Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

70 results about "Key server" patented technology

In computer security, a key server is a computer that receives and then serves existing cryptographic keys to users or other programs. The users' programs can be working on the same network as the key server or on another networked computer.

Communication encryption method, computer equipment and storage medium

PendingCN121126333ASecurity arrangementKey serverSAFER
The embodiment of the invention provides a communication encryption method, computer equipment and a storage medium, relates to the technical field of information security, and can provide a safer communication process. Comprising the following steps: a server receives a first key acquisition request sent by a first terminal, and acquires a first composite key from a plurality of composite keys; wherein the composite key is a key obtained after fusion processing based on multiple types of quantum keys. And the server obtains a second composite key matched with the user information of the first terminal from the plurality of composite keys. And sending the second composite key to the server, so that the server encrypts the first composite key through the second composite key to obtain the encrypted first composite key. And the server sends the encrypted first composite key to the first terminal, so that the first terminal encrypts or decrypts communication data with the second terminal based on the first composite key after decrypting the encrypted first composite key.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD

Zero-trust software-based security model

Systems and methods are disclosed for computer attestation by generating, in a software enclave on a native application or browser and from a host device, a key generation request to a secure key client to generate a key pair; performing a multi-party key generation operation between the secure key client on the native application or browser and a secure key server; and storing a first private key share and public key on the secure key client, wherein a second private key share and a public key are stored on the secure key server and wherein the public key is sent from the secure key server to a host server for storage.
Owner:IDEEM INC

Signal encryption method and device based on quantum key distribution

The invention discloses a signal encryption method and device based on quantum key distribution, and relates to the technical field of satellite navigation, and the method comprises the steps: building a quantum key distribution system based on a plurality of interconnected quantum key servers, and enabling a user communication terminal to be connected with a nearby quantum key server; the communication relay unit performs basis vector comparison on the quantum state data of the satellite and the ground station through a key distribution protocol to generate a quantum key; the key distribution unit dynamically updates the quantum key and distributes the quantum key to the user communication terminal; the user communication terminal encrypts the satellite navigation data by using the quantum key to obtain an encrypted data packet, and sends the encrypted data packet to the receiving end through the communication relay unit; and the receiving end decrypts the encrypted data packet based on the quantum key to obtain the satellite navigation data. According to the method, the generation rate of the quantum key can be improved, the anti-interference performance of the quantum key distribution system in a complex environment is enhanced, and the stability and reliability of the quantum key distribution system are ensured.
Owner:CETC XINGHE BEIDOU TECH (XIAN) CO LTD

Secure control of access to data in an encrypted file

A security client of a mobile computing platform transmits a request for the secret key to a key server. The request includes environmental data characterizing a current state of the environment of the node and establishes a cryptographic heartbeat with the key server. The security client receives a secret key from the key server, stores the secret key in volatile memory and decrypts the encrypted file using the secret key to create a decrypted file in the volatile memory. The security client monitors a time since a last authenticated heartbeat message was received. Responsive to the time exceeding a predetermined timeout window or responsive to receiving a message from the key server indicating that authorization to the decrypted file is revoked or responsive to determining that the node is not in an authorized environment, the security client deletes the secret key from the volatile memory and closes the decrypted file.
Owner:NORTHROP GRUMMAN SYSTEMS CORP

Information processing system, one or more non-transitory computer-readable storage media having program stored therein, and authentication method

A server issues challenge data and transmits the challenge data to a client. The client stores encrypted group data including a plurality of encrypted data encrypted with a server key, and parameter data A, in a memory, receives the challenge data, generates response data using a response key on the client side, and transmits the response data, the encrypted group data, and the parameter data A to the server. The server selects encrypted data to be used from the received encrypted group data, based on the received parameter data A, sets a response key on the server side, based on the selected encrypted data and data decrypted with the server key, verifies the received response data, based on the challenge data and the response key on the server side, and notifies a result of the verification to the client. The client receives the notification.
Owner:NINTENDO CO LTD

System and method for secure key management for encrypted core dump

A method of a decryptor including receiving, from an encryptor of an electronic device, a core dump that has been encrypted with a symmetric key generated by the encryptor, and core dump metadata, extracting crash metadata from the core dump metadata, transmitting the crash metadata to a remote key server for regenerating the symmetric key, obtaining, from the remote key server, a regenerated symmetric key based the crash metadata, and decrypting the core dump based on the regenerated symmetric key and the crash metadata.
Owner:SAMSUNG ELECTRONICS CO LTD

End-to-end encryption with distributed key management in a tracking device environment

A tracking device can provide a hashed identifier to a mobile device, for instance within an advertisement packet. The mobile device can query each of a plurality of entities with the hashed identifier to identify an entity associated with the hash key used to generate the hashed identifier. In some embodiments, the mobile device can query a centralized key server, which in turn can query the plurality of entities to identify the entity associated with the hash key. The mobile device can then receive a public key from the identified entity, can determine a location of the mobile device, and can encrypt the location with the public key. The mobile device can then provide the hashed identifier and the encrypted location to the identified entity, which can provide the encrypted location to an owner of the tracking device for decryption using a private key corresponding to the public key.
Owner:TILE

Post-quantum secure media access control security (macsec) pre-shared key auto-refresh

Techniques for utilizing post-quantum pre-shared key (PPK) identifiers (PPK_ID) to determine control association key(s) (CAK(s)) and / or secure association key(s) (SAK(s)) utilized in MACsec sessions are described herein. A key server (KS) and a non-key server (NKS) may advertise capabilities indicating an ability to utilize PPKs as CAKs and / or SAKs in MACsec sessions. The KS may leverage a quantum key distribution (QKD) service to determine a PPK_ID and a PPK, which may be utilized as a CAK for a MACsec session with the NKS. The PPK_ID may be transmitted to the NKS, where the NKS may retrieve the PPK from the QKD, and a new group connectivity association may be established using the PPK as the CAK. In some examples, the KS may be configured to refresh the PPK as the CAK for instantiating subsequent MACsec sessions. Additionally, the KS may be configured to distribute a SAK in a similar manner.
Owner:CISCO TECHNOLOGY INC

Systems, apparatus, and methods for generation, packaging, and secure distribution of symmetric quantum cypher keys

Methods for quantum key distribution are disclosed including forming a quantum production key package with a production file name; forming a first quantum sacrificial key package with a first sacrificial file name associated with a portion of the first production file name; sending the quantum sacrificial key package to a sacrificial key server; and sending the quantum production key package to computer devices to set up a quantum key encryption tunnel between the computer devices. The quantum production key packages are received by computer devices that send the production file name to the sacrificial key server to receive the sacrificial return key. The sacrificial return key is used to decrypt the quantum production key package with the quantum production keys. A first quantum production key is retrieved to encrypt and decrypt data at each computer device.
Owner:ZEROPROOF LLC +1

Lightweight hybrid defense method and system for federated learning gradient leakage

The invention discloses a lightweight hybrid defense method and system for federated learning gradient leakage, and the method comprises the steps: firstly calculating the importance of model parameters based on local data through employing Fisher information, and generating a local important parameter mask; a plurality of clients jointly determine a global encryption parameter set, important parameters are reserved locally as personalized knowledge, and other non-key parameters are classified into a noise area; the client performs homomorphic encryption on the global encryption parameter set by using the public key, adds differential privacy noise to the parameters in the noise area, and uploads the processed parameters; the system adopts a double-server architecture, an aggregation server aggregates encryption parameters and noise parameters respectively, a key server is responsible for decrypting the aggregated encryption parameters and merging the encrypted parameters with the noise parameters, and through selective encryption and personalized parameter reservation, the calculation and communication overhead is remarkably reduced, and the system has the advantages of being high in security and high in reliability. And meanwhile, relatively high model accuracy and strong privacy protection capability are still kept in a non-independent identically distributed data environment.
Owner:XI AN JIAOTONG UNIV

Data transmission method based on direct communication

The invention discloses a direct communication-based data transmission method, which comprises the following steps that: each of a plurality of terminals initiates an identity authentication request to an aggregation security gateway, the aggregation security gateway constructs a topological connection relationship based on the terminals passing the identity authentication, and the terminals establish connection according to the topological connection relationship to form a communication network; the method comprises the following steps: in a communication network, acquiring a symmetrical communication key file 1 from a key server by two mutually connected terminals through an aggregation security gateway; the sending terminal determines a communication route, processes the service data mes, generates a sending data packet MES and sends the sending data packet MES to the receiving terminal; the receiving terminal carries out decryption and verification operation on the sending data packet MES, after verification is passed, service data mes' are obtained, and service processing operation is executed. A full-link safety guarantee system from identity authentication, connection establishment, secret key management to data transmission is built, and essential improvement of safety is achieved while high communication efficiency is guaranteed.
Owner:MATRICTIME DIGITAL TECH CO LTD

Hardware-backed password security for cloud systems

Methods, systems, and devices for data processing are described. A server host may receive a login request that includes a clear text password for an account associated with a tenant of a multi-tenant cloud platform. The server host may retrieve an encrypted payload associated with the account. The encrypted payload may include a hash value of a user-configured password for the account and an indication of a hashing algorithm used to transform the user-configured password into the hash value. The server host may obtain a wrapped symmetric key provisioned by a symmetric key distribution service. The server host may transmit a request that includes the encrypted payload, the clear text password, and the wrapped symmetric key. The server host may receive a response that indicates whether a hash value of the clear text password from the login request corresponds to the hash value of the user-configured password.
Owner:SALESFORCE INC

A federated learning method for model quality evaluation based on functional encryption

The disclosure provides a federated learning method for model quality evaluation based on functional encryption, in which a server selects a plurality of clients to establish a federated learning protocol, generates a master public key and a master private key; the server calculates a global model update for a given global model and processes it to an integer domain, and calculates a decryption key in combination with the master private key. The server sends the global model and the master public key to the selected clients; the clients calculate a local model update using the global model and process it to an integer domain, and generate ciphertext in combination with the master public key and send it to the server. The server decrypts the ciphertext using the decryption key, and calculates the cosine similarity between the decrypted client local model and the server global model. Through cosine similarity clustering, the client models are divided into high-quality, qualified and low-quality models and are assigned weights, and the server updates the global model through weighted aggregation. Using the present application, model quality evaluation can be performed on the basis of high efficiency and privacy protection, and then global model updating is realized.
Owner:BEIJING INST OF TECH +1

Symmetric-key infrastructure

Techniques for provisioning a key server to facilitate secure communications between a web server and a client by providing the client with a first data structure including information on how the web server may obtain a target symmetric key are presented. The techniques can include: provisioning the key server with a second data structure including information on how the key server may generate the first data structure; receiving a request on behalf of a web server for a third data structure comprising information on how the client may obtain the first data structure from the key server; and obtaining the third data structure, such that the third data structure is published in association with an identification of the web server, and such that the client uses the third data structure to obtain the first data structure and uses the first data structure to communicate with the web server.
Owner:VERISIGN INC

Security Systems and Methods for Encoding and Decoding Content

Systems and methods may be provided for masking data on public networks, such as social networking sites. At a publishing node, the system may monitor data input fields in a webpage, and intercept and encode content, such as text, images, and video input at the data input fields, prior to the content being posted online on a public service provider's website. A privacy agent may process input field content to try to detect encoding markers in the input field content, which define portions of the content that are to be encoded. A third party key server may be used to store decoding keys. A URI reference to the decoding key may be used to access the decoding key by a node attempting to view the decoded version of the input field content.
Owner:KAXXA HOLDINGS INC

Scalable key state for network encryption

Systems and methods are provided for implementing encryption of data-in-motion and / or otherwise stored data using a key server and a secure enclave of a Network Interface Card (NIC). The NIC acts as a passthrough between the client device and the shared infrastructure of the supercomputer system to help ensure data security in a massively scaled and distributed system. For example, in response to an enrollment process that stores a decrypted key in the secure enclave of a NIC, the NIC can receive a data packet from a client device. The NIC can transmit a key request to a key server that includes an encrypted key corresponding to the decrypted key. The key server can look up the previously stored private / public key pair to authenticate the NIC. The key server can provide private / public key pair to the NIC to allow the NIC to later encrypt data-in-motion.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Method and system for obtaining preset root key offline by quantum safety equipment terminal

The invention discloses a method and system for obtaining a preset root key offline by a quantum security device terminal, and the method comprises the steps: enabling the quantum security device terminal to initiate a registration application to a root key server through network communication equipment based on the hardware number of the quantum security device terminal; the root key server generates a root key file for the quantum security device terminal based on the registration application, encrypts the root key file by using an encryption key, and issues a root key ciphertext to the quantum security device terminal offline through an intermediate medium; the quantum security equipment terminal executes identity authentication operation to obtain a decryption key of the root key ciphertext; and the quantum security equipment terminal performs decryption operation on the root key ciphertext by using the received decryption key to obtain a plaintext-state root key file, and locally stores the plaintext-state root key file. According to the method, the security, reliability and controllability of the quantum security equipment terminal in the network access initialization process are ensured through a root key security acquisition system which is linked with one another and is deeply defended.
Owner:MATRICTIME DIGITAL TECH CO LTD

Threshold searchable symmetric encryption

A data owner can provide shares of a cryptographic key to N key servers. The N key servers can store the shares of a cryptographic key from the data owner such that T shares of the cryptographic key can be used to reconstruct the cryptographic key. A client computer can send a blinded query to T key servers of the N key severs, wherein the T key servers can encrypt a blinded query of a client computer using the share of the cryptographic key to determine a partial encryption. The client computer can receive T partial encryptions, assemble T partial encryptions to form an encrypted blinded query, and deblind the encrypted blinded query. The client computer can then use the encrypted query to perform a search on encrypted data of a remote database server using a searchable symmetric encryption scheme.
Owner:VISA INTERNATIONAL SERVICE ASSOCIATION

Authenticating an electronic device based on threshold cryptography using partial secret keys

It is provided a method for performing an action by an electronic device (2), based on a first partial secret key (10a) and a corresponding second partial secret key (10b), wherein the first partial secret key (10a) and the second partial secret key (10b) form part of a threshold cryptography scheme (11) associated with a public key (12). The method comprises: transmitting (40), upon the device initialising, a request for a first partial secret key (10a) to a key server (3); receiving (42) the first partial secret key (10a) from the key server (3); storing (44) the first partial secret key (10a) only in volatile memory (70); retrieving (46) a second partial secret key (10b) from non-volatile memory (71); and performing (48) an action based on applying both the first partial secret key (10a) and the second partial secret key (10b).
Owner:ASSA ABLOY AB

Instant messaging secret key determination method and device and storage medium

The invention provides a secret key determination method and device for instant messaging and a storage medium, relates to the field of communication security, and can solve the problem that a secret key cannot be decrypted due to expiration. The method comprises the following steps: receiving a first request message, wherein the first request message is used for requesting a key; the first request message at least comprises respective identifiers of the two clients; determining root keys corresponding to the two clients based on the first request message; generating a key based on the root key and respective identifiers of the two clients; and sending a first response message, wherein the first response message comprises the key and the validity period of the key. The corresponding key can be generated under the condition that the key does not exist or expires, for the server, the key can be generated according to the root key and the respective identifiers of the two clients, all keys do not need to be stored, the complexity of key management is simplified, the storage space is saved, and the manageability of the key is improved.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD +1

Secure networked respiratory therapy systems

Methods and apparatus provide communications among respiratory therapy device (“TD”), server and intermediary (e.g., a control device (“CTLD”) for the therapy device) to improve security. More secure communication channel(s) may be established using shared secrets derived with different channels. The communications may include transmitting therapy data from TD to server for authentication. The CTLD may receive the data and a nonce from a server. The CTLD receives from the TD a signing key dependent on the nonce and a secret shared by TD and server. The CTLD generates an authorisation code with received therapy data and the key for authentication of the data by the server upon its receipt of the code and data. The server computes (1) a key from the nonce and the secret known to TD, and (2) another authorisation code from received therapy data and the key. Data authentication may involve comparing received and computed codes.
Owner:RESMED INC

Unique identification key downloading method and system

The invention discloses a unique identification key downloading method and system. The method comprises the following steps: a transaction terminal imports a certificate through a secure transmission terminal and a key server; the transaction terminal sends the unique serial number and the certificate to the key server through the secure transmission terminal; the key server checks the unique serial number and the certificate, if the unique serial number and the certificate are legal, a unique identification key corresponding to the unique serial number is obtained, and a unique identification key ciphertext and a first key check value are generated according to the unique identification key and the certificate; the unique identification key is a key required for verification and use during transaction of the transaction terminal and the special mechanism; and the key server sends the unique identification key ciphertext and the first key verification value to the transaction terminal through the secure transmission terminal. As the unique identification keys of the transaction terminals corresponding to the same unique serial number in the whole life cycle are the same, the unique identification keys do not change; therefore, during subsequent maintenance, the unique identification key in the transaction terminal is ensured to be consistent with the unique identification key of the terminal of the UnionPay background.
Owner:FUJIAN LANDI COMMERCIAL EQUIPMENT CO LTD

A method, device and medium for security authentication of a PostgreSQL database

PendingCN122634644AKey serverPassword
This specification discloses a method, device, and medium for secure authentication of a PostgreSQL database, relating to the field of security authentication technology, and is used to solve the problem of unauthorized login and unauthorized covert login caused by user password leakage, which is difficult to address with existing authentication methods. The method includes: a client receiving a username and password input by a user, and generating a first communication key using a key derivation function by combining the username, the password, a first preset password, and a first count value; a server receiving a username sent by the client, querying the PostgreSQL database to obtain the corresponding stored password, a second preset password, and a second count value, and generating a second communication key using the key derivation function; and the server receiving the first communication key and performing password authentication based on the first and second communication keys to obtain the authentication result of the PostgreSQL database.
Owner:HIGHGO SOFTWARE

A reversible information hiding method for the ciphertext field based on multi-key threshold decryption

This invention discloses a method for reversible information hiding in the ciphertext domain based on multi-key threshold decryption, comprising: generating a system public key and a private key share through a key server, and distributing the private key share to a decryption end; acquiring an original image through an image provider, encrypting the original image according to the system public key to obtain an encrypted image; dividing the embedded message into a first message and a second message through a data hiding end, embedding the first message into the encrypted image using a value expansion embedding algorithm, and embedding the second message into the encrypted image containing the first message using a random number refresh embedding algorithm to obtain a ciphertext image containing the ciphertext; extracting messages from the ciphertext image containing the ciphertext to obtain the second message through a decryption end, and decrypting the ciphertext image containing the ciphertext to obtain a distributed decrypted image; and jointly decrypting several distributed decrypted images through an image receiver to obtain a plaintext image, extracting messages from the plaintext image and recovering the original image to obtain the first message and the original image.
Owner:ENG UNIV OF THE CHINESE PEOPLES ARMED POLICE FORCE

Security systems and methods for encoding and decoding content

Systems and methods may be provided for masking data on public networks, such as social networking sites. At a publishing node, the system may monitor data input fields in a webpage, and intercept and encode content, such as text, images, and video input at the data input fields, prior to the content being posted online on a public service provider's website. A privacy agent may process input field content to try to detect encoding markers in the input field content, which define portions of the content that are to be encoded. A third party key server may be used to store decoding keys. A URI reference to the decoding key may be used to access the decoding key by a node attempting to view the decoded version of the input field content.
Owner:ESW HOLDINGS INC

Securing application communication

In embodiments of systems and methods for synchronous content presentation, a user equipment (UE) may generate a freshness parameter, generate a unique session key based on a first session key and the freshness parameter, and send the freshness parameter to a Network Application Function (NAF) of a network device in a configuration that will enable the NAF to generate the unique session key. The network device may receive the freshness parameter, receive from a Key Server Function (KSF) the first session key, and generate based on the freshness parameter and the first session key the unique session key. The UE and the network device may then conduct secure communications using the unique session key without exchanging the unique session key between the two devices.
Owner:QUALCOMM INC

User-transparent updatable encryption deduplication method and system in cloud environment

The invention discloses a user-transparent updatable encryption deduplication method and system in a cloud environment, and relates to the technical field of encryption deduplication. According to the method, a data label sent by a data owner is repeatedly retrieved through a cloud server, when the data label is not retrieved, a secret key server group determines a secret share through non-allocation secret sharing, an encryption key is generated in combination with a threshold DH-OPRF protocol to encrypt data, and an ownership certificate is generated based on a Merkel tree and DH-OPRF; and when the certification is retrieved, the cloud server sends the certification verification information to a verifier, and the verifier generates an ownership certification and compares the ownership certification with the stored certification to complete verification. According to the method, transparent ciphertext updating of the user is achieved, the user does not need to participate in key and ciphertext updating, the communication overhead is reduced through client de-duplication, access revocation is achieved by means of dynamic ownership proof, safety and high efficiency are both considered, and the method is suitable for a cloud storage scene.
Owner:XIDIAN UNIV

Internet-based communication key generation method

ActiveCN120825282BEncryption is handled wellEnsure transmission securityKey distribution for secure communicationKey serverTelecommunications
The application discloses a communication key generation method based on the Internet, and relates to the technical field of communication. A packaging chain is arranged between an Internet platform and an access port, wherein the packaging chain comprises a first packaging pool, a second packaging pool and a transmission channel; the access port is used to access the Internet platform to obtain access information, the access information is packaged by the second packaging pool to generate a key information package; the key information package is transmitted to the first packaging pool through the transmission channel, and the access information is obtained by decrypting the key information package through the first packaging pool and provided to the access port. The key information package is generated by encryption through the key issued by the key server, data can be better encrypted, the access information is split and folded, and double encryption transmission is performed in cooperation with the key, so that the transmission safety of data is ensured.
Owner:SHANGHAI LEILONG INFORMATION TECH CO LTD

Secure control of access to data in an encrypted file

A security client of a mobile computing platform transmits a request for the secret key to a key server. The request includes environmental data characterizing a current state of the environment of the node and establishes a cryptographic heartbeat with the key server. The security client receives a secret key from the key server, stores the secret key in volatile memory and decrypts the encrypted file using the secret key to create a decrypted file in the volatile memory. The security client monitors a time since a last authenticated heartbeat message was received. Responsive to the time exceeding a predetermined timeout window or responsive to receiving a message from the key server indicating that authorization to the decrypted file is revoked or responsive to determining that the node is not in an authorized environment, the security client deletes the secret key from the volatile memory and closes the decrypted file.
Owner:NORTHROP GRUMMAN SYSTEMS CORP

Communication-oriented key dynamic distribution method and device and medium

The invention discloses a communication-oriented key dynamic distribution method and device and a medium, and relates to the technical field of communication network security, and the method comprises the steps: setting a key monitoring node according to communication network node distribution, a network security threat situation and a key transmission link, and obtaining key monitoring data including key encryption strength, key transmission security and the like; determining a key distribution pointer and a node trust index entry through feature analysis; and then configuring a hierarchical distribution mechanism, coordinating distribution action spaces of the master and slave key server clusters in each key security risk area, generating a joint distribution strategy containing key strength dynamic adjustment and the like, and loading the joint distribution strategy to a switch to complete key parameter configuration iteration. The technical problems that traditional key distribution is insufficient in flexibility and poor in safety adaptability are solved, and the technical effects of adapting to dynamic characteristics of a communication scene and achieving key distribution meeting actual requirements are achieved.
Owner:安徽明生恒卓科技有限公司