Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

80 results about "Key recovery" patented technology

A Recovery Key is a combination of numbers and letters that is attributed to your account after you register your account.

Access management and database recovery for encrypted indexes

Methods for database recovery for encrypted indexes are performed by systems and devices. A query with a decryption key is received from a client device, where the query modifies an encrypted index of a database using a secure enclave. When events requiring remedial actions for the database occur during the querying, some transactions of the query and later queries are deferred, and a remedial action is initiated that includes restarting the database. A determination of the remedial action being unsuccessful in recovering the encrypted index causes the action to be re-performed until another query having the decryption key is received whereupon the action is performed again to recover the encrypted index utilizing the decryption key. Deferred transactions are then performed with the decryption key. When a database restarts for access without secure enclaves, the encrypted index for the database is invalidated, and the remedial actions are otherwise completed or discarded.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Multi-user data delivery method for locking application scene

The invention discloses a multi-user data delivery method for locking an application scene, and the method comprises the steps: firstly segmenting a high-value data set into a plurality of data subsets, then dynamically generating a symmetric secret key, segmenting the secret key into a plurality of share secret keys, encrypting each piece of data by using the secret key, and transmitting the encrypted data to a server; then, an access strategy is made for the share of each data user according to the attribute provided by each data user, a share key distributed to the data user is encrypted, meanwhile, the encrypted share key is uploaded to a server, the data user downloads a ciphertext, the secret key is recovered by utilizing the share key of the data user and the share keys of other data users, and the data user sends the secret key to the server; and all the users decrypt the own data and then complete a specific application scene in a federal learning modeling mode. According to the invention, the problem of security control when the data is delivered to a plurality of data users for use is solved, 'special data and special purpose 'is realized, and the economic benefits of data providers are guaranteed.
Owner:GUIZHOU DATABAO NETWORK TECH CO LTD

Efficient multi-authority responsibility investigation multi-party authorization method and device based on attribute encryption

The invention discloses a high-efficiency multi-authority responsibility investigation multi-party authorization method and device based on attribute encryption, and belongs to the technical field of cryptography and information security. A multi-authority attribute-based encryption mechanism is adopted to protect a responsibility investigation private key, a signer encrypts a signature share and generates a zero-knowledge proof; after verification and certification of the combiner, an encrypted share is aggregated in a ciphertext domain to generate an aggregated ciphertext, the block chain stores a hash abstract, and an authorization tracker decrypts the aggregated ciphertext through an attribute key recovery responsibility investigation private key to recover a threshold signature and a participant set, so that cryptology privacy protection, constant-level responsibility investigation efficiency, decentralized governance and reliable auditing are realized.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Medical information privacy protection method and device based on image dual watermarking and medium

The application provides a medical information privacy protection method and device based on image double watermarking, and a medium. The method steps include: step S01. obtaining medical information to be protected and preprocessing to form binary ciphertext; step S02. mapping the binary ciphertext to a corresponding medical image to form a medical image with ciphertext, and generating a mapping key; step S03. inputting the medical image with ciphertext into a modal conversion network to convert it into a medical image with ciphertext in another modal, and using a PVT module to align the source domain and target domain semantics through self-attention and cross-modal attention in the modal conversion network; and step S04. in the recovery stage, inputting the medical image into the reverse recovery modal conversion network to recover the medical image, and using the mapping key to recover the medical information. The application can enhance medical information privacy protection based on double watermarking, while improving recovery accuracy, capacity and robustness.
Owner:XIANGTAN UNIV

Key recovery method, device, system, storage medium and electronic device

Embodiments of the present application provide a key recovery method, device, system, storage medium and electronic device, wherein the method comprises: obtaining N sub-ciphertexts, wherein the N sub-ciphertexts are ciphertexts obtained by a second object encrypting N sub-keys using a target public key and respectively sending to N third objects, the N sub-keys are keys obtained by the second object fragmenting a target key, and the N sub-ciphertexts are respectively sent to a first object by the N third objects notified by the second object after the first object sends a first target request to the second object to request to recover the target key; and decrypting the N sub-ciphertexts using a target private key to recover the target key, wherein the target public key and the target private key are a key pair generated by the first object using a predetermined algorithm. Through the present application, the problem of low security of the key in the related art is solved, and the effect of improving the security of the key is achieved.
Owner:ZHEJIANG DAHUA TECH CO LTD

A key management system based on version management

The present invention discloses a key management system based on version management, comprising: a cryptographic device and a key backup central server; the cryptographic device comprises: a key card, which is used to generate keys of different version numbers according to a time baseline in a hardware security environment, and encrypt the keys of different version numbers through a device key; a local key synchronization service module, which is used to detect key changes and synchronize them to a central server; a key backup central server, which stores the key version directory and encrypted key files of all devices; the cryptographic device and the key backup central server communicate via a network to achieve two-way synchronization of key version data, support the selection of multiple version keys for merge recovery, and resolve index conflicts through hash comparison. The present invention manages the key life cycle of the cryptographic device based on the version number, making the management work clearer; multiple version key backups can be used for fusion recovery to meet more key recovery scenarios.
Owner:BEIJING SANSEC TECH DEV

VEHICLE-BASED SYSTEM AND COMMUNICATION PROCEDURES

Vehicle-mounted system (1) for communicating with an external tool (2), wherein the vehicle-mounted system (1) comprises: a communication device (16); a tool key recovery device (11, S62-S64); and a communication controller (11, S65), wherein the vehicle-integrated system (1) and an external server (3) provide a vehicle communication system, wherein the external tool (2) stores a secret tool key, where the external server (3) stores information about an external tool, where the information about an external tool provides a public tool key and key identification information that are linked together, wherein the public tool key provides a public key that forms a pair with the secret tool key, wherein the key identification information provides identification information about the public tool key, wherein the communication device (16) communicates with the external server (3), wherein, when the external tool (2) requests a communication connection with the vehicle-bound system (1), the tool key acquisition device (11, S62-S64) sends the key identification information according to the external tool (2), which is a request source, to the external server (3) via the communication device (16), so that the tool key acquisition device (11, S62-S64) obtains the public tool key associated with the key identification information from the external server (3) via the communication device (16), wherein the communication controller (11, S65) performs cryptographic communication with the external tool (2) representing the request source using the public tool key obtained through the tool key acquisition device (11, S62-S64), wherein the communication controller (11, S65) performs the cryptographic communication with the external tool (2) in a public key encryption system using the public tool key, such that the communication controller (11, S65) shares a common key with the external tool (2), where the shared key provides cryptographic communication in a shared key encryption system, wherein the vehicle-mounted system (1) further comprises an update device (11, S67) for updating the common key, and wherein the update device (11, S67) generates an updated common key based on vehicle information.
Owner:DENSO CORP

Power emergency communication recovery method and related device

The invention belongs to the field of power systems, and discloses a power emergency communication recovery method and a related device, and the method comprises the steps: recognizing a communication node corresponding to a power key recovery node based on a node coupling correlation model of a power network and a communication network, and forming a to-be-analyzed node; tracing power service communication links taking the nodes as starting points, and constructing a to-be-recovered communication node set; calculating the recovery importance degree of each node in the set, wherein the importance degree is obtained by weighted superposition of three types of indexes, namely coupling association strength, bearing service value and network hub attribute; and determining the recovery priority of each communication node according to the recovery importance and executing hierarchical recovery. Communication nodes strongly associated with key loads of a power grid are accurately identified, the recovery value of the communication nodes is quantitatively evaluated, a hierarchical recovery strategy with a clear priority is formed, limited emergency resources are guided to be accurately focused to core communication nodes, the problem that resource allocation and recovery effects are disjointed in a traditional strategy is solved, and the recovery efficiency is improved. And the pertinence and the overall efficiency of power emergency communication recovery are improved.
Owner:CHINA ELECTRIC POWER RESEARCH INSTITUTE CO LTD +2

Certificate authorization private key recovery method and device, storage medium and electronic equipment

PendingCN121792050ASolving technical issues such as low securityimprove securityKey distribution for secure communicationEngineeringRecovery procedure
The invention discloses a certificate authorization private key recovery method and device, a storage medium and electronic equipment, and the method comprises the steps: sending a fragment obtaining request to a service cluster under the condition that an encryption key of a certificate authorization private key is to be recovered for the service cluster; obtaining multiple pieces of request response information returned by responding to the fragment obtaining request from the service cluster; verifying the request response information by using the public key list; under the condition that the request response information passes verification, key fragments are extracted from the request response information; and recovering the encryption key by using the extracted key fragment. By adopting the technical scheme, the problems of low security and the like in a certificate authorization private key recovery process in related technologies are solved.
Owner:CCB FINTECH CO LTD

Integrated triggering method and system for one-key recovery of computer based on shutdown state

This invention relates to the field of computer integrated control technology, specifically an integrated triggering method and system for one-key recovery of a computer in a power-off state. The method involves monitoring user operations under power-off conditions via hardware circuitry. Under the constraint of the Recovery module's anti-accidental touch measures, the method arbitrates and determines user-triggered actions, generating a valid trigger signal and writing it to the wake-up register. Combining an RC delay circuit and trigger sampling analysis of power-on voltage changes, the system automatically enters Recovery mode upon the next power-on without needing to access the operating system or BIOS. After the device is powered off, power data in the power domain is read from the coin cell battery, and the PG distortion signal is reconstructed in the frequency domain. Based on this signal, stable power-on screening and CLRTC physical trigger detection are performed, automatically clearing the real-time clock data when conditions are met. The System Reset module identifies the actual system crash state by constructing a power-on anomaly variable domain and automatically triggers a system restart upon detecting a Reset signal, thus achieving one-key maintenance and recovery of the computer in a crash state.
Owner:SHENZHEN DE SHENG DA ELECTRONIC SCI & TECH CO LTD

Private key recovery device, private key recovery method, and storage medium

A private key recovery device uses a parameter, being data obtained by taking a sum of first biometric information and an encoded key obtained by encoding a private key using an encoding scheme having an error correction capability, and second biometric information, to generate data in which data based on the encoded key and a difference obtained by subtracting the second biometric information from the first biometric information is decoded using the encoding scheme.
Owner:NEC CORP

A key management system with key recovery

The present invention presents a key management system for handling cryptographic keys. The key management system comprises a computer device. The key management system is configured to be in data communication with at least one identity provider, IdP, server and at least one group of computing servers. The IdP servers is configured to send an authentication token to the key management system upon an authentication request from the key management system. The key management system is configured to generate an access ID related to said IdP servers. The key management system is configured to perform one or both of following: a) generate an encryption key from said access ID, b) send a decryption request to the group of computing servers, wherein the group of computing servers is configured to generate a decryption key and sending the decryption key or shares of the decryption key to the computer device or a selected device different from the computer device.
Owner:PARTISIA INFRASTRUCTURE APS

Hierarchical retracement processing method and system for security check CT (Computed Tomography) image

The invention discloses a hierarchical retracement processing method and system for security check CT (Computed Tomography) images. The method comprises the following steps: acquiring a security check CT image of a parcel to be checked and responding to user operation; the user performs sectioning, image processing, measuring or marking operations to generate a sequence of images; responding to a user retracement instruction, judging an operation type and executing a corresponding retracement strategy: if the operation type is not the data exchange type, calling screen snapshots in sequence to realize plane layer non-inductive retracement and video memory snapshots to recover real-time imaging; if the type is the data exchange type, quickly reconstructing a target image based on preloaded package data and an intermediate calculation result; and the user can operate again in the state after withdrawing until the result is satisfactory. Through the serialized recording operation process and the multi-level snapshot management, the precise and low-delay withdrawing of the security check CT image operation process is realized, the problems that the intermediate state cannot be backtracked, the withdrawing delay is high and the cross-parcel operation efficiency is low in the traditional one-key restoration are effectively solved, and the security check image discrimination efficiency and the passing experience are remarkably improved.
Owner:THE FIRST RES INST OF MIN OF PUBLIC SECURITY +1

Key management method and system based on KMS technology

The invention relates to a key management method based on a KMS technology, and the method is characterized in that the method comprises the following steps: enabling a key management service KMS to generate a CMK key for a user in a client application based on the first login of the user; generating a DEK key in the client application and storing the DEK key in a safe area of a first device based on the first selection service provider point deduction for the first time when a user purchases a commodity for the first time; in the client application, enabling the KMS to encrypt the DEK key by using the CMK key, generating an encrypted DEK key and transmitting the encrypted DEK key to the client application; encrypting transmission data by using the DEK key in the client application; the encrypted DEK key and the encrypted transmission data are transmitted to the server of the service provider in the client application. According to the scheme, a CMK-DEK hierarchical architecture is adopted, a KMS manages a CMK to transmit an ID, and a DEK locally stores a security area to prevent a core key from being leaked; and AES-256-CBC is used for encryption, a server stores a ciphertext, and the DEK is destroyed after decryption. Key recovery, multi-device synchronization, compliance with laws and regulations, operation traceability, safety and experience balance and adaptation to high-safety scenes are supported.
Owner:吴东

Template attack method and device aiming at Dillite

The invention provides a template attack method and a template attack device aiming at a Dillite. The method comprises a modeling stage and a private key recovery stage. The modeling stage comprises the following steps of: acquiring an energy trace generated by the mask Dillite in a signature process, and extracting an energy feature which is generated by the mask Dillite when a sensitive intermediate value is calculated in a number theory transform domain and is related to the mask of a random polynomial from the energy trace; establishing a template for the Hamming weight of the sensitive intermediate value according to the extracted energy features; the private key recovery stage comprises the following steps: acquiring an energy trace and signature information of target equipment; extracting energy characteristics related to calculation of a sensitive intermediate value in a number theory transform domain by using the Dillite mask from the obtained energy trace of the target equipment; calculating mahalanobis distances between the extracted energy features and all templates, and recovering a random polynomial according to the template corresponding to the minimum mahalanobis distance; and according to the linear relationship between the recovered random polynomial and the number-theory transform domain private key of the mask Dillitium and the signature information, recovering the number-theory transform domain private key.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

Block cipher side channel analysis method based on experience accumulation and three-dimensional decision

The invention relates to a block cipher side channel analysis method based on experience accumulation and three-dimensional decision, and belongs to the technical field of cipher security analysis and side channel analysis. Aiming at the problems of large search space, low information utilization rate, computing power waste and the like in the traditional correlation coefficient energy analysis, the method provides an analysis framework combining a dynamic hierarchical screening mechanism and a cross validation strategy. The method comprises the following steps: randomly initializing each byte of a key to generate a candidate set; constructing a three-dimensional decision-making structure comprising a data layer, a statistical layer and a decision-making layer so as to record and analyze correlation coefficient distribution; screening conditions are automatically tightened through dynamic threshold attenuation, and the search range is gradually reduced; and adopting a multi-stage single-byte perturbation and cross validation strategy to carry out iterative optimization and ranking on each byte candidate value, and finally selecting an optimal key combination to carry out verification. According to the method, the success rate, robustness and convergence speed of side channel analysis are effectively improved, and the method is suitable for key recovery of block cipher.
Owner:BEIJING INST OF TECH +1

End-to-End Encryption and Hot Wallet Key Recovery Apparatuses, Processes and Systems

The End-to-End Encryption and Hot Wallet Key Recovery Apparatuses, Processes and Systems (“E2EEHWKR”) transforms key backup request, key recovery request datastructure / inputs via E2EEHWKR components into key backup response, key recovery response outputs. A key backup request datastructure specifying a wallet private key, a private key backup server identifier, a PIN shard fracture scheme definition, and a plurality of PIN shard backup devices is obtained. A user security PIN is obtained and utilized to encrypt the wallet private key. A symmetric key is calculated from a public key associated with the private key backup server identifier and an app private key. The encrypted wallet private key is encrypted utilizing the symmetric key. The twice encrypted wallet private key is sent to a private key backup server. The user security PIN is encrypted utilizing an asymmetric keypair. Encrypted user security PIN shards are generated and sent to PIN shard backup devices.
Owner:FMR CORP

A multi-source adversarial side channel analysis method for cryptographic algorithms based on random models

The present invention relates to the fields of cryptography and multi-source side channel analysis, and more specifically, to a multi-source adversarial side channel analysis method for cryptographic algorithms based on random models. By introducing the idea of ​​multi-source adversarial learning into the random model modeling process, the modeling accuracy of the random model is improved, and key recovery is achieved more efficiently. The present invention utilizes a noise source and an energy source for adversarial learning, introduces the conditional probability of the normal distribution and the KS test as a basis for adversarial learning judgment, and independently designs a random model modeling parameter iteration mechanism to improve the accuracy of traditional random model parameters; the method converts it into a more intuitive mathematical formula, which helps to improve the accuracy of various methods related to random models and reduce the difficulty of cryptographic algorithm side channel analysis; the present invention introduces the multi-source adversarial idea, sets a basis for adversarial learning judgment, improves the multi-source modeling accuracy of the random model, and has higher parameter quality and lower cryptographic algorithm key recovery difficulty.
Owner:BEIJING INST OF TECH +1

A distributed identity private key recovery method based on weighted voting

The present invention provides a distributed identity private key recovery method based on weighted voting, which belongs to the field of 5G and information security technology. In the user registration stage, the user uploads the public key to the blockchain and initializes the principal activity evaluation factor on the smart contract; in the private key recovery stage, the principal performs weighted voting based on the principal activity. When the voting result exceeds m' / n', it is considered to have passed the verification and the user's public key in the blockchain is replaced, where m' represents the weighted number of votes of the voting principal, and n' represents the total number of votes that all principals should have after weighting. The present invention pays more attention to highly active principals and reduces dependence on low-activity principals, thereby improving the efficiency of private key recovery while increasing the success rate of user private key recovery and reducing the risk of user identity loss.
Owner:POWERCHINA BEIJING ENG CORP

Artificial intelligence side-channel analysis method and apparatus based on cross-device incremental learning

PendingCN122640111AData setAlgorithm
The application relates to an artificial intelligence side channel analysis method and device based on cross-device incremental learning, applied to the field of information security password technology, and comprising the following steps: collecting side information when multiple modeling devices running symmetric password algorithms perform secret information related operations, then constructing a key leakage model, taking the Hamming weight of a secret intermediate value corresponding to each piece of side information as a label to construct a data set, using a memory sample playback strategy to sequentially train multiple data sets, obtaining a final neural network model for predicting corresponding secret intermediate value information according to side information, finally using the trained model to predict the intermediate value information to calculate the key, and completing key recovery; the final model trained by the scheme has stronger generalization ability and robustness when facing new target devices, effectively solves the bottleneck problem of cross-device side channel analysis, reduces the influence of device changes on the performance of the cross-device modeling type password side channel analysis method, and realizes efficient recovery of the key.
Owner:BEIJING INST OF TECH +1

Private key recovery system, private key recovery method, and program

A first recovery key acquisition module (302) of a private key recovery system (1) acquires a first recovery key managed by a first service in which a first private key stored in a user terminal of a user is used. A second recovery key acquisition module (303) acquires a second recovery key managed by a second service different from the first service. A private key recovery module (304) recovers the first private key based on the first recovery key and the second recovery key.
Owner:RAKUTEN GROUP INC

IoT device anomaly identification and isolation method and apparatus, electronic device, and storage medium

The embodiment of the application discloses an IoT device anomaly identification and isolation method and device, electronic equipment and a storage medium, and relates to the technical field of network security and edge computing, wherein the method comprises: when an IoT device accesses a gateway and utilizes edge computing to perform traffic fingerprint analysis, recording communication characteristics and integrating them into a behavior benchmark atlas. In device use, current network traffic data is continuously captured, compared and analyzed with the behavior benchmark atlas in real time, and it is judged whether there is an anomaly. If the device is abnormal, an abnormal traffic threshold is set, an alarm mechanism is triggered, and an isolation instruction is generated and pushed to the underlying router. The router dynamically adjusts network configuration by using micro-isolation technology, and migrates the abnormal device to an isolated VLAN to limit network access. The isolated device information and reasons can be visually displayed through a development management interface. After the user confirms the safety of the device and performs a one-key recovery operation, the device is migrated back to the main network and the permission is restored. The application effectively solves the problem of IoT device anomaly processing in the prior art.
Owner:SHENZHEN SINOBRY ELECTRONICS LTD

Computationally Efficient Transfer Processing, Auditing, and Search Apparatuses, Mechanisms, Mediums, Processes and Systems

The Computationally Efficient Transfer Processing, Auditing, and Search Apparatuses, Mechanisms, Mediums, Processes and Systems (“SOCOACT”) transforms transfer of assets (TOA) initiation request, brokerage order request, blockchain transaction request, agency action request, borrow transaction request, contract deployment request, transaction signing request, key backup request, key recovery request datastructure / inputs via SOCOACT components into TOA confirm., brokerage order confirm., transaction confirm., agency action notif., borrow transaction init notification, borrow transaction sync notification, contract deployment response, transaction signing resp., key backup resp., key recovery resp. datastructure / outputs. A plurality of transaction record datastructures is received. Transaction amount availability is verified. The transaction record datastructure is cryptographically recorded in a blockchain. Received source address and destination address are hashed. A list representation of the matrix datastructure is generated, where each entry in the list comprises a tuple having the source wallet address, the destination wallet address, the transaction amount and the timestamp.
Owner:FMR CORP

Electricity-carbon data secure storage and access method and device based on alliance chain

The invention provides an alliance chain-based electricity and carbon data secure storage and access method and device. According to the implementation scheme, the method comprises the following steps: in response to a data use request for first ciphertext electric carbon data, obtaining corresponding first ciphertext key fragments from nodes in an alliance chain; updating the reputation value of each node based on the synchronization condition of the timestamp of each first ciphertext key fragment; updating the minimum number of participants based on a default basic value corresponding to the minimum number of participants required for restoring the original key and the updated reputation value of each node; based on the updated minimum number of participants, performing key recovery on each first ciphertext key fragment to obtain a first ciphertext key; decrypting the first ciphertext key to obtain a first plaintext key; and based on the first plaintext key, decrypting the first ciphertext electric carbon data to obtain first plaintext electric carbon data. Therefore, the storage and access security of the data is improved.
Owner:STATE GRID DIGITAL TECHNOLOGY HOLDING CO LTD +1

An image encryption and decryption method based on chaos and elliptic curve encryption algorithm

ActiveCN115146296BDigital data protectionImage data processing detailsAlgorithmChaotic synchronization
The present invention discloses an image encryption and decryption method based on chaos and elliptic curve encryption algorithms. This method utilizes the characteristics of chaos and the elliptic curve public key encryption system to perform image encryption operations. The steps include: generating a key using a chaotic sequence; chaotic scrambling of image blocks; chaotic diffusion of the image; transmitting the key using an elliptic curve encryption algorithm; decrypting the key using the elliptic curve encryption algorithm; and restoring image pixels to restore the image. The chaotic sequence utilized is an optical chaotic synchronization sequence based on light injection. The chaotic sequence can be synchronized at the receiving and transmitting ends, and the chaotic sequence is used to generate a key library for image encryption. Each key library is transmitted separately through the synchronized chaotic sequence and the elliptic curve encryption algorithm, providing dual encryption characteristics and improving encryption security.
Owner:HANGZHOU DIANZI UNIV

Multi-source artificial intelligence side channel analysis method for public key password protection

The invention relates to a multi-source artificial intelligence side channel analysis method for public key password protection, and belongs to the technical field of information security passwords. The method comprises the following steps: firstly, acquiring multi-source side information of asymmetric cryptographic algorithm equipment with public key cryptographic protection, and positioning an area for executing secret information related operation in the side information; side information traces of a secret information operation are analyzed and divided into segments. Multi-dimensional features are extracted from each trace segment of each type of side information, and features and noise are separated by using a principal component analysis method. Then, carrying out clustering analysis on the information on the single source side by using a Fuzzy C-Means algorithm; and multi-source information is fused, and more accurate key recovery is realized through a clustering probability distribution model. According to the method, the operation characteristics of the protection type asymmetric cryptographic algorithm can be effectively distinguished, and efficient key recovery is realized through multi-source information fusion.
Owner:BEIJING INST OF TECH +1

A method for managing group keys of a UAV self-organizing network supporting dynamic joining, leaving and key recovery of members

PendingCN122394779AKey exchangeConfidentiality
The application discloses a kind of unmanned aerial vehicle self-organizing network group key management methods supporting member dynamic joining, quitting and key recovery, belongs to unmanned aerial vehicle self-organizing network security communication technical field.The method includes: system initialization;UAV node is registered, and based on physically unclonable function generation and equipment binding key material;Utilize Cuckoo filter to quickly screen legal members;Two-way authentication and key exchange process are executed between adjacent nodes and establish edge session key;Group key derivation is realized based on edge session key;When node is lost, group key recovery is executed;When member dynamic joins, quits or is revoked, group key update is executed.The method can reduce authentication and key management overhead, improve the processing efficiency when node recovery and member change, and ensure the forward security, backward security, integrity and confidentiality of group communication.
Owner:HAINAN UNIV

Non-contact authentication for key recovery and platform security provisioning

ActiveUS12719681B2Ultra-widebandEngineering
Secure AI authentication is implemented for selectable environments with a selectable combination of ML models processing selectable input credentials, e.g., biometric and / or non-biometric credentials, such as a key associated with a secure model, user location information, a user gesture credential, and / or a user movement pattern credential. ML models may be selectively applied in serial or parallel in a selected authorization procedure. ML model applicability may vary based on one or more parameters, such as time of day, or one or more detected input credentials, such as user gestures, secure model keys, or biometric voice or face recognition. For example, AI authorization (e.g., for biometric credentials) augmented with an ultra-wideband (UWB) communication protocol provides robust user authentication via a native cryptographic exchange and accurate user location credentials for proximity and geo-fenced confirmation of other user credentials, such as biometric credentials, thereby preventing false positives by spoofing.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

A Distributed Key Recovery Method, System, and Medium

The present invention discloses a distributed key recovery method, system and medium; the key recovery method includes constructing a secret value according to a key; determining a prime number for splitting the secret value, and respectively calculating shares corresponding to each prime number in combination with the secret value; distributing each prime number and the corresponding share to different servers; when the key needs to be recovered, obtaining the prime numbers and the corresponding shares stored in each server based on authentication to achieve key recovery. The present invention jointly maintains the security of the key by multiple servers, reduces the trust requirement for any single entity, and can effectively solve the single point of failure and trust problems in the prior art.
Owner:BEIJING YINSUAN TECH CO LTD

Method and system for key recovery based on password strength assignment and threshold combination

The application discloses a key recovery method and system based on password strength distribution and threshold combination, relates to the password management and cryptography field, and comprises four stages of initialization, recovery password registration, recovery password revocation and key recovery. The initialization stage constructs secret sharing public parameters and a recovery bucket storage structure. In the registration stage, a candidate recovery password is assigned with a corresponding number of real shares according to the strength of the candidate recovery password, random data is filled to form fixed-length recovery data, and the recovery data is stored in a corresponding recovery bucket in an encrypted manner. In the revocation stage, the recovery permission of a specified recovery password can be cleared, and the storage state is synchronously updated. When a user forgets a master password, an effective share is extracted by inputting a registered recovery password, and the password library key is reconstructed after the cumulative threshold is reached, so that the password library access permission is recovered. The application does not require the user to additionally remember a special recovery password, considers the recovery availability and the cryptographic security, and has good cloud observation resistance.
Owner:NANKAI UNIV