Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

21 results about "Key revocation" patented technology

Key revocation is the manner in which PGP public keys are permanently retired. It is suggested that a key revocation certificate should be generated as soon as the key pair is created. This certificate should be held by a trusted third party, exactly as the key-escrow facility described above.

Integrated key revocation with a field loading process and / or related safety checks related to an asset system

Various embodiments relate to integrated key revocation with a field loading process and / or related safety and security checks related to an asset system. In an implementation, a data loading request to store a data file via a target storage device of an asset is received. The data file can be signed based on a first key. In response to the data loading request, a key identifier for the first key associated with the data file is compared against (i) a list of key identifiers stored in a key revocation list and (ii) a one-time programmable (OTP) memory of the asset. Additionally, in response to a determination that the data file is successfully authenticated against the key revocation list and the OTP memory, a key revocation process is performed with respect to a second key for the data file associated with the data loading request.
Owner:HONEYWELL INTERNATIONAL INC

Anti-quantum satellite-ground convergence network access authentication method based on block chain

The invention discloses an anti-quantum satellite-ground fusion network access authentication method based on a block chain, and the method comprises the specific steps: S1, a system initialization stage: generating a root PKG, extracting and generating a sub-PKG based on the root PKG, carrying out the key distribution of an AP layer through the root PKG, managing the key distribution of a user on a corresponding AP chain through the sub-PKG, and carrying out the key distribution of the user on the AP chain through the sub-PKG; the public parameters of the sub-PKG and the root PKG and blockchain information managed by the sub-PKG and the root PKG are uploaded to a system control chain; each of the root PKG and the sub PKG comprises a corresponding main public key, a main private key, a pseudo identity generation key, a revocation key and a verification key; the whole system has a unified key architecture, a key PSK for pseudo identity generation, a trap door key RK in a revocation mechanism and a public key VK for revocation verification are conveniently and safely initialized, deployed and expanded, and the system can support a complete authentication and revocation function module in the initialization stage.
Owner:HANGZHOU POST QUANTUM CRYPTOGRAPHY TECH CO LTD

Internet of Things equipment encryption method and device and electronic equipment

The invention relates to the technical field of Internet of Things equipment encryption, and discloses an Internet of Things equipment encryption method and device and electronic equipment, and the method comprises the steps of secret key level-to-level management, dynamic secret key updating, hierarchical encryption communication, and secret key revocation and recovery. According to the invention, a three-level architecture of the master key, the regional key and the equipment key is adopted, hierarchical isolation management of the keys is realized, and the key leakage risk is effectively reduced; a dynamic key updating mechanism can automatically identify and update expired or abnormal keys, so that the flexibility of the system is improved; equipment-level, area-level and core-level data isolation protection is realized through a layered encryption communication strategy, and cross-level attacks are prevented; by quickly identifying abnormal equipment and executing key revocation and recovery, safe operation of the system is ensured; a verification mechanism is introduced to guarantee the integrity and reliability of data transmission. The method is suitable for various scenes such as smart cities and industrial Internet of Things, and provides all-around safety guarantee for Internet of Things equipment.
Owner:JINING POLYTECHNIC

Method and system for a secure platform driven root of trust (ROT) for information handling system components

A method for securely updating a firmware (FW) of a component of an information handling system (IHS) includes: receiving an update package for the component; analyzing the update package to extract at least a manifest and an FW update file associated with the component; making a first determination that the manifest is authenticated; making, based on the first determination, a second determination that a key revocation criterion is met, in which the key revocation criterion specifies that a certificate revocation list (CRL) does not specify an authentication key to be used to authenticate an updated FW of the component; updating, based on the second determination, the FW of the component using the FW update file, in which, after being updated, the component has the updated FW; and initiating notification of a user of the IHS about the updated FW of the component.
Owner:DELL PROD LP

Terminal hard disk key centralized management method and device, storage medium and computer program product

The invention discloses a terminal hard disk key centralized management method and device, a storage medium and a computer program product, and relates to the technical field of information security, the method comprises the following steps: receiving a hard disk partition encryption strategy issued by a terminal agent, the hard disk partition encryption strategy being created by a domain control background according to an encryption strategy parameter configured by an administrator; terminal state verification is carried out according to the hard disk partition encryption strategy, and under the condition that the terminal state verification is passed, bottom layer encryption is executed based on the hard disk partition encryption strategy and four-dimensional dynamic binding is triggered, so that a data encryption key and a recovery key are generated; and the recovery key is reported to a domain control background through the terminal agent, so that the domain control background updates the terminal encryption state according to the recovery key to perform key life cycle management, and the key life cycle management comprises key distribution, key use and key revocation. And terminal hard disk key centralized management which is matched with a domestic system, safe, compliant and efficient in operation and maintenance is realized.
Owner:CHINA MERCHANTS BANK

Full offline accessory key full life cycle management system and method

PendingCN122293323AFull life cycleNetwork data
This invention discloses a fully offline accessory key lifecycle management system and method, belonging to the field of smart terminal accessory security management technology. This invention constructs a six-stage, closed-loop management system covering key generation and programming, factory pre-binding, initial activation verification, continuous usage control, offline key revocation, and physical destruction upon disposal. This invention utilizes a PUF (Physically Unclonable Function) circuit to generate unique key pairs for each device. The private key is permanently embedded within the chip, unreadable and unexportable. A physical unidirectional programming link eliminates the risk of internal key leakage, enabling offline pre-binding between the terminal and accessories, offline key revocation, and hardware-level physical key destruction capabilities. This invention operates entirely offline in a closed loop on the local terminal, without requiring cloud-based network data interaction. It effectively solves the security flaws of traditional accessory key systems, such as easy key leakage, easy mass forgery, lack of offline revocation capabilities, and the possibility of reused discarded keys. This provides a full-process, hardware-level, and highly reliable security management solution for the fully offline bionic interactive terminal accessory ecosystem.
Owner:李俪安

Edge side data security co-processing method of power system

The invention discloses an edge-side data security collaborative processing method for a power system, relates to a comprehensive management method for edge-side data of a power grid, and aims to solve the problems of poor accuracy and low security of edge-side data security collaborative decision-making of the conventional power system. A lightweight security module with a quantum key distribution function is deployed at a distributed edge node of a power grid, the module serves as a trusted root and generates and distributes a unique quantum key pair for the edge node, and the quantum key pair is used for encrypting locally collected power data for the first time; the edge node preprocesses the power data encrypted for the first time by using local computing resources of the edge node; parameter updating of the global model is protected through a homomorphic encryption technology; and setting a dynamic trust evaluation mechanism, continuously monitoring behavior data of each edge node, and automatically triggering a key revocation and model parameter isolation mechanism when any node is evaluated to be untrusted. The method has the advantages of being good in edge data processing accuracy and high in safety.
Owner:国网黑龙江省电力有限公司信息通信公司

Apparatus and method for binding system-on-chip and memory device with key

Methods and apparatus relating to providing multi-key support within a die architecture, such as a system on a chip. In some examples, a die package includes a key activation fuse, a key revocation fuse, and a key fuse for a plurality of keys. The die package also includes a processor electrically coupled to the key activation fuse, the key revocation fuse, and the plurality of key fuses. Further, the processor may generate a first key value and write the first key value to the key fuse to generate a first key. The processor may also write to the key activation fuse to activate the first key. The processor may further supply the first key to the first memory device. When the first memory device is replaced with the second memory device, the processor may write to the key revocation fuse to revoke the first key and may supply the second key to the second memory device.
Owner:QUALCOMM INC

Signature private key management method and device, server and signature system

The invention discloses a signature private key management method and device, a server and a signature system, and the method comprises the steps: building a private key revocation list of a corresponding user, wherein each information record in the private key revocation list comprises a user identity, a signature private key number, a signature index and an encryption key; the encryption key is a key for the user to encrypt and send the message; a new signature index and an encryption key are synchronously added into the private key revocation list when the user signs each time, and a new signature private key number is synchronously added into the private key revocation list when the signature private key of the user is updated each time; and providing an encryption key for the signature verification party according to the private key revocation list, so that the signature verification party decrypts the message in the received legal signature and then verifies the message. According to the scheme, the validity of the signature can be ensured, and the user can conveniently and flexibly replace the signature private key.
Owner:SHANGHAI FUDAN MICROELECTRONICS GROUP

Apparatus and methods for binding a system on chip and a memory device with a key

Methods and apparatuses directed to providing multi-key support within die architectures, such as System-on-a-Chips. In some examples, a die package includes key activation fuses, key revocation fuses, and key fuses for multiple keys. The die package also includes a processor electrically coupled to the key activation fuses, the key revocation fuses, and the plurality of key fuses. Further, the processor can generate a first key value and write the first key value to the key fuses to generate a first key. The processor can also write to the key activation fuses to activate the first key. The processor can further provision the first key to a first memory device. When the first memory device is replaced with a second memory device, the processor can write to the key revocation fuses to revoke the first key, and can provision a second key to the second memory device.
Owner:QUALCOMM INC

Automobile electronic control unit key management method and device, vehicle and storage medium

The invention relates to the technical field of automobile electronics, in particular to an automobile electronic control unit key management method and device, a vehicle and a storage medium, and the method comprises the steps: recognizing the key type of a target key of an automobile electronic control unit; a target key management action of the target key in the life cycle is determined according to the key type, and the target key management action comprises multiple stages of key generation, key distribution, key storage, key import and export, key use, key update, key backup and recovery, key archiving, key revocation and key destruction; and managing the target key in the life cycle based on the target key management action. Therefore, the problems that in the related technology, management of the full life cycle of the secret key cannot be achieved, the aspects involved in management are not comprehensive, and consequently the safety of an automobile is low are solved.
Owner:DEEPAL AUTOMOBILE NANJING RESEARCH INSTITUTE CO LTD

Handling of database encryption key revocation

Systems and methods include storage of a plurality of encrypted data pages of a row store database table in a persistent storage system, determination of a first encryption key associated with one of the plurality of encrypted data pages based on a header of the one of the plurality of encrypted data pages, determination of whether the first encryption key has been revoked, and, if it is determined that the first encryption key has been revoked, adding of a portion of volatile memory allocated to the one of the plurality of data pages to a free list.
Owner:SAP SE

A version chain-based fine-grained multi-modal intelligence management and control and security tracing method

The present application relates to a kind of based on version chain's fine-grained multi-modal intelligence management and control and safety traceability method, comprising the following steps: S1: construct cloud edge end three-layer collaborative architecture, deploy multi-authority attribute management node, establish the infrastructure of version chain system;S2: design attribute management mechanism based on version chain, generate versioned attribute identification, bind intelligence access strategy with attribute version, realize fine-grained encryption control;S3: establish anti-collusion verification mechanism, combine multi-authority key fragmentation technology and version chain consistency check, prevent the collusion attack of user and authority node;S4: based on version chain full life cycle record, realize the full-process safety traceability of intelligence access, attribute change and key revocation, dynamically update multi-modal intelligence management and control risk state.The present application can realize intelligence management and control " encryption-verification-traceability " integration, realize attribute dynamic management and full-process safety traceability, greatly improve the security and reliability of intelligence management and control.
Owner:BEIHANG UNIV

Lightweight revocable broadcast encryption scheme suitable for ADS-B system

The invention discloses a lightweight revocable broadcast encryption scheme suitable for an ADS-B (Automatic Dependent Surveillance-Broadcast) system, and belongs to the technical field of avionics communication security. An identity-based broadcast encryption group key scheme is adopted, a sender only needs to encrypt once to broadcast a key to a plurality of legal receivers; and a receiver performs decryption by using the same key, so that key management is simplified, and encryption efficiency is improved. And a message data header compression technology is adopted, so that the data redundancy in the encryption process is reduced, and the message transmission overhead is reduced. The AA and ME fields of the ADS-B message are encrypted, so that the identity of the aircraft can be effectively hidden, key flight data can be protected, monitoring, tracking and data tampering behaviors are prevented, and the confidentiality and the anti-attack capability of the system are further enhanced. And meanwhile, a key revocation mechanism is supported, so that the access authority of the key can be revoked in time when the private key of the aircraft or the ground station is leaked or illegal, and the security and flexibility of the system are enhanced.
Owner:BEIHANG UNIV

Key management optimization method based on post quantum cryptography algorithm

The invention relates to the technical field of information security, and discloses a key management optimization method based on a post quantum cryptography algorithm. The method comprises the following steps: firstly, obtaining an anti-noise quantum key by using a lattice-based key generation algorithm and a fault-tolerant coding technology; then generating a multivariable encryption key and a hierarchical verification key through a multivariable polynomial encryption algorithm and a hash chain structure; secret key fragmentation storage and dynamic threshold signature are realized through a distributed hash tree technology and a threshold signature protocol; then, a dynamic weight updating algorithm and a zero-knowledge proof protocol are utilized to adjust and verify the secret key fragment weight; and finally, anonymous revocation and secure destruction of the key are completed by means of a revocable ring signature algorithm and a quantum secure erasure protocol. According to the method, the security and reliability of key management are effectively improved, challenges brought by quantum computing can be coped with, and the method has important application value in the field of information security.
Owner:JIANGSU IDEABANK MICROELECTRONICS TECH

Unmanned aerial vehicle-oriented key management method, medium and equipment

The invention relates to the technical field of key management, in particular to an unmanned aerial vehicle-oriented key management method, a medium and equipment, symmetric session keys uniquely associated with a flight session identifier are cooperatively generated through symmetric key generation nodes not less than a first preset number threshold, the dependence of a single node is eliminated, and the key management efficiency is improved. The precise matching of the secret key and the flight session life cycle is realized; by continuously maintaining the effective state of the secret key in the flight session operation and detecting the triggering condition of the revocation condition in real time, the secret key state and the flight session state are synchronized, and the potential safety hazard caused by the effective secret key when the session is abnormal is avoided; after the revocation condition is triggered, the key mark is invalid when the suggested revocation node number reaches the second preset number threshold value, abnormal key revocation caused by single node misoperation or malicious behaviors is avoided, meanwhile, the node load is dispersed, the performance bottleneck of centralized key management is solved, and the processing efficiency and expandability are improved.
Owner:THE SECOND RES INST OF CIVIL AVIATION ADMINISTRATION OF CHINA

Chip security starting method based on variable credential

The invention belongs to the technical field of chip security, and particularly relates to a chip security starting method based on variable credentials, which comprises the following steps of: blocking illegal algorithm calling and border-crossing public key access by solidifying key parameters such as an algorithm type, a public key table hash value and the like in one time programmable (OTP) and combining a bit fusing mechanism of a public key state flag; based on a dynamic key derivation mechanism of a firmware decryption base key and a salt value, remote (FOTA) updating of a symmetric key is realized, and the leakage risk of an OTP direct storage key is avoided; the OTP state flag is updated through linkage of a public key revocation mask, multi-public-key one-way revocation and chained verification of a firmware hash value table are supported, and a multi-level firmware starting scene is adapted. Finally, dynamic replacement and multi-dimensional legality verification of the public key and the secret key are realized while the irreversible security characteristic of the OTP is guaranteed, and the anti-attack capability and the expandability of the system are improved.
Owner:SHENZHEN ROADROVER TECH

ADS-B secure identity authentication method based on blockchain

The present invention discloses a method for secure identity authentication of an ADS-B system based on blockchain, which belongs to the technical field of ADS-B systems and includes the following steps: a blockchain system setting phase, generating a genesis block and setting a smart contract and a consensus algorithm; a blockchain system registration phase, uploading a public key registration list to the blockchain; a blockchain system authentication phase, realizing ground station-to-aircraft authentication, aircraft-to-ground station authentication, and aircraft-to-aircraft authentication in the system; an on-chain public key update phase, ensuring real-time storage of the latest public key list on the chain; and an on-chain public key revocation phase, timely detecting and deleting illegal users. The present invention automatically realizes the registration, update, and revocation of user identity public keys. It not only solves the problem of dynamic identity legitimacy of ADS-B system members and ensures the integrity and non-repudiation of communication information, but also the PBFT consensus algorithm running at the same time better adapts to the proposed architecture and improves on-chain transaction efficiency.
Owner:BEIHANG UNIV

On-lattice puncturable attribute-based proxy re-encryption method and system

The invention relates to the technical field of proxy re-encryption, in particular to an on-lattice puncturable attribute-based proxy re-encryption method and system. According to the invention, the trusted mechanism carries out centralized initialization and distributes the secret keys, so that the security guidance and authority management of the system are realized; the data owner autonomously executes encryption and re-encryption key generation, so that the flexibility of fine-grained access control and strategy updating of the full life cycle of the data is ensured; the cloud server only executes ciphertext conversion in a semi-trusted environment, so that efficient strategy migration is realized, and meanwhile, plaintext invisibility is ensured; the data receiver independently completes decryption and key puncture, so that the autonomy and controllability of the decryption process are ensured, a key revocation mechanism of a third party is not needed, the decryption authority of the specific label can be immediately and accurately revoked after the key is leaked, and the attack exposure time is greatly shortened. According to the method, the security problem caused by leakage of long-term data sharing in dynamic open environments such as the Internet of Vehicles is effectively solved, and unification of security, efficiency and privacy protection is realized.
Owner:BEIJING ELECTRONICS SCI & TECH INST

Key management method and system

The present invention discloses a key management method and system, which relates to the technical field of key management and includes a key distribution scheme and a key revocation scheme. The wireless sensor network consists of at most M base stations and N sensors, where the number of base stations is much less than the number of sensors. Each sensor node is at least γ-hop reachable from m base stations, and γ < m. Each base station or sensor node in the network is assigned a globally unique digital identifier. The key distribution scheme includes the following: A1: Pairwise keys and individual keys; A2: Session keys; A3: Encryption keys and message authentication keys. For the key management method and system of the present invention, the base stations and sensor nodes can verify each other's identity information; the capture or destruction of any base station does not affect the security of the entire sensor network.
Owner:BEIJING ZHONGDING HAOSHUO TECH CO LTD

Dynamic encryption and decryption method for weight information of deep learning model and related equipment

The invention discloses a deep learning model weight information dynamic encryption and decryption method and related equipment, and the method comprises the steps: responding to a client request, and verifying a user identity and model attribution; dynamically querying or generating an RSA key pair with a validity period based on the user and the model identifier, and returning a private key; a subsequent request is responded, decryption auxiliary information of the model is obtained after legality is verified, an AES key is dynamically generated to encrypt the information, the AES key is encrypted through an RSA public key, and ciphertext of the AES key and ciphertext of the RSA public key are returned to the client so that the client can decrypt and restore the weight of the model finally; all keys, operation logs and associated information are stored in a non-tampering database; secret key logout and updating are supported when the secret key is expired or the authority is changed, and a full-link traceability report is generated based on a database. Accurate dynamic authorization, session-level double encryption protection and complete operation traceability of model weight access are realized, and illegal acquisition and abuse of the model are effectively prevented.
Owner:SHENZHEN MUYU TECH CO LTD