Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

67 results about "Keyfile" patented technology

A keyfile (or key-file) is a file on a computer which contains encryption or license keys. A common use is web server software running secure socket layer (SSL) protocols. Server-specific keys issued by trusted authorities are merged into the keyfile along with the trusted root certificates. By this method keys can be updated without recompiling software or rebooting the server.

Image information encryption and decryption method and software system based on digital image steganography technology

The invention relates to the technical field of information encryption and decryption, in particular to an image information encryption and decryption method and software system based on a digital image steganography technology. According to the technical scheme, the method comprises the following steps that a carrier image format and a to-be-processed information type are determined, the carrier image format comprises a PNG image and a JPEG image, and the to-be-processed information type comprises text information, picture information and audio information; encrypting the plaintext information to generate ciphertext information; and selecting a corresponding steganography path according to the format of the carrier image, embedding the ciphertext information into the carrier image, generating an encrypted image, and generating a key file recording the embedded related information. According to the method, various image formats and information types are supported, the compatibility, safety, robustness and practicability of information encryption and decryption are improved through key encryption, face binding verification and a compensation mechanism for JPEG, and the method is suitable for scenes such as information protection and private transmission.
Owner:INST OF ENERGY HEFEI COMPREHENSIVE NAT SCI CENT (ANHUI ENERGY LAB)

Root key acquisition method of quantum security gateway

The invention discloses a root key acquisition method of a quantum security gateway, which comprises the following steps: a security gateway initiates a registration request to a command and control center, and the command and control center generates and issues a network access code and sends identity category information including identity information or the network access code to a root key pool; the root key pool generates a source key file and a root key file based on the identity category information; the security gateway carries out initialization operation on the security gateway; the aggregation security gateway confirms whether the security gateway initiates a first access request or not and whether a data transmission link is established with the security gateway or not through monitoring; the security gateway initiates a root key downloading request to an aggregation security gateway based on the message for establishing the data transmission link; the aggregation security gateway obtains a root key file from a root key pool, generates a data transmission packet and sends the data transmission packet to the security gateway; and the security gateway obtains and temporarily stores the root key file, and performs consistency authentication on the temporarily stored root key file: if the authentication is passed, persistently stores the root key file.
Owner:MATRICTIME DIGITAL TECH CO LTD

Method for dynamically adjusting secret key distribution flow

The invention discloses a method for dynamically adjusting key distribution flow, and the method comprises the steps: a quantum key pool server receives a key distribution request sent by network element equipment connected with the quantum key pool server, generates a corresponding key distribution task according to the key distribution request, and generates a corresponding to-be-sent key file; then, distributing a key distribution task corresponding to the key distribution request to a task list of a distribution thread through the key distribution request; and the distribution thread of the quantum key pool server extracts the key distribution task with the minimum next start time Next value in the task parameters of all key distribution tasks from the task list of the distribution thread, and judges whether the next start time Next value in the key distribution task is the current time or not. According to the invention, the sending bandwidth B of the key distribution task is dynamically adjusted through the quantum key pool server, so that the distribution operation of the key file is completed under the condition that the service process of the network element equipment is not occupied.
Owner:MATRICTIME DIGITAL TECH CO LTD

File format-based transparent encryption

This specification relates to file format-based transparent encryption tailored for big data. In some aspects, a method includes receiving a write request including a table with one or more columns to be stored in a storage device; compressing table data in a unit of block, wherein each column includes a number of blocks; generating a column key for each column and a block key for each block including sensitive information; encrypting (i) each block including sensitive information with a corresponding block key and (ii) rest of blocks in each column with a corresponding column key; generating wrapped keys for the column keys and block keys and storing the wrapped keys into a key file; and storing the encrypted blocks of each column into a data file in a data folder of the storage device.
Owner:LEMON INC(GB) +1

A root key file verification method and device

The present invention discloses a root key file verification method and device. The method of the present application generates a verification request message through a terminal. The key distribution end performs identity authentication on the terminal according to the hash value of the root key ciphertext file and the device ID in the received verification request message, and returns the hash value of the root key plaintext file and the key extension parameter for decrypting the root key ciphertext file after the identity authentication is legal; the terminal obtains the decryption key according to the key extension parameter to decrypt the root key ciphertext file to obtain the root key plaintext file, and performs a hash verification on it again; the verification method is based on the hash verification of the root key ciphertext file and the root key plaintext file, which effectively ensures the integrity and correctness of the root key file; the verification device of the present application mainly includes: a reading module and a verification module; wherein the reading module is used to read the attribute information corresponding to the root key file, and the verification module is used for hash verification.
Owner:MATRICTIME DIGITAL TECH CO LTD

System switching method, electronic device, storage medium, and program product

The application discloses a system switching method, an electronic device, a storage medium and a program product, and belongs to the technical field of key storage. The method comprises the following steps: in response to the fact that a current system is switched from a first system to a second system, reading a second key file from a secure storage area, wherein the secure storage area stores a first key file which is valid for the first system and a second key file which is valid for the second system; and importing the obtained second key file.
Owner:ZTE CORP

Working method and working system of root key center

The invention discloses a working method and a working system of a root key center. The method comprises the following steps: a terminal device initiates a registration request to the root key center; the root key center generates root key files corresponding to the terminal equipment according to the registration request, generates a first key file list according to all the root key files and stores the first key file list locally; the root key center performs encryption operation on the root key file, generates a second key file list based on a root key file ciphertext, and issues the second key file list to the terminal equipment according to information in the registration request; and after receiving the second key file list, the terminal equipment initiates an authentication operation to the root key center, and after the authentication is passed, the terminal equipment obtains the root key file and locally stores the root key file. According to the method, the security of root key generation and distribution is guaranteed, the overall robustness of the quantum security network is improved, the convenience of deployment and the high efficiency of operation are taken into account, and the method has extremely high practical value and popularization prospect.
Owner:MATRICTIME DIGITAL TECH CO LTD

Output quantum security key and authentication parameter method, device and root key center

This application discloses a method, device, and root key center for outputting quantum secure keys and authentication parameters. When exporting key files, the root key center also exports fixed data determined based on the authentication parameters corresponding to each key file. The authentication parameters include a first random number to be expanded for encrypting and decrypting each key file, an index for searching the authentication parameters, a first random number for encrypting the encrypted data in an access request, and a second random number for decrypting the decrypted data in an access response. The first random number to be expanded enables the encrypted output of the key file and its injection into a quantum secure device, ensuring the security of the key file. The first and second random numbers enable the quantum secure device to use ciphertext communication during its initial access to a quantum secure base station, ensuring the security of the initial access process.
Owner:MATRICTIME DIGITAL TECH CO LTD

Secret key file updating method based on same mapping address, electronic equipment and medium

The invention discloses a key file updating method based on the same mapping address, electronic equipment and a medium, and the method comprises the following steps: after initialization, locally creating three program processes: a first process, a second process and a third process; the third process determines an available key file m and a current public offset position, maps the key file m and the current public offset position into a virtual address, and loads the virtual address into a memory; the first process and the second process respectively execute encryption operation and decryption operation and respectively obtain a first offset position and a second offset position, and the third process updates the current public offset position; the third process determines the serial number of the current key file according to the updated current public offset position and updates the virtual address; and after the execution of the first process and the second process is finished, performing persistence operation on the residual key quantity in the key file.
Owner:MATRICTIME DIGITAL TECH CO LTD

A quantum-secure root key derivation device, method, root key center, and medium

The present application discloses a quantum-secure root key derivation device, method, root key center and medium. Since the root key derivation instruction obtained by the root key center carries the screening conditions for the root key to be derived, more flexible derivation of the root key can be achieved according to these screening conditions, and the derived root key files all meet the user's requirements, improving the user experience and avoiding the problem of manual mis-derivation of root key files. Moreover, the root key center can obtain each root key file that meets the screening conditions from the root key files corresponding to different device identifiers obtained in advance. Each root key file can correspond to a different device identifier, thereby realizing the simultaneous derivation of the root key files of multiple quantum-secure devices and greatly improving the efficiency of root key derivation.
Owner:MATRICTIME DIGITAL TECH CO LTD

Methods and systems for secure data sharing between the first and second zones

This specification provides a method and system for secure data sharing between a first region and a second region, wherein the second region is equipped with a secure access platform. In the first region, plaintext data to be shared with multiple users on the secure access platform is encrypted to generate an encrypted data file. A key file is generated based on the target user's access permissions to the encrypted data file. The encrypted data file needs to be accessed through the secure access platform using the key file. An evidence file is generated based on a security control policy configured for the encrypted data file, including the access permissions for each user. The encrypted data file and key file are transmitted to the target user via a network gateway. The evidence file is transmitted to the secure access platform via the network gateway, and the secure access platform controls the target user's access to the data in the encrypted data file according to the security control policy in the evidence file. This approach balances data sharing and data security.
Owner:ANT BLOCKCHAIN TECHNOLOGY (SHANGHAI) CO LTD

Data communication system and method based on same-level areas

The invention discloses a data communication system and method based on same-level areas. The system comprises a first first-level area and a second first-level area which are connected with each other, the first primary area is used for performing data encryption operation on to-be-sent data, generating a relay key with the second primary area, generating a transmission ciphertext from the encrypted data ciphertext by using the relay key, and sending the transmission ciphertext to the second primary area; and the second primary region decrypts the transmission ciphertext by using the relay key, and decrypts the decrypted data again by using the decrypted key to finally obtain the data to be sent. According to the invention, the relay key is negotiated in real time and cannot be predicted, so that the transmission security of the encryption key is ensured; moreover, the relay key file is simultaneously related to local key files of the first-level key centers in the two first-level areas, and a bad user needs to attack the two key centers at the same time and also needs to know a splicing scheme negotiated by the two key centers in real time, which is very difficult.
Owner:MATRICTIME DIGITAL TECH CO LTD

Key presetting method, electronic equipment and storage medium

The invention discloses a key presetting method, electronic equipment and a storage medium. The method comprises the steps that a root key center generates an authentication key file and a data key file based on equipment identity information; the root key center presets and stores the authentication key file in a security module of the quantum security terminal, and presets and stores the data key file in an encryption processor of the quantum security terminal; the quantum security terminal establishes a corresponding relationship between the security module and the encryption processor; after it is determined that the corresponding relation is legal, the encryption processor carries out first access authentication on the root key center through the access base station, and authentication key information distributed by the root key center is obtained after the authentication is passed; and the encryption processor of the quantum security terminal performs security verification based on the authentication key information, obtains a data key after the verification is passed, and notifies the access base station to execute a key synchronization operation. According to the method, a key presetting and dynamic authentication mechanism is adopted, and potential attacks in a quantum computing environment can be resisted.
Owner:MATRICTIME DIGITAL TECH CO LTD

A method, system, device, and network payment clearing platform for processing reconciliation documents

This invention discloses a method, system, apparatus, and online payment clearing platform for processing reconciliation files. The method includes: generating a key file corresponding to a terminal; generating a first reconciliation file based on the transaction flow data of the terminal within a transaction period; encrypting the first reconciliation file based on a first digital envelope included in the key file to generate a second reconciliation file; performing hash signature processing on the key file to generate a first signature file; and performing hash signature processing on the second reconciliation file to generate a second signature file; and sending the key file, the first signature file, the second reconciliation file, and the second signature file to the terminal, so that the terminal can perform business reconciliation processing based on the received files. Encrypting the reconciliation file through a two-layer data encryption mechanism improves the security of the information data in the reconciliation file; the two-layer data signature mechanism enhances the non-repudiation and tamper-proof capabilities of the reconciliation file.
Owner:NETSUNION CLEARING CORP

Quantum key secure acquisition method and device, and storage medium

The invention discloses a quantum key security acquisition method and device and a storage medium, and the method comprises the steps: carrying out the equal-proportion configuration or non-equal-proportion configuration of an encryption and decryption host and a key host, and connecting the network ports of the encryption and decryption host and the key host through a network cable or an optical fiber; the encryption and decryption host uses an agent process of the encryption and decryption host to establish a socket channel with a key process of the key host in a socket mode, and performs temporary message communication through the socket channel; wherein the encryption and decryption host analyzes the content of the socket communication message by using a kernel mode protocol stack, and the key host analyzes the content of the socket communication message by using a user mode protocol stack. The key host not only can provide key management for a plurality of quantum encryption network elements, but also separates a key file from an application program, so that the security of the key is ensured; and meanwhile, the key process on the key host adopts a user mode protocol stack, so that illegal access of the encryption and decryption host to the key host can be avoided.
Owner:MATRICTIME DIGITAL TECH CO LTD

Method and device for acquiring symmetric communication key for first time between terminals, and storage medium

The invention discloses a method and device for obtaining a symmetric communication key between terminals for the first time and a storage medium, and the method comprises the steps that a first terminal detects whether a symmetric communication key file communicating with a second terminal exists in a local key pool or not, and responds to the situation that the key file does not exist locally; the first terminal initiates a downloading request of the symmetric communication key file to the key center through the security gateway; the key center responds to the downloading request, extracts a symmetric communication key file mile1 to be issued from the local, and records a first association relationship between the symmetric communication key file mile1 and the first terminal; according to the scheme, the single key file is adopted as the encryption key and the decryption key at the same time, the key paired downloading process of the terminal equipment is remarkably simplified, the terminal equipment only needs to successfully download the same key file to establish two-way secure communication, the encryption key and the decryption key do not need to be obtained respectively, and the user experience is improved. And the complexity of key distribution and storage is reduced.
Owner:MATRICTIME DIGITAL TECH CO LTD

Method and system for obtaining preset root key offline by quantum safety equipment terminal

The invention discloses a method and system for obtaining a preset root key offline by a quantum security device terminal, and the method comprises the steps: enabling the quantum security device terminal to initiate a registration application to a root key server through network communication equipment based on the hardware number of the quantum security device terminal; the root key server generates a root key file for the quantum security device terminal based on the registration application, encrypts the root key file by using an encryption key, and issues a root key ciphertext to the quantum security device terminal offline through an intermediate medium; the quantum security equipment terminal executes identity authentication operation to obtain a decryption key of the root key ciphertext; and the quantum security equipment terminal performs decryption operation on the root key ciphertext by using the received decryption key to obtain a plaintext-state root key file, and locally stores the plaintext-state root key file. According to the method, the security, reliability and controllability of the quantum security equipment terminal in the network access initialization process are ensured through a root key security acquisition system which is linked with one another and is deeply defended.
Owner:MATRICTIME DIGITAL TECH CO LTD

Working method and system of quantum security firewall

The invention discloses a working method and system of a quantum security firewall, and the working method comprises the steps: obtaining a plurality of business types from a business terminal by the quantum security firewall, and dividing servers in the Internet into a current business server and other business servers according to different business types; meanwhile, the quantum security firewall initiates a request for configuring a symmetric key file file0 to the quantum key service equipment, so that the quantum security firewall and the service server obtain the symmetric key file; the quantum security firewall configures IP address information and executes IP notification operation on a server in the Internet; and the quantum security firewall receives and filters the first access request from the server in the Internet to obtain a legal second access request, and sends the legal second access request to the service terminal for service processing. According to the invention, the problem of DDOS attack caused by useless access is solved through a dual filtering mechanism.
Owner:MATRICTIME DIGITAL TECH CO LTD

Method and system for activating preset key

The invention discloses a preset key activation method and system. The method comprises the steps that a preset key distribution mechanism distributes a preset key file 1 and an authentication key file 0 to first equipment and second equipment; the device authentication mechanism performs device identity authentication on the first device and the second device based on the authentication key file file0; according to the message that the identity authentication of the device is passed, the first device and the second device respectively execute an activation operation on the preset key file (file1); the first device authenticates the key data with the second device based on the data information of the preset key file file1; and the first device and the second device determine an available preset key file (file2) according to the message that the key authentication is passed. According to the method disclosed by the invention, before the terminal equipment enters a communication network for use, the key storage module of the preset key unit is in a black box state and an inaccessible state and is not interacted or connected with any unit, so that the possibility that bad users steal the preset key is avoided from the source.
Owner:MATRICTIME DIGITAL TECH CO LTD

Key use method and device and storage medium

The invention discloses a secret key using method and device and a storage medium. The method comprises the steps that n data processing processes are created and used for conducting concurrent processing on data; obtaining n unused key files with the length of L from the key files with the total length of M according to the data average length L within a past period of time T, and sequentially and correspondingly distributing the n key files to corresponding data processing processes; and distributing the to-be-processed data to the corresponding data processing process for encryption processing. According to the invention, a segment of key is preset in each data processing process, so that the data processing process can immediately execute encryption operation when receiving the to-be-processed data without waiting to request to distribute the key to a key file; particularly, under the condition that the length of the data to be processed is smaller than the length of the preset key, encryption can be completed by directly using the preset key, the encryption preparation time is remarkably shortened, and the real-time performance of data processing is improved.
Owner:MATRICTIME DIGITAL TECH CO LTD

File format-based transparent encryption on big data

This specification relates to file format-based transparent encryption tailored for big data. In some aspects, a method includes receiving, by one or more computing devices, a write request including a table with one or more columns to be stored in a storage device, wherein each column includes a number of pages; generating a column key for each column and a page key for each page including sensitive information; encrypting (i) each page including sensitive information with a corresponding page key and (ii) each column with a corresponding column key; generating wrapped keys for the column keys and page keys and storing the wrapped keys into a key file; storing the encrypted columns into a data file of the storage device and storing the wrapped keys in a separate key file; and storing a reference to the key file in a file footer of the data file.
Owner:LEMON INC(GB) +1

Bitlocker encrypted partition data damage recovery method, electronic equipment and computer program product

The invention provides a Bitlocker encrypted partition data damage recovery method, electronic equipment and a computer program product, and the method can recover information such as key information or key files through password information provided by a user, search and locate Bitlocker encrypted metadata information on a disk by performing full-disk search on the disk, and improve the recovery efficiency of the Bitlocker encrypted partition data damage. According to the method, a decryption key is verified, the initial position of a Bitlock encryption partition is dynamically calculated, forced decryption and data recovery are carried out on data, the method can be used for forcibly carrying out decryption attempt and data recovery on Bitlock encryption partition data damage caused by destructive behaviors such as mistakenly deleting the Bitlock encryption partition and mistakenly formatting the Bitlock encryption partition, and the Bitlock encryption partition is decrypted into data in an unencrypted state.
Owner:XIAMEN MEIYABAIKE INFORMATION SECURITY RES INST CO LTD

Key file management method and device and storage medium

The invention discloses a key file management method and device and a storage medium, and the method comprises the steps: determining the size of a local storage space of the device, and if the size of the local storage space is smaller than or equal to a preset space size, selecting to execute a corresponding source key file downloading operation or a key expansion operation according to the number of current source key files, storing the downloaded source key file or the expanded key file according to the position; and if the size of the local storage space is greater than the preset space size, segmenting a key file downloading space and a key file using space from the local storage space, executing corresponding source key file downloading operation and key expansion operation in the key file downloading space and the key file using space, and storing the source key file downloading operation and the key expansion operation. According to the method, downloading of the source key file and expansion of the key file are carried out by selecting different modes, and finally storage and use management are carried out, so that the use orderliness of the key file is ensured.
Owner:MATRICTIME DIGITAL TECH CO LTD

Encryption and decryption method and device based on symmetric key, and storage medium

The invention discloses an encryption and decryption method and device based on a symmetric key and a storage medium, and the method comprises the steps: a first security gateway as a sender determines whether a second security gateway as a receiver is in an online state, and if yes, the encryption and decryption operation continues to be executed; if not, ending the process; and the first security gateway obtains the encryption key from the local first key file, records the key index of the encryption key, and updates the state of the first key file to be in use. According to the security gateway disclosed by the invention, the key file in the security gateway does not distinguish uplink and downlink any more, but uses one key file, that is, uplink and downlink traffic are encrypted and decrypted by adopting the unified key file, and only a unique position mark needs to be read and modified before and after encryption and decryption operations; and compared with the condition that the encryption key file and the decryption key file are separated in the earlier stage, the logic for obtaining the encryption and decryption keys in the security gateway is simplified, and the processing efficiency is higher.
Owner:MATRICTIME DIGITAL TECH CO LTD

Key distribution method based on differential instruction, electronic equipment and storage medium

The invention discloses a key distribution method based on a differential instruction, electronic equipment and a storage medium, participants of the method comprise a key center and a quantum security terminal which are in communication connection, and the method comprises the following steps: step 1, the quantum security terminal initiates a key acquisition request to the key center, the key center calculates the number of key files needing to be acquired according to the key acquisition request; step 2, the key center responds to the key acquisition request, carries out key distribution, generates a differential instruction and sends the differential instruction to the quantum security terminal; and step 3, the quantum security terminal initiates a secret key downloading request to a secret key center according to the received differential instruction, and obtains a target secret key file. When the key center carries out key distribution, only the differential instruction is sent to the quantum security terminal, and the key content of the local key file is not split or combined, so that the local source key file of the key center is not wasted, and the utilization rate of key resources is ensured.
Owner:MATRICTIME DIGITAL TECH CO LTD

A method and system for processing root key file requests

The present invention discloses a method and system for processing root key file requests. The root key file request processing method of the present application encrypts the device ID and target key identifier in the message when sending a key request message. After receiving the key request message, the key distribution end first obtains the decryption key according to the index, then decrypts the encrypted content in the key request message, and further authenticates the device ID obtained by decryption before returning the corresponding root key response message. Since the information is encrypted throughout the entire communication process and the encrypted keys are all in the hands of the communicators, the security of the communication is greatly improved. The root key file request processing system of the present application mainly includes a terminal, a key relay end and a key distribution server. The information in the key request message is generated by terminal encryption, and the key relay end does not store the key used to encrypt the key request message, thereby reducing the possibility of key leakage.
Owner:MATRICTIME DIGITAL TECH CO LTD

Optimized file storage strategy for increasing usability of key files

An information handling system includes a storage and a processor. The storage stores a key file in a partition of the storage. The processor receives a request for the key file and determines whether the key file is located within the partition of the storage. In response to the key file not being within the partition of the storage, the processor retrieves metadata for the key file. The processor determines a physical location for the key file based on the metadata. Based on the physical location, the processor retrieves segments of the key file from the partition of the storage. The processor downloads segments of the key file from a backend server. The processor re-creates the key file based on the segments of the key file retrieved from the partition of the storage and on the segments of the key file downloaded from the backend server.
Owner:DELL PROD LP

A user access security management method, a terminal device, and a storage medium

This invention relates to a user access security management method, terminal device, and storage medium. The method includes: S1: After receiving a successful user login message, obtaining the user's username and creation time, and combining the username and creation time to generate a verification code corresponding to the user; S2: Encrypting the verification code to obtain a corresponding encrypted verification code; S3: Generating a corresponding password and key file based on the verification code and the encrypted verification code; S4: Decrypting the key file; if decryption is successful, proceed to S5; if decryption fails, the process ends; S5: Loading the user's file directory based on the password and key file; if loading is successful, proceed to S7; if loading fails, proceed to S6; S6: Initializing the user's file directory; S7: Loading the user's storage files and operation files generated after the user's login into the user's file directory. This invention can achieve physical isolation of one user, one data, and one storage.
Owner:XIAMEN MEIYA PICO INFORMATION CO LTD

File format-based transparent encryption on big data

This specification relates to file format-based transparent encryption tailored for big data. In some aspects, a method includes receiving, by one or more computing devices, a write request including a table with one or more columns to be stored in a storage device, wherein each column includes a number of pages; generating a column key for each column and a page key for each page including sensitive information; encrypting (i) each page including sensitive information with a corresponding page key and (ii) each column with a corresponding column key; generating wrapped keys for the column keys and page keys and storing the wrapped keys into a key file; storing the encrypted columns into a data file of the storage device and storing the wrapped keys in a separate key file; and storing a reference to the key file in a file footer of the data file.
Owner:LEMON INC(GB) +1

Data decryption method and device based on lock and storage medium

The invention discloses a data decryption method and device based on a lock and a storage medium, and the method comprises the steps: obtaining transmitted ciphertext data, proofreading the checksum of the ciphertext data, and if the proofreading is passed, decrypting the ciphertext data; if yes, determining the position of the current decryption key file and the initial position of the decryption key in the current decryption key file based on a decryption key index carried in the ciphertext data; analyzing the ciphertext data to obtain a decryption key quantity required by decryption, and judging whether the current decryption key file meets the decryption key quantity or not; according to the method and the device, the decryption key file mapped to the memory is locked, so that the locked decryption key file only serves the current corresponding decryption process and cannot be used by other decryption processes at the same time, and the smoothness of the decryption operation is ensured; moreover, the locking mechanism effectively prevents resource competition and operation disorder possibly caused by the fact that a plurality of decryption processes access the same key file at the same time, so that the decryption processes can run independently without mutual interference.
Owner:MATRICTIME DIGITAL TECH CO LTD