Patents
Literature
Patsnap Copilot is an intelligent assistant for R&D personnel, combined with Patent DNA, to facilitate innovative research.
Patsnap Copilot

142 results about "End to end security" patented technology

Defining "End". The traditional definition of an endpoint is a client or server. In this definition end-to-end security starts on the client and ends on the server. Given the multitude of applications running in parallel on an operating system, and given increasing virtualization, this definition is usually no longer precise enough.

Methods, devices and systems for establishing end-to-end secure connections and for securely communicating data packets

The invention provides methods, devices (102, 110, 124, 136) and communication systems (100) for establishing end-to-end secure connections and for securely communicating data packets. Such a communication system (100) comprises a first device (124, 136), an intermediate device (110) and a second device (102). The first device (124, 136) communications via a first network (120), which is based on a first transport protocol and a first transport security protocol with the intermediate device (110). The second device (102) communications via a second network, which is based on a second transport protocol and a second transport security protocol with the intermediate device (110). The intermediate device (110) modifies packets received via first network to packets suitable for communication via the second network, and vice versa. The first device (124, 136) is able to reconstruct a header of a received packet as if the packet was sent via the second network (108) and its transport and security protocols. Further, the first device (124) is able to verify, on basis of the reconstructed header, verification fields which are generated on basis of the second transport security protocol.
Owner:KONINKLIJKE PHILIPS ELECTRONICS NV

Method and apparatus for application-independent end-to-end security in shared-link access networks

Clients that are connected on a private network and which are assigned a private IP address that is not routable on the Internet can connect to the Internet through a router/server that includes a network address translator (NAT). For outgoing packets, the NAT translates the client's private source IP address and generalized port number (GPN) to the NAT's global IP address and GPN. For incoming packets sent to the NAT's global IP address and GPN, the NAT translates the global destination IP address and GPN to the client's private IP address and GPN. For protocols which cannot be directly supported by the NAT, such as those in the IPSec security protocol suite, the NAT is extended by creating in the NAT's translation table an entry that associates, for a specific unsupported protocol, a client's private IP address and GPN, the NAT's global IP address and GPN, and a foreign address on the Internet, that is valid until a specified or default expiration time. Outgoing packets from the client to that foreign address and incoming packets from that foreign address to the NAT's global IP address and GPN are translated according to the entry until the entry expires. In associations with these translations to outgoing and incoming packets, the client implements any Application Layer Gateway (ALG) that would otherwise be implemented at the NAT. Further, at the client, outgoing packets are modified before being transmitted so as to pre-compensate for the effects of the translations. Incoming packets at the client from the NAT are similarly modified so as to post-compensate for the effects of the translations. For the IPSec protocol, these modification include adjusting the checksum in the TCP or UDP header to account for IP address and TCP or UDP port number translations.
Owner:ALCATEL-LUCENT USA INC

End-to-end security assurance method under IoT (Internet of Things) cloud environment

The invention relates to an end-to-end security assurance method under an IoT (Internet of Things) cloud environment, belonging to the fields of loT and cloud computing. Firstly, a PKI authenticationmechanism based on an ellipse curve algorithm is used to realize the authentication and key negotiation of a gateway and a cloud server, and establish a secure channel between the gateway and the cloud server; then the bidirectional authentication protocol based on the modified symmetric key is used to realize the authentication and key negotiation of a resource-limited node and the gateway; and finally a session key between the gateway and the cloud server is used to encrypt a session key between the node and the gateway, and the encrypted session key is sent to the cloud server, thus completing the establishment of the secure channel between the terminal node and the cloud server. The invention guarantees the identity validity of the node and the cloud server, and meanwhile, effectivelyreduces the computing cost of the sensor node. The authentication of the cloud server is indirectly realized by the gateway, thus reducing the authentication times between the gateway and the cloud server, and realizing the secure communication between the terminal node and the cloud server.
Owner:INST OF IND INTERNET CHONGQING UNIV OF POSTS & TELECOMM

Safe embedded operating system capable of supporting multi-stage loading

The invention provides a safe embedded operating system capable of supporting multi-stage loading. The safe embedded operating system supports the dynamic loading operation of an application program of an embedded terminal, realizes the isolation of the application program and an embedded terminal platform and comprises a system management module, a safety management module, a resource management module, a functional unit module, a GUI (Graphical User Interface) module, an application execution engine module, an application program interface (API) module and the like. Meanwhile, the safe embedded operating system is at least divided into a basic stage and an expansion stage by adopting stage treatment on the basis of the traditional Linux inner core, a basic stage module is fixedly loaded, each module and each functional module in the expansion stage are selectively and dynamically loaded according to application requirements under the scheduling of a system management framework, and thus, loading the system by stage is realized. By using the safe embedded operating system, a function of safety management and control for the application program through a safe framework module is achieved, mechanisms such as end-to-end safe issuing and loading of an application, safe operation protection based on an application process isolation and trust mechanism, application operation monitoring and the like are applied, and safe management and control on the whole life cycle of the application from issuing, downloading, loading to operating is realized.
Owner:ZHENGZHOU SEANET TECH CO LTD

System and Method for Operating End-to-End Security Channel Between Server and IC Card

The present invention relates to a system and method for operating an end-to-end security channel between an IC card and a server on a communication network. A method for connecting an end-to-end security channel between an IC card and a server on a communication network includes the steps of: generating, by the server, a random number Rs for transmission to the IC card, generating an E(Rs) by encrypting the random number Rs by a user public key, and transmitting the E(Rs) to the IC card through the communication network; receiving, by the IC card, the E(Rs) through the communication network and extracting the random number Rs by decrypting the E(Rs) by a user private key; generating, by the IC card, a random number Rc to be transmitted to the server, generating a session key K′ by the random number Rs and the random number Rc, and generating a first card verifier MAC by encrypting the random number Rs by the session key K′; transmitting, by the IC card, the random number Rc and the first card verifier MAC to the server through the communication network; receiving, by the server, the random number Rc and the first card verifier MAC through the communication network, generating a session key K by the random number Rs and the random number Rc, and generating a first server verifier MAC by encrypting the random number Rs by the session key K; and comparing, by the server, the first card verifier MAC and the first server verifier MAC to certify the session key K.
Owner:LEE SUNG MAN

Image data security transmission system with support of transparent transcoding

InactiveCN103414686ARealize end-to-end security authenticationAchieve reorganizationTransmissionComputer hardwareEnd to end security
The invention provides an image data security transmission system with the support of transparent transcoding. The system comprises three kinds of nodes which are a sending node, an intermediate transcoding node and a receiving node. The sending node is an image data server. The receiving node comprises different types of terminal devices. The sending node is provided with a calculation sensing Hash module of the sending node, a compression encoding module, a bit stream recomposition module, a hierarchical encryption module, and a bit stream package module. The intermediate node is provided with a safe transparent transcoding module. The receiving point is provided with a packet analysis module, a bit stream decoding module, an analysis bit stream module, a decompression encoding module and a computation perception Hash module of the receiving node. According to the system, a network intermediate node can directly carry out code rate conversion on a ciphertext domain bit stream, the decoding and decompression of the bit stream before the encoding of a converted bit stream is not needed, the end to end safety transmission of image data is realized, the safety transmission comprises the confidentiality, integrity and non-repudiation protection of an image, and the cost of transcoding is greatly reduced.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products