Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

11 results about "Key revocation" patented technology

Key revocation is the manner in which PGP public keys are permanently retired. It is suggested that a key revocation certificate should be generated as soon as the key pair is created. This certificate should be held by a trusted third party, exactly as the key-escrow facility described above.

Method and system for a secure platform driven root of trust (ROT) for information handling system components

A method for securely updating a firmware (FW) of a component of an information handling system (IHS) includes: receiving an update package for the component; analyzing the update package to extract at least a manifest and an FW update file associated with the component; making a first determination that the manifest is authenticated; making, based on the first determination, a second determination that a key revocation criterion is met, in which the key revocation criterion specifies that a certificate revocation list (CRL) does not specify an authentication key to be used to authenticate an updated FW of the component; updating, based on the second determination, the FW of the component using the FW update file, in which, after being updated, the component has the updated FW; and initiating notification of a user of the IHS about the updated FW of the component.
Owner:DELL PROD LP

Full offline accessory key full life cycle management system and method

PendingCN122293323AFull life cycleNetwork data
This invention discloses a fully offline accessory key lifecycle management system and method, belonging to the field of smart terminal accessory security management technology. This invention constructs a six-stage, closed-loop management system covering key generation and programming, factory pre-binding, initial activation verification, continuous usage control, offline key revocation, and physical destruction upon disposal. This invention utilizes a PUF (Physically Unclonable Function) circuit to generate unique key pairs for each device. The private key is permanently embedded within the chip, unreadable and unexportable. A physical unidirectional programming link eliminates the risk of internal key leakage, enabling offline pre-binding between the terminal and accessories, offline key revocation, and hardware-level physical key destruction capabilities. This invention operates entirely offline in a closed loop on the local terminal, without requiring cloud-based network data interaction. It effectively solves the security flaws of traditional accessory key systems, such as easy key leakage, easy mass forgery, lack of offline revocation capabilities, and the possibility of reused discarded keys. This provides a full-process, hardware-level, and highly reliable security management solution for the fully offline bionic interactive terminal accessory ecosystem.
Owner:李俪安

Edge side data security co-processing method of power system

The invention discloses an edge-side data security collaborative processing method for a power system, relates to a comprehensive management method for edge-side data of a power grid, and aims to solve the problems of poor accuracy and low security of edge-side data security collaborative decision-making of the conventional power system. A lightweight security module with a quantum key distribution function is deployed at a distributed edge node of a power grid, the module serves as a trusted root and generates and distributes a unique quantum key pair for the edge node, and the quantum key pair is used for encrypting locally collected power data for the first time; the edge node preprocesses the power data encrypted for the first time by using local computing resources of the edge node; parameter updating of the global model is protected through a homomorphic encryption technology; and setting a dynamic trust evaluation mechanism, continuously monitoring behavior data of each edge node, and automatically triggering a key revocation and model parameter isolation mechanism when any node is evaluated to be untrusted. The method has the advantages of being good in edge data processing accuracy and high in safety.
Owner:国网黑龙江省电力有限公司信息通信公司

Apparatus and method for binding system-on-chip and memory device with key

Methods and apparatus relating to providing multi-key support within a die architecture, such as a system on a chip. In some examples, a die package includes a key activation fuse, a key revocation fuse, and a key fuse for a plurality of keys. The die package also includes a processor electrically coupled to the key activation fuse, the key revocation fuse, and the plurality of key fuses. Further, the processor may generate a first key value and write the first key value to the key fuse to generate a first key. The processor may also write to the key activation fuse to activate the first key. The processor may further supply the first key to the first memory device. When the first memory device is replaced with the second memory device, the processor may write to the key revocation fuse to revoke the first key and may supply the second key to the second memory device.
Owner:QUALCOMM INC

Signature private key management method and device, server and signature system

The invention discloses a signature private key management method and device, a server and a signature system, and the method comprises the steps: building a private key revocation list of a corresponding user, wherein each information record in the private key revocation list comprises a user identity, a signature private key number, a signature index and an encryption key; the encryption key is a key for the user to encrypt and send the message; a new signature index and an encryption key are synchronously added into the private key revocation list when the user signs each time, and a new signature private key number is synchronously added into the private key revocation list when the signature private key of the user is updated each time; and providing an encryption key for the signature verification party according to the private key revocation list, so that the signature verification party decrypts the message in the received legal signature and then verifies the message. According to the scheme, the validity of the signature can be ensured, and the user can conveniently and flexibly replace the signature private key.
Owner:SHANGHAI FUDAN MICROELECTRONICS GROUP

Apparatus and methods for binding a system on chip and a memory device with a key

Methods and apparatuses directed to providing multi-key support within die architectures, such as System-on-a-Chips. In some examples, a die package includes key activation fuses, key revocation fuses, and key fuses for multiple keys. The die package also includes a processor electrically coupled to the key activation fuses, the key revocation fuses, and the plurality of key fuses. Further, the processor can generate a first key value and write the first key value to the key fuses to generate a first key. The processor can also write to the key activation fuses to activate the first key. The processor can further provision the first key to a first memory device. When the first memory device is replaced with a second memory device, the processor can write to the key revocation fuses to revoke the first key, and can provision a second key to the second memory device.
Owner:QUALCOMM INC

Handling of database encryption key revocation

Systems and methods include storage of a plurality of encrypted data pages of a row store database table in a persistent storage system, determination of a first encryption key associated with one of the plurality of encrypted data pages based on a header of the one of the plurality of encrypted data pages, determination of whether the first encryption key has been revoked, and, if it is determined that the first encryption key has been revoked, adding of a portion of volatile memory allocated to the one of the plurality of data pages to a free list.
Owner:SAP SE

A version chain-based fine-grained multi-modal intelligence management and control and security tracing method

The present application relates to a kind of based on version chain's fine-grained multi-modal intelligence management and control and safety traceability method, comprising the following steps: S1: construct cloud edge end three-layer collaborative architecture, deploy multi-authority attribute management node, establish the infrastructure of version chain system;S2: design attribute management mechanism based on version chain, generate versioned attribute identification, bind intelligence access strategy with attribute version, realize fine-grained encryption control;S3: establish anti-collusion verification mechanism, combine multi-authority key fragmentation technology and version chain consistency check, prevent the collusion attack of user and authority node;S4: based on version chain full life cycle record, realize the full-process safety traceability of intelligence access, attribute change and key revocation, dynamically update multi-modal intelligence management and control risk state.The present application can realize intelligence management and control " encryption-verification-traceability " integration, realize attribute dynamic management and full-process safety traceability, greatly improve the security and reliability of intelligence management and control.
Owner:BEIHANG UNIV

Unmanned aerial vehicle-oriented key management method, medium and equipment

The invention relates to the technical field of key management, in particular to an unmanned aerial vehicle-oriented key management method, a medium and equipment, symmetric session keys uniquely associated with a flight session identifier are cooperatively generated through symmetric key generation nodes not less than a first preset number threshold, the dependence of a single node is eliminated, and the key management efficiency is improved. The precise matching of the secret key and the flight session life cycle is realized; by continuously maintaining the effective state of the secret key in the flight session operation and detecting the triggering condition of the revocation condition in real time, the secret key state and the flight session state are synchronized, and the potential safety hazard caused by the effective secret key when the session is abnormal is avoided; after the revocation condition is triggered, the key mark is invalid when the suggested revocation node number reaches the second preset number threshold value, abnormal key revocation caused by single node misoperation or malicious behaviors is avoided, meanwhile, the node load is dispersed, the performance bottleneck of centralized key management is solved, and the processing efficiency and expandability are improved.
Owner:THE SECOND RES INST OF CIVIL AVIATION ADMINISTRATION OF CHINA

On-lattice puncturable attribute-based proxy re-encryption method and system

The invention relates to the technical field of proxy re-encryption, in particular to an on-lattice puncturable attribute-based proxy re-encryption method and system. According to the invention, the trusted mechanism carries out centralized initialization and distributes the secret keys, so that the security guidance and authority management of the system are realized; the data owner autonomously executes encryption and re-encryption key generation, so that the flexibility of fine-grained access control and strategy updating of the full life cycle of the data is ensured; the cloud server only executes ciphertext conversion in a semi-trusted environment, so that efficient strategy migration is realized, and meanwhile, plaintext invisibility is ensured; the data receiver independently completes decryption and key puncture, so that the autonomy and controllability of the decryption process are ensured, a key revocation mechanism of a third party is not needed, the decryption authority of the specific label can be immediately and accurately revoked after the key is leaked, and the attack exposure time is greatly shortened. According to the method, the security problem caused by leakage of long-term data sharing in dynamic open environments such as the Internet of Vehicles is effectively solved, and unification of security, efficiency and privacy protection is realized.
Owner:BEIJING ELECTRONICS SCI & TECH INST

Dynamic encryption and decryption method for weight information of deep learning model and related equipment

The invention discloses a deep learning model weight information dynamic encryption and decryption method and related equipment, and the method comprises the steps: responding to a client request, and verifying a user identity and model attribution; dynamically querying or generating an RSA key pair with a validity period based on the user and the model identifier, and returning a private key; a subsequent request is responded, decryption auxiliary information of the model is obtained after legality is verified, an AES key is dynamically generated to encrypt the information, the AES key is encrypted through an RSA public key, and ciphertext of the AES key and ciphertext of the RSA public key are returned to the client so that the client can decrypt and restore the weight of the model finally; all keys, operation logs and associated information are stored in a non-tampering database; secret key logout and updating are supported when the secret key is expired or the authority is changed, and a full-link traceability report is generated based on a database. Accurate dynamic authorization, session-level double encryption protection and complete operation traceability of model weight access are realized, and illegal acquisition and abuse of the model are effectively prevented.
Owner:SHENZHEN MUYU TECH CO LTD