Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

40 results about "Public key infrastructure" patented technology

A public key infrastructure (PKI) is a set of roles, policies, hardware, software and procedures needed to create, manage, distribute, use, store and revoke digital certificates and manage public-key encryption. The purpose of a PKI is to facilitate the secure electronic transfer of information for a range of network activities such as e-commerce, internet banking and confidential email. It is required for activities where simple passwords are an inadequate authentication method and more rigorous proof is required to confirm the identity of the parties involved in the communication and to validate the information being transferred.

Method and system for implementing a privacy preserving, face-based protected public key infrastructure

A computer-implemented method of registering a user identifier in a public key infrastructure comprising a trusted device and a server is provided. The method includes the steps: receiving the user identifier as an input to the trusted device; obtaining a hash value of the user identifier; the trusted device obtaining biometric data comprising a facial image of the user; generating a public key and a privacy preserving data structure using the biometric data, encrypting the user identifier using the public key, and storing the encrypted user identifier as metadata in the privacy preserving data structure, wherein a private key for decrypting the encrypted user identifier can be generated from the privacy preserving data structure using subsequently acquired biometric data comprising the facial image of the user; generating a device token corresponding to the trusted device and obtaining a hash value of the device token, the server storing the privacy preserving data structure uniquely indexed by the hash value of the device token while using the hash value of the user identifier as a primary key, and the trusted device storing the device token.
Owner:SEVENTH SENSE ARTIFICIAL INTELLIGENCE PTE LTD

Power fault diagnosis method and system based on large model retrieval enhancement

The invention relates to a power fault diagnosis method and system based on large model retrieval enhancement. The method comprises the following steps: firstly, initializing a federated network, and locally vectorizing multi-modal heterogeneous power data at each node to generate a private vector index; performing federated collaborative retrieval by combining the fault diagnosis request, the private vector index and the public key infrastructure to obtain a globally sorted knowledge fragment list; and finally, constructing a retrieval enhancement prompt according to the knowledge fragment list and the diagnosis request, and generating a fault diagnosis conclusion text by utilizing large language model reasoning. By adopting the method, dispersed multi-source knowledge can be effectively fused on the premise of ensuring the data privacy security of each node, so that the accuracy and reliability of fault diagnosis are improved.
Owner:SHAANXI HUADIAN NEW ENERGY POWER GENERATION CO LTD

Systems and methods for data authentication using composite keys and signatures

A system for enhanced public key infrastructure is provided. The system includes a computer device. The computer device is programmed to receive a digital certificate including a composite signature field including a plurality of signatures. The plurality of signatures includes at least a first signature and a second signature. The computer device is also programmed to retrieve, from the digital certificate, a first key associated with the first signature from the digital certificate. The computer device is further programmed to retrieve the first signature from the composite signature field. In addition, the at least one computer device is programmed to validate the first signature using the first key.
Owner:CABLE TELEVISION LAB INC

Chain of authentication using public key infrastructure

A method for sequential authentication based on chain of authentication using public key infrastructure (PKI) is provided. The method includes generating, by a user, a first private key and a first public key corresponding to each other; generating, by an nth service provider, an nth private key and an nth public key corresponding to each other; transmitting, from the user to the nth service provider, a level n key; verifying, by the nth service provider, the level n key; generating, by the nth service provider, a level (n+1) key by concatenating the level n key and the nth public key signed with the nth private key; and transmitting, by the nth service provider, the level (n+1) key to the user, where n is a natural number, and when n=1, the level 1 key is the first public key signed with the first private key.
Owner:CHOI OK

Public key infrastructure based session authentication

Techniques are disclosed for public key infrastructure (PKI) based session authentication. An example network device includes one or more processors and memory coupled to the one or more processors. The memory stores instructions that, upon execution, cause one or more processors to: receive, from a source client device, a packet including a header for routing the packet to a destination client device specified within the header and metadata distinct from the header, the metadata specifying public key infrastructure (PKI) information and identity context information identifying a user or device participating in a session between the source client device and the destination client device; verify, based on the PKI information within the metadata, the metadata; and in response to verifying the metadata, apply, based on the identity context information, one or more policy rules for the session associated with the packet.
Owner:JUNIPER NETWORKS INC

A method for implementing an identification-based authentication mechanism

The application belongs to the technical field of information security, and discloses a kind of based on identification authentication mechanism implementation method, including: after multi-dimensional identification server receives device authentication request, parsing device identification and calculating device public key, then interact with authentication center, carry out identity verification, after authentication center receives authentication request, the public key of device is calculated and the signature in request is verified using the public key, pass the verification, and the authorization code is generated and returned to the authentication server, and the server further forwards it to the device, and the returned signature information is verified by the device to ensure the validity of the authorization code.The application not only simplifies the management process of traditional public key infrastructure, but also improves the efficiency of the authentication process, each device only needs to generate a public-private key pair through its unique identification (EID), avoiding the complexity in traditional key distribution and certificate management, making device authentication more flexible and easy to expand.
Owner:NANJING UNIV OF POSTS & TELECOMM +1

Certificate query method and device based on edge node, equipment, medium and product

The invention relates to the field of block chains, and provides a certificate query method and device based on edge nodes, equipment, a medium and a product. The method comprises the following steps: receiving registration transaction information initiated by an authoritative certification authority; under the condition that the pre-verification of the registration transaction information is passed, sending the root certificate to the distributed public key infrastructure block chain, and receiving a registration completion response fed back by the distributed public key infrastructure block chain; under the condition that the registration completion response passes verification, after the registration completion response is fed back to the authority authentication mechanism, the authority authentication mechanism issues an entity certificate and feeds the entity certificate back to the network element; receiving a certificate verification request sent by the network element; and carrying out certificate query according to the certificate verification request, and determining a certificate query result. According to the certificate query method based on the edge node, a bridge is built through the edge node, and during certificate query, the network element securely accesses the distributed public key infrastructure through the edge node, so that the query efficiency is improved.
Owner:CHINA MOBILE COMM LTD RES INST +1

Consideration is given to a method of authenticating an access layer based on a public key infrastructure in a handover in a next generation wireless communication system

This disclosure relates to 5G or 6G communication systems for supporting higher data transmission rates than 4G communication systems such as LTE. In a wireless communication system according to an embodiment of the invention, a method for operating a serving base station for mutual authentication in the access layer (AS) portion during handover includes the following steps: receiving a measurement report from a terminal; determining, based on the measurement report, whether the terminal meets handover conditions; if the terminal meets the handover conditions, determining whether the target base station to which the terminal will connect during handover and the serving base station belong to the same authentication area (AA); and sending a handover command to the terminal, the handover command being configured differently depending on whether the target base station and the serving base station belong to the same AA.
Owner:SAMSUNG ELECTRONICS CO LTD

Serial number generation for stateless cloud certificate authority

A system associated with a public key infrastructure certificate framework in a cloud computing environment may include a certificate authority data store that contains information about a plurality of certificate authority instances (with each certificate authority instance being associated with an instance index and an instance deployment time). A certificate authority server, coupled to the certificate authority data store, may retrieve an instance index and instance deployment time from the certificate authority data store. The certificate authority server may then determine a current certificate identifier generation timestamp. A unique certificate identifier for a public key certificate is generated by the certificate authority server based on a deterministic creation algorithm, the instance index, the instance deployment time, and the certificate identifier generation timestamp. The public key certificate can then be issued using the unique certificate identifier.
Owner:SAP SE

Web application dynamic key encryption method based on SM3 and SM4

The invention relates to a Web application dynamic secret key encryption method based on SM3 and SM4, and relates to the technical field of data security. According to the method, a dynamic symmetric secret key is cooperatively generated at a front end and a rear end, a secret key seed is generated by utilizing an SM3 Hash algorithm, and sensitive data is encrypted and transmitted by combining an SM4 symmetric encryption algorithm, so that the secret key is not hard-coded and not transmitted; the session key is dynamically changed each time, the algorithm support can be completely localized, the encryption and decryption process is simple and efficient, a complicated certificate system or public key infrastructure is not needed, the front and rear ends only need to synchronize the key generation rule, and the method is suitable for an offline or weak network environment, does not depend on real-time network verification, and is easy to implement. The method can be used for offline or weak network environments such as an intranet and a government affair private network, and can effectively prevent historical data from being replayed by introducing factors such as dates and timestamps, so that sensitive data is effectively prevented from being stolen or tampered in the transmission process, and the overall security protection capability of Web application is improved.
Owner:BEIJING CATHAY INTERNET INFORMATION TECH CO LTD +1

Method and system for enabling custom features using public key infrastructure in storage device

The invention relates to managing custom memory functionality in a storage device coupled to a host device in an electronic system. The storage device obtains information items (e.g., programs, data, metadata) for implementing custom memory functions. The storage device receives a host signature and a public key from the host device and authenticates the host signature using the public key. In accordance with authentication of at least the host signature, the storage device performs the custom memory function based on the information item. In some embodiments, the host device selects a set of storage devices based on a first arrival first service order, and the custom memory functionality is implemented at each of the set of storage devices in accordance with authentication of at least a respective host signature issued by the host device.
Owner:SK HYNIX NAND PRODUCT SOLUTIONS CORP

Postponed certificate credential installation to wireless devices

This application describes techniques for postponed certificate credential installation to wireless devices, including generation and storage of secured scripts to be used for subsequent certificate credential installation on an eUICC of a wireless device after manufacturing. Management of certificate credentials, including installation on, modification to, and removal from, an eUICC can occur post-manufacturing, such as during a device activation procedure or as part of remote electronic subscriber identity module (eSIM) provisioning to the eUICC of the wireless device. Updating certificate credentials on an eUICC can allow for wireless device operation in different geographic regions that use different public key infrastructures (PKIs) with distinct root certificate issuers. The secured scripts can be pre-generated by an eUICC manufacturer (EUM) for the particular eUICC and stored at an OEM networked server and later used to install the certificate credentials on the eUICC of the wireless device.
Owner:APPLE INC

Generation of biometric-based reference tables to share cryptographic keys in a public network

Protocols for generating reference tables using biological information are disclosed. The protocols are usable for sharing cryptographic keys in a public key infrastructure (PKI). During an enrollment cycle, reference matrices or tables are constructed from the biometric images of one or more users (e.g., user's of client devices). To protect user privacy, the knowledge of these reference matrices cannot reveal the biometric images, and a third party cannot generate the same matrices from the biometric images. The shared keys may enable secure communication between a server and one or more of the users.
Owner:ARIZONA BOARD OF REGENTS ACTING FOR & ON BEHALF OF NORTHERN ARIZONA UNIV

A quantum public key infrastructure (QPKI) system

A quantum public key infrastructure (QPKI) system allowing for secure communications between a plurality of users and / or systems, comprising a quantum public key infrastructure (QPKI) machine, the machine comprises a quantum resistant cryptography (QRC)-Enabled Certificate Authority, the machine implements QRC-Enabled IP and Web Protocols to provide a QRC-Enabled PKI Ecosystem.
Owner:QUSECURE INC

Onboard security communication method and system based on national secret SSL (Secure Socket Layer)

The invention discloses an airborne security communication method and system based on a national secret SSL (Secure Socket Layer), and belongs to the technical field of information security. The method comprises the following steps: deploying a national secret public key infrastructure PKI which is integrated with CA and KM systems with RA functions; respectively deploying national secret certificate management modules at the airborne communication end and the ground communication end so as to manage national secret double certificates signed and issued by a PKI (Public Key Infrastructure); the airborne communication end and the ground communication end are respectively configured as a national secret SSL client and a service end; the airborne client initiates connection, and bidirectional identity authentication and key negotiation are completed based on the national secret double certificates; and after the authentication is passed, establishing a national secret SSL encryption secure channel for communication. The system comprises corresponding modules. According to the method, a national secret algorithm and a national secret dual certificate are adopted, an autonomous, controllable, lightweight and high-security end-to-end encryption channel is constructed in an airborne communication open environment, security threats such as identity counterfeiting, data leakage and tampering are effectively solved, and the security, reliability and autonomous and controllable capability of an airborne communication system are remarkably improved.
Owner:XIAN AVIATION COMPUTING TECH RES INST OF AVIATION IND CORP OF CHINA

Securing communication with security processors using platform keys

A computer platform comprises a security processor, at least one hardware processor, and memory. The security processor stores data representing a private platform key. The private platform key is part of an asymmetric key pair, and the asymmetric key pair contains a public platform key. The memory stores a firmware image. The firmware image contains data representing a root certificate of a public key infrastructure that signs a second certificate associated with the computer platform. The second certificate contains the public platform key and binding information that binds the second certificate to the computer platform.The firmware image contains instructions that, when executed by the hardware processor(s), cause the hardware processor(s) to access data representing the second certificate and, based on the root certificate and binding information, determine whether the second certificate is valid. Furthermore, when executed by the hardware processor(s), these instructions, in response to the determination that the second certificate is valid, cause the hardware processor(s) to use the public platform key to secure communication with the security processor.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Transitioning to and from crypto-agile hybrid public key infrastructures

In a general aspect, digital certificates are generated. In some aspects, a method includes accessing a primary root certificate of a root certificate authority of a PKI system. The primary root certificate includes a first public key based on a first cryptosystem and a first signature generated with a private key that corresponds to the first public key. A secondary crypto-agile root certificate is generated. The secondary crypto-agile root certificate includes the first public key of the root certificate authority, a second public key of the root certificate authority that is based on a second cryptosystem, a second signature of the root certificate authority that is created with a second private key that corresponds to the second public key, and a third signature of the root certificate authority that is generated with the first private key. The secondary crypto-agile root certificate is propagated to subordinate entities in the PKI system.
Owner:ISARA CORP

New hybrid method for quantum resistant off-line authentication of a payment device

Method for quantum resistant off-line authentication of a payment device by means of a payment terminal, comprising firstly authentication of the payment device using standard public key cryptography authentication and a certificate chain according to the Europay Mastercard Visa (EMV) Public Key Infrastructure (PKI) model, secondly the verification of a Certification Authority (CA) signature using a CA Post Quantum Cryptography (PQC) public key, the verification of the CA signature comprising: - Signing the payment device credentials with a Certification Authority (CA) Post Quantum Cryptography (PQC) private key to obtain a CA signature, - Storing the generated CA signature on the payment device together with the corresponding CA PQC public key identifier, - Transmitting the CA PQC public key to the payment terminal, - Presenting the payment device to a payment terminal, and - Verifying the CA signature by means of the payment terminal using the CA PQC public key.
Owner:MASTERCARD INT INC

Method and apparatus for public key management using blockchain

Blockchain networks are used to improve the public key infrastructure by providing fast and secure enrollment, revocation, and renewal of digital certificates.SOLUTION: The public key may be recorded in the blockchain by the certificate authority so that a third party can quickly and easily verify that the public key has been certified by the certificate authority and that the certificate has not been revoked. The certificate authority may invoke a certificate almost instantaneously and / or may certify a new key for the same entity while at the same time revoking an old key. In some cases, the ability to revoke a certificate may be given to the owner of the public key, or in some cases to one or a group of other entities.SELECTED DRAWING: Figure 1
Owner:NCHAIN LICENSING AG

Confidential cloud computing architecture based on supervision and expansion, data interaction method, terminal and medium

The invention discloses a confidential cloud computing architecture with supervision and expansion, a data interaction method, a terminal and a medium, and relates to the field of cloud computing, and the confidential cloud computing architecture comprises a hardware layer, a platform layer, a supervision layer and an adaptation layer. The hardware layer integrates the independent trusted execution environment into a trusted root of a preset public key infrastructure; the platform layer provides an extensible confidential calculation scheduling system; the supervision layer provides a full-life-cycle supervision system; the adaptation layer provides a compatibility and trust verification mechanism. According to the method, a unified trust system is established, the user trust verification cost is reduced, and full-process supervision of data circulation, computing power use and algorithm execution is realized by constructing a supervisible confidential cloud computing architecture. In addition, the invention also provides a high-expansibility cluster solution, supports large-scale data processing and elastic capacity expansion, adapts to different scene requirements, realizes plug-and-play deployment and use by being compatible with the existing cloud computing normal form, and reduces user migration and application cost.
Owner:SHENZHEN CONFIDENTIAL COMPUTING TECH CO LTD

Cryptographically authenticated database representing a multiple-key-pair root certificate authority

In a general aspect, a cryptography system includes a multiple-key pair root certificate authority. In some aspects, a plurality of distinct cryptographic pairs of public keys and private keys of a root certificate authority are generated. A plurality of distinct self-signed root certificates of the root certificate authority are generated. The plurality of distinct self-signed root certificates are each based on and correspond to a respective one of plurality of distinct cryptographic key pairs. A cryptographically authenticated database is generated that includes the plurality of distinct self-signed root certificates and represents the root certificate authority. The cryptographically authenticated database includes validity information of each of the plurality of self-signed root certificates. The cryptographically authenticated database is distributed to entities in a public key infrastructure. The entities can use the validity information to cryptographically verify the validity or invalidity of each of the plurality of distinct self-signed root certificate.
Owner:ISARA CORP

Enhancing artificial neural networks with ephaptic coupling

Systems and methods are disclosed for enhancing artificial neural networks using a computationally modeled ephaptic coupling mechanism to improve adaptability, efficiency, and learning performance. An example system includes a virtual modulation device configured to dynamically adjust one or more ephaptic coupling hyperparameters within an ephaptically coupled artificial neural network (EC-ANN) architecture. The modulation device operates via a Bayesian optimization agent within a closed feedback loop, enabling control over intra-layer field interactions. The virtual modulation device further includes a graphical user interface (GUI) for visualizing training metrics, configuring hyperparameters, and monitoring decision-making by the Bayesian optimization agent, with options for manual override and automated control. The virtual modulation device is integrated with a public key infrastructure and one or more hardware security modules to securely sign, deploy, and manage trained EC-ANN models. Secure elements embedded in deployment devices are used to enforce cryptographic authentication, lifecycle management, and revocation of deployed models.
Owner:EPHAPSYS INC

Systems and methods for data authentication using composite keys and signatures

PendingUS20260197189A1EngineeringDatabase
A system for enhanced public key infrastructure is provided. The system includes a computer device. The computer device is programmed to receive a digital certificate including a composite signature field including a plurality of signatures. The plurality of signatures includes at least a first signature and a second signature. The computer device is also programmed to retrieve, from the digital certificate, a first key associated with the first signature from the digital certificate. The computer device is further programmed to retrieve the first signature from the composite signature field. In addition, the at least one computer device is programmed to validate the first signature using the first key.
Owner:CABLE TELEVISION LAB INC

Internet-of-things device commissioning service

Security workflows of a smart home connectivity protocol are integrated to establish device identities and ensure certification within a device commissioning service of a provider network. The service provider of the provider network can synchronize the commissioning service's implementation of the protocol, relieving smart home device vendors of this responsibility. This streamlines the software complexity for vendors during device commissioning, removing their need for external data repositories or distributed networks. Some implementations feature a managed private certificate authority service in the provider network, issuing private certificates for validated device identification. This reduces cost and complexity for vendors, enabling them to focus on top-tier smart home solutions while relying on a secure, scalable provider network service for device commissioning. This approach also diminishes the necessity for individual public key infrastructure (PKI) management, enhancing efficiency and resource allocation.
Owner:AMAZON TECH INC

Method and system for implementing a privacy preserving, face-based protected public key infrastructure

A computer-implemented method of issuing a public key certificate in a public key infrastructure is provided. The public key infrastructure comprises a user device, a trusted server comprising a public key registry, and a third-party device operated by a third party. The method includes the steps: the user device obtaining biometric data comprising a facial image of the user; the user device or the trusted server generating a privacy preserving data structure using the biometric data; the user device receiving a purpose ID from the third-party device; the user device obtaining subsequently acquired biometric data comprising the facial image of the user; the user device or the trusted server generating a public key from the privacy preserving data structure using the subsequently acquired biometric data and the purpose ID, wherein a private key corresponding to the public key can be generated from the privacy preserving data structure using the purpose ID and further subsequently acquired biometric data comprising the facial image of the user; and the trusted server obtaining a public key certificate from an issuer, the public key certificate comprising the public key and a digital signature of the issuer, and the trusted server storing the public key certificate in the public key registry.
Owner:SEVENTH SENSE ARTIFICIAL INTELLIGENCE PTE LTD +1

OTA security authentication and data transmission method and system for intelligent networked automobile

The invention provides an intelligent networked automobile OTA security authentication and data transmission method and system. The method comprises the steps that an OTA upgrading process is divided into a security authentication establishment stage and a security data transmission stage; in the security authentication establishment stage, the PKI system completes vehicle cloud two-way identity authentication and establishes a national secret SSL channel; and in the secure data transmission stage, the KMS dynamically generates an in-vehicle communication key so as to realize encrypted transmission of the upgrade package from the vehicle-end gateway to the vehicle-end ECU. Therefore, a PKI (public key infrastructure) and a KMS (key management system) are deeply integrated into an OTA business process, seamless and end-to-end security guarantee is provided for each key stage (identity authentication, cloud transmission and in-vehicle distribution) of OTA upgrading, and whole-course trusted access and secure data transmission from a cloud server to a vehicle end ECU are realized.
Owner:EAST CHINA UNIV OF SCI & TECH +1

Systems and methods for blockchain-based secure key exchange with key escrow fallback

A system described herein provides for the secure maintaining and providing of information, such as public keys used in Public Key Infrastructure (“PKI”) techniques or other techniques, using a distributed ledger (e.g., “blockchain”) system with a fallback to a key escrow system. A first device may encrypt a communication using a first key, and output the encrypted communication to a second device. The first device may attempt to record a second key, that is associated with the first key, to the blockchain system, and may determine that the second key was not recorded to the blockchain system based on the attempt. The first device may output the second key to a third device based on determining that the second key was not recorded to the blockchain system. The second device may obtain the second key from the third device, and use the second key to decrypt the encrypted communication.
Owner:VERIZON PATENT & LICENSING INC

Device administration with public key infrastructure

ActiveUS12670050B2Internet privacyEngineering
A device access management server may facilitate secure access of a target device by an accessing device. The secure remote access of the target device by the accessing device may be facilitated by a public key infrastructure (PKI) certificate issued and / or validated by the device access management server.
Owner:ARISTA NETWORKS INC