Patents
Literature
Patsnap Copilot is an intelligent assistant for R&D personnel, combined with Patent DNA, to facilitate innovative research.
Patsnap Copilot

280 results about "Ephemeral key" patented technology

A cryptographic key is called ephemeral if it is generated for each execution of a key establishment process. In some cases ephemeral keys are used more than once, within a single session (e.g., in broadcast applications) where the sender generates only one ephemeral key pair per message and the private key is combined separately with each recipient's public key. Contrast with a static key.

Method and system for automating the recovery of a credential store

A system for automating the recovery of a credential store, in which client software generates a temporary key pair based on a new password, and sends client information including the user's name, the public half of the temporary key pair, and the host name of the client computer system to a server system, from which the client information is passed to a recovery process. The client software process displays a prompt indicating that the user should call a help desk. A help desk administrator verifies the user's identity and approves the user's request by causing an approval message to be sent to the recovery process. The recovery process obtains recovery information consisting of either the decryption key(s) for the credential store, or a decrypted copy of the credential store, and encrypts the recovery information using the temporary public key. The client process downloads the recovery information from the server, and decrypts it using private key of the temporary key pair. The credential store can then be decrypted using the recovery information if necessary, then re-encrypted based on the new password. The encrypted recovery information is stored on the server and re-used for a certain period of time, after which it is deleted, thus allowing multiple copies of the credential store to be conveniently recovered.
Owner:IBM CORP

Method and apparatus for providing a key distribution center without storing long-term server secrets

One embodiment of the present invention provides a system for operating a key distribution center (KDC) that provides keys to facilitate secure communications between clients and servers across a computer network, wherein the system operates without having to store long-term server secrets. The system operates by receiving a communication from a server at the KDC. This communication includes an identifier for the server, as well as a temporary secret key to be used in communications between a client and the server for a limited time period. In response the communication, the system attempts to authenticate the server. If the server is successfully authenticated, the system stores the temporary secret key at the KDC, so that the temporary secret key can be subsequently used to facilitate communications with the server. Upon subsequently receiving a request at the KDC from a client that desires to communicate with the server, the system produces a session key to be used in communications between the client and server, and then creates a ticket to the server by encrypting an identifier for the client and the session key with the temporary secret key for the server. Next, the system assembles a message that includes the identifier for the server, the session key and the ticket to the server, and sends the message to the client in a secure manner. The system subsequently allows the client to forward the ticket to the server in order to initiate communications between the client and the server.
Owner:ORACLE INT CORP

Identity authentication system and method based on electronic identification card

The invention provides an identity authentication system and method based on an electronic identification card. The identity authentication system comprises an intelligent terminal, an operator server, a network identity authentication center and an application platform. The intelligent terminal is used for storing a first temporary secret key only associated with the electronic identification card of a user, and generating to-be-authenticated encryption information and first encryption information. The operator server is used for acquiring the first encryption information, authenticating the first encryption information preliminarily, and then generating second encryption information. The network identity authentication center is used for acquiring the second encryption information, generating a second temporary secret key and authenticated encryption information, and comparing the to-be-authenticated encryption information with the authenticated encryption information so as to realize authentication of the user identity. The application platform is connected with a secret key server. The application platform sends an authentication request and is used for acquiring a result of user identity authentication from the operator server. The first temporary secret key is stored in a safe area of the intelligent terminal, so that the user does not need to carry a hardware carrier and are not worry about risks, such as information leakage and so on when in online payment or online identity authentication.
Owner:尤磊

Secret key management method, device and system

ActiveCN106712932ASolve the problem of requiring a lot of resources to manage symmetric keysSimplify complexityKey distribution for secure communicationCiphertextClient-side
The invention discloses a secret key management method, device and system, and belongs to the technical field of information security. The method comprises the steps that a client side generates a temporary secret key, and the temporary secret key is encrypted by using a public key provided by a background server so that a first cryptograph is obtained and transmitted to the background server; the background server applies a private key corresponding to the public key to decrypt the first cryptograph so as to obtain the temporary secret key, a session key and a key identifier are acquired, and the session key and the key identifier are encrypted by using the temporary secret key so that a second cryptograph is obtained and transmitted to the client side; and the client side applies the temporary secret key to decrypt the second cryptograph so as to obtain the session key and the key identifier, wherein the key identifier is used for identifying the session key, and the session key is used for encrypting the session data. The management complexity of the background server for the secret key can be simplified under the premise of considering the security of the secret key and the efficiency of encryption and decryption so that the processing and storage resources of the background server can be saved.
Owner:TENCENT TECH (SHENZHEN) CO LTD

System and method for dynamic assignment of dialed number identification services in call distribution system

A system and related techniques enhance the generation and delivery of dialed number identification service (DNIS) data to automatic call distributors and other destinations. Unlike conventional DNIS-based (800) or other call centers or other resources whose available DNIS-based identifications can become overtaxed during comparatively high call volumes, according to embodiments of the invention DNIS numbers are dynamically generated from an available pool on a per-call basis under call router supervision. According to embodiments of the invention in one regard, the dynamic DNIS may be associated with that call to the call's particular destination, such as an automatic call distributor, interactive voice response unit or other resource, during the duration of the call for the operative destination, with other calls being locked out from using that DNIS assignment while the call is in progress. The DNIS digits along with other tag or label information may likewise be used as a temporary key to access associated call data, such as dialed number, caller entered or other data or information, which may be stored in a data store for access by customer service representatives (CSRs) or others. After the call is completed, the temporarily assigned DNIS number may be released back to the pool for use by other calls to that destination.
Owner:T MOBILE INNOVATIONS LLC

ID-based authenticated dynamic group key agreement method

The invention relates to an ID-based authenticated dynamic group key agreement method, and belongs to the network communication safety technology field. The method is characterized in that 1, system initialization: a PKG is generated, and system parameters are disclosed; 2, private key extraction generation: every user sends a public key to the PKG, which is used to return a private key to the corresponding user; 3, two rounds of key agreement: a first round of key agreement is carried out in order to authenticate validity of neighbors of a group users and transmit an own temporary key, and a second round of key agreement is carried out after the successful authentication of the neighbors in order to disclose the related information used for generating the group conversation key; 4, the conversation key is calculated by using the information of the last step, and is used for the encryption and the decryption of the inter-group communication. Compared with the prior art, the method provided by the invention is advantageous in that the user dynamic event is supported at the same time of realizing the key agreements, and then the network is provided with the good dynamic performance and the expansibility, and at the same time, the internal attacker can be detected, and under the precondition of guaranteeing the safety performance, the encrypted items are less, and then the calculation quantity and the communication traffic are reduced.
Owner:BEIJING INSTITUTE OF TECHNOLOGYGY

Key agreement method and device

The invention discloses a key agreement method and a device. The method comprises the steps: a first user end obtains a long-term public key of a second user end conducting key agreement session with the first user end from a certificate authority; an ephemeral key of the first user end is selected randomly and the first hash calculation is conducted on the ephemeral key of the first user end and a long-term private key of the first user end to obtain a first intermediate value; according to the first intermediate value and the ephemeral key, first key agreement information is generated; after the first key agreement information is sent to the second user end, second key agreement information returned back from the second user end is received; and according to the second key agreement information, the long-term public key of the second user end, the ephemeral key of the first user end, the long-term private key of the first user end and the session identification of the key agreement session, the first user end conducts the second hash calculation to obtain a shared key. The method and the device improve the efficiency of the key agreement, and the long-term key and the ephemeral key of any party can not be simultaneously divulged, thus being capable of guaranteeing the security of agreement.
Owner:THE PLA INFORMATION ENG UNIV

Single interaction authenticated key agreement protocol of identity-based cryptosystem

The invention discloses a single interaction authenticated key agreement protocol of an identity-based cryptosystem, and relates to the field of cryptography. The key agreement efficiency can be effectively enhanced and the interaction frequency can be reduced. The solving technical scheme is that a random number is self-selected through combination of an opposite side public key and an own side private key, and a session key of both communication sides is constructed through bilinear operation and Hash operation. The single interaction authenticated key agreement protocol of the identity-based cryptosystem comprises the following steps that 1) a PKG generates system parameters and generates and distributes corresponding private keys to all the hosts in a local domain; and 2) a client side initiates a key agreement request to a server side and transmits key information, and generates the session key according to the algorithm and stores the session key. Natural binding of the identity and the public key is completed based on the identity-based cryptographic technology so that use of a certificate can be avoided; a master key and a temporary key are combined so as to meet the known session key security, partial forward security, partial key resistant disguise leaking, unknown key resistant sharing, message independence and known session temporary secret information security and resist the man-in-the-middle attack; and operation is easy and convenient and the computational complexity is low.
Owner:NAT UNIV OF DEFENSE TECH

Secured logon method for variable secret key encryption under HTTP

InactiveCN104580248AHas a life cycleEnsure safetyTransmissionPlaintextThird party
The invention relates to a secured logon method for variable secret key encryption under an HTTP. The method includes the following steps that a server terminal generates a temporary secret key K according to a login authentication request of a client terminal, and the temporary secret key is sent back to the client terminal and cached at the client terminal; the client terminal generates user information abstract data Hp1 according to a clear-text password and the temporary secret key in an encryption mode; whether the temporary secret key K with the IP being a key value exists or not is inquired by the server terminal according to the login authentication request, and if not, it is judged that the login authentication fails; if yes, a user password of the server terminal is inquired, server terminal information abstract data Hp2 are generated according to the user password of the server terminal and the temporary secret key, the Hp2 is compared with the Hp1, and whether the login authentication fails or succeeds is judged. According to the secured logon method, the secret key and the data are both dynamic, an illegal third party cannot calculate the password data used by current login, and therefore the technical problem that the security is low due to the fact that the passwords are likely to be leaked or forged during login authentication in the prior art can be solved.
Owner:中復保有限公司

Method and device for ownership transfer of radio frequency identification (RFID) tag

The invention discloses a method and a device for ownership transfer of a radio frequency identification (RFID) tag. Ownership transfer of the RFID tag is achieved through the RFID tag and a RFID reader-writer of an original owner and secret key updating of the RFID tag and a RFID reader-writer of a new owner. A temporary secret key Ktemp for the RFID tag is arranged by the RFID reader-writer of the original owner through shared ciphertext Kold. After the Ktemp is transmitted to the RFID reader-writer of the new owner through a secure channel, a temporary secret key in the RFID reader-writer of the original owner is deleted. After the RFID tag is read and authenticated by the RFID reader-writer of the new owner through tag identification (ID) and the temporary secret key save in a background server, a new secret key Knew is updated and set to replace the temporary secret key Ktemp. A hash function and an exclusive-or operation are led in the transfer of the RFID tag, secret keys of the RFID reader-writer of the original owner and the RFID reader-writer of the new owner are updated successively through the RFID tag so as to achieve that ownership of the RFID tag is transferred from a commercial retail organization to consumers really, the RFID tag on purchased commodities can be controlled by the consumers totally, and tag information illegal stealing of other people can be prevented.
Owner:深联致远(北京)科技有限公司
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products