Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

20 results about "Key establishment" patented technology

Key establishment and secure communications based on satellite-connected entropy sources

Systems and techniques for secure communications and distribution of random values, provided via satellite communications, are described. These random values are generated from one or more ground-based entropy sources (e.g., quantum random number generators (QRNGs) at terrestrial locations), and optionally combined with values from satellite-based entropy sources (e.g., QRNGs at non-terrestrial locations). An example method includes: receiving a first random value generated by a first QRNG at a terrestrial location; receiving a second random value and a third random value via at least one satellite communication, each additional random value generated by other QRNGs; and generating a cryptographic key based on the first random value, the second random value, and the third random value. The cryptographic key may be produced by a key derivation function that combines the random values, and the cryptographic key may be used to establish a secure communication session.
Owner:WELLS FARGO BANK NA

Non-integrated access protocol data unit session management

Methods, systems, and devices for wireless communications are described. A network entity (e.g., a user equipment (UE)) may establish, via a first radio access technology (RAT), a secure tunnel between the network entity and a user plane function (UPF) of a core network associated with a second RAT that is different from the first RAT. The network entity may perform, via the secure tunnel, an authentication and key establishment procedure with the UPF to obtain a key. The network entity may establish one or more protocol data unit (PDU) sessions with the UPF. The network entity may communicate, using the key, data communications with the core network via the UPF and via the one or more PDU sessions.
Owner:QUALCOMM INC

New-generation cryptographic system and method based on physics quantum dynamic public key and cloud entropy synchronous private key, terminal, server and medium

The invention discloses a new-generation cryptographic system and method based on a physics quantum dynamic public key and a cloud entropy synchronous private key, a terminal, a server and a medium, and relates to the technical field of quantum information technology, cryptography and Internet of Things security crossing. The system comprises a terminal, a server and a cloud entropy synchronization private key library, and the terminal is configured to generate a quantum random number by using a quantum random number generation module, generate a synchronization parameter based on the quantum random number, and send the synchronization parameter or a physics quantum dynamic public key exported by the synchronization parameter to the cloud entropy synchronization server; and the terminal and the cloud entropy synchronization server are further configured to determine the same target entropy material from the cloud entropy synchronization private key library by applying the same cloud entropy mapping algorithm based on the synchronization parameter, and generate the same session key based on the target entropy material. According to the key system, non-interactive key establishment, forward secrecy and endogenous quantum computing attack resistance are realized.
Owner:ANHUI YUNXI TECH CO LTD +1

Systems and methods for AI directed tiered post quantum protection of multimodal data

Training an artificial intelligence model to categorize data by sensitivity and for applying the model to selectively protect sensitive portions of multimodal datasets. Sensitive training data can be obfuscated with synthetic noise or randomized errors to preserve confidentiality while enabling the model to learn patterns correlated with sensitivity. The trained model is validated on labeled data and can be refined as classification standards evolve. In operation, the classifier assigns sensitivity levels to data elements and directs tiered protection. Elements assigned to a higher relative sensitivity classification level are protected using post-quantum key establishment, for example a key encapsulation mechanism, combined with symmetric authenticated encryption of payloads, and associated metadata is authenticated using a post-quantum digital signature scheme. Less sensitive elements can be protected using conventional symmetric encryption for efficiency. This approach automates sensitivity classification, optimizes cryptographic resource allocation, and improves confidentiality and integrity for simulation and mission data.
Owner:UNIVERSITY OF CENTRAL FLORIDA RESEARCH FOUNDATION INC

Non-integrated access protocol data unit session management

Methods, systems, and devices for wireless communications are described. A network entity (e.g., a user equipment (UE)) may establish, via a first radio access technology (RAT), a secure tunnel between the network entity and a user plane function (UPF) of a core network associated with a second RAT that is different from the first RAT. The network entity may perform, via the secure tunnel, an authentication and key establishment procedure with the UPF to obtain a key. The network entity may establish one or more protocol data unit (PDU) sessions with the UPF. The network entity may communicate, using the key, data communications with the core network via the UPF and via the one or more PDU sessions.
Owner:QUALCOMM INC

Remote authentication method, apparatus, device, storage medium and program product

The present disclosure provides a remote authentication method, device, equipment, storage medium and program product. The method comprises: providing a plurality of key establishment modes for a user, including a key transmission mode, a key negotiation mode and a public key distribution mode; obtaining verifier identity information and a target key establishment mode set by the user based on the plurality of key establishment modes, and generating configuration information based on the target key establishment mode and the verifier identity information; generating a first temporary public key based on the target key establishment mode; obtaining authentication reference information from a specified authentication file based on the first temporary public key, a first cryptographic hash of the verifier identity information and the configuration information; wherein the authentication reference information is used to provide to the verifier to authenticate whether the prover is trustworthy; generating an authentication request based on the configuration information, the first cryptographic hash, the first temporary public key and the authentication reference information; sending the authentication request to the verifier, and receiving an authentication result from the verifier for the authentication request.
Owner:DOUYIN VISION CO LTD

Data transmission method and apparatus

PCT designated stageWO2026137797A1PlaintextComputation complexity
Provided are a data transmission method and apparatus, relating to the technical field of computers. The method comprises: a transmitting node encrypts, on the basis of a symmetric key of the transmitting node, data to be transmitted, so as to obtain data ciphertext; the transmitting node encapsulates the symmetric key on the basis of a public key of the transmitting node and a homomorphic encryption algorithm, so as to obtain first key ciphertext; the transmitting node transmits the data ciphertext and the first key ciphertext to an intermediate node; the intermediate node executes a re-encapsulation operation on the first key ciphertext on the basis of a key switch key, so as to obtain second key ciphertext, an encapsulation key of the second key ciphertext being a public key of a receiving node; the intermediate node transmits the data ciphertext and the second key ciphertext to the receiving node; the receiving node decrypts the second key ciphertext to obtain the symmetric key; and then decrypts the data ciphertext by using the symmetric key, so as to obtain plaintext of the data to be transmitted. In this way, end-to-end secure data transmission is achieved, while computational complexity and communication volume during key establishment are effectively reduced.
Owner:HUAWEI TECH CO LTD

WIA-FA secure communication method based on hybrid public key encryption

The invention relates to a WIA-FA secure communication method based on hybrid public key encryption, and belongs to the technical field of communication, and the method comprises the following steps: S1, employing an improved WIA-FA device to safely join a process to establish a public key; s2, establishing a secret key based on a hybrid public key encryption (HPKE) method; and S3, the two communication parties use the newly established session key and the AEAD algorithm to perform encryption and integrity verification on all process data and control commands so as to construct an end-to-end secure communication link. According to the invention, an independent key packaging mechanism is introduced in the handshake stage of the key establishment of the equipment, so that the equipment can realize the confidentiality of a session key when the key is established, and also can generate a data encryption key, a broadcast data key, a unicast data key and a key encryption key which are directly suitable for link layer communication. Therefore, the overall security and flexibility are remarkably improved, and the compatibility with the existing standard message is ensured.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Multi-party and multi-use quantum resistant signatures and key establishment

A system for making digital signatures includes plural signers determining cleartext bits to sign in response to a hash of a pre-image known to the respective signer and message. Another system uses one-way functions and a plurality of authentication paths per signature. A key information distribution system uses physical media, physical media revealing means, and changing the configuration of the physical media revealing means to reveal secret indicia to observers.
Owner:PRIVATEGRITY CORP

System and method for key establishment

A computer-implemented method of establishing a key between a first and a second device in a network including a first and a second key node, the first and second key nodes with access to a same set of keys, the method including receiving, at the first device, data representative of first key establishment data from the first key node and the second device for calculating a Bilocation Key from a selected key from the set of keys; and receiving, at the second device, data representative of second key establishment data from the first device for requesting the Bilocation Key from the second key node, wherein the Bilocation Key is calculated based on the selected key from the set of keys; and wherein the first and second devices use corresponding Bilocation Keys to each generate a Final Key based on an agreed portion of the first and second key establishment data.
Owner:ARQIT LTD

Key establishment and secure communications using satellite-provided random number values

Systems and techniques for secure communications and distribution of random values for cryptographic key generation, coordinated with the use of specific key generation parameters, are described. An example method includes: receiving a first random value and a second random value generated from at least one quantum random number generator (QRNG), with at least one of the first random value and the second random value being provided from a satellite communication; obtaining key generation parameters associated with cryptographic key generation, where the key generation parameters specify a specific combination of the first random value and the second random value; and generating a cryptographic key, using the specific combination of the first random value and the second random value, as a seed to a cryptographic function.
Owner:WELLS FARGO BANK NA

Dual key establishment between two measurement states

Systems and techniques for key establishment are described. For example, a process may store a first trusted measurement of a first entity in a first storage location during a first encryption key derivation, store an expected measurement of a second entity in a second storage location, and generate a first instance of an encryption key using the first trusted measurement, the expected measurement, and a key derivation function (KDF). The process may obtain an expected measurement as a second trusted measurement for a second entity and store it in a second storage location during a second encryption key derivation, obtain a first trusted measurement as a second expected measurement and store it in the first storage location, and generating a second instance of the encryption key using the second expected measurement, the second trusted measurement, and the key derivation function.
Owner:QUALCOMM INC

A shared key establishment method in a quantum computing environment

This invention discloses a shared key establishment method in a quantum computing environment, relating to the field of shared key establishment technology. The method includes obtaining the cost of each quantum state, generating random numbers using a quantum random number generator, statistically analyzing the average length and number of random numbers generated per unit time for different quantum states, preparing corresponding quantum state keys based on the encoded random numbers, and recording the average preparation time for different quantum state keys; calculating the error rate of different quantum states; calculating a first key establishment evaluation coefficient based on the average length and number of random numbers generated per unit time; calculating a second key establishment evaluation coefficient based on the average preparation time and error rate; and calculating a comprehensive evaluation index for each quantum state based on the first key establishment evaluation coefficient, the second key establishment evaluation coefficient, and the cost of each quantum state to determine the key establishment quantum state. This method can adapt to different application scenarios and needs.
Owner:NANTONG DAGUANG TECH CO LTD

Key establishment and secure communications based on satellite entropy sources

Systems and techniques for secure communications and distribution of random values, produced from at least two satellite entropy sources, are described. These random values may be provided by respective quantum random number generators (QRNGs) at separate satellites, and optionally combined with values from ground-based entropy sources (e.g., QRNGs at terrestrial locations). An example method includes: receiving a first random value and a second random value via at least one satellite communication, where the first random value is generated by a first QRNG at a first satellite, and the second random value is generated by a second QRNG at a second satellite; and generating a cryptographic key based on the first random value and the second random value. The cryptographic key may be produced by a key derivation function that combines the random values, and the cryptographic key may be used to establish a secure communication session.
Owner:WELLS FARGO BANK NA

Beidou satellite-oriented end-to-end key negotiation and authentication method and system

The invention discloses a Beidou satellite-oriented end-to-end key negotiation and authentication method and system, belongs to the technical field of satellite communication security, and solves the problem of how to realize secure and efficient bidirectional authentication and key establishment in a resource-constrained environment. According to the method, a ground control station assists a terminal user in completing bidirectional identity authentication and session key negotiation in a Beidou satellite communication environment, and the method comprises the stages of system initialization, user and satellite registration and login and key negotiation. And the lightweight hash operation is adopted to replace public key password operation, so that the communication security is ensured, the communication overhead and the terminal calculation burden are remarkably reduced, and the method is suitable for a Beidou long message communication scene without a ground network and with limited terminal resources.
Owner:STATE GRID ANHUI ELECTRIC POWER CO LTD ELECTRIC POWER SCI RES INST

Protecting user privacy while bootstrapping an application function (AF) key from primary authentication

Methods and apparatus for protecting user privacy while bootstrapping an application function (AF) key from primary authentication are provided herein. In an example, a WTRU derives a KAKMA key for authentication and key management for applications (AKMA). Also, the WTRU derives a KAF key for an AF and a KAF key identity (ID) identifying the KAF key. Further, the KAF key and a KAF key ID are derived based on a freshness parameter, the KAKMA key, an AF ID identifying the AF, and a WTRU ID identifying the WTRU. The WTRU then transmits, to a network node, the freshness parameter, the AF ID and the WTRU ID. Also, the WTRU transmits to the AF, the KAF key ID. Moreover, the WTRU performs mutual authentication with the AF using the KAF key. In an example, the WTRU may also receive a key establishment confirmation, from the AF, for the KAF key.
Owner:INTERDIGITAL PATENT HOLDINGS INC

Protecting user privacy while bootstrapping an application function (AF) key from primary authentication

Methods and apparatus for protecting user privacy while bootstrapping an application function (AF) key from primary authentication are provided herein. In an example, a WTRU derives a KAKMA key for authentication and key management for applications (AKMA). Also, the WTRU derives a KAF key for an AF and a KAF key identity (ID) identifying the KAF key. Further, the KAF key and a KAF key ID are derived based on a freshness parameter, the KAKMA key, an AF ID identifying the AF, and a WTRU ID identifying the WTRU. The WTRU then transmits, to a network node, the freshness parameter, the AF ID and the WTRU ID. Also, the WTRU transmits to the AF, the KAF key ID. Moreover, the WTRU performs mutual authentication with the AF using the KAF key. In an example, the WTRU may also receive a key establishment confirmation, from the AF, for the KAF key.
Owner:INTERDIGITAL PATENT HOLDINGS INC

Systems and Methods for AI Directed Tiered Post Quantum Protection of Multimodal Data

Training an artificial intelligence model to categorize data by sensitivity and for applying the model to selectively protect sensitive portions of multimodal datasets. Sensitive training data can be obfuscated with synthetic noise or randomized errors to preserve confidentiality while enabling the model to learn patterns correlated with sensitivity. The trained model is validated on labeled data and can be refined as classification standards evolve. In operation, the classifier assigns sensitivity levels to data elements and directs tiered protection. Elements assigned to a higher relative sensitivity classification level are protected using post-quantum key establishment, for example a key encapsulation mechanism, combined with symmetric authenticated encryption of payloads, and associated metadata is authenticated using a post-quantum digital signature scheme. Less sensitive elements can be protected using conventional symmetric encryption for efficiency. This approach automates sensitivity classification, optimizes cryptographic resource allocation, and improves confidentiality and integrity for simulation and mission data.
Owner:UNIVERSITY OF CENTRAL FLORIDA RESEARCH FOUNDATION INC

A data transmission method and apparatus

A data transmission method and apparatus are provided. The method includes: a sending node encrypting data to be transmitted using its own symmetric key to obtain ciphertext; encapsulating the symmetric key using its own public key and a homomorphic encryption algorithm to obtain a first key ciphertext; sending the data ciphertext and the first key ciphertext to an intermediate node; the intermediate node performing a re-encapsulation operation on the first key ciphertext using a key conversion key to obtain a second key ciphertext, wherein the encapsulation key of the second key ciphertext is the public key of the receiving node; sending the data ciphertext and the second key ciphertext to the receiving node; the receiving node decrypting the second key ciphertext to obtain a symmetric key, and then using the symmetric key to decrypt the data ciphertext to obtain the plaintext of the data to be transmitted. This achieves end-to-end secure data transmission while effectively reducing the computational complexity and communication volume in the key establishment process.
Owner:HUAWEI TECH CO LTD

Key establishment method and device, equipment and medium

The embodiment of the invention relates to a key establishment method and device, equipment and a medium. According to an embodiment of the present disclosure, at a key establishment proxy for network time security (NTS), key information for communication between a network time protocol (NTP) client and at least one NTP server is acquired from a key establishment server for NTS; and sending the key information to the NTP client. In this manner, the large amounts of computing resources and further public key infrastructure (PKI) functionality that would otherwise be required to process key acquisition by the NTP client are transferred to the key establishment agent. Therefore, efficient deployment of the NTS can be realized.
Owner:ALCATEL LUCENT SHANGHAI BELL CO LTD +1