Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

298 results about "Master key" patented technology

A master key operates a set of several locks. Usually, there is nothing special about the key itself, but rather the locks into which it will fit. These master-keyed locks are configured to operate with two, or more, different keys: one specific to each lock (the change key), which cannot operate any of the others in the set, and the master key, which operates all the locks in the set. Locks that have master keys have a second set of the mechanism used to operate them that is identical to all of the others in the set of locks. For example, master keyed pin tumbler locks often have two shear points at each pin position, one for the change key and one for the master key. A far more secure (and more expensive) system has two cylinders in each lock, one for the change key and one for the master key.

Dynamic double-layer hidden watermark and encryption binding file protection method and system based on deep learning

The invention relates to a dynamic double-layer hidden watermark and encryption binding file protection method and system based on deep learning, and belongs to the technical field of digital content security. The problems of attack resistance, traceability obstruction and key-watermark unhooking in document cross-platform circulation are solved. According to the scheme, the method comprises the following steps of: extracting semantic fingerprints by using a sentence vector model Sentence-BERT; the fuzzy extractor generates a master key and derives a time key chain; the authentication encryption algorithm AEAD encrypts and binds the source and the timestamp load; container layer structure rearrangement and document layer zero-width character double embedding are carried out; the generative adversarial network or diffusion model adversarial training improves the optical character recognition and transcoding resistance; version binding and tracing are achieved through the watermark hash chain. The technical effects cover anti-counterfeiting migration, cross-layer fault-tolerant guarantee recoverability, rearrangement attack resistance, full-period accurate traceability and post-quantum security enhancement.
Owner:SOUTHWEST UNIV

Method and system for safely sharing operation data of low-altitude unmanned aerial vehicle

The invention provides a low-altitude unmanned aerial vehicle operation data security sharing method and system, and the method comprises the steps: initializing a low-altitude unmanned aerial vehicle operation data security sharing system through a low-altitude traffic management platform, and generating a public parameter, a master key and an identity private key of a user; wherein the master key comprises a master public key and a master private key; the unmanned aerial vehicle encrypts the operation data of the unmanned aerial vehicle based on the identity information of the agent side to obtain an initial ciphertext, and uploads the initial ciphertext to the cloud platform; the agent side decrypts the initial ciphertext based on an identity private key of the agent side to obtain operation data of the unmanned aerial vehicle, generates a re-encryption key and uploads the re-encryption key to the cloud platform; the cloud platform re-encrypts the initial ciphertext based on the re-encryption key to generate a re-encrypted ciphertext; and the multi-body sharer end decrypts the re-encrypted ciphertext based on the identity private key of the multi-body sharer end to obtain the operation data of the unmanned aerial vehicle. According to the invention, the sharing security of the operation data of the unmanned aerial vehicle in a dynamic open network environment can be efficiently guaranteed.
Owner:HANGZHOU INNOVATION RES INST OF BEIJING UNIV OF AERONAUTICS & ASTRONAUTICS

Data storage security protection method and system based on solid state disk

The invention relates to the field of computer security, and discloses a data storage security protection method and system based on a solid-state hard disk, which comprises the following steps: identifying the inherent physical difference of a flash memory chip in the solid-state hard disk so as to calculate the read-write time sequence micro-deviation of the solid-state hard disk; performing hash operation on the device root key and the unique identifier of the controller corresponding to the solid state disk to obtain a bound master control key; generating a temporary encryption key of the write-in operation to encrypt plaintext data of the host system to obtain ciphertext data; writing the ciphertext data into a flash memory physical page corresponding to the physical page address to obtain a ciphertext physical page address; when the access mode is a hostile attack mode, secretly updating the ciphertext physical page address into a new physical page address, and deleting the ciphertext physical page address; and when the access mode is a secure access mode and the verification key is consistent with the bound master control key, normal loading and data access requests of the solid state disk are allowed. According to the invention, the security and integrity of data storage can be improved.
Owner:深圳市彦胜科技有限公司

Identity authentication method and system based on national secret algorithm

The invention discloses an identity authentication method and system based on a national secret algorithm, and the method comprises the steps: building a hierarchical key management system based on a national secret IBE framework, generating a system master key pair through employing an SM2 algorithm, and achieving a decentralized key distribution mechanism; constructing a domain perception differential privacy protection module, defining a privacy budget allocation strategy according to the security level, and adding calibrated Laplace noise to the user identity feature vector; designing a distributed batch matrix multiplication protocol, and decomposing the distributed batch matrix multiplication protocol to a plurality of computing nodes for parallel processing through a secret sharing technology; a zero-knowledge proof verification mechanism is implemented, and identity verification is completed through a commitment scheme based on an SM3 hash algorithm; deploying a self-adaptive key updating strategy, and analyzing threat level change through a threat situation evaluation function; and establishing a secure communication channel based on SM4 symmetric encryption, and performing encryption processing by using the temporary session key. The security and expandability of the system are improved, the privacy of the user is effectively protected, and the system adapts to a dynamically changing network threat environment.
Owner:GUIZHOU BLUESKY INNOVATIVE SCI & TECH CO LTD

Data security management method, enterprise service bus system and electronic product

The invention relates to the technical field of communication, in particular to a data security management method, an enterprise service bus system and an electronic product, and is used for solving the problem that the enterprise service bus system in the prior art adopts a static privacy strategy, so that the system flexibility and security are poor. The method comprises the steps of determining the sensitivity level of received to-be-processed data based on the data structure type of the received to-be-processed data, determining a target storage node in a plurality of storage nodes with different safety coefficients according to the sensitivity level, and determining the target storage node based on the sensitivity level and the data volume corresponding to the to-be-processed data. Determining a target encryption strategy comprising an encryption algorithm and an encryption key generated based on the master key, encrypting the to-be-processed data based on the target encryption strategy, and storing the encrypted to-be-processed data to a target storage node; the storage node and the encryption strategy are determined through the sensitivity level, the flexibility of the service bus system is improved, the safety of high-sensitivity data is guaranteed, meanwhile, excessive protection of low-sensitivity data is avoided, and the system performance and the safety strength are improved.
Owner:CHINA CONSTRUCTION BANK +1

Secure data transmission over constrained one-way channel

The sender stores a pair of sender's public and private keys and a public key of the receiver, and carries out the steps of:A—generating a master key, that is a secret shared with the receiver, by key derivation from a current root key and using the sender's private key and the receiver's public key, and updating the root key with the generated master key;B—generating, by key derivation from said master key, a chain of message keys for securing messages to communicate to the receiver;C—generating a next pair of sender's public and private keys, sending the next sender's public key to the receiver and executing again the steps A andB using the next sender's private key and the same receiver's public key;wherein the current root key used in the step A isat a first iteration of step A, an initial root key prestored in the sender, said initial root key being a secret shared with the receiver, andat each subsequent iteration of the step A, the root key that has been updated at the preceding iteration of step A.
Owner:NAGRAVISION SRL

Vehicle information safety protection system based on combination of national secret algorithm and PUF (Physical Unclonable Function)

The invention discloses a vehicle information safety protection system based on combination of a national cryptographic algorithm and a PUF (Physical Unclonable Function), which belongs to the field of vehicle information safety and encrypted communication, and comprises a response generation module used for generating a PUF response in a safety chip of a vehicle; the key derivation module is used for generating an encrypted master key through a key derivation function based on the PUF response, the vehicle owner identity and the random number nonce; the encryption and signature module is used for generating a ciphertext and carrying out digital signature on the ciphertext; the state monitoring module is used for monitoring the running state of the vehicle hardware; the key management module is used for triggering a failure operation of the encrypted master key when the state monitoring module detects that the hardware state is abnormal; and the decryption verification module is used for regenerating the PUF response and verifying the consistency of the generated key so as to execute data decryption. According to the method, hardware-level encryption protection of the vehicle data is realized through combination of the PUF and the national cryptographic algorithm, so that the safety of the vehicle owner data is protected in the whole life cycle of the vehicle.
Owner:HUBEI UNIV

Local key secure storage method and device based on virtualized cryptographic module

The invention discloses a local key secure storage method and device based on a virtualized cryptographic module, and aims to solve the problem that the security, the cost and the flexibility of the existing scheme are difficult to consider at the same time. According to the method, a high-isolation virtualized cryptographic module (VCM) is created through a CPU hardware virtualization technology, a safe execution environment is constructed, and safe generation, packaging storage and unpackaging operation of a master key and a working key are achieved; the device comprises a hardware layer, a virtualization layer, a VCM and a communication interface, and all the layers are coordinated and are subjected to authority isolation. According to the scheme, the system is supported to start automatic loading or on-demand dynamic loading, and various attacks are resisted in combination with TPM (Trusted Platform Module) enhanced packaging and a strong encryption mechanism. Through verification of a 110kV intelligent substation scene, special hardware does not need to be newly added, the cost is only 0.1% of that of a traditional HSM scheme, the operation response delay meets the real-time requirement, and the method is suitable for key security storage scenes of various types of equipment.
Owner:GUANGXI POWER GRID CORP

Data transmission method and system for meteorological satellite communication system

The invention discloses a data transmission method for a meteorological satellite communication system, and relates to the technical field of data transmission. Receiving original meteorological data, performing security level analysis on the original meteorological data, determining a security level, and processing the key change parameter by using the master key based on a preset key derivation function to obtain an encrypted session key; performing encryption processing on the original meteorological data based on the encrypted session key to obtain first ciphertext data; combining the key change parameter with the communication identification information to obtain first associated data; performing message authentication code calculation on the first associated data and the first ciphertext data to obtain a message authentication code; assembling the security level, the first associated data, the first ciphertext data and the message authentication code based on a preset format to obtain a target data frame; and sending the target data frame to a meteorological data center so as to decrypt the target data frame to obtain original meteorological data. By implementing the technical scheme provided by the invention, the security in the transmission process is ensured.
Owner:ZHONGMAN TECH (BEIJING) CO LTD

Lightweight identity authentication and data security interaction method, system and equipment for protecting measurement and control device and medium

The invention discloses a lightweight identity authentication and data security interaction method, system, equipment and medium for a protection measurement and control device, and relates to the technical field of power system information security. The method comprises the steps that the protection measurement and control device and an edge gateway carry out bidirectional identity authentication based on a preset shared master key and random numbers generated by the protection measurement and control device and the edge gateway; after the authentication succeeds, the two parties derive a session key of the communication based on the random number; between the protection measurement and control device and the edge gateway, service data is encrypted by using a session key, an integrity check code is generated, and a security data message is constructed for transmission; the receiver performs integrity verification and decryption on the security data message to obtain plaintext data; and receiving a key updating instruction from the cloud based on the secure channel, and performing secure updating on a preset shared master key. According to the invention, a mechanism of combining the pre-shared master key with the dynamic session key is adopted, so that the complex certificate chain verification overhead of a PKI system is avoided.
Owner:GUIZHOU POWER GRID CO LTD

Digital identity encryption authentication method

The invention relates to the technical field of digital identity authentication, and discloses a digital identity encryption authentication method, which comprises the following steps of: acquiring a user identity information feature data set, and generating a master key library through multi-dimensional encryption preprocessing; extracting fragment verification features of each master key library to determine an authentication rule; and constructing a multi-level authentication chain and a verification node, and obtaining a node authentication state through bidirectional verification. In an effective authentication state, the master key library is subjected to association authentication according to permission levels; and in the invalid authentication state, identifying the abnormal verification node, calculating the authentication offset of the master key library under the abnormal verification node, and reconstructing the path of the abnormal verification node based on the authentication offset until the authentication is completed. Wherein the generation of the master key library relates to encryption, confusion and format standardization of various types of data; fragment verification feature extraction comprises key fragment sorting and the like; the authentication rule is determined based on the dynamic feature priority; and exception processing is combined with historical tracing and offset calculation. According to the method, the authentication security and the dynamic adaptability are improved.
Owner:YIQIBANG (ANHUI) DIGITAL TECHNOLOGY CO LTD

Model interface access control method and device, electronic equipment and storage medium

The invention discloses a model interface access control method and device, electronic equipment and a storage medium, and relates to the technical field of artificial intelligence. A dynamic interface key can be generated according to a user identity identifier, a timestamp and a master key and is updated in a preset period; meanwhile, multi-dimensional behavior data such as an IP address called by a user interface, calling frequency, request content semantic features and resource consumption are collected, multi-dimensional scoring is carried out based on the behavior data so as to execute an access control decision, and a user behavior model can be constructed and updated based on historical behavior data; according to the method and the system, the model is established, and a score threshold in an access control decision is dynamically adjusted according to the model, so that the problems of low interface key security, extensive access right control and poor access control decision adaptability caused by the adoption of a static interface key and lack of an access control mechanism of multi-dimensional behavior analysis and dynamic threshold adjustment in the prior art can be solved.
Owner:JINAN INSPUR DATA TECH CO LTD

Internet of vehicles cross-domain identity authentication method based on PUF (Physical Unclonable Function) and certificateless

The invention provides an Internet of Vehicles cross-domain identity authentication method based on PUF and certificateless, and the method comprises the steps: firstly generating a system master key and a master public key through a KGC, and disclosing system parameters; secondly, the vehicle generates a physical response and extracts a stable key, interacts with the KGC to complete generation of a certificateless key pair, and stores registration information to a block chain; then the edge server registers in the KGC, obtains a certificateless key pair, initiates an authentication request to the KGC, and obtains a block chain data reading authority; finally, bidirectional authentication is carried out between the vehicle and the edge server based on the certificateless signature and the PUF response, and a session key is generated; and the cross-domain vehicles are assisted by the edge server to complete mutual identity authentication and session key negotiation. According to the method, the key escrow and certificate management burden is eliminated by adopting a certificateless cryptosystem, the high computing load is released to the edge server in combination with the PUF hardware security characteristic and the block chain distributed trust, the computing and communication overhead is remarkably reduced, and the method is suitable for a large-scale Internet of Vehicles cross-domain authentication scene.
Owner:GUIZHOU UNIV

Anti-quantum migration method and system, electronic device, and storage medium

The application relates to an anti-quantum password migration method, system, electronic equipment and storage medium, and belongs to the technical field of anti-quantum data transmission. The method comprises the following steps: adaptively extending a transmission layer security protocol; and performing secure transmission of application data by an encryption end and a decryption end based on the extended transmission layer security protocol, wherein the secure transmission process of the application data comprises the following steps: respectively generating a master key, a multi-level sub-key and a path key chain based on an extended password suite according to a chained post-quantum key generation mechanism; generating an encryption key by the encryption end using part of the sub-key, encrypting the application data in a symmetric encryption mode to generate ciphertext, and sending the ciphertext and a path node key at the end of the path key chain to the decryption end; verifying the path node key by the decryption end, generating a decryption key by the decryption end using part of the sub-key after the path node key is verified, and decrypting the ciphertext. The application realizes the security and high efficiency of data transmission in the anti-quantum password migration process.
Owner:RELATED (BEIJING) TECHNOLOGY CO LTD

Anti-quantum security enhancement method for SSL VPN protocol

An anti-quantum security enhancement method for an SSL VPN protocol of a communication network. The method comprises: (011) acquiring a first quantum key and a quantum key identifier from a first network node that has accessed a network device; (012) performing post-quantum cryptographic encryption processing on the quantum key identifier, and sending a first encryption result of the post-quantum cryptographic encryption processing to a terminal; (013) decrypting a received second encryption result sent by the terminal, so as to obtain a second decryption result; (014) obtaining a first master key on the basis of the first encryption result and the second decryption result; and (015) generating and obtaining a second master key on the basis of the first master key, the first encryption result, the second decryption result, and the first quantum key, so as to encrypt communication between the network device and the terminal.
Owner:CHINA TELECOM QUANTUM INFORMATION TECH GRP CO LTD

Cross-domain quantum key charging method and system

The invention relates to the field of information security, and discloses a cross-domain quantum key charging method and system.The method comprises the steps that a first key charging site responds to a first service terminal request, analyzes a target terminal identifier and reports step by step when cross-domain judgment is conducted; the cross-domain key charging management center generates a cross-domain master key based on a quantum true random number according to the target attribution, and distributes the cross-domain master key to a source domain key charging service center and a target domain key charging service center through a quantum secure channel; the service centers of the two parties negotiate a derived session key by using the shared master key and issue the derived session key; and after receiving the session key, the site generates a service key in combination with the service context and charges the service key to the terminal. The system also integrates a dynamic request triggering mechanism based on consumption rate, a hybrid encryption channel mechanism and a storage unit physical overwriting destruction mechanism. According to the method, a hierarchical cascade architecture is adopted, and a quantum entropy source and a post-quantum algorithm are combined, so that the problem of trust transfer between heterogeneous domains is solved, and quantum computing attack-resistant key full-life-cycle safe closed-loop management is realized.
Owner:GUIYANG BUREAU OF CHINA SOUTHERN POWER GRID CO LTD EHV TRANSMISSION CO

Encryption communication system based on multistage key distribution

According to the encryption communication system based on multi-level key distribution provided by the invention, the environment sensing layer acquires target environment parameters in real time and forms closed-loop feedback with a dynamic security score generated by the strategy control layer, and the key management layer is driven to realize three-stage dynamic switching from an initial key to a session key to a master key; a key fragmentation bidirectional authentication mechanism of a secure transmission layer and a double-key pool non-inductive updating strategy of a password service layer are matched, under the quantum resistance storage guarantee of a hardware isolation layer, an annular defense system with a space-time adaptive characteristic is constructed, and the security and availability are greatly and comprehensively improved.
Owner:HUANENG SHANXI ENERGY SALES CO LTD +1

Automobile ECU and UDS security diagnosis method based on dynamic session key

The invention discloses an automobile ECU and UDS security diagnosis method and system based on a dynamic session key, and the method comprises the steps: in the diagnosis process, the ECU generates challenge information containing a random seed, a unique session identifier and an initial counter, and calculates an expected key in combination with a hardware identifier and a main key; and the diagnostic instrument calculates a client key and returns the client key by using the same hardware identifier, the master key and the received challenge parameters, and the ECU completes authentication by checking the session identifier, the counter and the key. And after the authentication is passed, the two parties independently derive a temporary session key by taking the master key as a root key and combining the dynamic factor of the session. When the diagnostic instrument sends a request, the counter is increased progressively, an authentication code is generated in combination with the session key, and the request, the authentication code and the counter are sent to the ECU; and the ECU checks the continuity of the counter and the consistency of the authentication code to verify the legality of the request, and also generates the authentication code to be verified by the diagnostic apparatus when sending a response, thereby completing bidirectional verification. And the diagnosis safety level of vehicle-mounted electronic equipment and the like is improved.
Owner:DONGFENG OFF ROAD VEHICLE CO LTD

Hadoop tenant-level encryption isolation implementation method and device

The invention discloses a Hadoop tenant-level encryption isolation implementation method, and aims to solve the problems of single key leakage risk, namespace planarization, encryption area unauthorized binding, no tenant dimension auditing and the like existing in an existing Ranger-KMS scheme. The method comprises the following steps: creating an independent master key for each tenant to realize physical isolation; the key alias, the encryption area paths and the strategy resources are forced to carry tenant prefixes, and the consistency is verified; a tenant context is transmitted through a thread local variable; when an encryption area is created, tenant attributes are persisted, and operation consistency is verified; and the key plaintext is only stored in the KMS memory and is safely reset after being used. According to the method, full-dimension isolation of keys, data, strategies and auditing is realized, single-tenant key leakage does not influence the cluster, unauthorized access and information leakage are completely eradicated, compliance auditing requirements are met, single-cluster multi-tenant safe coexistence is supported, and hardware cost is reduced.
Owner:CHINA ELECTRONICS CLOUD DIGITAL INTELLIGENCE TECH CO LTD

Wireless fast ad hoc network node security access and key management method based on quantum random number

The invention discloses a wireless fast ad hoc network node security access and key management method based on quantum random numbers, and belongs to the technical field of wireless communication. The method comprises the following steps: constructing a dynamic architecture of the Mesh ad hoc network; the constructed Mesh ad hoc network dynamic architecture is updated, and an optimal communication path is searched; the unpredictability of quantum physics is combined with the real-time state of the network to construct a dynamic master key; fragmenting the master key to generate key fragments; the key fragment is stored in a Mesh ad hoc network; and based on the state of the Mesh ad hoc network, judging whether the key fragment is stored again or not. According to the method, the Mesh ad hoc network architecture is quickly established, and a Mesh network distributed key fragmentation and storage mechanism is combined, so that key loss caused by single node leakage and node failure is avoided, node quick ad hoc access and dynamic key updating are supported, and secure communication under frequent topology change is ensured; and a safety management system covering node access, topology change and fault recovery full life cycle is constructed.
Owner:JIANGSU YUANNENG ELECTRIC POWER ENG

Lightweight encryption and decryption method

The invention relates to the technical field of information security, in particular to a lightweight encryption and decryption method, which comprises the following steps: acquiring a continuous binary data stream of a sensor and segmenting the continuous binary data stream into fixed-length groups; calling a pre-generated round key sequence and a whitening key, wherein the round key sequence is generated through master key shift operation and round constant iteration; performing XOR operation on the grouped data and the whitening key to output initial confusion data; segmenting the initial confusion data into four equal-length sub-segments to execute multiple rounds of iterative processing, wherein each round comprises 16-bit modular addition operation and fixed-bit cyclic shift; xOR is carried out on the shifted data and a current round key, a sub-segment state is updated according to a preset branch processing rule, and linear transformation is carried out on the updated state by adopting a self-inverse matrix; the last-round output sub-segments are spliced into a ciphertext to be transmitted to an execution mechanism; during decryption, reversely calling the round key sequence, and multiplexing the self-inverse matrix to execute inverse transformation and reverse operation to recover original data. The problem of high encryption delay of industrial control equipment is solved.
Owner:CHINA ELECTRONICS CORP 6TH RES INST

Rekeyable lock cylinder

A rekeyable lock cylinder with a cylinder body, an inner sleeve, and a plug assembly is provided. The plug assembly includes a plurality of key followers and a corresponding plurality of first racks and second racks disposed in carriers. The first racks correspond to operation of a user key and the second racks correspond to operation of a master key. As such, the lock cylinder is usable in a user / master key system. Disengaging either of the first or second racks from the key followers allows rekeying of the lock cylinder for the user key or the master key.
Owner:ASSA ABLOY AMERICAS RESIDENTIAL INC

Method for provisioning credentials to user equipment in a private telecommunications network - Patent Application 20070122997

The present invention proposes a method for provisioning a credential to a user equipment (10) in a private telecommunications network, the private telecommunications network including a credential holder and a gNB / AMF or eNB / MME, the method comprising: a) sending a provisioning request (40) from the user equipment (10) to the gNB / AMF or eNB / MME (11); b) establishing a PLS key (41) between the user equipment (10) and the gNB / AMF or eNB / MME (11) by physical layer security; c) providing a PLS key to the user equipment (10) via a PLS key; d) transmitting 43 a message from the user equipment 10 to the gNB / AMF or eNB / MME 11, the message including data permitting identification of the user of the user equipment 10 and / or the user equipment 10 and the master key, the message being integrity and confidentiality protected by a PLS key or a key derived from the PLS key; e) transmitting 44 a message from the gNB / AMF or eNB / MME 11 to the credential holder 12, the message including data permitting identification of the user of the user equipment 10 and / or the user equipment 10 and the master key, the message being integrity and confidentiality protected by a PLS key or a key derived from the PLS key. f) verifying in the credential holder (12) the data that allows identifying the user of the user equipment (10) and / or the user equipment (10); g) if the verification is positive, assigning in the credential holder (12) a unique subscription identifier to the user equipment (10) and generating corresponding keys, security parameters, and key derivation functions; h) transmitting the unique subscription identifier from the credential holder (12) to the gNB / AMF or eNB / MME (11). i) transmitting the unique subscription identifier, security parameters, and key derivation function from the gNB / AMF or eNB / MME (11) to the user equipment (10) in a message integrity and confidentiality protected by a PLS key or a key derived from the PLS key (47); j) generating a final key at the user equipment (10), the final key being a credential including the unique subscription identifier, security parameters, and final key (48);Including.
Owner:THALES SA +1

Rekeying in association with an encryption key hierarchy

Methods, systems, and devices for data management are described. A data management system (DMS) may store encrypted backup data across one or more storage locations using a hierarchical encryption key management design. The hierarchical design may include data encryption keys (DEKs) that are used to encrypt the backup data, and may also include one or more layers of key encryption keys (KEKs). For example, a root KEK may be implemented at the top of the hierarchy and may be used to encrypt intermediary KEKs, while intermediary KEKs may be implemented at one or more lower levels of the hierarchy and may be used to encrypt other intermediary KEKs and / or the DEKs, with the DEKs at the bottom of the hierarchy and used to encrypt data. In some examples, the root KEK may be wrapped by a customer master key, enabling customers of the DMS to provide their own encryption keys.
Owner:RUBRIK INC

End-to-end voice encryption methods, devices, and Bluetooth headsets applicable to multi-hop lossy channels

This invention provides an end-to-end voice encryption method, apparatus, and Bluetooth headset suitable for multi-hop lossy channels. The method includes front-end noise reduction, framing, and segmentation of the acquired voice at the transmitting end. Based on the session mode, a group public key or a point-to-point private key is automatically selected as the master key from a pre-configured key set. Then, multiple time-domain segments within each frame are scrambled, subjected to segment-by-segment Fast Fourier Transform, and frequency-domain encryption based on subkeys, according to the master key. The encrypted voice is then generated through inverse transformation and overlapping weighted smoothing concatenation, and transmitted through a multi-hop voice communication channel containing multi-level lossy encoding and decoding. At the receiving end, the reverse process is performed: framing and segmentation, transformation, inverse frequency-domain encryption, and inverse time-domain scrambling. Combined with U-shaped neural network noise reduction at both the front-end and back-end, the voice is restored to intelligible speech. This method enables flexible key management and high-quality secure voice transmission in scenarios where group calls and point-to-point private calls coexist and undergo multiple lossy compression operations.
Owner:VISION INTELLIGENCE CO LTD

Client device authentication using contactless traditional magnetic stripe data

A technique for generating diversified encryption keys for contactless conventional magnetic stripe cards is disclosed. Diversified keys can be generated using a master key, key diversification values, and an encryption algorithm. In one example embodiment, the key diversification value can be provided by a user using a fingerprint, digital code, or photograph. The user can provide the key diversification value to the card or mobile phone. The card can use the user-provided key diversification value to generate a diversified key. The card or mobile phone can send the user-provided diversification value to a server, and the server can regenerate the diversified key using the user-provided diversification value.
Owner:CAPITAL ONE SERVICES LLC

System and method for managing access rights and authorizations

Device and Method for Managing Access Rights and Authorizations This description concerns a method for managing access to the use of an automated system, comprising: - providing an identification value, associated with a user, to a first device; - generating, via a secure circuit of the first device, an account address based on a master key associated with the first device, the identification value, and a context value; - sending a transaction to the account address in a blockchain; - validating or invalidating the transaction, by the blockchain, based on the balance associated with the account address in the blockchain; and - if the transaction is validated by the blockchain, authorizing the first device to grant the user access to the automated system. Figure for the abstract: Fig. 8
Owner:COMMISSARIAT A LENERGIE ATOMIQUE ET AUX ENERGIES ALTERNATIVES

Remote key security management method and device for cloud virtualization cryptographic module

The invention discloses a remote key security management method and device for a cloud virtualization cryptographic module, and aims to solve the problems of cloud key trust root, transmission security and the like. The core of the method is to keep the master key control right of a user locally, and through cooperative work of a local client, a cloud management platform and a distributed vHSM instance, through the four steps of system initialization and key fragmentation distribution, remote certification and secure channel establishment, distributed cooperative operation and local result synthesis, and by utilizing IBE, Shamir secret sharing, a threshold cryptographic algorithm and TEE technologies, the user master key control right and the distributed vHSM instance are subjected to remote certification and secure channel establishment, distributed cooperative operation and local result synthesis. And the key is available and invisible. The device comprises three modules, namely a local client, a cloud management platform and a vHSM cluster. The method guarantees secret key confidentiality and completeness, supports a national secret algorithm, meets compliance requirements, adapts to cloud native elasticity requirements, and is suitable for cloud secret key management in industries such as electric power and the like.
Owner:GUANGXI POWER GRID CORP

Intelligent roadside terminal security processing method and system based on multimode communication cooperation and dynamic key chain

The invention provides an intelligent roadside terminal security processing method and system based on multimode communication collaboration and a dynamic key chain, and relates to the technical field of intelligent traffic and network space security crossover, and the method comprises the steps: obtaining a master key based on a trusted mechanism, and carrying out the registration of a roadside terminal through the master key, distributing a unique identification roadside terminal ID and an initial key for each roadside terminal; a secure link is established through an initial key, a roadside terminal collects 3D spatial position information of the roadside terminal and an accessed vehicle and forms a 3D point set to determine the spatial association priority of the vehicle and each roadside terminal, and meanwhile, the channel quality of a communication mode is evaluated in real time to obtain an evaluation result. The key message delay is less than or equal to 30ms, the cross-terminal authentication time is less than or equal to 10ms, the key leakage risk is reduced, and the vehicle-road collaborative real-time performance and security enhancement requirements are met.
Owner:XIAMEN JINLONG CAR ACCESSORIES CO LTD

Beidou navigation authentication receiving method and device

The embodiment of the invention discloses a Beidou navigation authentication receiving method and device. A specific embodiment of the method comprises the following steps: generating a system public parameter and a master key according to a security parameter and the maximum number of authorized users; inputting the obtained user identity number, the system public parameter and the master key into a key generation algorithm to obtain a user private key, and transmitting the user private key to the user through a secure channel; comparing the navigation message hash value with a preset hash value to obtain a comparison result; and in response to determining that the comparison result represents that comparison is consistent, determining the navigation message as a navigation message signal which is not tampered. According to the embodiment, the public key management process is simplified, and the encryption efficiency is improved. The decryption authority of the illegal user can be cancelled in time, and the illegal user is effectively prevented from stealing and tampering the Beidou navigation message.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University