Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

382 results about "Key storage" patented technology

Chip security key protection method and system capable of resisting side channel attack

The invention provides a chip security key protection method and system capable of resisting side channel attack, and relates to the technical field of chips, which comprises the following steps of: obtaining a key operation request, performing address space mapping based on a dynamic mapping rule to obtain encrypted key data, decrypting the encrypted key data, fragmenting key intermediate data, and allocating an independent processing channel to perform decoupling operation; and injecting a time-varying noise signal to cover the association between the key and the physical characteristics, and finally performing recombination and reverse conversion to generate a final key output. According to the method, side channel attacks such as power consumption analysis and electromagnetic analysis are effectively resisted, and the security of key storage and operation processes is improved.
Owner:WING SHIELD (SHANGHAI) INTELLIGENT TECH CO LTD

Unified identity authentication and access control method for power multi-service system based on national secret algorithm

The invention discloses a unified identity authentication and access control method for a power multi-service system based on a national secret algorithm. According to the invention, through systematic deployment of SM2, SM3 and SM4 cryptographic algorithms, a full-link security protection system from identity authentication to authority management is constructed. The unified identity authentication platform adopts a mode of combining a distributed micro-service architecture and a hardware encryption machine, so that the physical security of key storage and operation is guaranteed, and the stability and response speed of the system are improved through a master-slave synchronization mechanism and interface delay control. A multi-source identity information federation acquisition mechanism realizes real-time integration of static attributes and dynamic behavior data, abnormal characteristics of user operation can be accurately captured by combining a risk assessment matrix of an improved LSTM-attention mechanism, and an SM2 bidirectional dynamic authentication protocol is automatically triggered when a risk score exceeds a dynamic threshold. Closed-loop protection of collection-evaluation-authentication-auditing is formed, and security threats such as identity counterfeiting and authority crossing are effectively resisted.
Owner:GUIZHOU WUJIANG HYDROPOWER DEV

Key shard verification for key storage devices

In certain embodiments, verification operations are performed. A first device packaged with a second device may store a first key shard and a second key. The first key shard may be a same key shard as a corresponding key shard stored on the second device, where the second key is different from a corresponding key stored on the second device. Additionally, the first key shard and the corresponding key shard are associated with a user. In connection with a request from a web service, the first device or a computing device may generate a response to the request using the second key by identifying the second key using an identifier of the request. Furthermore, the first device or the computing device may send the response to the web service, where the web service confirms registration of the first key shard based on the response.
Owner:UNIT 410 LLC

Extension of network control system into public cloud

Some embodiments provide a method for a first data compute node (DCN) operating in a public datacenter. The method receives an encryption rule from a centralized network controller. The method determines that the network encryption rule requires encryption of packets between second and third DCNs operating in the public datacenter. The method requests a first key from a secure key storage. Upon receipt of the first key, the method uses the first key and additional parameters to generate second and third keys. The method distributes the second key to the second DCN and the third key to the third DCN in the public datacenter.
Owner:VMWARE INC

Encryption communication method and system used between EtherCAT slave station nodes

The invention is suitable for the field of communication technology improvement, and provides an encryption communication method and system used between EtherCAT slave station nodes, an OTP / nonvolatile storage, an encryption scrambling unit and a decryption descrambling unit are integrated in an EtherCAT slave station chip of a coupler and an I / O module, and encryption / decryption of an EtherCAT message is achieved on the hardware level; xOR operation or an AES algorithm is adopted for encryption, and a secret key is stored in an unmodifiable storage unit; and meanwhile, a parallel architecture of an encrypted network and a standard network is constructed, so that the standard interaction between the slave station node and the master station is not influenced by encrypted communication. The system solves the contradiction of poor real-time performance of a private protocol and easy plaintext communication plagiarism in the prior art, realizes the effects of no real-time performance loss, strong communication exclusiveness and flexible compatibility, and is suitable for an EtherCAT high-speed backplane bus system under industrial 4.0.
Owner:ANXIN MICRO SEMICON TECH (SHENZHEN) CO LTD

Controlling access to cryptographic resources using double encryption

A system for controlling access to cryptographic resources is disclosed. The system may receive a request to transfer cryptographic resources between users, including a user identifier and a first cryptographic signature. The system may verify the signature and retrieve an encrypted private key from a key vault using the user identifier. A command to sign the request may be transmitted over a private network to a signature device, which may generate a second cryptographic signature using the decrypted private key. The system may receive the second signature, generate a blockchain operation based on the request and signature, and transmit the operation to a blockchain node for commitment. The system may also handle new account generation, storing encrypted keys in jurisdiction-specific databases, and validating blockchain operations against request parameters.
Owner:CITIBANK N A

Remote signature system and tamper resistant device

The present invention realizes a remote signature system in which identity verification is performed for each signing request by combining the remote signature system with public key cryptography. A terminal device (2) comprises a means for generating a key pair for authentication to perform the public key cryptography. A generated secret key is stored in the terminal device (2), and a generated public key is transmitted to the tamper resistant device (5) and is stored in relation with the corresponding signature key. The tamper resistant device comprises a signature key storage means (12) for storing the signature key, a decryption key and signature key identification information as pairs for each user. When requesting a digital signing, a signing request including the signature key identification information, plaintext verification information, and a crypto token including the encrypted verification information and the encrypted signature object data is created and is transmitted to the tamper resistant device (5). The tamper resistant device accesses to the signature key storage means (12) and searches both the decryption key and the signature key. The tamper resistant device decrypts the crypto token using the searched decryption key, and verifies consistency between the decrypted verification information and the plaintext verification information. If they do not match each other, the signing request is excluded from the digital signing.
Owner:KEY TECHNO CO LTD

Data encryption method suitable for open source gap terminal equipment

The invention discloses a data encryption method applicable to open source gap terminal equipment, which comprises the following steps of: firstly, establishing communication connection based on a gap distributed soft bus technology, and generating a trust relationship through identity identification authentication; during data transmission, a national cryptographic algorithm, a symmetric or asymmetric encryption algorithm, a hybrid encryption algorithm and the like are dynamically selected according to data types, importance, transmission scenes and equipment performance. After being encrypted, the data are transmitted to the target device through the soft bus, and the target device decrypts and verifies the data. And the terminal equipment is integrated with the hardware security module to realize hardware encryption and key storage. Security module adaptation development is carried out based on an HDF library, and one-time development and multi-terminal operation are achieved. In the encryption process, a fragmentation encryption strategy can be adopted, multiple devices can perform collaborative encryption and decryption, and the encryption efficiency is improved by defining the task priority and sequence and utilizing a distributed task scheduling mechanism and reasonably allocating resources.
Owner:BEIJING SPACEFLIGHT TUOPUGAO SCI & TECH CO LTD

Quantum key synchronous storage method for QKD

The invention discloses a quantum key synchronous storage method for QKD (quantum key distribution), which belongs to the technical field of digital information transmission, and comprises the following steps of: monitoring a node connection state of a quantum key distribution network, generating a dynamic topological graph, acquiring a key generation rate of a node in the dynamic topological graph, generating a synchronous triggering rule by combining a synchronous period reference value to trigger a key synchronization instruction, and storing the key synchronization instruction. Sending the key synchronization instruction to the target node; receiving a returned key data packet, extracting a key hash value abstract, and performing edge collaborative pre-verification to generate a pre-verification result; executing a key storage operation based on the pre-verification result; and obtaining a key state label in the key data packet, writing the synchronized key into the corresponding physical storage area, and updating the priority mapping relationship of the logic index layer. According to the method, a linkage mechanism of dynamic topology sensing triggering, edge collaborative pre-verification and state self-adaptive storage is adopted, efficient key synchronization can be achieved in a dynamic network, and meanwhile the utilization rate of storage resources and the anti-attack capacity of the system are improved.
Owner:CHINA NAT INST OF STANDARDIZATION

Key management method and storage device

The invention discloses a key management method and a storage device, and belongs to the field of storage security, the method comprises the following steps: deriving different types of key fragments from an authentication key according to different preset classification strategies, and respectively storing the different types of key fragments in different storage partitions corresponding to the preset classification strategies; receiving a data access request, wherein the data access request comprises data index information; based on different preset classification strategies, reading candidate key fragments matched with the data index information from the different storage partitions respectively, verifying the legality of the candidate key fragments matched with the data index information, and determining the candidate key fragments passing the verification as effective key fragments; and aggregating the effective key fragments of different types to generate the authentication key, and obtaining target access data of the data access request through the authentication key. According to the invention, the security of key storage and the flexibility of key management can be effectively improved.
Owner:BIWIN STORAGE TECH CO LTD

Solid state disk key storage method and system and storage medium

The invention discloses a solid state disk key storage method and system and a storage medium, and belongs to the technical field of solid state disks. The method comprises the steps that a CPU component controls an SM4 component to generate a required medium key, and the medium key is temporarily stored in a register which cannot be read and written by the CPU component in the SM4 component; performing programming operation on the eFlash component through the eFlash controller component, and storing the medium key in an address specified by the key updating area; when the SM4 component detects that a programming operation completion indication signal is in a high level and key programming is successful, the SM4 component resets a medium key temporarily stored in the SM4 component and sets a key programming completion state register and a key programming success state register to be in a high level; and the CPU component performs storage verification, and when the CPU component queries that the secret key programming completion state register and the secret key programming success state register of the SM4 component are both high levels, secret key storage is completed. According to the invention, the medium key and the digital certificate cannot be stored out of the main control chip, so that the security is higher, and the key updating times are not limited.
Owner:JIANGSU XINSHENG INTELLIGENT TECH CO LTD +1

Controlling access to cryptographic resources using offline storage

A system for controlling access to cryptographic resources is disclosed. The system may receive a request to transfer cryptographic resources between users, including a user identifier and a first cryptographic signature. The system may verify the signature and retrieve an encrypted private key from a key vault using the user identifier. A command to sign the request may be transmitted over a private network to a signature device, which may generate a second cryptographic signature using the decrypted private key. The system may receive the second signature, generate a blockchain operation based on the request and signature, and transmit the operation to a blockchain node for commitment. The system may also handle new account generation, storing encrypted keys in jurisdiction-specific databases, and validating blockchain operations against request parameters.
Owner:CITIBANK N A

Single step transaction authentication using proximity and biometric input

A system and method provide efficient, secure and highly reliable authentication for transaction processing and / or access control applications in which only biometric input is required from the user. A Personal Digital Key stores a biometric profile that comprises a representation of physical or behavioral characteristics that are uniquely associated with an individual that owns and carries the PDK. The PDK wirelessly transmits the biometric profile over a secure wireless transaction to a Reader for use in a biometric authentication process. The Reader compares the received biometric profile to a biometric input acquired at the point of transaction in order to determine if the transaction should be authorized.
Owner:PROXENSE

System for integrated data provenance and reconciliation across heterogeneous financial systems

ActiveDE202025104886U1FinanceData streamGate array
A system for integrated data provenance and reconciliation across heterogeneous financial systems, the system includes: a data ingestion module implemented as a hardware interface and configured with high-throughput adapters for structured and unstructured data ingestion from multiple heterogeneous financial subsystems, including bank ledgers, securities trading platforms, risk management databases, and regulatory reporting systems; a schema harmonization processing unit consisting of a dedicated FPGA (Field Programmable Gate Array) structure configured to perform real-time schema alignment, metadata normalization, and semantic mapping across different data models; a lineage tracking processor array implemented on application-specific integrated circuits (ASICs) and configured to encode dataflow transitions into a graph-encoded structure in which each node represents a transformation and each edge represents a dependency; a reconciliation computation cluster unit embodied as a set of graphics processing units (GPUs) configured to execute parallelized reconciliation techniques, anomaly detection routines, and balance verification processes between transformed financial records and reference records; a cryptographic verification unit comprising secure key storage hardware, quantum-resistant encryption modules, and tamper-resistant enclaves configured to generate, anchor, and verify cryptographic signatures for provenance and reconciliation events; a secure storage subsystem configured in a WORM (write-once, read-many) configuration with hardware-based integrity locks for storing immutable provenance and reconciliation logs; a controller with a dedicated visualization processor configured to generate interactive dashboards and drill-down analyses of lineage charts and voting results; and a modular chassis structure consisting of a high-speed backplane interconnect, secure power distribution modules, and tamper-evident enclosures, enabling the system to achieve real-time scalability, hardware-level security, and auditability of financial data flows across heterogeneous infrastructures.
Owner:SUDHANSHU JAIN LITHIA

Verifying identity of an emergency vehicle during operation

A method includes: receiving, by a computing device of a first vehicle, a command from a host device; in response to receiving the command, storing a new device secret in memory; generating, by the computing device using the new device secret, a triple comprising an identifier, a certificate, and a public key; and sending, by the computing device, the triple to a second vehicle, where the second vehicle is configured to verify an identity of the first vehicle using the triple.
Owner:MICRON TECHNOLOGY INC

Intelligent key cabinet authority management method and device, electronic equipment and storage medium

The invention provides an intelligent key cabinet authority management method and device, electronic equipment and a storage medium, and the method comprises the steps: obtaining work ticket or operation ticket information which is from an electronic two-ticket system and comprises a worker in charge, a worker member and a corresponding key number, and dynamically generating key access authority configuration according to the information; the identity of the target user can be received and verified, whether the current time is within the permission configuration range or not can be judged, and an opening instruction is generated to open the corresponding key storage device after verification is passed. The problems that in the prior art, due to the fact that key taking permission is not associated with work ticket or operation ticket information of an electronic two-ticket system, permission configuration cannot be dynamically adjusted, compliance verification of user identity and taking time is lacked, key taking is disordered, the safety risk is high, and power operation specifications are not met can be solved.
Owner:NEW ENERGY BRANCH OF NORTH UNITED POWER CO LTD

Derivation-based Internet of Things equipment key management method and device

The invention belongs to the technical field of Internet of Things security, and discloses a derivation-based Internet of Things equipment key management method and device, and the method comprises the steps that a server generates a first-level data transmission key, and stores the first-level data transmission key in a cipher machine; the terminal sends a key request to the server; the server generates a second-level data transmission key through a first key derivation algorithm according to the terminal type and the first-level data transmission key; the server generates a third-level data transmission key through a second key derivation algorithm according to the security chip serial number and the data transmission root key, and issues the third-level data transmission key to the terminal; the terminal generates a session key through a third key derivation algorithm based on the three-level data transmission key and the random number during communication; the server side generates the same session key based on the received random number and the data transmission key calculated by the server side, and the server side only needs to store a small number of platform data transmission root keys in the mode, so that the key storage cost and the management cost are greatly reduced.
Owner:ZHENGZHOU ZHENGRAN PRESSURE ADJUSTING CONTROL TECH CO LTD

Reducing latency during cryptographic signature verification

A computer-implemented method, according to one approach, includes: generating lookup tables for signatures during compile time, the lookup tables having cryptographic information. A secret key is used to encrypt the lookup tables, and the secret key is stored in a secure storage which is accessible only to a secure engine. Moreover, in response to experiencing an initial boot: the lookup tables are decrypted using the secret key, and the decrypted lookup tables are stored in the secure storage. Other systems, methods, and computer program products are described in additional approaches.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

System and method for secure electronic transaction platform

A system for processing data within a Trusted Execution Environment (TEE) of a processor is provided. The system may include: a trust manager unit for verifying identity of a partner and issuing a communication key to the partner upon said verification of identity; at least one interface for receiving encrypted data from the partner encrypted using the communication key; a secure database within the TEE for storing the encrypted data with a storage key and for preventing unauthorized access of the encrypted data within the TEE; and a recommendation engine for decrypting and analyzing the encrypted data to generate recommendations based on the decrypted data.
Owner:ROYAL BANK OF CANADA

The main body of the key storage buckle accessory

ActiveCN309913221SS/KEYKey storage
1. Name of this design product: Main body of key storage buckle accessory. 2. Purpose of this design: The entire product is used in a key storage clip, through which the key can be pulled out, and the protected part is used as the main body of the key storage clip accessory. 3. The key design features of this product are the shape of the part that is to be protected. 4. The image or photograph that best illustrates the design's key points: 3D view 1. 5. Other situations requiring explanation: Other explanation: The dotted lines in the figure represent parts that do not require protection.
Owner:ORBITKEY PROJECTS PTY LTD

Method, device and storage medium for security authentication encryption in initial stage of communication link establishment

The application discloses a kind of communication link establishment initial stage security authentication encryption method, device and storage medium, the present application is limited to narrow bandwidth for end-to-end wireless communication link establishment, cannot apply conventional encryption preparation, it is difficult to guarantee that preset symmetric key is added after planning, abandon password protection is also prone to be maliciously controlled and so on Problem, an authentication encryption adaptive method based on pre-stored and diffusion key is proposed, by making full use of the key storage space of end device pre-stored key, supplemented by the diffusion transmission of new key with the process of link establishment, combined with the two modes of offline preset loading when opening and automatic online interaction after new communication terminal joins interworking, under the premise of no manual participation, maximum reduction to the occupation of link establishment narrow band, the security of information transmission is greatly improved, so as to improve user experience.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

System switching method, electronic device, storage medium, and program product

The application discloses a system switching method, an electronic device, a storage medium and a program product, and belongs to the technical field of key storage. The method comprises the following steps: in response to the fact that a current system is switched from a first system to a second system, reading a second key file from a secure storage area, wherein the secure storage area stores a first key file which is valid for the first system and a second key file which is valid for the second system; and importing the obtained second key file.
Owner:ZTE CORP

Password information processing method and device, electronic equipment and medium

The embodiment of the invention discloses a password information processing method and device, electronic equipment and a storage medium, multiple groups of encryption key pairs are bound with a key effective time interval, a key corresponding to a playing time period is quickly matched in combination with an index mapping table, a user does not need to manually input multiple passwords, and the user experience is improved. The problem that the password needs to be input repeatedly after being replayed after being modified is solved; a key is stored by an asymmetric encryption algorithm, and is transmitted through a secure transmission channel, so that the key storage and transmission security is ensured, and the problem of insufficient security of existing key management is improved; the integrity of the decrypted data is verified by means of the verification key, and the equipment end is triggered to retransmit incomplete data fragments, so that the defects of lack of data integrity guarantee and an exception recovery mechanism are overcome; and meanwhile, the key query efficiency is improved by the index mapping table.
Owner:SHENZHEN STARCAM TECH

Remote control locking key storage box interlocked with simultaneous alarm, remote control unlocking key storage system, and disaster countermeasure support system using remote control unlocking key storage system interlocked with simultaneous alarm

To provide a remote control locking / unlocking key storage box, a remote control locking / unlocking key storage system and a disaster countermeasure support system linked with a simultaneous alarm for realizing the opening of a shelter or the like without delay when a disaster occurs.SOLUTION: In this alarm cooperation remote control locking / unlocking key storage system, a remote control locking / unlocking box 7 incorporates a GPS, and transmits a position coordinate to an alarm cooperation remote control locking / unlocking key storage system management server 3 by an Internet communication service 5. The alarm-associated remote control locking / unlocking key storage system management server has a function of automatically transmitting an unlocking signal to the remote control locking / unlocking key storage box with a simultaneous alarm alert as a trigger through the simultaneous alarm system 2, communicates with the remote control locking / unlocking key storage system terminal 4 accessible from a personal computer of a local government, a rescue support person related to a shelter, or a mobile terminal of a person concerned, and can browse a locking / unlocking state of the remote control locking / unlocking key storage box and remotely control locking / unlocking.SELECTED DRAWING: Figure 2
Owner:BIT PARK CO LTD

certification

PendingJP2026528831AInternet privacyEngineering
A method for authentication between a first party and a second party is disclosed. This method comprises generating a current shared key by exchanging one or more messages between the first party and the second party, and authenticating the current shared key based on a previously authenticated shared key. In some examples, the current shared key may be authenticated based on both the previously authenticated shared key and the current shared key, and / or on at least one secret value obtained by the first party and / or the second party. In some examples, authenticating the current shared key comprises exchanging one or more messages between the first party and the second party, at least one of which is generated based on one or more of the current shared key, the previously authenticated shared key, and at least one secret value. In some examples, if it is determined that the current shared key is authenticated, the current shared key may be stored for use as the previously authenticated shared key when authenticating a new current shared key.
Owner:UNIVERSITY OF LEEDS

Substation key intelligent management machine

The application discloses a transformer substation key intelligent management machine and relates to the technical field of electric power operation and inspection.The machine comprises a device shell, a key storage module and a transformer substation key.The device shell comprises a management machine shell body, the inside of the management machine shell body is provided with a key storage area, and the management machine shell body is provided with a shell panel through a hinge connection.The shell panel is opened and closed with the management machine shell body through a panel handle.The key storage module is uniformly arranged in the key storage area.In the application, the position of the required key can be directly displayed through the key intelligent management machine, the time for searching the key is greatly reduced, the consistency of the key, the storage position and the label can be automatically identified, the return of the key is determined, the correctness is prevented, the state is prompted through a state display lamp, the operation and maintenance personnel and the key taking personnel are effectively prompted to reasonably manage the key, and the standardization of the transformer substation key is ensured.
Owner:STATE GRID XINJIANG ELECTRIC POWER CO URUMQI ELECTRIC POWER SUPPLY CO

Encryption method and system integrating anomaly detection and risk monitoring

The invention discloses an encryption method and system integrating anomaly detection and risk monitoring. The system comprises a key management module, a key storage module, a file encryption module and a dynamic security defense module. According to the invention, advanced hybrid encryption, blockchain, unsupervised machine learning algorithm, programming and other technologies are utilized to construct an open, credible, safe and efficient encryption and decryption system; secret key pairs are distributed for unit internal users by using hybrid encryption, public key data are coded and compressed and then registered to a block chain sharing smart contract, and private key data are segmented and encrypted and then registered to interstellar network nodes; public and efficient online encryption and decryption, digital signature and verification are provided for file circulation of internal users; machine learning anomaly detection and risk monitoring are fused, behavior-driven dynamic security defense and fine-grained permission control of an intelligent contract are implemented in real time, and system operation is safe and controllable.
Owner:TAIZHOU INST OF SCI &TECH NUST

Managing key rotation for endpoint devices using re-keying rules

Methods and systems for validating key rotation requests for endpoint devices are disclosed. The key rotation requests may be signed by one or more signing systems according to a set of re-keying rules for the endpoint device. The set of the re-keying rules may indicate that key rotation requests may be valid if signed using at least two different keys. The set of the re-keying rules may also indicate that each of the at least the two different keys be from a different grouping of keys of multiple groupings of keys included in a secure key repository. Each grouping of keys may be associated with a different organization. Therefore, key rotation requests may be serviced if signatures associated with the key rotation requests meet the re-keying rules thereby decreasing a likelihood of compromise of the endpoint devices via compromise of a key.
Owner:DELL PROD LP

Server quantum key storage system combined with trusted computing module

The invention discloses a server quantum key storage system combined with a trusted computing module, and relates to the technical field of quantum communication network security. The deeply fused trusted computing module is integrated on the server mainboard; the key storage unit is arranged on the server mainboard or is in communication connection with the server mainboard; and a key management engine. According to the server quantum key storage system combined with the trusted computing module, the risk that key data are exposed in an external interface or a system memory in a plaintext form is fundamentally avoided. Meanwhile, multiple independent verification and verification rules are applied to each state transition of generation, storage, use, backup, recovery and destruction of the secret key by a closed-loop management model based on a dynamic security state machine implemented by the system, so that the security constraint of single secret key operation is strengthened, and active and coherent management and control of the full life cycle of the secret key is realized.
Owner:ORIENTAL SENTAI TECHNOLOGY GROUP CO LTD