancing the overall system's robustness and resistance to censorship; and improving the system's determinism and observability.
Owner:GUANGZHOU GUCE CANGQIONG TECHNOLOGY CO LTD

Distributed high-availability interface service and data interaction system

PendingCN121907945ASecuring communicationEnd to end securityOperational system
The invention provides a distributed high-availability interface service and data interaction system. The distributed high-availability interface service and data interaction system comprises a unified access platform, a client application module and a distributed configuration center, client application modules are arranged on clients and servers of different operating systems and devices; performing corresponding protocol communication and data subscription on the transmission data through the client application module; receiving and protocol conversion are carried out on transmission data through the uniform access platform and the distributed access layer, and end-to-end secure transmission is carried out; and monitoring, parameter adjustment and anomaly detection are carried out on the unified access platform through the distributed configuration center.
Owner:BEIJING HONGSHAN INFORMATION TECH RES CO LTD

Method and apparatus for establishing end-to-end security in wireless communication system

ActiveUS12671592B2End to end securityCommunications system
The disclosure relates to a 5G or 6G communication system for supporting a higher data transmission rate. Disclosed is a method of a first terminal in a wireless communication system including transmitting a first request message for information required for establishing security between terminals to a first entity, receiving a first response message including the information required for establishing security between terminals from the first entity in response to the first request message, generating security information for the first terminal, based on the response message, transmitting a second request message including the security information for the first terminal to a relay terminal, establishing security with the relay terminal, receiving a second response message including security information for a second terminal from the relay terminal in response to the second request message, and generating an end-to-end session key between terminals, based on the received security information for the second terminal.
Owner:SAMSUNG ELECTRONICS CO LTD

A method and system for email data security based on identifier public key cryptography

This invention relates to a method and system for email data security based on identifier public-key cryptography, belonging to the field of information security technology. The method includes: the sender encrypting email attachments using a symmetric key to obtain ciphertext for the attachments; obtaining the recipient's identifier public key based on the recipient's email address; encrypting the email body using the symmetric key to obtain ciphertext for the body; generating email ciphertext structure data by creating a digital envelope based on the sender's identifier private key's signature of the body, the ciphertext, and key factors of the symmetric key encapsulated in the recipient's identifier public key, and sending this data to the recipient; the recipient obtaining the signature, ciphertext, and digital envelope based on the ciphertext structure data, and decrypting the digital envelope using the recipient's identifier private key to obtain the symmetric key; decrypting the ciphertext using the symmetric key to obtain the email body and verifying the signature using the sender's identifier public key; and decrypting the ciphertext for the attachments to obtain the email attachments. This invention achieves end-to-end security for email data, solving server-side performance bottlenecks and key management security issues.
Owner:BEIJING ZHONGHONG LIDA TECH DEV CO LTD +1

Mail data security method and system based on identification public key password

ActiveCN121547309ASecuring communicationComputer networkEnd to end security
The invention relates to a mail data security method and system based on an identification public key password, and belongs to the technical field of information security. The method comprises the following steps: a sender encrypts a mail attachment by using a symmetric key to obtain an attachment ciphertext; obtaining a receiver identification public key based on the receiver email address; encrypting the mail text based on the symmetric key to obtain a text ciphertext; based on the signature of the sender identification private key to the text, the text ciphertext and the digital envelope obtained by encapsulating the key factor of the symmetric key by the receiver identification public key, generating mail ciphertext structure data, and sending the mail ciphertext structure data to the receiver; the receiver obtains the signature, the body ciphertext and the digital envelope based on the mail ciphertext structure data, and decrypts the digital envelope based on the receiver identification private key to obtain the symmetric key; decrypting the body ciphertext based on the symmetric key to obtain the mail body, and verifying the signature through the sender identification public key; and decrypting the attachment ciphertext to obtain the mail attachment. According to the invention, the end-to-end security of the mail data is realized, and the problems of server performance bottleneck and key management security are solved.
Owner:BEIJING ZHONGHONG LIDA TECH DEV CO LTD +1

End-to-end secure communications with history

In one embodiment, an illustrative method herein may comprise: determining, by a device of a communication session, that a new epoch has occurred within the communication session, wherein the communication session has one or more member devices; generating, by the device and in response to the new epoch, a new key encryption key and a key bundle comprising one or more keys to decrypt content of the communication session from one or more previous epochs of the communication session; encrypting, by the device, the key bundle with the new key encryption key to create an encrypted key bundle; and sharing, from the device, the encrypted key bundle with the one or more member devices to allow the one or more member devices to access the content of the communication session from the one or more previous epochs.
Owner:CISCO TECHNOLOGY INC