Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

24 results about "Keyfile" patented technology

A keyfile (or key-file) is a file on a computer which contains encryption or license keys. A common use is web server software running secure socket layer (SSL) protocols. Server-specific keys issued by trusted authorities are merged into the keyfile along with the trusted root certificates. By this method keys can be updated without recompiling software or rebooting the server.

File format-based transparent encryption

This specification relates to file format-based transparent encryption tailored for big data. In some aspects, a method includes receiving a write request including a table with one or more columns to be stored in a storage device; compressing table data in a unit of block, wherein each column includes a number of blocks; generating a column key for each column and a block key for each block including sensitive information; encrypting (i) each block including sensitive information with a corresponding block key and (ii) rest of blocks in each column with a corresponding column key; generating wrapped keys for the column keys and block keys and storing the wrapped keys into a key file; and storing the encrypted blocks of each column into a data file in a data folder of the storage device.
Owner:LEMON INC(GB) +1

System switching method, electronic device, storage medium, and program product

The application discloses a system switching method, an electronic device, a storage medium and a program product, and belongs to the technical field of key storage. The method comprises the following steps: in response to the fact that a current system is switched from a first system to a second system, reading a second key file from a secure storage area, wherein the secure storage area stores a first key file which is valid for the first system and a second key file which is valid for the second system; and importing the obtained second key file.
Owner:ZTE CORP

Working method and working system of root key center

The invention discloses a working method and a working system of a root key center. The method comprises the following steps: a terminal device initiates a registration request to the root key center; the root key center generates root key files corresponding to the terminal equipment according to the registration request, generates a first key file list according to all the root key files and stores the first key file list locally; the root key center performs encryption operation on the root key file, generates a second key file list based on a root key file ciphertext, and issues the second key file list to the terminal equipment according to information in the registration request; and after receiving the second key file list, the terminal equipment initiates an authentication operation to the root key center, and after the authentication is passed, the terminal equipment obtains the root key file and locally stores the root key file. According to the method, the security of root key generation and distribution is guaranteed, the overall robustness of the quantum security network is improved, the convenience of deployment and the high efficiency of operation are taken into account, and the method has extremely high practical value and popularization prospect.
Owner:MATRICTIME DIGITAL TECH CO LTD

Methods and systems for secure data sharing between the first and second zones

This specification provides a method and system for secure data sharing between a first region and a second region, wherein the second region is equipped with a secure access platform. In the first region, plaintext data to be shared with multiple users on the secure access platform is encrypted to generate an encrypted data file. A key file is generated based on the target user's access permissions to the encrypted data file. The encrypted data file needs to be accessed through the secure access platform using the key file. An evidence file is generated based on a security control policy configured for the encrypted data file, including the access permissions for each user. The encrypted data file and key file are transmitted to the target user via a network gateway. The evidence file is transmitted to the secure access platform via the network gateway, and the secure access platform controls the target user's access to the data in the encrypted data file according to the security control policy in the evidence file. This approach balances data sharing and data security.
Owner:ANT BLOCKCHAIN TECHNOLOGY (SHANGHAI) CO LTD

A method, system, device, and network payment clearing platform for processing reconciliation documents

PendingCN122312287ATamper resistanceSignature file
This invention discloses a method, system, apparatus, and online payment clearing platform for processing reconciliation files. The method includes: generating a key file corresponding to a terminal; generating a first reconciliation file based on the transaction flow data of the terminal within a transaction period; encrypting the first reconciliation file based on a first digital envelope included in the key file to generate a second reconciliation file; performing hash signature processing on the key file to generate a first signature file; and performing hash signature processing on the second reconciliation file to generate a second signature file; and sending the key file, the first signature file, the second reconciliation file, and the second signature file to the terminal, so that the terminal can perform business reconciliation processing based on the received files. Encrypting the reconciliation file through a two-layer data encryption mechanism improves the security of the information data in the reconciliation file; the two-layer data signature mechanism enhances the non-repudiation and tamper-proof capabilities of the reconciliation file.
Owner:NETSUNION CLEARING CORP

Method and device for acquiring symmetric communication key for first time between terminals, and storage medium

The invention discloses a method and device for obtaining a symmetric communication key between terminals for the first time and a storage medium, and the method comprises the steps that a first terminal detects whether a symmetric communication key file communicating with a second terminal exists in a local key pool or not, and responds to the situation that the key file does not exist locally; the first terminal initiates a downloading request of the symmetric communication key file to the key center through the security gateway; the key center responds to the downloading request, extracts a symmetric communication key file mile1 to be issued from the local, and records a first association relationship between the symmetric communication key file mile1 and the first terminal; according to the scheme, the single key file is adopted as the encryption key and the decryption key at the same time, the key paired downloading process of the terminal equipment is remarkably simplified, the terminal equipment only needs to successfully download the same key file to establish two-way secure communication, the encryption key and the decryption key do not need to be obtained respectively, and the user experience is improved. And the complexity of key distribution and storage is reduced.
Owner:MATRICTIME DIGITAL TECH CO LTD

Method and system for obtaining preset root key offline by quantum safety equipment terminal

The invention discloses a method and system for obtaining a preset root key offline by a quantum security device terminal, and the method comprises the steps: enabling the quantum security device terminal to initiate a registration application to a root key server through network communication equipment based on the hardware number of the quantum security device terminal; the root key server generates a root key file for the quantum security device terminal based on the registration application, encrypts the root key file by using an encryption key, and issues a root key ciphertext to the quantum security device terminal offline through an intermediate medium; the quantum security equipment terminal executes identity authentication operation to obtain a decryption key of the root key ciphertext; and the quantum security equipment terminal performs decryption operation on the root key ciphertext by using the received decryption key to obtain a plaintext-state root key file, and locally stores the plaintext-state root key file. According to the method, the security, reliability and controllability of the quantum security equipment terminal in the network access initialization process are ensured through a root key security acquisition system which is linked with one another and is deeply defended.
Owner:MATRICTIME DIGITAL TECH CO LTD

Working method and system of quantum security firewall

The invention discloses a working method and system of a quantum security firewall, and the working method comprises the steps: obtaining a plurality of business types from a business terminal by the quantum security firewall, and dividing servers in the Internet into a current business server and other business servers according to different business types; meanwhile, the quantum security firewall initiates a request for configuring a symmetric key file file0 to the quantum key service equipment, so that the quantum security firewall and the service server obtain the symmetric key file; the quantum security firewall configures IP address information and executes IP notification operation on a server in the Internet; and the quantum security firewall receives and filters the first access request from the server in the Internet to obtain a legal second access request, and sends the legal second access request to the service terminal for service processing. According to the invention, the problem of DDOS attack caused by useless access is solved through a dual filtering mechanism.
Owner:MATRICTIME DIGITAL TECH CO LTD

File format-based transparent encryption on big data

This specification relates to file format-based transparent encryption tailored for big data. In some aspects, a method includes receiving, by one or more computing devices, a write request including a table with one or more columns to be stored in a storage device, wherein each column includes a number of pages; generating a column key for each column and a page key for each page including sensitive information; encrypting (i) each page including sensitive information with a corresponding page key and (ii) each column with a corresponding column key; generating wrapped keys for the column keys and page keys and storing the wrapped keys into a key file; storing the encrypted columns into a data file of the storage device and storing the wrapped keys in a separate key file; and storing a reference to the key file in a file footer of the data file.
Owner:LEMON INC(GB) +1

File format-based transparent encryption on big data

This specification relates to file format-based transparent encryption tailored for big data. In some aspects, a method includes receiving, by one or more computing devices, a write request including a table with one or more columns to be stored in a storage device, wherein each column includes a number of pages; generating a column key for each column and a page key for each page including sensitive information; encrypting (i) each page including sensitive information with a corresponding page key and (ii) each column with a corresponding column key; generating wrapped keys for the column keys and page keys and storing the wrapped keys into a key file; storing the encrypted columns into a data file of the storage device and storing the wrapped keys in a separate key file; and storing a reference to the key file in a file footer of the data file.
Owner:LEMON INC(GB) +1

Data decryption method and device based on lock and storage medium

The invention discloses a data decryption method and device based on a lock and a storage medium, and the method comprises the steps: obtaining transmitted ciphertext data, proofreading the checksum of the ciphertext data, and if the proofreading is passed, decrypting the ciphertext data; if yes, determining the position of the current decryption key file and the initial position of the decryption key in the current decryption key file based on a decryption key index carried in the ciphertext data; analyzing the ciphertext data to obtain a decryption key quantity required by decryption, and judging whether the current decryption key file meets the decryption key quantity or not; according to the method and the device, the decryption key file mapped to the memory is locked, so that the locked decryption key file only serves the current corresponding decryption process and cannot be used by other decryption processes at the same time, and the smoothness of the decryption operation is ensured; moreover, the locking mechanism effectively prevents resource competition and operation disorder possibly caused by the fact that a plurality of decryption processes access the same key file at the same time, so that the decryption processes can run independently without mutual interference.
Owner:MATRICTIME DIGITAL TECH CO LTD

A data processing method and device, electronic equipment, chip and medium

This disclosure provides a data processing method, apparatus, electronic device, chip, and medium, relating to the field of data encryption and decryption technology. It includes: acquiring target data corresponding to a first request; in response to the target data including file data and attribute data, generating a target key, the target key including a first key corresponding to the attribute data, a second key corresponding to the file data, and a starting offset of the file data within the target data; and processing the target data corresponding to the first request based on the target key. This disclosure determines the type of target data targeted by the first request, thereby assigning different keys to the file data and attribute data respectively, to achieve partitioned encryption and decryption of the file data and attribute data, saving storage space, improving storage efficiency, and further reducing the number of I / O requests.
Owner:BEIJING X RING TECHNOLOGY CO LTD

Key supplement method and system for large-scale power user terminals

The invention discloses a key supplement method and system for a large batch of power user terminals, and the method comprises the steps: obtaining corresponding and symmetrical key files through quantum safety equipment and Ath quantum safety equipment which need key supplement, and carrying out the key negotiation to obtain a same disturbance key; the above steps are repeated for many times until all m quantum security devices needing key supplementation obtain corresponding disturbance keys; then, the m quantum security devices respectively initiate m key supplement requests to the key center, and the key center generates corresponding key supplement files and then distributes the key supplement files; and each quantum security device processes the received key supplement file by using the respective disturbance key, and verifies the key supplement file. According to the invention, the differentiated disturbance key is extracted based on the local key file, so that even if the same key supplement file is received, the final key content stored by each quantum security device after the XOR operation still has uniqueness.
Owner:STATE GRID HEBEI ELECTRIC POWER CO LTD +1

A method for changing a root key file for obtaining a slice under an access network

PendingCN122293321AEliminate physical infusion costsEliminate logistics and transportationAccess networkNetwork communication
This application discloses a method for obtaining a root key file by segmentation under a changed access network, comprising: the root key operator randomly dividing the original decryption key into multiple sub-decryption keys; a quantum security device terminal obtaining an arbitrarily selected first sub-decryption key and first location information, performing a decryption operation using the first sub-decryption key to obtain a first sub-root key file, and sending the first location information to a first network communication device; the first network communication device obtaining the corresponding first sub-root key file based on the first location information; the quantum security device terminal and the first network communication device performing consistency authentication based on the first sub-root key file; after the consistency authentication is successful, in response to the quantum security device terminal changing its access to a second communication network, the quantum security device terminal obtaining a second sub-decryption key and its second location information, and repeating steps 2 to 3 in place of the first sub-decryption key and the first location information to obtain the corresponding second sub-root key file.
Owner:MATRICTIME DIGITAL TECH CO LTD

A key management method, device, terminal and storage medium

The present application relates to the technical field of data management, and particularly relates to a key management method and device, a terminal and a storage medium, the method comprising: generating a compressed package key library, adding the compressed package key library into a pre-constructed key library list; determining a target compressed package key library in the key library list, and performing identity authentication; generating a key file with key content in the target compressed package key library; determining a target key file in a key file list, and encrypting an object to be encrypted based on the key content of the target key file.The present application generates a key file in the compressed package key library, forms a list of the generated key files, realizes unified management, obtains a target key file from the compressed package key library when encrypting the object to be encrypted, and the encryption mode is simple; and only by identity authentication can the compressed package key library be opened, so that the key is safely managed while encryption is facilitated.
Owner:PENGYUAN CREDIT REPORTING CO LTD

Root key acquisition method and device, and storage medium

The invention discloses a root key acquisition method and device, and a storage medium. The method comprises the following steps: a quantum security device terminal initiates a registration request to a root key center; the root key center locally generates a root key file corresponding to the hardware code ID, generates a root key issuing file DOC based on the root key file, and sends the root key issuing file DOC to the quantum security equipment terminal; the quantum security device terminal receives the root key issuing file DOC and performs data authentication, after the data authentication is passed, the quantum security device terminal generates a root key authentication request and initiates root key authentication to the root key center, and after the root key authentication is passed, the quantum security device terminal persistently stores the root key. According to the method, the hardware code ID of the quantum security equipment terminal is bound with the root key, and the corresponding root key file is locally generated in the root key center, so that the uniqueness of the root key and the equipment relevance are ensured from the source, and the key is effectively prevented from being illegally copied or falsely used.
Owner:MATRICTIME DIGITAL TECH CO LTD

Key management method and device based on communication chip and storage medium

The invention discloses a key management method and device based on a communication chip and a storage medium, and the method comprises the steps: mapping key files of initial mapping into a continuous memory space of the communication chip, and the number of the key files of initial mapping is at least three; and in the use process of the key file, the used key file is swapped in and swapped out at an interval of one key file by taking the currently used key file as the center. According to the method and the device, a plurality of initial key files are mapped into a section of continuous physical storage memory space of the communication chip, so that centralized and ordered storage of the key data is realized, storage fragmentation is avoided, and the addressing and access complexity is reduced, thereby improving the overall efficiency of key calling; meanwhile, a unique swap-in and swap-out rule of taking the currently used key file as the center at an interval of one key file is adopted, so that the dynamic switching of the key in the using process can be ensured.
Owner:MATRICTIME DIGITAL TECH CO LTD

Data processing method and device, electronic equipment, chip and medium

The invention provides a data processing method and device, electronic equipment, a chip and a medium, and relates to the technical field of data encryption and decryption. Comprising the steps of obtaining target data corresponding to a first request; in response to the fact that the target data comprises the file data and the attribute data, a target key is generated, and the target key comprises a first key corresponding to the attribute data, a second key corresponding to the file data and the corresponding initial offset of the file data in the target data; and processing target data corresponding to the first request based on the target key. According to the method and the device, different keys are respectively allocated to the file data and the attribute data by judging the type of the target data aiming at the first request, so that partition encryption and decryption are performed on the file data and the attribute data, the storage space is saved, the storage efficiency is improved, and the IO request quantity is further reduced.
Owner:BEIJING X RING TECHNOLOGY CO LTD

Container technology-based password equipment security upgrading method and system

The invention discloses a security upgrading method and system for password equipment based on a container technology, and relates to the technical field of information security. According to the method, the configuration file and the key file are separated from the container mirror image and stored in the persistent data volume, so that the risks of loss, damage and leakage of the configuration or the key caused by mirror image replacement in the upgrading process are thoroughly avoided, the security of the upgrading process is greatly improved, and due to the fact that the containers of the new version and the old version share the same persistent data, the security of the upgrading process is greatly improved. The rollback operation only needs to switch the running container instance without recovering or migrating data, and the whole process can be automatically executed and can be completed in seconds, so that the fault recovery time is remarkably shortened, the service continuity is ensured, the container technology ensures the consistency of new version software, the upgrading success rate and the software running stability are improved, and the upgrading efficiency is improved. And the upgrading process is standardized into mirror image pulling, container starting and health checking, and the container is switched if the upgrading process fails, so that automatic and batch deployment is easy.
Owner:BEIJING CATHAY INTERNET INFORMATION TECH CO LTD +1

Lock-based encryption method, electronic equipment and storage medium

The invention discloses a lock-based encryption method, which comprises the following steps: executing an initialization operation, obtaining and storing an initial key file file0 as a current key file, and monitoring whether a transmission interface has to-be-encrypted data or not; when it is monitored that the to-be-encrypted data exists in the transmission interface, analyzing the to-be-encrypted data to obtain a current encryption demand m, and meanwhile, carrying out a locking operation on a current key file file0; obtaining the current residual secret key quantity M0 in the current locked secret key file file0; judging whether the current residual secret key quantity M0 meets the current encryption requirement m or not: if yes, distributing an encryption secret key, and executing encryption operation; if not, at least one other key file is loaded from the persistent file in sequence, and after loading is completed, a corresponding encryption key is distributed, and encryption operation is executed; after the encryption operation is completed, unlocking operation is executed, and key file information is updated. According to the invention, by introducing a key file locking mechanism, the problems of key distribution conflict and data competition are effectively solved.
Owner:MATRICTIME DIGITAL TECH CO LTD

File format-based transparent encryption

This specification relates to file format-based transparent encryption tailored for big data. In some aspects, a method includes receiving a write request including a table with one or more columns to be stored in a storage device; compressing table data in a unit of block, wherein each column includes a number of blocks; generating a column key for each column and a block key for each block including sensitive information; encrypting (i) each block including sensitive information with a corresponding block key and (ii) rest of blocks in each column with a corresponding column key; generating wrapped keys for the column keys and block keys and storing the wrapped keys into a key file; and storing the encrypted blocks of each column into a data file in a data folder of the storage device.
Owner:LEMON INC(GB) +1

Key file switching method and device based on different mapping addresses and storage medium

The invention discloses a key file switching method and device based on different mapping addresses and a storage medium, and the method comprises the steps: reading a currently used key file serial number m and address offsets of the currently used key file in encryption and decryption directions from key files stored in a key pool after initialization; then, key file mapping operation is carried out in the encryption direction and the decryption direction respectively, and respective mapping addresses are obtained; according to the method, independent key file mapping addresses are arranged in the encryption direction and the decryption direction respectively, the memory does not need to be actually occupied, and the storage space occupied by the mapping addresses is small; moreover, an established notification mechanism during file switching in the decryption direction can timely and effectively synchronize change information of the key file to the encryption direction, so that the encryption direction and the decryption direction are always operated based on the same latest key file, and the problem of encryption and decryption failure or data inconsistency caused by inconsistency of keys is fundamentally avoided.
Owner:MATRICTIME DIGITAL TECH CO LTD

Method for terminal to acquire communication key, electronic equipment and storage medium

The invention discloses a method for a terminal to acquire a communication key, electronic equipment and a storage medium, and the method comprises the steps: a terminal A and a terminal B establish an association relationship, and locally store the association relationship; the terminal A initiates a downloading request of the encrypted key file to the key center; the key center responds to the downloading request, extracts and numbers key files, and respectively distributes the extracted key files to the terminal A and the terminal B according to the downloading request; and the terminal A and the terminal B respectively receive the key file, execute an alignment verification operation of the key file, and persistently store the key file passing the verification. According to the application, by establishing a terminal association and centralized key distribution mechanism, it is ensured that the encryption key is accurately delivered to the associated terminal; by introducing a key number and an alignment verification process, encryption and decryption dislocation caused by inconsistent keys is effectively avoided, and the key distribution reliability and the communication security are remarkably improved.
Owner:MATRICTIME DIGITAL TECH CO LTD

Information processing apparatus, information processing method, and storage medium

An information processing apparatus includes processing circuitry. The processing circuitry writes an encryption key file that is encrypted into a second storage. The encryption key file includes first encryption key data and a first hash value of the first encryption key data. The first encryption key data is used for decrypting data stored in a first storage. The processing circuitry decrypts the encryption key file that is encrypted using a second encryption key data to obtain the encryption key file that is decrypted. The processing circuitry calculates a second hash value from the first encryption key data included in the encryption key file that is decrypted. The processing circuitry performs verification of the second encryption key data based on a determination of whether the first hash value matches the second hash value. The processing circuitry notify a verification result when the verification fails.
Owner:RICOH CO LTD