Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

26 results about "Ephemeral key" patented technology

A cryptographic key is called ephemeral if it is generated for each execution of a key establishment process. In some cases ephemeral keys are used more than once, within a single session (e.g., in broadcast applications) where the sender generates only one ephemeral key pair per message and the private key is combined separately with each recipient's public key. Contrast with a static key.

Firmware updating method, electronic device, server and system

This disclosure relates to a firmware update method, an electronic device, a server, and a system. The method includes: obtaining from a user device an encrypted firmware update package sent by a server to the user device in response to a firmware update request from the electronic device, and a firmware decryption key enDecKey encrypted by the server using a key encryption key KEK, wherein the key encryption key KEK is a temporary key derived based on a predetermined key derivation function; decrypting the received encrypted firmware decryption key enDecKey using the key encryption key KEK to obtain a firmware decryption key decKey; and decrypting the encrypted firmware update package using the firmware decryption key decKey to obtain a firmware update package for updating the firmware in the electronic device.
Owner:TP-LINK INT SHENZHEN CO LTD

Blockchain-based methods for protecting medical data privacy and authorizing sharing

This invention discloses a blockchain-based method for medical data privacy protection and authorized sharing, relating to the field of medical data technology. This invention achieves medical data privacy protection and compliant sharing through a four-step closed-loop process. The first step is data splitting and encryption: the original data from the target hospital is split into cell units according to the smallest clinical semantic unit, independently encrypted using the SM4 algorithm, and then differentiated enhancement processing is implemented according to sensitivity to build a strong privacy defense. The second step is storage and evidence preservation: the encrypted units are distributed and stored in fragments, and the fragment hash value, semantic tag, and storage index are uploaded to the shared chain for evidence preservation, simultaneously building a cross-chain gateway and protocol to break down sharing barriers. The third step is authorization and verification: a four-dimensional intelligent authorization model is built to verify requests and generate a temporary key bound to this authorization, achieving precise authorization. The fourth step is usage control: the user decrypts and reassembles the data in a TEE adapted to the cryptographic algorithm, with real-time monitoring of the entire operation and synchronization to both chains, ensuring end-to-end security, controllability, and traceability.
Owner:ANQING VOCATIONAL & TECHN COLLEGE

Data sharing method and device of vehicle, electronic equipment and storage medium

PendingCN122457242AData integrityHash function
The application relates to a data sharing method and device of a vehicle, electronic equipment and a storage medium, wherein the method comprises the following steps: in response to a data sharing instruction, a preset sharing random number of the vehicle is acquired, and a first random number of the vehicle is generated; a preset sharing random number is calculated by using a hash function to obtain a temporary key, and the first random number is encrypted by using the temporary key to obtain a first encrypted random number; a corresponding sharing ciphertext is generated by combining the first encrypted random number, a current time, a data integrity check value of the vehicle and a registration identification mark of the vehicle, and the sharing ciphertext is sent to a sharing end; after the sharing ciphertext is verified at the sharing end, an encrypted session generated by a second random number of the sharing end is received; the encrypted session is verified, and in the case that the encrypted session is verified to be qualified, the to-be-transmitted data of the vehicle is shared to the sharing end. Therefore, the technical problem that in the related art, it is difficult to avoid illegal means, the user's privacy information is called without user authorization, and there is a great security risk is solved.
Owner:CHERY AUTOMOBILE CO LTD

Secure device communication using mult-key encapsulation

A method for establishing secure communication between a first device and a second device. The method includes generating ephemeral keys at the first device, encapsulating a public key of the second device to generate a first cipher key and a first shared secret key, transmitting a first message to the second device including the ephemeral public key and the first cipher key, receiving a second message from the second device containing a second cipher key, decapsulating the second cipher key to achieve a second shared secret key, receiving and decapsulating a third cipher key to achieve a third shared secret key, deriving a final encryption key using the first, second, and third shared secret keys, and establishing secure communication by encrypting communication using the final encryption key. The method further includes verifying the final encryption key with the second device through hash exchange.
Owner:AAPOON INC

A patient data privacy encryption processing method and system based on digital signature encryption

The application provides a patient data privacy encryption processing method and system based on digital signature encryption, which comprises the following steps: when a first entity requests to access patient privacy data held by a second entity, the following steps are performed: the first entity sends an access request to the second entity, and attaches a first message signed by a long-term digital signature private key of the first entity; after the second entity verifies the signature, the second entity generates a temporary key exchange key pair, signs a second message containing the temporary public key using the long-term digital signature private key of the second entity, and sends the second message to the first entity; a shared secret is calculated based on the long-term or temporary private key of the first entity and the temporary public key of the second entity, and a symmetric session key dedicated to this data access is derived therefrom; and the metadata information of this data access is jointly signed using the signature private keys of the first entity and the second entity to form an unalterable audit log for storage. The above method guarantees the data security of patient privacy.
Owner:WOMEN & CHILDRENS MEDICAL CENTER AFFILIATED WITH GUANGZHOU MEDICAL UNIVERSITY

Method for managing secret information in secret information management system composed of computing devices and computing device for performing the same

The present disclosure relates to a method for managing secret information. The method for managing secret information in a secret information management system comprising a computing device comprises receiving a first secret share from among a plurality of secret shares for a secret key, a first additive share from among additive shares for the secret key, and a public key for the secret key by using a first terminal; generating a temporary key using the received public key as a coefficient for a random number; generating encrypted information by encrypting the secret information using an encryption key derived from the random number and the public key; storing the received first additive share and the public key in a database of the first terminal; and transmitting the generated temporary key and the encrypted information to a first server that possesses a second secret share and a second additive share.
Owner:ATOMRIGS LAB INC

Secure communication with a backscatter device

Secure communication with a Backscatter Device (BKD) may be provided. A temporal key may be created. The temporal key and a network Identifier (ID) may be encrypted with a public key of a public private key pair associated with the BKD. An excitation frame including the encrypted temporal key and the encrypted network ID may be transmitted to the BKD. The AMP BKD may include a sensor. A BKD frame may be received from the BKD in response to the excitation frame. The BKD frame may include a sensor data encoded with the temporal key and the network ID as a target destination. The BKD frame may be signed using a private key of the public private key pair.
Owner:CISCO TECHNOLOGY INC

Authentication and security for ultra-high reliability (UHR) roaming

PendingUS20260149965A1Security arrangementNetwork data managementSecurity associationMaster key
This disclosure provides methods, components, devices and systems for authentication and security for ultra-high reliability (UHR) roaming. Some aspects more specifically relate to devices in a seamless mobility domain (SMD), such as access point (AP) multi-link devices (MLDs) and non-AP MLDs, supporting the generation of different temporal keys (TKs) for each AP MLD. For example, the non-AP MLD may establish, via authenticator associated with the SMD, a pairwise master key security association (PMKSA) and a single pairwise transient key security association (PTKSA). Thus, the non-AP MLD may communicate with a first AP MLD (such as of multiple AP MLDs associated with the SMD) in accordance with a first pairwise transient key (PTK) and, after roaming to a second AP MLD (such as of the multiple AP MLDs), may communicate with the second AP MLD in accordance with a second PTK, where the second TK is different than the first PTK.
Owner:QUALCOMM INC

A student online time management and control method and system based on an encryption network

This invention discloses a method and system for managing student internet access time based on an encrypted network. It employs a multi-stage user adaptation model to deeply analyze time-series data, tailored to the learning needs of different educational stages, to accurately generate differentiated time-segment control requirement descriptions and access restriction specifications that match the current stage and time. Subsequently, based on these differentiated time-segment control requirement descriptions, execution rules are derived to dynamically generate personalized access control rules applicable to the current time. When a user initiates an authentication request, after successful unified identity authentication, the system determines whether the user is currently within an allowed access period based on the control rules. If allowed, a temporary key generation mechanism is triggered to establish a secure communication link and unlock compliant paths. Simultaneously, target resources are filtered, allowing only educational content. This invention significantly improves the effectiveness of internet protection for minors and enhances their focus on learning.
Owner:HUNAN ENG POLYTECHNIC

System and procedure for pre-authentication encryption

An example procedure includes: selecting an access point to connect to; obtaining a public key of the access point; generating a temporary key for pre-authentication encryption; encrypting the temporary key with the access point's public key; sending an authentication request to the access point to initiate an authentication process with the access point, the authentication request containing the encrypted temporary key; completing the authentication process to begin authenticated communications with the access point; and discarding the temporary key.
Owner:ZEBRA TECHNOLOGIES CORP

Mutually authenticated ECDHE key exchange for a device and a network using multiple PKI key pairs

A device can (i) store public keys Ss and Sn for a network and (ii) record private key sd. A network can record a corresponding private keys ss and sn. The device can (i) generate a device ephemeral PKI key pair (Ed, ed) and (ii) send public key Ed to the network. The device can receive an ephemeral public key Es from the network. The device can calculate values for A: an elliptic curve point addition over Ss, Sn, and Es, and B: (sd+ed) mod n. The device can input values for X and Y into an elliptic curve Diffie Hellman key exchange (ECDH) in order to determine a mutually derived shared secret X5, where the network can also derive shared secret X5. The device can (i) use X5 to derive a key K2 and (ii) decrypt a ciphertext from the network using key K2.
Owner:IOT & M2M TECHNOLOGIES LLC

Combination of challenge-response pair mechanisms for multi-factor authentication schemes protecting private keys

Protocols for providing multi-factor authentication to secure private encryption keys for an asymmetrical encryption algorithm are disclosed. According to the method, a user device is in possession of multiple CRP generation factors, which may include a physical addressable PUF array, a biometric print, a virtual token derived from a digital file, and a sensor-based PUF. The user device builds a combined reference table of responses from two or more of its factors, and derives an ephemeral key from the table used to encrypt a secret key. The terminal device may decrypt the key despite loss of the physical addressable PUF.
Owner:ARIZONA BOARD OF REGENTS ACTING FOR & ON BEHALF OF NORTHERN ARIZONA UNIV

Method, device, equipment and medium for automatically driving data to encrypt and return to cloud

PendingCN122293374AEngineeringMaster key
This invention discloses a method, apparatus, device, and medium for encrypted transmission of autonomous driving data back to the cloud, belonging to the field of autonomous driving data transmission technology. The method includes: generating a master key pair and a temporary key pair using the national cryptographic algorithm SM2 at the vehicle end and the cloud end respectively; exchanging a master public key and a temporary public key signed by their own master private keys and completing signature verification; if the signature verification is successful, obtaining a shared secret point based on their own temporary private key and the other party's temporary public key using the national cryptographic algorithm SM2; extracting the x-coordinate of the shared secret point and processing it using the national cryptographic algorithm SM3 to obtain a session key; encrypting the autonomous driving data to be transmitted using the national cryptographic algorithm SM4 based on the session key and transmitting it to the cloud; and decrypting the target autonomous driving data at the cloud using the session key. This technical solution achieves the technical effects of secure key transmission, high data transmission efficiency, and fine-grained key management.
Owner:DONGFENG MOTOR GRP

Key generation method, device and system

PendingCN122339687AKey exchangeSecure communication
This application provides a key generation method, apparatus, and system. The key generation method, applied to Internet of Things (IoT) devices, includes: generating a first temporary key pair based on first identification information of the IoT device, the first temporary key pair including a first public key and a first private key; determining a connection request based on the first public key and the first identification information; sending the connection request to a cloud server; obtaining verification information sent by the cloud server; and generating a master key based on the verification information and the first identification information; wherein the connection request and verification information are configured to be transmitted through a secure communication channel established by a key exchange protocol between the IoT device and the cloud server. The key generation method of this application achieves a strong association between the master key and the physical hardware of the IoT device, significantly reducing the risk of device cloning due to firmware copying, and improving the security and maintainability of the IoT system.
Owner:SHANGHAI SUMI TECH CO LTD +1

Casual key mobile edge communication

PendingUS20260156458A1Security arrangementEphemeral keyEncryption
One or more computer processors indexing one or more communications between a sending device and a receiving device. The one or more computer processors generate a casual key based on the one or more indexed communications, wherein the casual key is an encryption key. The one or more computer processors encrypt a subsequent communication with the generated casual key. The one or more computer processors create a payload comprising the encrypted communication. The one or more computer processors broadcast the payload.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

A method for privacy-preserving computation and sharing of biosample data based on a trusted execution environment.

PendingCN122316785APlaintextData integrity
This invention discloses a method for privacy-preserving computation and sharing of biological sample data based on a Trusted Execution Environment (TEE), belonging to the field of bioinformation security and privacy computation. The method includes: standardized preprocessing of multi-source biological data to generate integrity verification values; constructing a three-level hierarchical key system based on a TEE to perform three-dimensional encrypted fragmentation and distributed storage of the biological data; completing data decryption, integrity verification, and privacy computation within a TEE-isolated enclave, ensuring that the data remains in plaintext throughout the secure environment; outputting the computation results after anonymization and synchronizing logs to a consortium blockchain for auditing; and destroying temporary keys and data after the task is completed. This invention ensures data integrity, key security, and result anonymization. Combining hardware isolation and domestic cryptographic technology, it achieves "usable but invisible, controllable and auditable" biological data, solving the problems of privacy leakage, insufficient compliance, and low computational efficiency in cross-institutional sharing. It is suitable for collaborative scenarios involving highly sensitive data in biomedicine, medical research, and other fields.
Owner:HENAN XINLAI BIOTECHNOLOGY CO LTD

Secure virtualized cryptographic subsystems for autonomous systems and applications

In various examples, the disclosed techniques include receiving, from an application executing in a virtual machine (VM), a request to perform a cryptographic operation, wherein the request specifies an ephemeral key identifier and source data. The techniques also determine, using key metadata received from a trusted execution environment, a key slot identifier associated with the ephemeral key identifier, wherein the key slot identifier identifies a key slot in which a cryptographic key is stored. The techniques further cause the cryptographic operation to be performed on the source data in the trusted execution environment using the cryptographic key, where the cryptographic key used to perform the cryptographic operation is accessed from the key slot identified by the key slot identifier. The techniques further provide, to the application, a cryptographic operation result received form the trusted execution environment.
Owner:NVIDIA CORP

Modular lattice-based key exchange method, device and storage medium

PendingCN122372191Abig errorLarge sampling rangeKey exchangeModular lattice
This invention discloses a key exchange method, apparatus, and storage medium based on a modular lattice. The key exchange method includes: Party A generating a random number seed, obtaining a compressed public key, and sending it to Party B; Party B using the random number seed to obtain the compressed public key; recovering data from the received compressed public key from Party A and calculating a temporary key; processing the temporary key using a segmented signal function to obtain a signal value; using the signal value to coordinate the temporary key to obtain a shared temporary key, thereby generating a verification tag and deriving the final key; Party A recovering data from the received compressed public key from Party B, recalculating the verification tag, and comparing them; only when a match is successful, the final key is derived using the same method. This ensures the randomness of the data and the ability to detect tampering with the data received by Party A, thus achieving higher security. This invention significantly reduces the failure probability while improving security.
Owner:XIAN JIAOTONG LIVERPOOL UNIV

System and Method for Pre-Authentication Encryption

An example method includes: selecting an access point to connect to; obtaining a public key of the access point; generating a temporary key for pre-authentication encryption; encrypting the temporary key with the public key of the access point; sending an authentication request to the access point to initiate an authentication process with the access point, the authentication request including the encrypted temporary key; completing the authentication process to begin authenticated communications with the access point; and discarding the temporary key.
Owner:ZEBRA TECHNOLOGIES CORP

Key agreement method and system

This application relates to the field of communication technology and discloses a key negotiation method and system. The method includes: a requesting party generating a temporary key, encrypting the temporary key using the public key of the requesting party to obtain a first ciphertext, and broadcasting a first message containing the first ciphertext; the requesting party receiving the broadcast first message, decrypting the first ciphertext in the message using its own private key to obtain a decrypted temporary key, using the decrypted temporary key as the key for a message authentication code to generate a message authentication code for the first message and the second ciphertext, and sending a response message in response to the first message, the response message containing the message authentication code and the second ciphertext, the second ciphertext containing a session key with the requesting party; the requesting party A receiving the response message, verifying the validity of the message authentication code in the message based on the temporary key, and if valid, obtaining the session key from the response message. The implementation of this application reduces the complexity of communication while improving the security of the communication process and both parties.
Owner:SHANGHAI JIAOTONG UNIV

SECURE KEY DELIVERY

UndeterminedDE102026100592A1EngineeringBus
Approaches in accordance with various illustrative embodiments provide encryption of communications entering and leaving a device, such as a chip or proprietary bus. The encryption can take place in a central root of trust (RoT), which may include agents for individual communication protocols to generate session keys used to encrypt communications for individual sessions. The data can then be sent to a crypto engine for the respective communication protocol.A key tunneling unit can be used to receive a packaged session key over the public bus and then unpack the key in hardware. The unpacked session key can then be sent to the appropriate crypto engine without exposing the session key to software running on the device outside the RoT. A nonce can be used with a current derivation key from a set of ephemeral keys to generate a new set of ephemeral keys. These new keys are used to perform various cryptographic operations, thus enabling secure rotation of package keys as well as other keys, such as derivation and message keys.
Owner:NVIDIA CORP

Authentication and security for ultra-high reliability (UHR) roaming

PCT designated stageWO2026112630A1Key distribution for secure communicationSecurity arrangementSecurity associationMaster key
This disclosure provides methods, components, devices and systems for authentication and security for ultra-high reliability (UHR) roaming. Some aspects more specifically relate to devices in a seamless mobility domain (SMD), such as access point (AP) multi-link devices (MLDs) and non-AP MLDs, supporting the generation of different temporal keys (TKs) for each AP MLD. For example, the non-AP MLD may establish, via authenticator associated with the SMD, a pairwise master key security association (PMKSA) and a single pairwise transient key security association (PTKSA). Thus, the non-AP MLD may communicate with a first AP MLD (such as of multiple AP MLDs associated with the SMD) in accordance with a first pairwise transient key (PTK) and, after roaming to a second AP MLD (such as of the multiple AP MLDs), may communicate with the second AP MLD in accordance with a second PTK, where the second TK is different than the first PTK.
Owner:QUALCOMM INC