Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

524 results about "Key storage" patented technology

Sensing data chip-level dynamic key negotiation method

The invention relates to the technical field of sensing data security, and discloses a sensing data chip-level dynamic key negotiation method, which comprises the following steps of: acquiring a unique hardware identifier and key parameters of a sensor node, and generating a dynamic key seed matrix; after acquisition is completed, randomly intercepting data segments, performing median filtering and normalization preprocessing, extracting local statistical features and global features to generate a data feature sequence, and splicing the data feature sequence to a seed matrix to obtain a dynamic key generation matrix; a dynamic negotiation key is generated through standardization and SM3 Hash algorithm encryption, and is stored in a cloud and node security unit; during verification, dual verification is realized through hash comparison and plaintext bit-by-bit matching; and setting an environment parameter exception triggering mechanism, and updating the key if accumulative exception exceeds the limit. According to the method, hardware and dynamic data features are fused, and the key security and adaptability are improved.
Owner:ZHONGYING QINGCHUANG TECH CO LTD

Firmware encryption method and system based on device unique identifier and dynamic key verification

The invention provides a firmware encryption method and system based on a device unique identifier and dynamic key verification, and relates to the technical field of firmware protection, and the method comprises the steps: obtaining a unique identifier of a device, the unique identifier being hardware feature information which cannot be modified; a dynamic key is generated based on the unique identifier and the random number, and the dynamic key is realized through an encryption algorithm and is regenerated every time the device is started or firmware is updated; the dynamic key is stored in a storage area protected by hardware, and the storage area is subjected to double protection of hardware isolation and logic encryption; and when the device is started, the dynamic key is regenerated, the unique identifier of the dynamic key and the unique identifier of the dynamic key stored in the storage area are compared and verified, if the dynamic key and the unique identifier are consistent, firmware operation is allowed, and otherwise, a safety response mechanism is triggered. According to the invention, the security and reliability of firmware protection can be improved.
Owner:SANY HEAVY EQUIP CO LTD +1

Chip security key protection method and system capable of resisting side channel attack

The invention provides a chip security key protection method and system capable of resisting side channel attack, and relates to the technical field of chips, which comprises the following steps of: obtaining a key operation request, performing address space mapping based on a dynamic mapping rule to obtain encrypted key data, decrypting the encrypted key data, fragmenting key intermediate data, and allocating an independent processing channel to perform decoupling operation; and injecting a time-varying noise signal to cover the association between the key and the physical characteristics, and finally performing recombination and reverse conversion to generate a final key output. According to the method, side channel attacks such as power consumption analysis and electromagnetic analysis are effectively resisted, and the security of key storage and operation processes is improved.
Owner:WING SHIELD (SHANGHAI) INTELLIGENT TECH CO LTD

Unified identity authentication and access control method for power multi-service system based on national secret algorithm

The invention discloses a unified identity authentication and access control method for a power multi-service system based on a national secret algorithm. According to the invention, through systematic deployment of SM2, SM3 and SM4 cryptographic algorithms, a full-link security protection system from identity authentication to authority management is constructed. The unified identity authentication platform adopts a mode of combining a distributed micro-service architecture and a hardware encryption machine, so that the physical security of key storage and operation is guaranteed, and the stability and response speed of the system are improved through a master-slave synchronization mechanism and interface delay control. A multi-source identity information federation acquisition mechanism realizes real-time integration of static attributes and dynamic behavior data, abnormal characteristics of user operation can be accurately captured by combining a risk assessment matrix of an improved LSTM-attention mechanism, and an SM2 bidirectional dynamic authentication protocol is automatically triggered when a risk score exceeds a dynamic threshold. Closed-loop protection of collection-evaluation-authentication-auditing is formed, and security threats such as identity counterfeiting and authority crossing are effectively resisted.
Owner:GUIZHOU WUJIANG HYDROPOWER DEV

Key shard verification for key storage devices

In certain embodiments, verification operations are performed. A first device packaged with a second device may store a first key shard and a second key. The first key shard may be a same key shard as a corresponding key shard stored on the second device, where the second key is different from a corresponding key stored on the second device. Additionally, the first key shard and the corresponding key shard are associated with a user. In connection with a request from a web service, the first device or a computing device may generate a response to the request using the second key by identifying the second key using an identifier of the request. Furthermore, the first device or the computing device may send the response to the web service, where the web service confirms registration of the first key shard based on the response.
Owner:UNIT 410 LLC

Extension of network control system into public cloud

Some embodiments provide a method for a first data compute node (DCN) operating in a public datacenter. The method receives an encryption rule from a centralized network controller. The method determines that the network encryption rule requires encryption of packets between second and third DCNs operating in the public datacenter. The method requests a first key from a secure key storage. Upon receipt of the first key, the method uses the first key and additional parameters to generate second and third keys. The method distributes the second key to the second DCN and the third key to the third DCN in the public datacenter.
Owner:VMWARE INC

Systems and methods for secure user authentication with passkeys on shared computing devices

Embodiments described herein provide systems and methods for secure and efficient user authentication across a variety of computing devices, such as desktops, laptops, smartphones, and tablets across operating systems such as Windows, MacOS, IOS, Android, and iPadOS. The system incorporates an authenticator application configured to communicate with internal or external user identifier scanners, such as RFID / NFC readers, fingerprint scanners, facial recognition cameras, and QR / Barcode scanners, using transport protocols like USB, BLE, or NFC. The authenticator application serves as a third-party passkey provider by interfacing with platform WebAuthn APIs, enabling WebAuthn-based authentication for native applications, browsers, and services, or alternatively as a browser extension, intercepting WebAuthn API calls directly within a browser environment. An authentication server, accessible over a network, verifies user identities by mapping unique identifiers to stored authenticators and requesting additional authentication factors as needed, such as a security PIN. Upon successful authentication, the server transmits passkeys and a session token to the authenticator application, enabling it to handle further authentication requests locally. The system supports advanced session management for shared device environments, allowing configurable passkey storage with options for one-time, time-based, or shift-based expiration, automatically clearing passkeys upon session completion. This design delivers a versatile, secure, and seamless authentication experience across diverse user environments.
Owner:IDMELON TECH INC

Low-latency multi-key encryption and decryption engine and techniques

Disclosed systems and techniques involve low-latency multi-key encryption processing in which block keys are precomputed based on multiple cryptographic keys, stored, and then selected for encryption or decryption of data during run-time cryptographic operations. The block keys may be precomputed, for each cryptographic key, in such quantities that allow uninterrupted flow of encryption or decryption operations. Replacement block keys may be concurrently generated to replace the blocks being consumed and authentication values may be computed or updated. Various described techniques allow parallel processing for efficient low-latency block key generation and cryptographic operations.
Owner:CRYPTOGRAPHY RESEARCH INC

Encryption and decryption method, system and device, equipment and storage medium

The invention discloses an encryption and decryption method, system, device and equipment and a storage medium, and relates to the technical field of data security of a storage system.The encryption and decryption method comprises the steps that a system password is received through an RAID controller, a derived password is generated in combination with a pre-stored random number salt value and an encryption key, and the derived password is sent to the RAID controller; and converting the password into a readable password conforming to the password rule of the self-encryption disk, and encrypting and storing the readable password so as to control the locking or unlocking of the self-encryption disk. According to the method, the salt value and the encryption key are stored in advance, so that the exposure of a plaintext password is avoided, the problems of performance bottleneck and key storage security risk caused by centralized encryption of a traditional RAID controller are solved, meanwhile, the encryption characteristic of the self-encryption disk is utilized, automatic encryption during data storage and automatic locking after power failure are realized, and the security of data storage is improved. The technical effects of reducing the calculation load, improving the key security and guaranteeing the end-to-end encryption of the data storage are achieved, so that RAID redundancy and the security mechanism of the self-encryption disk are deeply combined, and the data protection capability of the whole system is enhanced.
Owner:SHANDONG YUNHAI GUOCHUANG CLOUD COMPUTING EQUIP IND INNOVATION CENT CO LTD

Method For Authenticating To A Remote Server Using Service-Specific Credentials Stored In The eUICC

An apparatus configured to receive, from a provisioning server, a request to create at least one sub-profile of at least one profile stored within an embedded universal integrated circuit card of the apparatus; wherein the request comprises encrypted subscription data comprising a symmetric key between a service provider and a user of the apparatus; store the symmetric key within the embedded universal integrated circuit card of the apparatus; and create the at least one sub-profile of the at least one profile stored within the embedded universal integrated circuit card of the apparatus; wherein the at least one sub-profile of the at least one profile stored within the embedded universal integrated circuit card of the apparatus is configured to be used to authenticate the user of the apparatus to the service provider with use of the symmetric key without involvement of a mobile network operator.
Owner:NOKIA TECHNOLOGIES OY

Encryption communication method and system used between EtherCAT slave station nodes

The invention is suitable for the field of communication technology improvement, and provides an encryption communication method and system used between EtherCAT slave station nodes, an OTP / nonvolatile storage, an encryption scrambling unit and a decryption descrambling unit are integrated in an EtherCAT slave station chip of a coupler and an I / O module, and encryption / decryption of an EtherCAT message is achieved on the hardware level; xOR operation or an AES algorithm is adopted for encryption, and a secret key is stored in an unmodifiable storage unit; and meanwhile, a parallel architecture of an encrypted network and a standard network is constructed, so that the standard interaction between the slave station node and the master station is not influenced by encrypted communication. The system solves the contradiction of poor real-time performance of a private protocol and easy plaintext communication plagiarism in the prior art, realizes the effects of no real-time performance loss, strong communication exclusiveness and flexible compatibility, and is suitable for an EtherCAT high-speed backplane bus system under industrial 4.0.
Owner:ANXIN MICRO SEMICON TECH (SHENZHEN) CO LTD

Controlling access to cryptographic resources using double encryption

A system for controlling access to cryptographic resources is disclosed. The system may receive a request to transfer cryptographic resources between users, including a user identifier and a first cryptographic signature. The system may verify the signature and retrieve an encrypted private key from a key vault using the user identifier. A command to sign the request may be transmitted over a private network to a signature device, which may generate a second cryptographic signature using the decrypted private key. The system may receive the second signature, generate a blockchain operation based on the request and signature, and transmit the operation to a blockchain node for commitment. The system may also handle new account generation, storing encrypted keys in jurisdiction-specific databases, and validating blockchain operations against request parameters.
Owner:CITIBANK N A

Remote signature system and tamper resistant device

The present invention realizes a remote signature system in which identity verification is performed for each signing request by combining the remote signature system with public key cryptography. A terminal device (2) comprises a means for generating a key pair for authentication to perform the public key cryptography. A generated secret key is stored in the terminal device (2), and a generated public key is transmitted to the tamper resistant device (5) and is stored in relation with the corresponding signature key. The tamper resistant device comprises a signature key storage means (12) for storing the signature key, a decryption key and signature key identification information as pairs for each user. When requesting a digital signing, a signing request including the signature key identification information, plaintext verification information, and a crypto token including the encrypted verification information and the encrypted signature object data is created and is transmitted to the tamper resistant device (5). The tamper resistant device accesses to the signature key storage means (12) and searches both the decryption key and the signature key. The tamper resistant device decrypts the crypto token using the searched decryption key, and verifies consistency between the decrypted verification information and the plaintext verification information. If they do not match each other, the signing request is excluded from the digital signing.
Owner:KEY TECHNO CO LTD

Data encryption method suitable for open source gap terminal equipment

The invention discloses a data encryption method applicable to open source gap terminal equipment, which comprises the following steps of: firstly, establishing communication connection based on a gap distributed soft bus technology, and generating a trust relationship through identity identification authentication; during data transmission, a national cryptographic algorithm, a symmetric or asymmetric encryption algorithm, a hybrid encryption algorithm and the like are dynamically selected according to data types, importance, transmission scenes and equipment performance. After being encrypted, the data are transmitted to the target device through the soft bus, and the target device decrypts and verifies the data. And the terminal equipment is integrated with the hardware security module to realize hardware encryption and key storage. Security module adaptation development is carried out based on an HDF library, and one-time development and multi-terminal operation are achieved. In the encryption process, a fragmentation encryption strategy can be adopted, multiple devices can perform collaborative encryption and decryption, and the encryption efficiency is improved by defining the task priority and sequence and utilizing a distributed task scheduling mechanism and reasonably allocating resources.
Owner:BEIJING SPACEFLIGHT TUOPUGAO SCI & TECH CO LTD

Middlebox visibility for post quantum KEM

Some embodiments are directed to a communication system comprising a one or more clients, a server and a middlebox. The middlebox may access to the multiple short-term server private keys of the server. The middlebox may recover a shared key that is negotiated between server and client by decapsulating encapsulation data using a stored client public key and a server private key from the key storage.
Owner:KONINKLIJKE PHILIPS NV

Key management system and method, medium and product

The invention discloses a key management system and method, a medium and a product, an offline key generation part and a key storage part are deployed, the offline key generation part stores a first initial key, and the key storage part stores a second initial key paired with the first initial key. According to the method and the device, an offline key generation part is used for generating an encrypted key based on a first initial key in an offline mode, a key storage part is used for decrypting the encrypted key by using a second initial key, and the decrypted key is written into a preset secure storage area. Generation, distribution and storage of the secret key are realized, so that the system cost is effectively reduced.
Owner:SHENZHEN XIHUA TECHNOLOGY CO LTD +2

Key generation method and device, equipment, medium and product

The embodiment of the invention discloses a key generation method and device, equipment, a medium and a product, and the method comprises the steps: generating a random key through an encryption machine under the condition that the total number of keys currently stored in a database is different from a preset target value; encrypting the random key through an encryption algorithm, and storing the encrypted random key as a key in the database; and returning to the step of generating the random key by using the encryption machine under the condition that the total number of the keys currently stored in the database is different from the preset target value until the total number of the keys is the same as the preset target value. According to the technical scheme, the total number of the keys stored in the database is judged based on the preset target value, and the random keys are generated by using the encryption machine until the total number of the keys is the same as the preset target value under the condition that the total number of the keys is different from the preset target value, so that the condition that repeated keys exist in the keys is avoided, and the user experience is improved. And the security and the accuracy of the secret key are improved.
Owner:CHONGQING WEIBINAI TECHNOLOGY CO LTD

Quantum key synchronous storage method for QKD

The invention discloses a quantum key synchronous storage method for QKD (quantum key distribution), which belongs to the technical field of digital information transmission, and comprises the following steps of: monitoring a node connection state of a quantum key distribution network, generating a dynamic topological graph, acquiring a key generation rate of a node in the dynamic topological graph, generating a synchronous triggering rule by combining a synchronous period reference value to trigger a key synchronization instruction, and storing the key synchronization instruction. Sending the key synchronization instruction to the target node; receiving a returned key data packet, extracting a key hash value abstract, and performing edge collaborative pre-verification to generate a pre-verification result; executing a key storage operation based on the pre-verification result; and obtaining a key state label in the key data packet, writing the synchronized key into the corresponding physical storage area, and updating the priority mapping relationship of the logic index layer. According to the method, a linkage mechanism of dynamic topology sensing triggering, edge collaborative pre-verification and state self-adaptive storage is adopted, efficient key synchronization can be achieved in a dynamic network, and meanwhile the utilization rate of storage resources and the anti-attack capacity of the system are improved.
Owner:CHINA NAT INST OF STANDARDIZATION

Pre-authorized transaction in cold cryptographic key storage

A system may store, in an offline storage, a private cryptographic key that corresponds to a public cryptographic key that corresponds to a blockchain address of a blockchain. The system may connect temporarily to the offline storage to generate one or more pre-authorized transaction requests using the private cryptographic key stored in the offline storage. The system may disconnect the offline storage from the computing device. The system may store the one or more pre-authorized transaction requests in the computing device, wherein the one or more pre-authorized transaction requests include pre-determined parameters such that the one or more pre-authorized transaction requests are broadcastable to the blockchain without further retrieving the private cryptographic key stored in the disconnected storage.
Owner:BLOCKDAEMON INC

Key management method and storage device

The invention discloses a key management method and a storage device, and belongs to the field of storage security, the method comprises the following steps: deriving different types of key fragments from an authentication key according to different preset classification strategies, and respectively storing the different types of key fragments in different storage partitions corresponding to the preset classification strategies; receiving a data access request, wherein the data access request comprises data index information; based on different preset classification strategies, reading candidate key fragments matched with the data index information from the different storage partitions respectively, verifying the legality of the candidate key fragments matched with the data index information, and determining the candidate key fragments passing the verification as effective key fragments; and aggregating the effective key fragments of different types to generate the authentication key, and obtaining target access data of the data access request through the authentication key. According to the invention, the security of key storage and the flexibility of key management can be effectively improved.
Owner:BIWIN STORAGE TECH CO LTD

Solid state disk key storage method and system and storage medium

The invention discloses a solid state disk key storage method and system and a storage medium, and belongs to the technical field of solid state disks. The method comprises the steps that a CPU component controls an SM4 component to generate a required medium key, and the medium key is temporarily stored in a register which cannot be read and written by the CPU component in the SM4 component; performing programming operation on the eFlash component through the eFlash controller component, and storing the medium key in an address specified by the key updating area; when the SM4 component detects that a programming operation completion indication signal is in a high level and key programming is successful, the SM4 component resets a medium key temporarily stored in the SM4 component and sets a key programming completion state register and a key programming success state register to be in a high level; and the CPU component performs storage verification, and when the CPU component queries that the secret key programming completion state register and the secret key programming success state register of the SM4 component are both high levels, secret key storage is completed. According to the invention, the medium key and the digital certificate cannot be stored out of the main control chip, so that the security is higher, and the key updating times are not limited.
Owner:JIANGSU XINSHENG INTELLIGENT TECH CO LTD +1

Controlling access to cryptographic resources using offline storage

A system for controlling access to cryptographic resources is disclosed. The system may receive a request to transfer cryptographic resources between users, including a user identifier and a first cryptographic signature. The system may verify the signature and retrieve an encrypted private key from a key vault using the user identifier. A command to sign the request may be transmitted over a private network to a signature device, which may generate a second cryptographic signature using the decrypted private key. The system may receive the second signature, generate a blockchain operation based on the request and signature, and transmit the operation to a blockchain node for commitment. The system may also handle new account generation, storing encrypted keys in jurisdiction-specific databases, and validating blockchain operations against request parameters.
Owner:CITIBANK N A

Single step transaction authentication using proximity and biometric input

A system and method provide efficient, secure and highly reliable authentication for transaction processing and / or access control applications in which only biometric input is required from the user. A Personal Digital Key stores a biometric profile that comprises a representation of physical or behavioral characteristics that are uniquely associated with an individual that owns and carries the PDK. The PDK wirelessly transmits the biometric profile over a secure wireless transaction to a Reader for use in a biometric authentication process. The Reader compares the received biometric profile to a biometric input acquired at the point of transaction in order to determine if the transaction should be authorized.
Owner:PROXENSE

Dynamic hierarchical data encryption and decryption method, system and device based on Internet of Things and medium

The invention discloses a dynamic hierarchical data encryption and decryption method, system and device based on the Internet of Things, and a medium, belongs to the technical field of Internet of Things security, and aims to solve the technical problem of how to dynamically adjust an encryption and decryption mode in an Internet of Things data transmission process, provide high security and flexibility of Internet of Things data transmission, and improve the security and reliability of Internet of Things data transmission. According to the technical scheme, the method comprises the following steps: data layering: dividing data into a plurality of hierarchies through a data analysis and classification algorithm according to the sensitive degree and transmission requirements of the data; dynamic encryption and decryption: dynamically adjusting the encryption and decryption hierarchy and key of the data according to the transmission demand of the data and the current network environment by means of a real-time network monitoring technology and a data transmission demand analysis model; key management: storing the key on a block chain by adopting a block chain technology to realize secure storage and distribution of the key; and formulating encryption strategies: formulating different encryption strategies according to the hierarchy and transmission requirements of the data.
Owner:INSPUR ENTERPRISE CLOUD TECHNOLOGY (SHANDONG) CO LTD

System for integrated data provenance and reconciliation across heterogeneous financial systems

ActiveDE202025104886U1FinanceData streamGate array
A system for integrated data provenance and reconciliation across heterogeneous financial systems, the system includes: a data ingestion module implemented as a hardware interface and configured with high-throughput adapters for structured and unstructured data ingestion from multiple heterogeneous financial subsystems, including bank ledgers, securities trading platforms, risk management databases, and regulatory reporting systems; a schema harmonization processing unit consisting of a dedicated FPGA (Field Programmable Gate Array) structure configured to perform real-time schema alignment, metadata normalization, and semantic mapping across different data models; a lineage tracking processor array implemented on application-specific integrated circuits (ASICs) and configured to encode dataflow transitions into a graph-encoded structure in which each node represents a transformation and each edge represents a dependency; a reconciliation computation cluster unit embodied as a set of graphics processing units (GPUs) configured to execute parallelized reconciliation techniques, anomaly detection routines, and balance verification processes between transformed financial records and reference records; a cryptographic verification unit comprising secure key storage hardware, quantum-resistant encryption modules, and tamper-resistant enclaves configured to generate, anchor, and verify cryptographic signatures for provenance and reconciliation events; a secure storage subsystem configured in a WORM (write-once, read-many) configuration with hardware-based integrity locks for storing immutable provenance and reconciliation logs; a controller with a dedicated visualization processor configured to generate interactive dashboards and drill-down analyses of lineage charts and voting results; and a modular chassis structure consisting of a high-speed backplane interconnect, secure power distribution modules, and tamper-evident enclosures, enabling the system to achieve real-time scalability, hardware-level security, and auditability of financial data flows across heterogeneous infrastructures.
Owner:SUDHANSHU JAIN LITHIA

Verifying identity of an emergency vehicle during operation

A method includes: receiving, by a computing device of a first vehicle, a command from a host device; in response to receiving the command, storing a new device secret in memory; generating, by the computing device using the new device secret, a triple comprising an identifier, a certificate, and a public key; and sending, by the computing device, the triple to a second vehicle, where the second vehicle is configured to verify an identity of the first vehicle using the triple.
Owner:MICRON TECHNOLOGY INC

Intelligent key cabinet authority management method and device, electronic equipment and storage medium

The invention provides an intelligent key cabinet authority management method and device, electronic equipment and a storage medium, and the method comprises the steps: obtaining work ticket or operation ticket information which is from an electronic two-ticket system and comprises a worker in charge, a worker member and a corresponding key number, and dynamically generating key access authority configuration according to the information; the identity of the target user can be received and verified, whether the current time is within the permission configuration range or not can be judged, and an opening instruction is generated to open the corresponding key storage device after verification is passed. The problems that in the prior art, due to the fact that key taking permission is not associated with work ticket or operation ticket information of an electronic two-ticket system, permission configuration cannot be dynamically adjusted, compliance verification of user identity and taking time is lacked, key taking is disordered, the safety risk is high, and power operation specifications are not met can be solved.
Owner:NEW ENERGY BRANCH OF NORTH UNITED POWER CO LTD

Block cipher implementation method, device and equipment based on lightweight algorithm structure

The invention provides a block cipher implementation method, device and equipment based on a lightweight algorithm structure. The method comprises the steps that cache equipment or a data interface obtains a plaintext needing cipher implementation; loading plaintexts by the register or the cache, and grouping the plaintexts into four branches for parallel processing by using the SIMD register; generating a round key by designing a key scheduling algorithm, and storing the round key in a special register; designing a lightweight algorithm structure for performing password implementation on the four branches stored in the SIMD register; and performing I-round encryption / decryption iteration on four branches of initial input of the plaintext / ciphertext by using a lightweight algorithm structure to generate the ciphertext / plaintext. According to the method disclosed by the invention, the cryptographic algorithm based on the lightweight algorithm structure is designed to encrypt and decrypt the data transmitted by the network or the communication, so that the software and hardware implementation cost in the application process is reduced while the requirement of easily implementing the lightweight password application is met, and the security is good.
Owner:KAIYUAN INTERNATIONAL MATHEMATICS RESEARCH INSTITUTE

System and method for pairing a utility meter with a remote display module

A method of pairing a metering device with a remote display module. The method comprises storing a pairing public key of an asymmetric key pair in respective memories of the metering device and remote display module; communicating to the metering device and the remote display module, a temporary public key of a temporary asymmetric key pair, the temporary public key signed using a pairing private key of the asymmetric key pair; authenticating, by the metering device and the remote display module, the temporary public key, using the stored pairing public key; communicating to the metering device and the remote display module, a pairing request signed using a temporary private key of the temporary asymmetric key pair, wherein the pairing request comprises a meter public key of a meter asymmetric key pair; authenticating, by the metering device and the remote display module, the pairing request using the authenticated temporary public key; and storing the meter public key in the remote display module.
Owner:LANDIS GYR TECH INC