Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

50 results about "Master key" patented technology

A master key operates a set of several locks. Usually, there is nothing special about the key itself, but rather the locks into which it will fit. These master-keyed locks are configured to operate with two, or more, different keys: one specific to each lock (the change key), which cannot operate any of the others in the set, and the master key, which operates all the locks in the set. Locks that have master keys have a second set of the mechanism used to operate them that is identical to all of the others in the set of locks. For example, master keyed pin tumbler locks often have two shear points at each pin position, one for the change key and one for the master key. A far more secure (and more expensive) system has two cylinders in each lock, one for the change key and one for the master key.

End-to-end voice encryption methods, devices, and Bluetooth headsets applicable to multi-hop lossy channels

This invention provides an end-to-end voice encryption method, apparatus, and Bluetooth headset suitable for multi-hop lossy channels. The method includes front-end noise reduction, framing, and segmentation of the acquired voice at the transmitting end. Based on the session mode, a group public key or a point-to-point private key is automatically selected as the master key from a pre-configured key set. Then, multiple time-domain segments within each frame are scrambled, subjected to segment-by-segment Fast Fourier Transform, and frequency-domain encryption based on subkeys, according to the master key. The encrypted voice is then generated through inverse transformation and overlapping weighted smoothing concatenation, and transmitted through a multi-hop voice communication channel containing multi-level lossy encoding and decoding. At the receiving end, the reverse process is performed: framing and segmentation, transformation, inverse frequency-domain encryption, and inverse time-domain scrambling. Combined with U-shaped neural network noise reduction at both the front-end and back-end, the voice is restored to intelligible speech. This method enables flexible key management and high-quality secure voice transmission in scenarios where group calls and point-to-point private calls coexist and undergo multiple lossy compression operations.
Owner:VISION INTELLIGENCE CO LTD

System and method for managing access rights and authorizations

Device and Method for Managing Access Rights and Authorizations This description concerns a method for managing access to the use of an automated system, comprising: - providing an identification value, associated with a user, to a first device; - generating, via a secure circuit of the first device, an account address based on a master key associated with the first device, the identification value, and a context value; - sending a transaction to the account address in a blockchain; - validating or invalidating the transaction, by the blockchain, based on the balance associated with the account address in the blockchain; and - if the transaction is validated by the blockchain, authorizing the first device to grant the user access to the automated system. Figure for the abstract: Fig. 8
Owner:COMMISSARIAT A LENERGIE ATOMIQUE ET AUX ENERGIES ALTERNATIVES

A prison access control strategy management system

PendingCN122454663AMaster keyCondition Code
The present application relates to the technical field of key management, in particular to a prison access control strategy management system, the system comprises.The present application executes chain arrangement around the regional master key identification, the door area number, the shift state code, the time slice length, the task number and the control state bit, and uses a hash algorithm to press the door area, the shift, the time period, the task and the control state into a continuous node to generate a path, so that the key change no longer stays at the periodic rotation level, performs identity verification around the post type, the supervision level, the belonging prison area, the time interval, the task state and the emergency state flag, and uses an HKDF algorithm to write the door area number, the approval batch number and the task number into an access key symbol derivation path, so that the same subject forms mutually distinguished key symbol contents in different door areas, different approval batches and different task scenarios, the authorization voucher is synchronously bound with the door area, the task and the approval link, and cross-region reuse, cross-batch use and cross-task application are more strongly restricted.
Owner:ANHUI BOHUI ELECTRONIC TECH CO LTD

Method for pairing a content provider system and a receiving device, corresponding computer program product and devices

ActiveUS12671577B2ID-based encryptionUnique identifier
A method for pairing a content provider system and a receiving device, a cryptographic function and a receiving device unique identifier being populated in the receiving device. According to such method, the receiving device executes: obtaining a first key which is a result of a first function taking as arguments an Identity Based Encryption scheme master key owned by an authority server and an output of the cryptographic function applied to the receiving device unique identifier; receiving, from the content provider system, a content provider unique identifier; and computing a secret key which is a result of a second function taking as operands the first key and an output of the cryptographic function applied to the content provider unique identifier, the secret key being known from the content provider system.
Owner:NAGRAVISION SA

Decryption method and apparatus for data page, computer device, readable storage medium, and program product

PCT designated stageWO2026103836A1Digital data protectionTablespaceSoftware engineering
The present application relates to a decryption method and apparatus for a data page, a computer device, a readable storage medium, and a program product. The method comprises: upon receiving an access request for accessing an encrypted target table, acquiring a master key, and a target value and a secondary key in a tablespace file corresponding to the target table, wherein the tablespace file comprises different data pages (202); acquiring a page identifier of a target data page among the data pages (204); on the basis of the page identifier and the target value, determining a target mode from among at least two candidate modes (206); and when the secondary key is decrypted using the master key so as to obtain a plaintext secondary key, decrypting the target data page on the basis of the target mode and the plaintext secondary key so as to obtain data corresponding to the target table (208).
Owner:CHINA TELECOM CLOUD TECH CO LTD

Authentication and security for ultra-high reliability (UHR) roaming

PendingUS20260149965A1Security arrangementNetwork data managementSecurity associationMaster key
This disclosure provides methods, components, devices and systems for authentication and security for ultra-high reliability (UHR) roaming. Some aspects more specifically relate to devices in a seamless mobility domain (SMD), such as access point (AP) multi-link devices (MLDs) and non-AP MLDs, supporting the generation of different temporal keys (TKs) for each AP MLD. For example, the non-AP MLD may establish, via authenticator associated with the SMD, a pairwise master key security association (PMKSA) and a single pairwise transient key security association (PTKSA). Thus, the non-AP MLD may communicate with a first AP MLD (such as of multiple AP MLDs associated with the SMD) in accordance with a first pairwise transient key (PTK) and, after roaming to a second AP MLD (such as of the multiple AP MLDs), may communicate with the second AP MLD in accordance with a second PTK, where the second TK is different than the first PTK.
Owner:QUALCOMM INC

A mass key management method and device

This invention discloses a method and apparatus for managing massive amounts of keys, comprising: responding to a user access request, authenticating the user based on their identity identifier and password; generating or obtaining a pseudo-identity identifier, a pseudo-service identifier, and a pseudo-job identifier after successful authentication; generating a data key by calling a first random number generator, and performing multi-layer encryption on the data key using a master key and a data key protection key to obtain a encrypted data key; storing the encrypted data key and obtaining its storage address, encrypting the storage address using a data key address protection key to obtain an encrypted storage address and storing it in a key address matrix; retrieving the encrypted storage address from the key address matrix based on the pseudo-identity identifier, the pseudo-service identifier, and the pseudo-job identifier, decrypting it to obtain the storage address, and then retrieving and decrypting the encrypted data key to recover the data key. This invention achieves hierarchical isolation and efficient management of massive amounts of keys.
Owner:BEIJING ELECTRONICS SCI & TECH INST

Trust-driven blockchain consensus method for internet of vehicles

PendingCN122293318ADistributed key generationSecure communication
This invention belongs to the field of vehicle-to-everything (V2X) secure communication and blockchain consensus technology, specifically disclosing a trust-driven V2X blockchain consensus method. This method achieves decentralized management of the master key through a distributed key generation protocol, eliminating the traditional Root-TA single-point trust problem. Combining a dynamic trust evaluation mechanism based on Beta distribution with incentive contract design based on a delegate-agent game model, it constructs a trust-driven dynamic PoW consensus mechanism, achieving two-layer dynamic control of global security state and individual reputation level. This invention significantly improves the decentralization, consensus fairness, and operational efficiency of V2X systems while ensuring security and privacy.
Owner:ANHUI UNIV

A chain-based preservation and diffusion-based internet cloud security thumbnail keeping encryption method

This invention discloses an internet cloud security thumbnail preservation encryption method based on chain-based sum-diffusion. The main steps are as follows: Extracting the plaintext image size information and invariant features such as pixel sums for each color channel, hashing and fusing them with the master key to generate a derived key related to the image content; using the derived key to drive a chaotic system to generate a pseudo-random sequence with anti-degradation performance; employing a binary space partitioning strategy to process the three channels of the image into irregular rectangular blocks; within each independent sub-block, globally scrambling the pixel positions according to the pseudo-random sequence; finally, based on a pseudo-random traversal path, performing a chain-based sum-diffusion cyclic shift operation on each scrambled sub-block to achieve non-linear diffusion of pixel values. This invention effectively eliminates cross-channel boundary leakage that may result from regular block partitioning while ensuring the semantic usability of the encrypted image at low resolution, and significantly enhances encryption security through a dual mechanism of "scrambling-chain-diffusion".
Owner:HUNAN INSTITUTE OF SCIENCE AND TECHNOLOGY

Systems and methods for cryptographic authentication of contactless cards

Example embodiments of systems and methods for data transmission system between transmitting and receiving devices are provided. In an embodiment, each of the transmitting and receiving devices can contain a master key. The transmitting device can generate a diversified key using the master key, protect a counter value and encrypt data prior to transmitting to the receiving device, which can generate the diversified key based on the master key and can decrypt the data and validate the protected counter value using the diversified key.
Owner:CAPITAL ONE SERVICES LLC

Transferring Payload Information Comprising Key Information

A method including the steps of obtaining key information from a secure electronic memory. The key information represents one or more keys. Determining, at least partially based on a plurality of session parameters and a master key, an encryption key. The plurality of session parameters includes a session identifier, a sender identifier and a receiver identifier. Encrypting at least partially based on the determined encryption key, the key information. Providing payload information. The payload information includes at least the encrypted key information and the sender identifier.
Owner:UTIMACO IS GMBH

A privacy-preserving computer-aided diagnostic method based on inner product function encryption

ActiveCN117786735BImplement proxy authorizationImplement ciphertext access controlDigital data protectionMedical automated diagnosisComputer aided diagnosticsAlgorithm
This invention discloses a privacy-preserving computer-aided diagnostic method based on inner product function encryption. The steps include: 1) A key generation center calls a group generation algorithm to generate a master key msk and public parameters pp; 2) Calculates and returns a key to the data owner based on msk, the data owner's identifier ID, and the input vector; 3) The model owner calculates D = e(h1, h2) based on pp, ID, and the input vector. r And then send the ciphertext to the computer-aided diagnostic device; 4) The data owner obtains the inner product operation result based on the ciphertext and the key, and then calculates the prediction result.
Owner:PEKING UNIV

Device and method for managing access rights and authorizations

The present description concerns a method of management of the access to the use of an automaton comprising the supply of an identification value, associated with a user, to a first device; the generation, by a secure circuit of the first device, of an account address based on a master key associated with the first device, on the identification value, and on a context value; the sending of a transaction to the account address in a blockchain; the validation or invalidation of the transaction by the blockchain based on the balance associated with the account address in the blockchain; and if the transaction is validated by the blockchain, the authorizing, by the first device, for the user to access the use the automaton.
Owner:COMMISSARIAT A LENERGIE ATOMIQUE ET AUX ENERGIES ALTERNATIVES

Storage device having an RPMB reset function and RPMB management method thereof

A method for managing a replay protection memory block (RPMB) of a storage device includes allocating an RPMB master region managed separately from an RPMB region in which an RPMB key is stored in the RPMB of the storage device, programming a master key into the RPMB master region responsive to a request from a host, receiving a reset request for the RPMB region using the master key from the host, resetting the RPMB key in response to the reset request for the RPMB region, and receiving a reset lock request for the RPMB region from the host.
Owner:SAMSUNG ELECTRONICS CO LTD

Method, device, equipment and medium for automatically driving data to encrypt and return to cloud

PendingCN122293374AEngineeringMaster key
This invention discloses a method, apparatus, device, and medium for encrypted transmission of autonomous driving data back to the cloud, belonging to the field of autonomous driving data transmission technology. The method includes: generating a master key pair and a temporary key pair using the national cryptographic algorithm SM2 at the vehicle end and the cloud end respectively; exchanging a master public key and a temporary public key signed by their own master private keys and completing signature verification; if the signature verification is successful, obtaining a shared secret point based on their own temporary private key and the other party's temporary public key using the national cryptographic algorithm SM2; extracting the x-coordinate of the shared secret point and processing it using the national cryptographic algorithm SM3 to obtain a session key; encrypting the autonomous driving data to be transmitted using the national cryptographic algorithm SM4 based on the session key and transmitting it to the cloud; and decrypting the target autonomous driving data at the cloud using the session key. This technical solution achieves the technical effects of secure key transmission, high data transmission efficiency, and fine-grained key management.
Owner:DONGFENG MOTOR GRP

A method for multi-functional blockchain editing

To address the issue of limited editable functionality in existing editable blockchains, this invention discloses a multifunctional blockchain editing method, comprising: a key center (KGC) performing system initialization and outputting publicly available system parameters (mpk). ch and master key msk ch The calculation process for periodic and revocable keys: The Key Center (KGC), the server, and the user respectively generate keys for periodic encryption and decryption; The blockchain editing process: Users perform hash calculation and verification to generate and verify the chameleon hash value of the block. Users holding editing permissions and keys, as modifiers, execute rewrite and update algorithms to edit the hash value and time of the new block respectively. The KGC executes an auditing algorithm to determine whether the server's decryption actions have exceeded the limit. The KGC executes a revocation algorithm to periodically revoke users' editing permissions. Users run hash calculations, outputting chameleon hashes, random numbers, and temporary trapdoors based on different editing conditions.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

An operating system kernel security encryption method based on AES algorithm

PendingCN122365523ARealize hierarchical managementimprove securityComplete dataData integrity
This invention discloses a secure encryption method for the operating system kernel based on the AES algorithm, relating to the fields of operating system security and data encryption technology. The method comprises the following steps: S1, traversing and scanning the data in the operating system kernel, identifying sensitive data, and classifying it according to its sensitivity level; S2, generating an encryption master key and hierarchical subkeys based on the AES algorithm; S3, encrypting data of different sensitivity levels using AES encryption algorithms with different rounds and encryption modes; S4, dynamically updating the key and encrypting and storing the updated key in the kernel secure storage area; S5, adding a checksum to the encrypted sensitive data and verifying data integrity; S6, reading the corresponding key and decrypting the data to complete data access. This invention significantly improves key security and data integrity, effectively balances encryption efficiency and system performance, has strong adaptability and high practicality, and is easy to promote and apply.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

Anti-laser attack ai chip key storage and computing security region design method

PendingCN122339680AAttackMaster key
This invention discloses a method for designing a secure key storage and computation area for AI chips resistant to laser attacks, comprising the following steps: S1: Constructing a dedicated hardware secure area at the physical level of the AI ​​chip. The secure area is surrounded by a multi-layer heterogeneous shielding structure, within which a tunable filter is integrated; and integrating an array of heterogeneous physical attack detection sensors for light, heat, and electromagnetic fields within the secure area; S2: Preprocessing the master key to generate multiple key fragments, and using different physical obfuscation mechanisms to disperse and store them in multiple physically isolated non-volatile storage units within the secure area; S3: When a secure computation task is triggered, the security control unit synchronously collects time-series data from each sensor, performs an environmental security status assessment using a multi-sensor fusion attack judgment model, and outputs a fusion attack probability value. This invention can enhance the AI ​​chip's resistance to laser attacks and ensure key and computational security.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

Key generation method, device and system

PendingCN122339687AKey exchangeSecure communication
This application provides a key generation method, apparatus, and system. The key generation method, applied to Internet of Things (IoT) devices, includes: generating a first temporary key pair based on first identification information of the IoT device, the first temporary key pair including a first public key and a first private key; determining a connection request based on the first public key and the first identification information; sending the connection request to a cloud server; obtaining verification information sent by the cloud server; and generating a master key based on the verification information and the first identification information; wherein the connection request and verification information are configured to be transmitted through a secure communication channel established by a key exchange protocol between the IoT device and the cloud server. The key generation method of this application achieves a strong association between the master key and the physical hardware of the IoT device, significantly reducing the risk of device cloning due to firmware copying, and improving the security and maintainability of the IoT system.
Owner:SHANGHAI SUMI TECH CO LTD +1

Intelligent Pairwise Master Key (PMK) Cache Sharing

Techniques for intelligently sharing Pairwise Master Key (PMK) cache information among Wi-Fi access points (APs) in a network are provided. With these techniques, Wi-Fi clients that roam from a first radio frequency (RF) coverage area of the network to a second RF coverage area of the network that is separate (i.e., disjoint) from the first RF coverage area can avoid full 802.1X authentication at the time of connecting to Wi-Fi APs in the second RF coverage area.
Owner:ARISTA NETWORKS INC

Virtual keys for column dataset access management

ActiveUS12670288B2Data setEngineering
A key management system can store, in a tag repository, information associating policy tags with column datasets. The system can receive a client request for an encrypted encryption key (EEK) to access a column dataset, where the client request includes a column name for the column dataset. Based on the client request, the system can perform a lookup in the tag repository to identify one or more tags associated with the column dataset and determine whether the client device is authorized to access the column dataset. Based on determining that the client device is authorized to access the column dataset, the system can generate an original encryption key, and generate the EEK using a shared master key, the original encryption key, and at least the column name for the column dataset. The system may then provide the EEK to the client device over the one or more networks.
Owner:UBER TECHNOLOGIES INC

Face identity authentication method based on terminal device legitimacy precondition constraint and related device

The present application relates to face identity authentication method based on terminal device legitimacy precondition constraint and related device. Including: face recognition terminal sends device check request including device identification to server; Server generates device key based on master key and device identification, and performs device check using device key; If not pass the check, terminate the authentication; If pass, generate collection permission token through the server, so that the terminal collects face feature data based on the collection permission token, calculates the first message authentication code using the pre-stored authentication material for face feature, device identification and session identification, generates face identity authentication request, and forwards to the server through the client; Through the server, generate device key based on master key and received device identification using key derivation algorithm, and verify the first message authentication code based on the device key, and determine the identity authentication result according to the verification result. The security of identity authentication is improved, and the risk of privacy leakage is reduced.
Owner:BEIJING EETRUST TECH CO LTD

A BOM-based cross-organization engineering data security collaborative editing method

PendingCN122372199ASoftware engineeringMaster key
This invention discloses a cross-organizational collaborative editing method for engineering data security based on Bill of Materials (BOM). The method first involves a Trusted Institution (TA) setting global parameters and generating a master key. Participating companies register with the TA, forming a consortium blockchain and deploying smart contracts. Next, the company initiating the collaborative project acts as the lead company, selecting a Service Provider Corporation (SPC). The SPC's public key is bound to a secret shared structure, and the lead company completes data encryption and encapsulation. Then, during the data sharing phase, two processes are included: data decryption and encrypted update. When the service provider company makes modifications, a joint approval process is triggered. Finally, the service provider company can perform multi-version access and trace the behavior when retrieving data entities. This invention effectively solves three core problems faced in cross-organizational collaborative manufacturing scenarios: difficulty in fine-grained sharing, uncontrollable modification authorization, and difficulty in defining and tracing operational responsibility.
Owner:HANGZHOU DIANZI UNIV +1

Attribute-based encryption method and system supporting fast multi-keyword search with access policy hiding

PendingCN122457294APlaintextCiphertext
The application discloses an attribute-based encryption method and system supporting quick multi-keyword search with access strategy hiding, and the method comprises the following steps: step one, a trusted agency generates a master key, generates system parameters according to the master key, and sends the system parameters to a medical data owner and all users; step two, the medical data owner generates a user key according to the system parameters, and sends the user key to all users; step three, the medical data owner generates ciphertext, and sends the ciphertext to a cloud server; step four, a user generates a trapdoor according to a search keyword set and the user key, and sends the trapdoor to the cloud server; and step five, the cloud server matches the keywords in a medical data plaintext keyword set with the keywords in the search keyword set in the trapdoor, if the matching is successful, decryption is performed, and if the matching fails, no matching result is displayed. The application improves the privacy of user information, and also provides multi-keyword search and quick search functions.
Owner:HENAN UNIVERSITY

Method and system for encrypted storage of power data

PendingCN122268674AImprove forward secrecyImprove resistance to attackKey distribution for secure communicationDigital data protectionCiphertextEngineering
This invention discloses a method and system for encrypted storage of power data, applied in the field of power system information security technology. The method includes: acquiring power data to be encrypted from a target power system; determining a dynamic time-series characteristic sequence based on historical operating status data of the target power system; grouping the power data to be encrypted into individual data groups; determining a session key for each data group based on the analysis results of the historical operating status data; encrypting each corresponding data group using each session key to obtain ciphertext data; encrypting all session keys using the master key in an asymmetric encryption algorithm to obtain encrypted session keys; associating and encapsulating all ciphertext data and encrypted session keys, and storing the association and encapsulation result in a secure database. This invention achieves secure and stable encrypted storage of power data.
Owner:STATE GRID ZHEJIANG ELECTRIC POWER CO LTD HANGZHOU POWER SUPPLY CO +1

A power system equipment data security acquisition method and system

This invention relates to the field of industrial internet and data security technology, and discloses a method and system for secure data acquisition from power system equipment. The method includes establishing a synchronized key system containing a data encryption key derived from a master key and a random number encryption key. Power system equipment acquires sensor data, generates a high-entropy random number sequence, and constructs standardized data blocks. The standardized data blocks are encrypted using the data encryption key to generate ciphertext data, and the random number sequence is independently encrypted using the random number encryption key to generate a random number ciphertext stream. These are then encapsulated and sent as a data packet containing both. The data center receives the data and uses the key system to decrypt and restore the standardized data blocks and random number sequence. Based on the restored random number sequence, the original sensor data is accurately separated from the standardized data blocks. This invention masks the statistical characteristics of low-entropy data through high-bit random padding, effectively resisting side-channel attacks and statistical analysis targeting power data.
Owner:HUANENG LANCANG RIVER HYDROPOWER CO LTD +1

A data processing method, apparatus, device, medium, and product

PendingCN122339669ACiphertextDynamic monitoring
This invention discloses a data processing method, apparatus, device, medium, and product. The method includes: an authorized agency generating a user key for each user based on public parameters, a master key, an attribute set, and codewords generated for each user; and distributing the public parameters, master key, and user key to the data owner; the data owner encrypting the plaintext file using an attribute-based encryption algorithm based on the public parameters, master key, user key, and access policy to obtain a ciphertext file, and uploading the ciphertext file to a cloud service provider. Through the technical solution of this invention, it is ensured that the fingerprint code is bound to the private key from the source of key generation, guaranteeing the unique association between the key and the user's identity. This enables dynamic monitoring and precise location of the leakage source in an outsourced decryption environment, fundamentally enhancing the security robustness of the ABE system, improving its credibility in practical applications, and ensuring the feasibility of secure outsourcing and sharing of sensitive data.
Owner:HANGZHOU XINGUANG SEMICONDUCTOR CO LTD

A chip-level multi-encryption method and system for an internet of things terminal

PendingCN122457310AMultiple encryptionSecure communication
The application relates to a chip-level multiple encryption method and system for an Internet of Things terminal, in particular to the field of key distribution, which realizes safe dynamic networking access of the Internet of Things terminal through attribute matching and a dynamic credential mechanism, effectively filters unauthorized nodes, utilizes a terminal real-time context to cooperatively generate a unique basic seed, ensures that key materials are strongly bound to a task scene, has forward security, based on a non-interactive negotiation mechanism, efficiently derives a unified session key without multiple rounds of handshake communication, significantly reduces delay and overhead, through hierarchical derivation and rolling update of a master key, provides isolated and short-life-cycle encryption protection for different communication requirements, and realizes high-safety, low-delay and extensible in-group security communication in a resource-limited Internet of Things edge environment.
Owner:SHAOXING YULI SEMICON CO LTD

Data protection method and electronic device

ActiveCN116527246BCiphertextPassword
Embodiments of the present application provide a data protection method and an electronic device, the method comprising: after inputting a first lock screen code of a first electronic device and enabling a synchronization function of a password safe service, a user triggers a second control in a current display interface, triggers the first electronic device to create a first trust circle corresponding to a first account, and after the first trust circle is created and joined, displays prompt information in the interface to prompt that the first trust circle has been created. The data protection method protects the account-level master key MK based on a user secret, such as a device lock screen code. Since the user secret is unknown to the cloud side, the cloud side cannot decrypt the hosted master key ciphertext, thereby reducing the risk of master key leakage, improving the security of the master key MK, and enabling the cloud side to prove its innocence.
Owner:HONOR DEVICE CO LTD