Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

51 results about "Hardware security module" patented technology

A hardware security module (HSM) is a physical computing device that safeguards and manages digital keys for strong authentication and provides cryptoprocessing. These modules traditionally come in the form of a plug-in card or an external device that attaches directly to a computer or network server. A hardware security module contains one or more secure cryptoprocessor chips.

Virtualizing secure vault of data processing unit for secure hardware security module for hosts

PendingUS20260187257A1VirtualizationHardware security module
A system and method of securing and virtualizing firmware trusted platform modules (TPMs) for virtualizing a hardware security module (HSM) for a host within a network fabric is provided. The system and method include operably coupling a set of components associated with a host comprising a data processing unit (DPU) secure vault and a firmware trusted platform module (TPM). The firmware TPM is configured as a virtual firmware TPM. The DPU secure vault secures the virtual firmware TPM into one or more virtual firmware TPMs based on one or more partitions configured with the DPU secure vault. A virtual TPM manager communicatively coupled to the DPU secure vault manages one or more virtual TPMs for hosting a set of Virtual Machines (VMs) or Containers.
Owner:CISCO TECHNOLOGY INC

Zoned system for a vehicle

A computer-implemented method causes a data processing hardware to perform operations when executed by the data processing hardware. The operations include providing a common encryption key and a unique encryption key at a system on a chip (SoC) of a radar module, providing a unique key pair at the SoC, the unique key pair including a unique public key and a unique private key, and encrypting software with the common encryption key. The operations further include generating a secure boot certificate for the encrypted software, signing the secure boot certificate using the unique private key, and writing the encrypted software to an external flash memory. The operations further include updating the software at the SoC, verifying the software update via a regional public key, and signing the secure boot certificate with a device unique private key via a hardware security module (HSM) of the SoC.
Owner:GM GLOBAL TECHNOLOGY OPERATIONS LLC

Hardware security modules integrated in memory devices and systems

PCT designated stageWO2026136276A1Unauthorized memory use protectionDigital data protectionControl storeHardware security module
This application is directed to memory methods, systems, and devices for managing secure data and implementing secure operations locally. In one aspect, a memory device includes a non-volatile memory, a memory controller, a secure controller, and an integrated memory enclosure. The non-volatile memory includes a secure memory portion and a data memory portion. The secure memory portion stores secure data, and the data memory portion stores user data. The memory controller is coupled to the data memory portion, and configured to receive a data access request and access the user data in response to the data access request. The secure controller is coupled to the secure memory portion, and configured to access the secure data and implement a secure operation on the secure data. The integrated memory enclosure encloses the secure controller, the memory controller, and the non-volatile memory.
Owner:SK HYNIX NAND PRODUCT SOLUTIONS CORP

Bluetooth data transmission encryption method based on intelligent terminal

The application relates to the field of Bluetooth data transmission security technology and discloses a Bluetooth data transmission encryption method based on an intelligent terminal. After the intelligent terminal and a receiving device establish a Bluetooth connection, a temporary session key is generated. A built-in hardware security module of the terminal is accessed to obtain a pre-stored root key. The root key and the temporary session key are used as inputs to generate a session encryption key with higher strength through a key derivation function. The session encryption key is used to encrypt data to be transmitted by using a symmetric encryption algorithm. The hash value of the original transmission data is independently calculated based on a hash function and used as an integrity check code of the data. The encrypted data and the integrity check code are encapsulated and sent to the receiving device through a Bluetooth protocol stack. The application strengthens the security of the key by combining hardware security and dynamic negotiation, and improves the anti-attack ability and reliability of Bluetooth data transmission by adopting an independent integrity check mechanism.
Owner:深圳市乾海芯联科技有限公司 +1

Secure hardware programmable architecture

ActiveCN114616566BInternal/peripheral component protectionComputer architectureHardware security module
The invention relates to an electrical structure comprising: (a) functional modules, which are both capable of acting as transaction initiators and as transaction targets, so that a transaction initiator functional module can require a transaction target functional module to perform functions for and on its behalf; (b) a first interconnect architecture connecting the functional modules and providing communication between them; wherein the (electrical) structure is arranged such that a selected transaction initiator functional module is capable of temporarily exclusively accessing the transaction target functional module(s) performing functions for and on its behalf to ensure that transaction initiator functional modules other than the selected transaction initiator functional module cannot access it uncontrolled, wherein said selected transaction initiator functional module is a hardware security module.
Owner:SILICON MOBILITY SAS

System and method for cryptographically sovereign, hardware-rooted identity and execution authority for autonomous ai agents

PendingUS20260189392A1Hardware security moduleDatabase
A system and method provide cryptographically sovereign, hardware-rooted identity and execution authority for autonomous AI agents. Each agent is assigned a permanent Sovereign Agent Identity Token (SAIT) that is physically bound at manufacture or first boot to a hardware security module on the host device. The SAIT carries an immutable genesis block containing the agent's model lineage, training data hashes, owner chain, and current compliance state. No agent may initialize, generate plans, or issue actuation commands unless a valid, live SAIT is presented and attested by the hardware. Remote revocation or suspension of the SAIT instantly renders the agent inoperable across all instances. The system includes deterministic execution gating, swarm propagation of revocation signals, and immutable provenance logging. The invention establishes the root of trust for agent existence and action, transforming digital governance into physical, non-bypassable control.
Owner:BICKERSTAFF III GEORGE WILLIAM

Method for executing an application program using a hardware security module equipped with secure memory.

ActiveFR3164301B1Hardware security moduleSoftware engineering
A method for executing a program by a secure processor (SPROC), comprising the steps of providing a non-volatile memory space (DMEM) for storing the data necessary for executing the application program, providing in the non-volatile memory space a first database (ADB) and storing the data in the first database (ADB), and a second database (TDB) configured to form a sparse Merkle tree, providing at least one management processor (DPROC) to manage the first and second databases, reading (S52) into the first database (ADB) data created or modified by the secure processor, and updating the second database after each modification of the contents of the first database, so that its current state reflects the current state of the first database.calculate or determine and then store in secure non-volatile memory (SMEM) a root hash code (RHm) of the Merkle tree representative of the current state of the second database. Abbreviated figure: Figure 1,
Owner:LEDGER

An ap platform management system and method

PendingCN122310512ASecure stateTerm memory
This application provides an AP platform management system and method. In this system, after receiving a startup request from an in-vehicle application, the EM module directly triggers the HSM module to verify the application's legitimacy. After successful application verification, the EM module triggers the runtime monitoring module to perform security monitoring on the application's real-time runtime data, enabling timely identification of abnormal behaviors caused by memory injection and malicious code execution. Simultaneously, the policy analysis module performs risk analysis based on a preset security policy library and outputs response strategies. The EM module then executes the corresponding security response operations, thereby establishing a complete application security status management system and a closed loop for security incident handling. This achieves deep collaboration between the EM and hardware security modules, providing stable security support covering the entire application lifecycle for the AP platform and effectively enhancing the AP platform's ability to respond to various cybersecurity threats.
Owner:NEUSOFT REACH AUTOMOBILE TECH (SHENYANG) CO LTD

A virtual electric field automatic transaction settlement method using a blockchain smart contract

The application belongs to the technical field of power systems and relates to a virtual electric field automatic transaction settlement method using a blockchain smart contract, wherein a hardware security module integrated with a built-in unique private key of an electric energy metering device is used to register and generate a trusted digital identity on a main settlement chain, an energy contract is created on a double-chain architecture, and a performance position state machine containing balance, surplus and deficit states is initialized; metering credentials signed by the hardware security module form a trusted data stream after being verified on the chain; a dynamic settlement contract calculates a performance deviation value in real time, automatically triggers state migration and generates economic adjustment instructions, guides users to adjust their power consumption behavior through real-time cost changes, forms a closed-loop regulation and control, and generates a final net settlement list to complete on-chain clearing after the contract expires; and the application solves the problems that the prior art cannot provide real-time price signals and economic feedback for participants and effectively guide each energy node to adjust its power generation or power consumption behavior according to real-time demand of a power grid.
Owner:SHANDONG PANHAI OPTOELECTRONIC TECHNOLOGY CO LTD

A method for processing financial data with improved security

This invention discloses a method for improving the confidentiality of financial data processing. In the field of information security technology, the method automatically identifies the source department and data type based on the submitter information of the financial data, determines the confidentiality level of the data using a confidentiality level rating table, and dynamically parses the key length and arrangement rules accordingly. It uses the characterization conversion results of the submitter's account and submission time, along with a random string, to perform multi-source fusion to construct a high-entropy basic key. After being hosted by a hardware security module, this key is intercepted to form the final encryption key, ensuring its unpredictability and security. An encryption algorithm combined with a random initialization vector is used to encrypt the original data text, ensuring the confidentiality and integrity of the data. The encrypted data is segmented according to the key length, generating a random number sequence and binding it to the data block. The number mapping relationship is stored on the blockchain. After being encapsulated with a unique identifier, the data block is randomly shuffled and further divided, and finally distributed and stored in the cloud.
Owner:JINAN JUSHI INFORMATION TECH CO LTD

Controller and its safe operation method and system

PendingCN122433138AHardware security moduleControl engineering
The application relates to the technical field of embedded systems, and provides a controller and a safe operation method and system thereof. The method is applied to a controller without a hardware security module, and comprises the following steps: obtaining device unique characteristic information of the controller; generating a device root key through a key derivation function based on the device unique characteristic information; wherein the device root key exists in a volatile memory; deriving a function key based on the device root key; and performing a safe operation on target data by using the function key. The safe operation of the controller is realized by combining the device unique characteristic information in a software mode, and security threats such as firmware tampering and data leakage are effectively resisted.
Owner:WUHAN JIANGXIA CHUNENG AUTOMOBILE TECHNOLOGY R&D CO LTD

Procedure for resetting a battery system

PendingDE102024211352A1Cells structural combinationPlatform integrity maintainanceThird partyHardware security module
The invention relates to a method for resetting a battery system (10) with at least one battery (12) and a hardware security module (14) from a primary application to a secondary application (38). The following process steps are carried out: First, battery systems (10) are collected by a third party at a production facility (28) to prepare them for the secondary application (38). Next, deactivation software (16) is created, which deletes the primary application of the battery systems (10) and includes a generic interface (20) that serves as a software interface for the third party to upload the secondary application (38) to the battery system (10). Finally, hardware security module deactivation software (22) is created, which disables security mechanisms such as authentication, signature verification, and overwrite protection.Subsequently, the deactivation software (16) is uploaded to the battery system (10) to be reset at the production facility (28) via an interface (30) as part of factory programming after authentication using a factory key (32), such that the accompanying hardware safety module deactivation software (22) allows the secondary application (38) to be uploaded. Finally, the generic programming interface (30) is used to prepare for uploading the secondary application (38) to the reset battery system (10).
Owner:ROBERT BOSCH GMBH

Single user binded hardware security module (sub HSM)

The present invention discloses a SUB HSM (1) in the form of a wirelessly charged battery powered card, comprises a card body (1) integrated with a plurality of hardware modules; wherein the hardware modules include: one or more peripheral modules to which a user can interact therewith for providing input and / or output data, a transmission module (20) for establishing a data transfer link to connect with a device which a user interface is operated thereon via a communication protocol, a battery module (30) for supply electricity to the operational modules, and a centralised microcontroller unit (40) for controlling the operations of the hardware modules.
Owner:FOO YONG KWANG

Method for resetting a battery system with at least one battery

The invention relates to a method for resetting a battery system (12) with at least one battery (14) comprising at least one hardware security module (16) for a secondary application (38) of the battery system (12). These applications are protected by a vehicle manufacturer (30) through authentication and / or crypto-based signature verification. Deactivation software (18) is used, which puts the battery (14) and / or the battery system (12) into a state that enables resetting. The deactivation software (18) is signed by a vehicle manufacturer key (32) of the vehicle manufacturer (30). By uploading the vehicle manufacturer-signed deactivation software (18), the current software and data of the vehicle manufacturer (30) and / or the end user are deleted, and a third party is enabled to upload its own software for the secondary application (38) to the battery (14) and / or the battery management system (12).This overwrites the previously installed, vehicle manufacturer-signed deactivation software (18). Furthermore, the invention relates to the use of the method for resetting a battery system (12) with at least one battery (14) for a secondary application (38).
Owner:ROBERT BOSCH GMBH

A vehicle networking dynamic password generation method and system, and a vehicle

PendingCN122372187AHardware security modulePassword
The application discloses a kind of vehicle networking dynamic password generation method, system and vehicle, generation method includes: reading the unique identification code VIN code of vehicle and time stamp;Time stamp is intercepted to hour precision;VIN is spliced with time stamp to form original message, and is carried out encoding conversion;Using hash algorithm, the original message after encoding is operated, and hash digest is generated;Using the preset key of car end and message authentication code algorithm, hash digest is operated, and message authentication code is generated;The preset length byte of message authentication code is cut off as dynamic password, symmetric key is stored in the hardware security module of car end, the present application is combined with the unique identification code of vehicle and hour precision time stamp, the time limit and efficiency binding characteristics of password are realized, through two layers of algorithm encryption and selection fixed length byte, while maintaining lightweight calculation, greatly increase attack cost and uncertainty, effectively improve the security and reliability of password.
Owner:CHINA FAW CO LTD

An AI model copyright protection and trusted inference method and system

This invention provides a method and system for AI model copyright protection and trusted reasoning, comprising the following steps: The model provider encrypts the AI ​​model using a first key and sends the first key to a verification service; the verification service configures access control conditions for the first key, the access control conditions being associated with the hardware identity identifier and platform trusted state requirements of the target deployment platform; when the deployment platform requests to load the encrypted AI model, a remote proof and key release process is executed: The deployment platform generates proof information containing its hardware identity identifier and current platform state measurement value; the proof information is sent to the verification service; the verification service verifies the authenticity of the proof information and determines whether the hardware identity identifier and platform state measurement value comply with the access control conditions; if they comply, the verification service encrypts the first key using an encryption key corresponding to the deployment platform's hardware security module and then issues it; the deployment platform decrypts to obtain the first key.
Owner:XIAN THERMAL POWER RES INST CO LTD +2

Method for resetting a hardware security module-free battery system with at least one battery and a battery management system

PendingDE102024211351A1Software testing/debuggingPlatform integrity maintainanceThird partyHardware security module
The invention relates to a method for resetting a hardware safety module-free battery system (10) from a primary application to a secondary application (38), comprising the following process steps: A deactivation software (16) is created which deletes the primary application, performs a software diagnostic, and includes a generic interface (20) for a third party to upload the secondary application (38) to the hardware safety module-free battery system (10). This is followed by the creation of a software package (26) containing the deactivation software (16) and an activator (24) of the deactivation software (16). The software package (26) is then delivered to a vehicle manufacturer (34), who installs the software package (26) onto the hardware safety module-free battery system (10) to be reset as part of a customer update performed by the vehicle manufacturer.This is followed by the deactivation of security mechanisms of the hardware security module-free battery system (10) to be reset, initiated by the installation of the software package (26), the deletion of memory areas of the hardware security module-free battery system (10) containing sensitive data of the first application, and the installation of the second application (38) on the now reset battery system (10).
Owner:ROBERT BOSCH GMBH

Hardware Security Module Implementation as Edge Devices in a Networked System

Hardware security modules (HSM) may be implemented at distributed edge devices to provide faster and dynamic processing of data. HSM-implemented edge devices may be used to process data to enhance data security. For example, HSM edge devices may provide encryption, decryption, data masking, tokenization, or anonymization. The HSM edge devices may interface with one or more blockchains to invoke smart contracts, and to record data transaction events. In some examples, smart contracts may be used to provide uniform policies and functions across multiple edge devices and their corresponding end user devices.
Owner:BANK OF AMERICA CORP

Key processing method based on hardware security module, storage medium and device

PendingCN122451925AComputer hardwareHardware security module
Embodiments of the present application provide a key processing method based on a hardware security module, a storage medium and an equipment. The method comprises the following steps: in response to an operation request issued by a user through an application program, reading an encryption key from a preset hardware security module, and performing decryption processing on the encryption key to obtain a decrypted key; wherein the operation request indicates that an operation is performed on to-be-processed data; and the to-be-processed data indicated by the operation request is called from a storage space different from a storage space where the preset hardware security module is located; and then, in the preset hardware security module, the to-be-processed data called is processed according to the decrypted key to obtain processed data. The method is used to achieve the effect of high security, low cost and simple operation of key use.
Owner:RICHFIT INFORMATION TECH +1

REGIONALIZATION SYSTEM FOR A VEHICLE

PendingDE102025102094A1Platform integrity maintainanceSoftware deploymentHardware security moduleSoftware update
A computer-implemented procedure, when executed by data processing hardware, causes the data processing hardware to perform operations. These operations include providing a shared encryption key and a unique encryption key in a system-on-chip (SoC) of a radar module, providing a unique key pair on the SoC, where the unique key pair comprises a unique public key and a unique private key, and encrypting software using the shared encryption key. The operations also include generating a secure boot certificate for the encrypted software, signing the secure boot certificate using the unique private key, and writing the encrypted software to external flash memory.The processes also include updating the software on the SoC, verifying the software update via a regional public key, and signing the secure boot certificate with a device-native private key via a hardware security module (HSM) of the SoC.
Owner:GM GLOBAL TECHNOLOGY OPERATIONS LLC

A vehicle information security risk threat protection assessment method and electronic device

PendingCN122160128AKey distribution for secure communicationFull life cycleHardware security module
The present application relates to the technical field of vehicle information security, and specifically discloses a vehicle information security risk threat protection evaluation method and electronic equipment, wherein the present application identifies vehicle component security nodes and vehicle component threat behavior nodes, comprehensively analyzes a multi-dimensional security evaluation index system according to the vehicle component threat behavior nodes, determines the security risk level of the vehicle component, outputs a security risk starting process according to the security risk level of the vehicle component by building a hardware security architecture, realizes security boot verification, designs a security flashing process and a security access control process to realize software security protection, realizes unified management, forwarding and execution of security service requests based on a layered software architecture, adopts an encryption task publishing and notification mechanism to realize efficient cooperation with a hardware security module, and realizes full life cycle management of security keys, thereby significantly improving the effectiveness of vehicle information security protection and providing reliable protection for safe operation of vehicles.
Owner:JIANGSU HEYI TECH CO LTD

Blockchain-based power plant material procurement traceability and collaborative management system

PendingCN122452987AData integrityOriginal data
The application discloses a blockchain-based power plant material procurement traceability and collaborative management system, which comprises a data acquisition layer, a blockchain network layer, an intelligent contract layer and an application layer.The data acquisition layer is used for collecting original data of material production, logistics, quality inspection and acceptance in real time.The blockchain network layer is used for storing data of each link and hash digest, and realizing data sharing and permission control across organizations.The intelligent contract layer is used for realizing cooperation among intelligent contracts through an event listening mechanism, and automatically triggering the execution of associated contracts according to business state changes.The application layer is used for data visualization, business operation and risk early warning.The application deploys heterogeneous Internet of Things terminals and edge computing units in workshops of suppliers, logistics vehicles, quality inspection laboratories and power plant warehouses, combines hardware security modules and national encryption algorithms to encrypt and sign data, and verifies equipment identity and data integrity in the blockchain network layer, so that it is ensured that the chained data is from a trusted device and is irrefutable, and the problem of trusted data source is solved.
Owner:HUANENG POWER INT INC

Method for resetting a battery system with at least one battery

PendingDE102024211342A1Batteries circuit arrangementsElectric powerHardware security moduleElectrical battery
The invention relates to a method for resetting a battery system (12) with at least one battery (14) and at least one hardware safety module (16) for a secondary application (38), comprising the following process steps: A deactivation software (18) is created which deletes a primary application of the battery system (12), initiates a software diagnostic procedure, and includes a generic programming interface (20) that represents a software interface (22) for uploading the secondary application (38) to the battery system (12) to be reset. This is followed by the creation of a series software (10) that latently contains the previously created deactivation software (18), which can be activated by means of an authenticatable activator (34). The series software (10), which contains the latent deactivation software (18), is uploaded to the battery system (12) as part of a regular vehicle manufacturer software update.Once the battery system (12) has been reset for the secondary application (38), the reset is activated by the vehicle manufacturer (30) after authentication using a crypto-based key (36). Furthermore, the invention relates to the use of the method for resetting a battery system (12) with a primary application to a secondary application (38) different from the primary application.
Owner:ROBERT BOSCH GMBH

Method for quantum-secured communication

A method of encryption for quantum-secured communication includes structuring a pair of quantum-enabled hardware security modules to include an interface to a temporarily common quantum channel and an interface to a communication channel. A secret key is shared with the pair of quantum-enabled hardware security modules for a symmetrical encryption between the pair of quantum-enabled hardware security module. The secret key is obtained using quantum key distribution via the temporarily common quantum channel. The temporarily common quantum channel is disconnected from at least one of the pair of quantum-enabled hardware security modules and a communication network is structured to include at least two nodes configured to communicate using symmetrical encryption between the pair of quantum-enabled hardware security modules sharing a same secret key.
Owner:UNIV OF HAMBURG

Security control and management method using commercial mobile terminal

PCT designated stageWO2026127159A1Securing communicationPrivate networkHardware security module
A method for controlling and managing security in a military unit using a commercial mobile terminal may comprise the steps of: authenticating a hardware security module mounted on the commercial mobile terminal; activating a virtual private network (VPN) client of the commercial mobile terminal when the authentication of the hardware security module is successful; and synchronizing a network connection state of the commercial mobile terminal with a mobile device management (MDM) server through the VPN client, and applying a security policy to the commercial mobile terminal.
Owner:AHOPE

Qkd remote key distribution method, system, device and medium based on pqc channel

ActiveCN121923817BImplement identity authenticationlower the thresholdRisk exposureHardware security module
The present application belongs to the technical field of quantum communication, and particularly relates to a QKD remote key distribution method, system, device and medium based on a PQC channel. In view of the fact that the prior art fails to coordinate performance overhead and risk exposure, the present application adopts the following technical solution: a QKD remote key distribution method based on a PQC channel, comprising: pre-storing a parent key in a service end in a hardware security module; establishing a temporary, forward-secure, anti-quantum-attack PQC authentication key exchange channel between a client and the service end, the service end performing identity authentication by using a standard PQC digital signature, and the client indirectly implementing identity authentication of the service end through a key encapsulation mechanism; the remotely distributed key is a one-time business key; and the business keys are used for encrypted communication between clients. The present application has the beneficial effect of resolving the contradiction between performance overhead and risk exposure through an asymmetric authentication protocol and a strict risk isolation architecture.
Owner:ELECTRIC POWER RES INST OF STATE GRID ZHEJIANG ELECTRIC POWER COMAPNY

Security systems and methods for managing information within security systems

This invention provides a method for managing information in security systems and security devices that securely manage information for protecting data. [Solution] The security system 1 includes a manufacturer's HSM (hardware security module) and a user's HSM. The manufacturer's HSM includes a communication unit 35, a secure ROM 33, and a CPU 31. The secure ROM stores key information registered in the user's HSM used by a specific user. The CPU outputs the key information stored in the secure ROM via the communication unit 35 when the biometric authentication of the specific user by the biometric authentication device is successful. The user's HSM includes a communication unit 45, a ROM 42, and a CPU 41. The ROM 42 has a predetermined memory area for storing key information. The CPU 41 obtains the key information output by the manufacturer's HSM via the communication unit 45 when the biometric authentication of the specific user by the biometric authentication device is successful, and registers the key information in the predetermined memory area.
Owner:KK TOSHIBA