Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

31 results about "Key server" patented technology

In computer security, a key server is a computer that receives and then serves existing cryptographic keys to users or other programs. The users' programs can be working on the same network as the key server or on another networked computer.

Secure control of access to data in an encrypted file

A security client of a mobile computing platform transmits a request for the secret key to a key server. The request includes environmental data characterizing a current state of the environment of the node and establishes a cryptographic heartbeat with the key server. The security client receives a secret key from the key server, stores the secret key in volatile memory and decrypts the encrypted file using the secret key to create a decrypted file in the volatile memory. The security client monitors a time since a last authenticated heartbeat message was received. Responsive to the time exceeding a predetermined timeout window or responsive to receiving a message from the key server indicating that authorization to the decrypted file is revoked or responsive to determining that the node is not in an authorized environment, the security client deletes the secret key from the volatile memory and closes the decrypted file.
Owner:NORTHROP GRUMMAN SYSTEMS CORP

Information processing system, one or more non-transitory computer-readable storage media having program stored therein, and authentication method

ActiveUS12683940B2Information processingKey server
A server issues challenge data and transmits the challenge data to a client. The client stores encrypted group data including a plurality of encrypted data encrypted with a server key, and parameter data A, in a memory, receives the challenge data, generates response data using a response key on the client side, and transmits the response data, the encrypted group data, and the parameter data A to the server. The server selects encrypted data to be used from the received encrypted group data, based on the received parameter data A, sets a response key on the server side, based on the selected encrypted data and data decrypted with the server key, verifies the received response data, based on the challenge data and the response key on the server side, and notifies a result of the verification to the client. The client receives the notification.
Owner:NINTENDO CO LTD

System and method for secure key management for encrypted core dump

A method of a decryptor including receiving, from an encryptor of an electronic device, a core dump that has been encrypted with a symmetric key generated by the encryptor, and core dump metadata, extracting crash metadata from the core dump metadata, transmitting the crash metadata to a remote key server for regenerating the symmetric key, obtaining, from the remote key server, a regenerated symmetric key based the crash metadata, and decrypting the core dump based on the regenerated symmetric key and the crash metadata.
Owner:SAMSUNG ELECTRONICS CO LTD

Post-quantum secure media access control security (macsec) pre-shared key auto-refresh

PendingUS20260081767A1Key distribution for secure communicationUser identity/authority verificationKey serverSecurity association
Techniques for utilizing post-quantum pre-shared key (PPK) identifiers (PPK_ID) to determine control association key(s) (CAK(s)) and / or secure association key(s) (SAK(s)) utilized in MACsec sessions are described herein. A key server (KS) and a non-key server (NKS) may advertise capabilities indicating an ability to utilize PPKs as CAKs and / or SAKs in MACsec sessions. The KS may leverage a quantum key distribution (QKD) service to determine a PPK_ID and a PPK, which may be utilized as a CAK for a MACsec session with the NKS. The PPK_ID may be transmitted to the NKS, where the NKS may retrieve the PPK from the QKD, and a new group connectivity association may be established using the PPK as the CAK. In some examples, the KS may be configured to refresh the PPK as the CAK for instantiating subsequent MACsec sessions. Additionally, the KS may be configured to distribute a SAK in a similar manner.
Owner:CISCO TECHNOLOGY INC

Data transmission method based on direct communication

The invention discloses a direct communication-based data transmission method, which comprises the following steps that: each of a plurality of terminals initiates an identity authentication request to an aggregation security gateway, the aggregation security gateway constructs a topological connection relationship based on the terminals passing the identity authentication, and the terminals establish connection according to the topological connection relationship to form a communication network; the method comprises the following steps: in a communication network, acquiring a symmetrical communication key file 1 from a key server by two mutually connected terminals through an aggregation security gateway; the sending terminal determines a communication route, processes the service data mes, generates a sending data packet MES and sends the sending data packet MES to the receiving terminal; the receiving terminal carries out decryption and verification operation on the sending data packet MES, after verification is passed, service data mes' are obtained, and service processing operation is executed. A full-link safety guarantee system from identity authentication, connection establishment, secret key management to data transmission is built, and essential improvement of safety is achieved while high communication efficiency is guaranteed.
Owner:MATRICTIME DIGITAL TECH CO LTD

Hardware-backed password security for cloud systems

Methods, systems, and devices for data processing are described. A server host may receive a login request that includes a clear text password for an account associated with a tenant of a multi-tenant cloud platform. The server host may retrieve an encrypted payload associated with the account. The encrypted payload may include a hash value of a user-configured password for the account and an indication of a hashing algorithm used to transform the user-configured password into the hash value. The server host may obtain a wrapped symmetric key provisioned by a symmetric key distribution service. The server host may transmit a request that includes the encrypted payload, the clear text password, and the wrapped symmetric key. The server host may receive a response that indicates whether a hash value of the clear text password from the login request corresponds to the hash value of the user-configured password.
Owner:SALESFORCE INC

Symmetric-key infrastructure

Techniques for provisioning a key server to facilitate secure communications between a web server and a client by providing the client with a first data structure including information on how the web server may obtain a target symmetric key are presented. The techniques can include: provisioning the key server with a second data structure including information on how the key server may generate the first data structure; receiving a request on behalf of a web server for a third data structure comprising information on how the client may obtain the first data structure from the key server; and obtaining the third data structure, such that the third data structure is published in association with an identification of the web server, and such that the client uses the third data structure to obtain the first data structure and uses the first data structure to communicate with the web server.
Owner:VERISIGN INC

Security Systems and Methods for Encoding and Decoding Content

Systems and methods may be provided for masking data on public networks, such as social networking sites. At a publishing node, the system may monitor data input fields in a webpage, and intercept and encode content, such as text, images, and video input at the data input fields, prior to the content being posted online on a public service provider's website. A privacy agent may process input field content to try to detect encoding markers in the input field content, which define portions of the content that are to be encoded. A third party key server may be used to store decoding keys. A URI reference to the decoding key may be used to access the decoding key by a node attempting to view the decoded version of the input field content.
Owner:KAXXA HOLDINGS INC

Scalable key state for network encryption

Systems and methods are provided for implementing encryption of data-in-motion and / or otherwise stored data using a key server and a secure enclave of a Network Interface Card (NIC). The NIC acts as a passthrough between the client device and the shared infrastructure of the supercomputer system to help ensure data security in a massively scaled and distributed system. For example, in response to an enrollment process that stores a decrypted key in the secure enclave of a NIC, the NIC can receive a data packet from a client device. The NIC can transmit a key request to a key server that includes an encrypted key corresponding to the decrypted key. The key server can look up the previously stored private / public key pair to authenticate the NIC. The key server can provide private / public key pair to the NIC to allow the NIC to later encrypt data-in-motion.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Method and system for obtaining preset root key offline by quantum safety equipment terminal

The invention discloses a method and system for obtaining a preset root key offline by a quantum security device terminal, and the method comprises the steps: enabling the quantum security device terminal to initiate a registration application to a root key server through network communication equipment based on the hardware number of the quantum security device terminal; the root key server generates a root key file for the quantum security device terminal based on the registration application, encrypts the root key file by using an encryption key, and issues a root key ciphertext to the quantum security device terminal offline through an intermediate medium; the quantum security equipment terminal executes identity authentication operation to obtain a decryption key of the root key ciphertext; and the quantum security equipment terminal performs decryption operation on the root key ciphertext by using the received decryption key to obtain a plaintext-state root key file, and locally stores the plaintext-state root key file. According to the method, the security, reliability and controllability of the quantum security equipment terminal in the network access initialization process are ensured through a root key security acquisition system which is linked with one another and is deeply defended.
Owner:MATRICTIME DIGITAL TECH CO LTD

Threshold searchable symmetric encryption

A data owner can provide shares of a cryptographic key to N key servers. The N key servers can store the shares of a cryptographic key from the data owner such that T shares of the cryptographic key can be used to reconstruct the cryptographic key. A client computer can send a blinded query to T key servers of the N key severs, wherein the T key servers can encrypt a blinded query of a client computer using the share of the cryptographic key to determine a partial encryption. The client computer can receive T partial encryptions, assemble T partial encryptions to form an encrypted blinded query, and deblind the encrypted blinded query. The client computer can then use the encrypted query to perform a search on encrypted data of a remote database server using a searchable symmetric encryption scheme.
Owner:VISA INTERNATIONAL SERVICE ASSOCIATION

Unique identification key downloading method and system

The invention discloses a unique identification key downloading method and system. The method comprises the following steps: a transaction terminal imports a certificate through a secure transmission terminal and a key server; the transaction terminal sends the unique serial number and the certificate to the key server through the secure transmission terminal; the key server checks the unique serial number and the certificate, if the unique serial number and the certificate are legal, a unique identification key corresponding to the unique serial number is obtained, and a unique identification key ciphertext and a first key check value are generated according to the unique identification key and the certificate; the unique identification key is a key required for verification and use during transaction of the transaction terminal and the special mechanism; and the key server sends the unique identification key ciphertext and the first key verification value to the transaction terminal through the secure transmission terminal. As the unique identification keys of the transaction terminals corresponding to the same unique serial number in the whole life cycle are the same, the unique identification keys do not change; therefore, during subsequent maintenance, the unique identification key in the transaction terminal is ensured to be consistent with the unique identification key of the terminal of the UnionPay background.
Owner:FUJIAN LANDI COMMERCIAL EQUIPMENT CO LTD

Security systems and methods for encoding and decoding content

Systems and methods may be provided for masking data on public networks, such as social networking sites. At a publishing node, the system may monitor data input fields in a webpage, and intercept and encode content, such as text, images, and video input at the data input fields, prior to the content being posted online on a public service provider's website. A privacy agent may process input field content to try to detect encoding markers in the input field content, which define portions of the content that are to be encoded. A third party key server may be used to store decoding keys. A URI reference to the decoding key may be used to access the decoding key by a node attempting to view the decoded version of the input field content.
Owner:ESW HOLDINGS INC

Internet-based communication key generation method

ActiveCN120825282BEncryption is handled wellEnsure transmission securityKey distribution for secure communicationKey serverTelecommunications
The application discloses a communication key generation method based on the Internet, and relates to the technical field of communication. A packaging chain is arranged between an Internet platform and an access port, wherein the packaging chain comprises a first packaging pool, a second packaging pool and a transmission channel; the access port is used to access the Internet platform to obtain access information, the access information is packaged by the second packaging pool to generate a key information package; the key information package is transmitted to the first packaging pool through the transmission channel, and the access information is obtained by decrypting the key information package through the first packaging pool and provided to the access port. The key information package is generated by encryption through the key issued by the key server, data can be better encrypted, the access information is split and folded, and double encryption transmission is performed in cooperation with the key, so that the transmission safety of data is ensured.
Owner:SHANGHAI LEILONG INFORMATION TECH CO LTD

Secure control of access to data in an encrypted file

PCT designated stageWO2026084826A1Digital data protectionSecuring communicationKey serverInternet privacy
A security client of a mobile computing platform transmits a request for the secret key to a key server. The request includes environmental data characterizing a current state of the environment of the node and establishes a cryptographic heartbeat with the key server. The security client receives a secret key from the key server, stores the secret key in volatile memory and decrypts the encrypted file using the secret key to create a decrypted file in the volatile memory. The security client monitors a time since a last authenticated heartbeat message was received. Responsive to the time exceeding a predetermined timeout window or responsive to receiving a message from the key server indicating that authorization to the decrypted file is revoked or responsive to determining that the node is not in an authorized environment, the security client deletes the secret key from the volatile memory and closes the decrypted file.
Owner:NORTHROP GRUMMAN SYSTEMS CORP

Communication-oriented key dynamic distribution method and device and medium

The invention discloses a communication-oriented key dynamic distribution method and device and a medium, and relates to the technical field of communication network security, and the method comprises the steps: setting a key monitoring node according to communication network node distribution, a network security threat situation and a key transmission link, and obtaining key monitoring data including key encryption strength, key transmission security and the like; determining a key distribution pointer and a node trust index entry through feature analysis; and then configuring a hierarchical distribution mechanism, coordinating distribution action spaces of the master and slave key server clusters in each key security risk area, generating a joint distribution strategy containing key strength dynamic adjustment and the like, and loading the joint distribution strategy to a switch to complete key parameter configuration iteration. The technical problems that traditional key distribution is insufficient in flexibility and poor in safety adaptability are solved, and the technical effects of adapting to dynamic characteristics of a communication scene and achieving key distribution meeting actual requirements are achieved.
Owner:安徽明生恒卓科技有限公司

Information processing system, program, and authentication method

According to the present disclosure, a server issues challenge data and transmits the challenge data to a client. The client stores, in a memory, encrypted group data including a plurality of encrypted data encrypted with a server key, and parameter data A, receives the challenge data, generates response data using a client-side response key, and transmits the response data, the encrypted group data, and the parameter data A to the server. The server selects encrypted data to be used from among the received encrypted group data on the basis of the received parameter data A, sets a server-side response key on the basis of data obtained by decrypting the selected encrypted data with the server key, verifies the received response data on the basis of the challenge data and the server-side response key, and notifies the client of a verification result. The client receives the notification.
Owner:NINTENDO CO LTD

Database access method, apparatus, device, and storage medium

The present disclosure provides a database access method and device, equipment and storage medium, relates to the technical field of computers, in particular to the field of cloud computing and cloud security computing. The specific implementation scheme is: a key encryption request is sent to a key server, wherein the key encryption request includes a local key; a target key from the key server is obtained, wherein the target key is obtained by encrypting the local key by the key server according to a key server key; in response to receiving a write request for a database, using a custom type converter corresponding to the database, the data to be written corresponding to the write request is encrypted according to the key, to obtain encrypted data, wherein the custom type converter is obtained by injecting encryption logic code and decryption logic code into a default type converter; and the encrypted data is written into the database.
Owner:BEIJING BAIDU NETCOM SCI & TECH CO LTD

Method, device and readable storage medium for processing a national secret handshake request

Embodiments of the present application provide a kind of national secret handshake request processing method, equipment and readable storage medium, after node server receives the national secret handshake request from terminal device, when needing to use private key in the process of executing handshake procedure for national secret handshake request, suspend handshake procedure and send the request message carrying to-be-processed data to private key server.Private key server processes to-be-processed data using private key to obtain target data, constructs response message according to target data and sends to node server.Node server recovers handshake procedure according to target data, and with terminal device continues the handshake procedure of following down.Using this kind of scheme, without customer providing the private key corresponding to national secret certificate, national secret handshake request processing can also be completed without sensing, improve the application scope of national secret HTTPS protocol, improve business security.
Owner:CHINANETCENT TECH

A security verification method and system in an API request process

The application provides a security verification method and system in an API request process, and relates to the technical field of network security. The method comprises the following steps: receiving an API calling instruction and an HTTP request sent by a browser; generating a server public key and a symmetric key; generating a digital envelope according to the symmetric key and a server private key corresponding to the server public key; sending the symmetric key, the server public key and the digital envelope to the browser to obtain a digital digest after decryption; generating browser information; combining the digital digest, the browser information, request information and a request method to generate a second digital signature of the HTTP request; sending the browser information and the second digital signature as a request header of the HTTP request to the server for verification; if the HTTP request is verified, performing a business processing flow of the HTTP request, otherwise, terminating the business processing flow. The efficiency and effectiveness of the anti-replay attack are improved.
Owner:LUBAN (BEIJING) ELECTRONIC COMMERCE TECH CO LTD

A key-based resilient file system authentication method and device

The application discloses a kind of based on key's flexible file system authentication method and device, it is related to cloud computing, distributed storage technical field.The method, by issuing the key that user is created for file system under the flexible file management and control platform to the flexible file service success, NFS server is configured file for file system;NFS server receives RPC request sent after NFS client executes mounting command;Receive RPC request, complete parameter analysis, check parameter;NFS server sends request to key server, and key server checks key and judges whether the decrypted ciphertext is consistent with the key information in configuration file, if consistent, mounting request is legal;If not consistent, refuse mounting request.The permission authentication of the key and NAT gateway combination distinguishes the NFS mounting request from different user virtual machines, and realizes more accurate permission control compared with traditional NFS protocol.
Owner:CHINA TELECOM CLOUD TECH CO LTD

A signal encryption method and device based on quantum key distribution

This application discloses a signal encryption method and apparatus based on quantum key distribution, relating to the field of satellite navigation technology. The method includes: constructing a quantum key distribution system based on multiple interconnected quantum key servers, with a user communication terminal connected to the nearest quantum key server; a communication relay unit performing basis vector comparison on quantum state data from satellites and ground stations using a key distribution protocol to generate a quantum key; a key distribution unit dynamically updating the quantum key and distributing it to the user communication terminal; the user communication terminal using the quantum key to encrypt satellite navigation data, obtaining an encrypted data packet, which is then sent to a receiving end via the communication relay unit; and the receiving end decrypting the encrypted data packet based on the quantum key to obtain the satellite navigation data. This method can improve the quantum key generation rate, enhance the anti-interference performance of the quantum key distribution system in complex environments, and ensure the stability and reliability of the quantum key distribution system.
Owner:CETC XINGHE BEIDOU TECH (XIAN) CO LTD

Navigation message authentication method and device for navigation satellite PPP-b2b signals

The application relates to a navigation message authentication method for navigation satellite PPP-B2b signals, which comprises the following steps: generating a public-private key pair based on an SM2 algorithm, and obtaining a navigation message of a navigation satellite PPP-B2b signal; generating a page digest corresponding to a navigation message page according to an SM3 algorithm; generating a digital signature corresponding to the page digest according to a private key in the public-private key pair; embedding the digital signature in a newly designed message page to generate a new navigation message page; inserting the generated navigation message page into each playing period of the navigation satellite PPP-B2b signal according to a preset rule; uploading the new navigation message page to a navigation satellite; and playing the new navigation message page by the navigation satellite; and verifying whether the new navigation message page is tampered with by using a public key from a public key server. In the technical scheme of the application, the national SM2 asymmetric encryption algorithm and the SM3 hash algorithm are used, so that the security risks and compliance problems possibly existing in the use of foreign encryption algorithms are avoided.
Owner:BEIJING JIAOTONG UNIV +1

Circuit board key burning method and device, equipment and storage medium

The invention relates to the technical field of data burning, and discloses a circuit board key burning method, which comprises the following steps: when an intelligent terminal runs, identifying an operation from a user; and when the operation of the user is identified as the target operation, judging whether target key data required by the target operation is burnt to a circuit board of the intelligent terminal or not. And when the target key data is not burnt to the circuit board, applying for the target key data from the key server. And burning the target key data issued by the key server to the circuit board. In the application, the intelligent terminal can apply for the key data required by the target operation according to the target operation of the user and burn the key data required by the target operation to the circuit board, so that the process of automatically burning the key data to the circuit board is realized, the user is prevented from manually applying and burning the key data on a circuit board production line, and the user experience is improved. Therefore, the condition that the circuit board burns the key data mistakenly is reduced, and the reliability of burning the key data of the circuit board is improved. The invention further discloses a device and equipment for burning the key on the circuit board and a storage medium.
Owner:GUANGZHOU SHIKUN ELECTRONICS TECH CO LTD

Method and system for synchronizing data between digital car key servers based on event driving

The invention provides an event-driven data synchronization method and system between digital vehicle key servers, and belongs to the technical field of vehicle digital vehicle keys, and the method comprises the steps: obtaining a key state change event notification packet sent by an equipment server; updating a key state database according to the key state change event notification packet; the key status is synchronized to the device server. Through the event-driven architecture, the efficient data format and the dynamic synchronization strategy, the data synchronization efficiency and reliability between the digital vehicle key servers are remarkably improved, the problems of high delay, resource waste and inaccurate event processing in the prior art are solved, and the method is suitable for a digital key system of an intelligent networked vehicle and has a wide application prospect. Wide application prospects and commercial values are realized.
Owner:DONGFENG MOTOR GRP

System and method for securely delivering keys and encrypting content in cloud computing environments

A cloud-based system and method for encrypting media content is disclosed. The system comprises a key server microservice, for receiving control word requests and for generating encoded control words and a software encryption microservice, communicatively coupled to the key server microservices, the encryption microservice for receiving the media content, for generating the control word requests, for receiving the encoded control words, and for white-box encrypting the media content according to the generated encoded control words.
Owner:ARRIS ENTERPRISES LLC

Key determination method, application device and key determination system

The embodiment of the invention discloses a key determination method, application equipment and a key determination system, and belongs to the technical field of communication. In the embodiment of the invention, two application devices in a QKD network negotiate who is used as an active end for obtaining a quantum key by interacting QKD information, and then a target CAK and a target CKN required for using MKA protocol communication between the two application devices are determined based on the obtained quantum key. On one hand, technicians do not need to configure who is an active end and who is a passive end in advance, so that the configuration process can be simplified. And on the other hand, QKD information of the opposite end does not need to be pre-configured on each application device, and according to the embodiment of the invention, two communication parties negotiate who is used as an active end for obtaining the quantum key by interacting the QKD information instead of directly using a key server as the active end for obtaining the quantum key, so that the application range is wide.
Owner:HUAWEI TECH CO LTD

A voice data transmission method, device, apparatus and storage medium

ActiveCN116155482BKey serverNumber generator
This application discloses a voice data transmission method, apparatus, and storage medium applied to the calling end. The method includes: sending a call request to a server when sending a call request to the called end; receiving a session key sent by the server; encrypting voice data using the session key to obtain encrypted voice data; and sending the encrypted voice data to the called end for the called end to decrypt the encrypted voice data using the session key sent by the server. During each call, the server receives a quantum random number sent by a quantum random number generator, generates a session key based on the quantum random number, and sends the generated session key to both the calling and called ends. The calling end encrypts the voice data using the session key to obtain encrypted voice data, and the called end decrypts the encrypted voice data using the session key to obtain the voice data. This method enables "one-time key" encryption, effectively saving SIM card storage space and reducing costs.
Owner:CHINA MOBILE GROUP ANHUI +1

Anonymous password authentication and encryption method for deduplication-oriented cloud storage system

The application discloses an anonymous password authentication and encryption scheme for a deduplication cloud storage system, and is characterized in that, in the deduplication cloud storage system, under a three-party architecture of a key server, a cloud server and a user, the three parties jointly generate an MLE key, encryption data deduplication is realized, and the problems of brute force attack and single point failure are avoided; an anonymous authentication of the user to the cloud storage server is constructed based on a non-interactive zero-knowledge proof scheme, and the privacy protection of the user identity information is realized; a key protection mechanism based on a reinforced password is constructed by using an identity-based careless pseudo-random function, so that the user can safely store and maintain the key at the remote cloud server side without occupying local resources. The security analysis and simulation experiment results show that the scheme can guarantee the encryption and authentication security, and provide higher calculation and communication efficiency.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

Key determination method, application device and key determination system

PCT designated stageWO2026066343A1Key distribution for secure communicationKey serverEngineering
The present application belongs to the technical field of communications. Disclosed in the embodiments of the present application are a key determination method, an application device and a key determination system. In the embodiments of the present application, two application devices in a QKD network negotiate, by means of interaction of QKD information, which one will act as an active party for acquiring a quantum key, and then, on the basis of the acquired quantum key, determine a target CAK and a target CKN that are required for communication between the two parties using an MKA protocol. First, there is no need for technicians to preconfigure which device will act as an active party and which device will act as a passive party, thereby simplifying the configuration process; second, there is no need to preconfigure on each application device QKD information of a peer device; moreover, in the embodiments of the present application, two communication parties negotiate, by means of interaction of QKD information, which one will act as an active party for acquiring a quantum key, instead of a key server being directly assigned as an active party for acquiring a quantum key, thus achieving a wide application range.
Owner:HUAWEI TECH CO LTD