Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

96 results about "Key server" patented technology

In computer security, a key server is a computer that receives and then serves existing cryptographic keys to users or other programs. The users' programs can be working on the same network as the key server or on another networked computer.

Method for applying anti-quantum certificate to TLS1.2 handshake process

The invention discloses a method for applying an anti-quantum certificate to a TLS1.2 handshake process, which realizes the application of an MLDSA anti-quantum signature algorithm and an MLKEM anti-quantum key encapsulation mechanism in the handshake process by expanding a cipher suite and a signature algorithm field of a TLS1.2 protocol. The method specifically comprises the following steps: defining a cipher suite supporting MLKEM and an MLDSA signature algorithm enumeration value; the client declares algorithm support in ClientHello, and the server responds and returns a certificate chain containing the double-antibody quantum certificate; after the client verifies the certificate, the pre-master key is encapsulated by using MLKEM, and the server de-encapsulates the derived session key; and the two parties send Finished messages to each other to complete handshake. According to the scheme, on the premise that a TLS1.2 basic framework is not changed, the communication security is enhanced through double-resistance quantum algorithm integration, international and national cryptographic algorithms are supported, quantum computing attacks can be resisted, meanwhile, adaptation of the international and national cryptographic algorithms is supported, compatibility with an existing system is ensured, the security risk of a traditional cryptographic algorithm in a quantum environment is solved, and the security risk of the traditional cryptographic algorithm in the quantum environment is reduced. And a standardized solution is provided for anti-quantum upgrade of the TLS1.2 protocol.
Owner:BEIJING SKYFAITH TECH CO LTD

Multiple post-quantum cryptography key encapsulations with authentication and forward secrecy

A server and a device can conduct mutually authenticated post-quantum cryptography (PQC) key encapsulation mechanisms (KEM) that also support forward secrecy. The device can store a trusted server public key (PK.server) and the server can store a trusted device public key (PK.device). The device can generate (i) a first KEM ciphertext and (ii) a first key with PK.server and encrypt an ephemeral public key (ePK.device) using the first key. The server can generate (i) a second KEM ciphertext and (ii) a second key with ePK.device. The server can generate (i) a third KEM ciphertext and (ii) a third key with PK.device. The server can encrypt an ephemeral public key (ePK.server) using the first, second, and third keys. The device can generate (i) a fourth KEM ciphertext and (ii) a fourth key with ePK.server. The device can encrypt application data using at least the first, second, third, and fourth keys.
Owner:ADEIA EMERGING TECHNOLOGIES INC

Threshold searchable symmetric encryption

A data owner can provide shares of a cryptographic key to N key servers. The N key servers can store the shares of a cryptographic key from the data owner such that T shares of the cryptographic key can be used to reconstruct the cryptographic key. A client computer can send a blinded query to T key servers of the N key severs, wherein the T key servers can encrypt a blinded query of a client computer using the share of the cryptographic key to determine a partial encryption. The client computer can receive T partial encryptions, assemble T partial encryptions to form an encrypted blinded query, and deblind the encrypted blinded query. The client computer can then use the encrypted query to perform a search on encrypted data of a remote database server using a searchable symmetric encryption scheme.
Owner:VISA INTERNATIONAL SERVICE ASSOCIATION

Communication encryption method, computer equipment and storage medium

PendingCN121126333ASecurity arrangementKey serverSAFER
The embodiment of the invention provides a communication encryption method, computer equipment and a storage medium, relates to the technical field of information security, and can provide a safer communication process. Comprising the following steps: a server receives a first key acquisition request sent by a first terminal, and acquires a first composite key from a plurality of composite keys; wherein the composite key is a key obtained after fusion processing based on multiple types of quantum keys. And the server obtains a second composite key matched with the user information of the first terminal from the plurality of composite keys. And sending the second composite key to the server, so that the server encrypts the first composite key through the second composite key to obtain the encrypted first composite key. And the server sends the encrypted first composite key to the first terminal, so that the first terminal encrypts or decrypts communication data with the second terminal based on the first composite key after decrypting the encrypted first composite key.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD

Zero-trust software-based security model

Systems and methods are disclosed for computer attestation by generating, in a software enclave on a native application or browser and from a host device, a key generation request to a secure key client to generate a key pair; performing a multi-party key generation operation between the secure key client on the native application or browser and a secure key server; and storing a first private key share and public key on the secure key client, wherein a second private key share and a public key are stored on the secure key server and wherein the public key is sent from the secure key server to a host server for storage.
Owner:IDEEM INC

Systems and methods of personalizing contactless card

Methods and systems for personalizing contactless cards are provided. An exemplary method includes: preinstalling, by a server, an applet on the contactless card; assigning, by the server, a first unique identifier to the contactless card; pre-provisioning, by the server, a first unique derived key to the contactless card; generating, by the server a first nonce; generating, by the server, a data file containing script for updating the contactless card and further containing a message authentication code (MAC); transmitting, by the server, the data file and the first nonce to the contactless card; validating, by the contactless card, the MAC based on the first unique derived key and the first nonce; and personalizing the contactless card by the preinstalled applet executing the script.
Owner:CAPITAL ONE SERVICES LLC

Signal encryption method and device based on quantum key distribution

The invention discloses a signal encryption method and device based on quantum key distribution, and relates to the technical field of satellite navigation, and the method comprises the steps: building a quantum key distribution system based on a plurality of interconnected quantum key servers, and enabling a user communication terminal to be connected with a nearby quantum key server; the communication relay unit performs basis vector comparison on the quantum state data of the satellite and the ground station through a key distribution protocol to generate a quantum key; the key distribution unit dynamically updates the quantum key and distributes the quantum key to the user communication terminal; the user communication terminal encrypts the satellite navigation data by using the quantum key to obtain an encrypted data packet, and sends the encrypted data packet to the receiving end through the communication relay unit; and the receiving end decrypts the encrypted data packet based on the quantum key to obtain the satellite navigation data. According to the method, the generation rate of the quantum key can be improved, the anti-interference performance of the quantum key distribution system in a complex environment is enhanced, and the stability and reliability of the quantum key distribution system are ensured.
Owner:CETC XINGHE BEIDOU TECH (XIAN) CO LTD

Information security storage method

The invention belongs to the field of information security, and particularly relates to an information security storage method, which comprises the following steps of: receiving uploaded original file data, and dynamically segmenting the original file data into a plurality of data fragments; adding a key to each data fragment in the encryption pool by using a random encryption algorithm to obtain an encrypted fragment; establishing a key group corresponding to each encryption fragment, and uploading a key field encrypted by the key group to a special key server; the file is dynamically segmented for fragmented storage, the file is stored in a multi-level encryption mode, when leakage occurs in any link, the other levels of encryption means can still prevent leakage of the file, and the reliability of file storage is ensured. An attacker permeates the system for a long time, fragments and keys are slowly collected, defense is expanded from a fragment dispersion space dimension to a key timeliness time dimension through dynamic rotation, fragment integrity and key timeliness need to be met at the same time during cracking, and file storage safety is improved.
Owner:BEIJING BEIRUAN MINGZHAN TECHNOLOGY CO LTD

Lattice-based updatable private key password protection secret sharing method

The invention discloses a lattice-based updatable private key password protection secret sharing method. The method comprises the steps of system initialization, a secret recovery method and a secret key share updating method. According to the method, a zero update technology is adopted, password protection secret sharing dynamic key update is achieved, key share update is achieved between servers, the correctness of key update is verified through a Lagrange interpolation polynomial, the key does not affect the value of a master key, the application range is expanded, and the method is suitable for popularization and application. According to the invention, quantum resistance, continuous leakage resistance and online password guess attack resistance are realized, authentication with a plurality of key servers can be carried out securely, an encryption key for decrypting cloud privacy data is reconstructed, user privacy is effectively guaranteed, secure storage and controllable access of data are realized, and key privacy protection is provided for a cloud storage technology. The method has the advantages of being good in robustness, high in secret key updating efficiency, high in reliability, wide in application range and the like, and can be applied to the technical field of privacy of password protection secret sharing.
Owner:SHAANXI NORMAL UNIV

Cloud-edge collaborative ubiquitous network ciphertext data security management system

The invention relates to the technical field of network and information security, and discloses a cloud-side collaborative ubiquitous network ciphertext data security management system, which comprises a user side module, an edge node module, a cloud server module, a key server module and a backup and integrity verification module. The user side performs local de-duplication by using the simple tag and generates an attribute ciphertext and a multi-level de-duplication tag; the edge node judges duplication and then forwards; the cloud side matches the label in parallel to realize unique storage. The backup module fragments the ciphertext according to a Shamir secret sharing threshold value and carries out distributed encryption backup; and the integrity verification module adopts lattice signature based on learning with an error problem, cloud, edge and end multi-point verification, and dynamic access is realized in combination with a reputation threshold value. The system gives consideration to confidentiality, duplicate removal efficiency, disaster recovery capability and anti-quantum integrity, and is suitable for large-scale data scenes of the Internet of Vehicles, the Internet of Things and the like.
Owner:CHANGCHUN UNIV OF SCI & TECH

Secure control of access to data in an encrypted file

A security client of a mobile computing platform transmits a request for the secret key to a key server. The request includes environmental data characterizing a current state of the environment of the node and establishes a cryptographic heartbeat with the key server. The security client receives a secret key from the key server, stores the secret key in volatile memory and decrypts the encrypted file using the secret key to create a decrypted file in the volatile memory. The security client monitors a time since a last authenticated heartbeat message was received. Responsive to the time exceeding a predetermined timeout window or responsive to receiving a message from the key server indicating that authorization to the decrypted file is revoked or responsive to determining that the node is not in an authorized environment, the security client deletes the secret key from the volatile memory and closes the decrypted file.
Owner:NORTHROP GRUMMAN SYSTEMS CORP

Information processing system, one or more non-transitory computer-readable storage media having program stored therein, and authentication method

A server issues challenge data and transmits the challenge data to a client. The client stores encrypted group data including a plurality of encrypted data encrypted with a server key, and parameter data A, in a memory, receives the challenge data, generates response data using a response key on the client side, and transmits the response data, the encrypted group data, and the parameter data A to the server. The server selects encrypted data to be used from the received encrypted group data, based on the received parameter data A, sets a response key on the server side, based on the selected encrypted data and data decrypted with the server key, verifies the received response data, based on the challenge data and the response key on the server side, and notifies a result of the verification to the client. The client receives the notification.
Owner:NINTENDO CO LTD

System and method for secure key management for encrypted core dump

A method of a decryptor including receiving, from an encryptor of an electronic device, a core dump that has been encrypted with a symmetric key generated by the encryptor, and core dump metadata, extracting crash metadata from the core dump metadata, transmitting the crash metadata to a remote key server for regenerating the symmetric key, obtaining, from the remote key server, a regenerated symmetric key based the crash metadata, and decrypting the core dump based on the regenerated symmetric key and the crash metadata.
Owner:SAMSUNG ELECTRONICS CO LTD

End-to-end encryption with distributed key management in a tracking device environment

A tracking device can provide a hashed identifier to a mobile device, for instance within an advertisement packet. The mobile device can query each of a plurality of entities with the hashed identifier to identify an entity associated with the hash key used to generate the hashed identifier. In some embodiments, the mobile device can query a centralized key server, which in turn can query the plurality of entities to identify the entity associated with the hash key. The mobile device can then receive a public key from the identified entity, can determine a location of the mobile device, and can encrypt the location with the public key. The mobile device can then provide the hashed identifier and the encrypted location to the identified entity, which can provide the encrypted location to an owner of the tracking device for decryption using a private key corresponding to the public key.
Owner:TILE

Post-quantum secure media access control security (macsec) pre-shared key auto-refresh

Techniques for utilizing post-quantum pre-shared key (PPK) identifiers (PPK_ID) to determine control association key(s) (CAK(s)) and / or secure association key(s) (SAK(s)) utilized in MACsec sessions are described herein. A key server (KS) and a non-key server (NKS) may advertise capabilities indicating an ability to utilize PPKs as CAKs and / or SAKs in MACsec sessions. The KS may leverage a quantum key distribution (QKD) service to determine a PPK_ID and a PPK, which may be utilized as a CAK for a MACsec session with the NKS. The PPK_ID may be transmitted to the NKS, where the NKS may retrieve the PPK from the QKD, and a new group connectivity association may be established using the PPK as the CAK. In some examples, the KS may be configured to refresh the PPK as the CAK for instantiating subsequent MACsec sessions. Additionally, the KS may be configured to distribute a SAK in a similar manner.
Owner:CISCO TECHNOLOGY INC

Systems, apparatus, and methods for generation, packaging, and secure distribution of symmetric quantum cypher keys

Methods for quantum key distribution are disclosed including forming a quantum production key package with a production file name; forming a first quantum sacrificial key package with a first sacrificial file name associated with a portion of the first production file name; sending the quantum sacrificial key package to a sacrificial key server; and sending the quantum production key package to computer devices to set up a quantum key encryption tunnel between the computer devices. The quantum production key packages are received by computer devices that send the production file name to the sacrificial key server to receive the sacrificial return key. The sacrificial return key is used to decrypt the quantum production key package with the quantum production keys. A first quantum production key is retrieved to encrypt and decrypt data at each computer device.
Owner:ZEROPROOF LLC +1

Lightweight hybrid defense method and system for federated learning gradient leakage

The invention discloses a lightweight hybrid defense method and system for federated learning gradient leakage, and the method comprises the steps: firstly calculating the importance of model parameters based on local data through employing Fisher information, and generating a local important parameter mask; a plurality of clients jointly determine a global encryption parameter set, important parameters are reserved locally as personalized knowledge, and other non-key parameters are classified into a noise area; the client performs homomorphic encryption on the global encryption parameter set by using the public key, adds differential privacy noise to the parameters in the noise area, and uploads the processed parameters; the system adopts a double-server architecture, an aggregation server aggregates encryption parameters and noise parameters respectively, a key server is responsible for decrypting the aggregated encryption parameters and merging the encrypted parameters with the noise parameters, and through selective encryption and personalized parameter reservation, the calculation and communication overhead is remarkably reduced, and the system has the advantages of being high in security and high in reliability. And meanwhile, relatively high model accuracy and strong privacy protection capability are still kept in a non-independent identically distributed data environment.
Owner:XI AN JIAOTONG UNIV

Data transmission method based on direct communication

The invention discloses a direct communication-based data transmission method, which comprises the following steps that: each of a plurality of terminals initiates an identity authentication request to an aggregation security gateway, the aggregation security gateway constructs a topological connection relationship based on the terminals passing the identity authentication, and the terminals establish connection according to the topological connection relationship to form a communication network; the method comprises the following steps: in a communication network, acquiring a symmetrical communication key file 1 from a key server by two mutually connected terminals through an aggregation security gateway; the sending terminal determines a communication route, processes the service data mes, generates a sending data packet MES and sends the sending data packet MES to the receiving terminal; the receiving terminal carries out decryption and verification operation on the sending data packet MES, after verification is passed, service data mes' are obtained, and service processing operation is executed. A full-link safety guarantee system from identity authentication, connection establishment, secret key management to data transmission is built, and essential improvement of safety is achieved while high communication efficiency is guaranteed.
Owner:MATRICTIME DIGITAL TECH CO LTD

Intelligent device key management system based on cloud service

The invention provides a cloud service-based intelligent device key management system, which comprises a plurality of terminal devices, and is characterized in that the terminal devices are configured to perform encryption through public keys according to device serial numbers and timestamp data to generate real-time keys; each terminal device comprises a first storage module and a second storage module, and the first storage module is configured to store first key data reported successfully; the second storage module is configured to store the second key data which fails to be reported; the cloud server is configured to verify the real-time secret key through the public key and generate a secret key verification result; the secret key verification result is used for marking success or failure of real-time secret key reporting; and the key server is configured to store the successfully reported key data. According to the system, the problems of single derived key path, lack of a key log tracing function and incapability of real-time risk blocking in the existing key management technology are solved.
Owner:SICHUAN HONGMEI INTELLIGENT TECH CO LTD

Hardware-backed password security for cloud systems

Methods, systems, and devices for data processing are described. A server host may receive a login request that includes a clear text password for an account associated with a tenant of a multi-tenant cloud platform. The server host may retrieve an encrypted payload associated with the account. The encrypted payload may include a hash value of a user-configured password for the account and an indication of a hashing algorithm used to transform the user-configured password into the hash value. The server host may obtain a wrapped symmetric key provisioned by a symmetric key distribution service. The server host may transmit a request that includes the encrypted payload, the clear text password, and the wrapped symmetric key. The server host may receive a response that indicates whether a hash value of the clear text password from the login request corresponds to the hash value of the user-configured password.
Owner:SALESFORCE INC

A federated learning system and method based on differential privacy against poisoning attacks

The present invention discloses a federated learning system and method based on differential privacy to prevent poisoning attacks. The system includes a key center, a server S1, and a server S2. Server S1 and a user negotiate to obtain a symmetric key. Server S1 generates Gaussian noise, encrypts it with the symmetric key, and sends it to the user. Normal users send local model parameters trained by noise perturbation to server S2, while malicious users upload random numbers as local model parameters to server S2. Servers S1 and S2 exchange information to complete model parameter verification and aggregation. Server S1 sends the aggregated model parameters to each user. The system determines whether the model has converged. If so, the process ends. If not, the above steps are repeated until the model converges. The present invention enables the server to verify whether the model parameters have been poisoned without infringing user privacy, and reduces computing and communication overhead.
Owner:NANJING UNIV OF POSTS & TELECOMM

A federated learning method for model quality evaluation based on functional encryption

The disclosure provides a federated learning method for model quality evaluation based on functional encryption, in which a server selects a plurality of clients to establish a federated learning protocol, generates a master public key and a master private key; the server calculates a global model update for a given global model and processes it to an integer domain, and calculates a decryption key in combination with the master private key. The server sends the global model and the master public key to the selected clients; the clients calculate a local model update using the global model and process it to an integer domain, and generate ciphertext in combination with the master public key and send it to the server. The server decrypts the ciphertext using the decryption key, and calculates the cosine similarity between the decrypted client local model and the server global model. Through cosine similarity clustering, the client models are divided into high-quality, qualified and low-quality models and are assigned weights, and the server updates the global model through weighted aggregation. Using the present application, model quality evaluation can be performed on the basis of high efficiency and privacy protection, and then global model updating is realized.
Owner:BEIJING INST OF TECH +1

Symmetric-key infrastructure

Techniques for provisioning a key server to facilitate secure communications between a web server and a client by providing the client with a first data structure including information on how the web server may obtain a target symmetric key are presented. The techniques can include: provisioning the key server with a second data structure including information on how the key server may generate the first data structure; receiving a request on behalf of a web server for a third data structure comprising information on how the client may obtain the first data structure from the key server; and obtaining the third data structure, such that the third data structure is published in association with an identification of the web server, and such that the client uses the third data structure to obtain the first data structure and uses the first data structure to communicate with the web server.
Owner:VERISIGN INC

Security Systems and Methods for Encoding and Decoding Content

Systems and methods may be provided for masking data on public networks, such as social networking sites. At a publishing node, the system may monitor data input fields in a webpage, and intercept and encode content, such as text, images, and video input at the data input fields, prior to the content being posted online on a public service provider's website. A privacy agent may process input field content to try to detect encoding markers in the input field content, which define portions of the content that are to be encoded. A third party key server may be used to store decoding keys. A URI reference to the decoding key may be used to access the decoding key by a node attempting to view the decoded version of the input field content.
Owner:KAXXA HOLDINGS INC

Scalable key state for network encryption

Systems and methods are provided for implementing encryption of data-in-motion and / or otherwise stored data using a key server and a secure enclave of a Network Interface Card (NIC). The NIC acts as a passthrough between the client device and the shared infrastructure of the supercomputer system to help ensure data security in a massively scaled and distributed system. For example, in response to an enrollment process that stores a decrypted key in the secure enclave of a NIC, the NIC can receive a data packet from a client device. The NIC can transmit a key request to a key server that includes an encrypted key corresponding to the decrypted key. The key server can look up the previously stored private / public key pair to authenticate the NIC. The key server can provide private / public key pair to the NIC to allow the NIC to later encrypt data-in-motion.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Method and system for obtaining preset root key offline by quantum safety equipment terminal

The invention discloses a method and system for obtaining a preset root key offline by a quantum security device terminal, and the method comprises the steps: enabling the quantum security device terminal to initiate a registration application to a root key server through network communication equipment based on the hardware number of the quantum security device terminal; the root key server generates a root key file for the quantum security device terminal based on the registration application, encrypts the root key file by using an encryption key, and issues a root key ciphertext to the quantum security device terminal offline through an intermediate medium; the quantum security equipment terminal executes identity authentication operation to obtain a decryption key of the root key ciphertext; and the quantum security equipment terminal performs decryption operation on the root key ciphertext by using the received decryption key to obtain a plaintext-state root key file, and locally stores the plaintext-state root key file. According to the method, the security, reliability and controllability of the quantum security equipment terminal in the network access initialization process are ensured through a root key security acquisition system which is linked with one another and is deeply defended.
Owner:MATRICTIME DIGITAL TECH CO LTD

System and device for data protection and method thereof

A method of operating a user device includes: receiving a command from a user to power on the user device; determining whether the user device is located within a restricted zone through accessing a key server located within the restricted zone by a first monitoring entity of the user device before an operating system of the user device is executed, wherein the key server is configured to store a key for encrypting or decrypting the user device; and granting access of the user to the user device by the first monitoring entity in response to determining the user device as being within the restricted zone through successfully accessing the key server.
Owner:TAIWAN SEMICONDUCTOR MANUFACTURING CO LTD

Threshold searchable symmetric encryption

A data owner can provide shares of a cryptographic key to N key servers. The N key servers can store the shares of a cryptographic key from the data owner such that T shares of the cryptographic key can be used to reconstruct the cryptographic key. A client computer can send a blinded query to T key servers of the N key severs, wherein the T key servers can encrypt a blinded query of a client computer using the share of the cryptographic key to determine a partial encryption. The client computer can receive T partial encryptions, assemble T partial encryptions to form an encrypted blinded query, and deblind the encrypted blinded query. The client computer can then use the encrypted query to perform a search on encrypted data of a remote database server using a searchable symmetric encryption scheme.
Owner:VISA INTERNATIONAL SERVICE ASSOCIATION

Authenticating an electronic device based on threshold cryptography using partial secret keys

It is provided a method for performing an action by an electronic device (2), based on a first partial secret key (10a) and a corresponding second partial secret key (10b), wherein the first partial secret key (10a) and the second partial secret key (10b) form part of a threshold cryptography scheme (11) associated with a public key (12). The method comprises: transmitting (40), upon the device initialising, a request for a first partial secret key (10a) to a key server (3); receiving (42) the first partial secret key (10a) from the key server (3); storing (44) the first partial secret key (10a) only in volatile memory (70); retrieving (46) a second partial secret key (10b) from non-volatile memory (71); and performing (48) an action based on applying both the first partial secret key (10a) and the second partial secret key (10b).
Owner:ASSA ABLOY AB

Instant messaging secret key determination method and device and storage medium

The invention provides a secret key determination method and device for instant messaging and a storage medium, relates to the field of communication security, and can solve the problem that a secret key cannot be decrypted due to expiration. The method comprises the following steps: receiving a first request message, wherein the first request message is used for requesting a key; the first request message at least comprises respective identifiers of the two clients; determining root keys corresponding to the two clients based on the first request message; generating a key based on the root key and respective identifiers of the two clients; and sending a first response message, wherein the first response message comprises the key and the validity period of the key. The corresponding key can be generated under the condition that the key does not exist or expires, for the server, the key can be generated according to the root key and the respective identifiers of the two clients, all keys do not need to be stored, the complexity of key management is simplified, the storage space is saved, and the manageability of the key is improved.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD +1