Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

83 results about "Public key infrastructure" patented technology

A public key infrastructure (PKI) is a set of roles, policies, hardware, software and procedures needed to create, manage, distribute, use, store and revoke digital certificates and manage public-key encryption. The purpose of a PKI is to facilitate the secure electronic transfer of information for a range of network activities such as e-commerce, internet banking and confidential email. It is required for activities where simple passwords are an inadequate authentication method and more rigorous proof is required to confirm the identity of the parties involved in the communication and to validate the information being transferred.

Systems and methods for implementing a service identity platform with cloud-based Public Key Infrastructure (PKI)

Systems and methods for implementing a service identity platform with cloud-based Public Key Infrastructure (PKI) include providing security as a service via a cloud-based system for a plurality of tenants, wherein the cloud-based system includes a plurality of components communicatively coupled and adapted to communicate with one another based on mutual Transport Layer Security (mTLS) authentication; responsive to a new component requiring deployment within the cloud-based system, performing an enrollment process for the new component; and subsequent to the enrollment process, utilizing the new component within the cloud-based system for providing security as a service.
Owner:ZSCALER INC

Safety communication method and device for upper computer and ECU, storage medium and program product

The invention provides a secure communication method and device for an upper computer and an ECU (Electronic Control Unit), a storage medium and a program product, which are respectively applied to an upper computer end and an ECU end, and the method comprises the following steps: the upper computer obtains an encryption public key of the ECU and a decryption private key of the upper computer, generates a session key for data encryption and decryption, and sends the session key to the ECU; and the session key is subjected to double encryption by sequentially using an encryption public key of the ECU and a decryption private key of the ECU, and a communication ciphertext is generated and sent to the ECU end. And after receiving the communication ciphertext, the ECU end performs dual decryption by using the encryption public key of the upper computer and the decryption private key of the ECU end in sequence, so that the session key is recovered. And after the key negotiation is completed, the two parties encrypt and decrypt communication data through a symmetric encryption mode based on the session key. According to the invention, a hybrid encryption communication mechanism taking the public key infrastructure as the root of trust is constructed, confidentiality and integrity protection of communication data is realized, and the authentication capability of the identity of the communication entity is remarkably enhanced.
Owner:SHANGHAI GEOMETRICAL PERCEPTION & LEARNING CO LTD

Method and system for implementing a privacy preserving, face-based protected public key infrastructure

A computer-implemented method of registering a user identifier in a public key infrastructure comprising a trusted device and a server is provided. The method includes the steps: receiving the user identifier as an input to the trusted device; obtaining a hash value of the user identifier; the trusted device obtaining biometric data comprising a facial image of the user; generating a public key and a privacy preserving data structure using the biometric data, encrypting the user identifier using the public key, and storing the encrypted user identifier as metadata in the privacy preserving data structure, wherein a private key for decrypting the encrypted user identifier can be generated from the privacy preserving data structure using subsequently acquired biometric data comprising the facial image of the user; generating a device token corresponding to the trusted device and obtaining a hash value of the device token, the server storing the privacy preserving data structure uniquely indexed by the hash value of the device token while using the hash value of the user identifier as a primary key, and the trusted device storing the device token.
Owner:SEVENTH SENSE ARTIFICIAL INTELLIGENCE PTE LTD

Hash-based digital signatures for hierarchical internet public key infrastructure

Techniques for signing internet data are disclosed. The techniques include accessing a plurality of internet data records. The techniques also include generating, using at least one electronic processor, leaf nodes from the plurality of internet data records, and constructing a recursive hash tree from the plurality of leaf nodes. The techniques also include deriving information sufficient to validate the root node, and publishing, in an internet public key infrastructure (PKI) as a synthesized public key, the information sufficient to validate the root node. The techniques also include providing, through the internet and as a signature on at least one of the plurality of internet data records, validation data including sibling path data from the recursive hash tree, such that an internet client validates the at least one of the internet data records using at least the validation data and the synthesized public key.
Owner:VERISIGN INC

Cross-domain authentication method and device, electronic equipment and storage medium

The invention relates to the technical field of block chains, and provides a cross-domain authentication method and device, electronic equipment and a storage medium, and the method comprises the steps: receiving an access credential sent by a vehicle when the vehicle is in a coverage range of a road side unit; the access credential comprises a hash value of the identity credential; based on the hash value in the access credential, querying the distributed account book recording the hash value of the identity credential to obtain a query result; and verifying the authentication validity of the vehicle based on the query result. According to the method, multiple road side unit nodes form an alliance chain and jointly maintain a distributed account book of an identity certificate hash value, a decentralized unified trust foundation is constructed, and trusted transmission and verification of vehicle identities are achieved; by using the access credential only comprising the hash value, the storage overhead and the authentication delay on the chain are remarkably reduced, the single-point fault problem of the traditional public key infrastructure is avoided, the long-term identity information of the vehicle is effectively protected by means of the unidirectivity of the hash function, and privacy leakage is prevented.
Owner:INSPUR TIANYUAN COMM INFORMATION SYST CO LTD

Power fault diagnosis method and system based on large model retrieval enhancement

The invention relates to a power fault diagnosis method and system based on large model retrieval enhancement. The method comprises the following steps: firstly, initializing a federated network, and locally vectorizing multi-modal heterogeneous power data at each node to generate a private vector index; performing federated collaborative retrieval by combining the fault diagnosis request, the private vector index and the public key infrastructure to obtain a globally sorted knowledge fragment list; and finally, constructing a retrieval enhancement prompt according to the knowledge fragment list and the diagnosis request, and generating a fault diagnosis conclusion text by utilizing large language model reasoning. By adopting the method, dispersed multi-source knowledge can be effectively fused on the premise of ensuring the data privacy security of each node, so that the accuracy and reliability of fault diagnosis are improved.
Owner:SHAANXI HUADIAN NEW ENERGY POWER GENERATION CO LTD

System for hardware-based compliance with legal regulations in blockchain smart contracts

A system for autonomous compliance with legal regulations in smart contracts; the system includes: a regulatory data collection unit comprising a network interface controller physically connected to an external communications port, a hardware-based public key infrastructure circuit configured to validate digital certificates of regulatory servers, and a direct memory access controller configured to transfer authenticated regulatory update packets from the network interface controller to a volatile buffer memory without processor intervention; a Compliance Code Conversion Unit with a hardware lexicon scanner implemented as a finite state machine and embedded in reconfigurable FPGA logic blocks, a microcontroller executing a hardware-based lexical analysis pipeline stored in firmware registers, and a translation cache memory configured to temporarily store tokenized compliance rules before writing them to a non-volatile instruction memory; a policy evaluation and enforcement unit comprising a transaction verification processor connected to a secure enclave memory, a hardware comparator circuit configured to compare transaction parameters with compliance thresholds stored in the secure enclave memory, and a logic gate circuit configured to generate execution gate signals that selectively allow, block, or modify smart contract execution signals transmitted to a blockchain execution processor; and an audit logging unit with a cryptographic hashing circuit configured to generate block hashes of enforcement records, a timestamp oscillator configured to generate temporal signatures of compliance enforcement actions, and a Merkle tree generation circuit configured to create tamper-proof hierarchical hash structures, with the enforcement records being passed to a decentralized storage interface for anchoring in the chain or distributed ledger.
Owner:KEMPAIAH MADHURA GAYATHRI BENGALURU +3

Systems and methods for data authentication using composite keys and signatures

A system for enhanced public key infrastructure is provided. The system includes a computer device. The computer device is programmed to receive a digital certificate including a composite signature field including a plurality of signatures. The plurality of signatures includes at least a first signature and a second signature. The computer device is also programmed to retrieve, from the digital certificate, a first key associated with the first signature from the digital certificate. The computer device is further programmed to retrieve the first signature from the composite signature field. In addition, the at least one computer device is programmed to validate the first signature using the first key.
Owner:CABLE TELEVISION LAB INC

Client-Rooted Decryption Public Key Infrastructure (PKI) for Secure Cloud-Based Inspection of Encrypted Traffic

PendingUS20260005873A1User identity/authority verificationDigital data authenticationIntermediate certificate authoritiesInternet privacy
Techniques for implementing a client-rooted decryption Public Key Infrastructure (PKI) to securely inspect encrypted traffic in cloud-based proxy environments are disclosed. A proxy node generates an intermediate Certificate Authority (CA) certificate signing request (CSR) and sends it to a client device equipped with a locally-managed root CA. The client device cross-signs the CSR, creating a client-specific intermediate CA certificate, which it returns to the proxy node. This client-specific intermediate CA certificate is scoped uniquely to the individual client device, significantly reducing the potential blast radius in case of CA key compromise. The proxy node uses the client-specific CA certificate to dynamically generate short-lived, scoped decryption certificates for inspecting encrypted traffic. This architecture provides client-level control of trust boundaries, enhanced traceability, reduced complexity, and improved scalability of encrypted traffic inspection, minimizing the operational risks associated with conventional centralized certificate management.
Owner:ZSCALER INC

Systems and methods for managing public key infrastructure certificates for components of a network

A device may determine that a network function of a network has been instantiated to facilitate communication via the network. The device may request a certificate authority to provide a certificate for the network function. The device may receive, from the certificate authority, the certificate. The device may generate a certificate profile to enable other network functions of the network to authenticate communications with the network function, wherein the certificate profile identifies: the certificate and a certification protocol. The device may provide, to the network function, the certificate profile to cause the network function to use the certificate to communicate with the other network functions.
Owner:VERIZON PATENT & LICENSING INC

Chain of authentication using public key infrastructure

A method for sequential authentication based on chain of authentication using public key infrastructure (PKI) is provided. The method includes generating, by a user, a first private key and a first public key corresponding to each other; generating, by an nth service provider, an nth private key and an nth public key corresponding to each other; transmitting, from the user to the nth service provider, a level n key; verifying, by the nth service provider, the level n key; generating, by the nth service provider, a level (n+1) key by concatenating the level n key and the nth public key signed with the nth private key; and transmitting, by the nth service provider, the level (n+1) key to the user, where n is a natural number, and when n=1, the level 1 key is the first public key signed with the first private key.
Owner:CHOI OK

System for automated, middleware-based intelligent data mapping between heterogeneous ERP systems and cloud platforms

A system for automated, middleware-based intelligent data mapping between heterogeneous enterprise resource planning (ERP) systems and cloud platforms, the system comprising the following: an ERP data acquisition unit with a variety of physical communication ports, selected from Ethernet and serial ports, a network interface controller physically connected to the communication ports, and a DMA (Direct Memory Access) controller configured to transfer raw ERP data packets into a volatile buffer memory without processor intervention; a Semantic Mapping Unit consisting of a Field Programmable Gate Array (FPGA) configured as a lexical analyzer to analyze ERP schema definitions and extract entity descriptors, and a Tensor Processing Unit (TPU) configured to evaluate the semantic similarity between heterogeneous schema elements based on ontological models stored in a non-volatile memory repository; a transformation logic unit comprising a parallelized vector processor configured to perform matrix-based transformations, field normalizations and structural reorganization of ERP data into a harmonized format, and a rule application circuit configured to perform compliance-based anonymization, unit conversions and value scaling prior to cloud distribution; a cloud interface unit comprising a protocol adapter bank with encoders, translators, and message queue writers, wherein the cloud interface unit is coupled with a cryptographic controller configured with a hardware public key infrastructure (PKI) circuit to generate digital signatures and verify integrity codes for all outgoing payloads; and a Feedback Learning Control Unit implemented in the firmware, wherein the engine is electrically coupled to the Semantic Mapping Unit and the Transformation Logic Unit and is configured to monitor error logs, success rates and acknowledgment codes received from the cloud platforms and to update the semantic and transformation rules stored in the non-volatile memory repository accordingly.
Owner:RUNGTA RAJEEV VINODKUMAR

Public key infrastructure based session authentication

Techniques are disclosed for public key infrastructure (PKI) based session authentication. An example network device includes one or more processors and memory coupled to the one or more processors. The memory stores instructions that, upon execution, cause one or more processors to: receive, from a source client device, a packet including a header for routing the packet to a destination client device specified within the header and metadata distinct from the header, the metadata specifying public key infrastructure (PKI) information and identity context information identifying a user or device participating in a session between the source client device and the destination client device; verify, based on the PKI information within the metadata, the metadata; and in response to verifying the metadata, apply, based on the identity context information, one or more policy rules for the session associated with the packet.
Owner:JUNIPER NETWORKS INC

A method for implementing an identification-based authentication mechanism

The application belongs to the technical field of information security, and discloses a kind of based on identification authentication mechanism implementation method, including: after multi-dimensional identification server receives device authentication request, parsing device identification and calculating device public key, then interact with authentication center, carry out identity verification, after authentication center receives authentication request, the public key of device is calculated and the signature in request is verified using the public key, pass the verification, and the authorization code is generated and returned to the authentication server, and the server further forwards it to the device, and the returned signature information is verified by the device to ensure the validity of the authorization code.The application not only simplifies the management process of traditional public key infrastructure, but also improves the efficiency of the authentication process, each device only needs to generate a public-private key pair through its unique identification (EID), avoiding the complexity in traditional key distribution and certificate management, making device authentication more flexible and easy to expand.
Owner:NANJING UNIV OF POSTS & TELECOMM +1

A tracking tag terminal based on ZETA technology

This invention discloses a tracking tag terminal based on ZETA technology, belonging to the field of ZETA technology. It includes a tag initialization module for initializing the tag terminal and configuring a multi-dimensional sensor and communication module; a data acquisition module for real-time acquisition of multi-dimensional data at preset time intervals; a data fusion module for fusing the multi-dimensional data; an authentication module for assigning a unique identifier to each tag and authenticating the tag's identity through a public key infrastructure-based authentication mechanism; a positioning module for accurately locating the tag using ultra-wideband technology, combining signal arrival time and time difference algorithms with the cooperation of multiple base stations to calculate the tag's precise location; and a data transmission module for uploading the multi-dimensional data to a base station or cloud platform via the ZETA protocol. Through ultra-wideband technology and the ZETA protocol, it provides high-precision positioning and real-time tracking capabilities while achieving low-power, high-efficiency data transmission.
Owner:CHINA SOUTHERN POWER GRID SUPPLY CHAIN TECH (GUANGDONG) CO LTD

Asynchronous distributed key generation method and device

PendingCN120956410AKey distribution for secure communicationDistributed key generationCorrection algorithm
The invention discloses an asynchronous distributed key generation method and device. The method comprises a sharing stage, a negotiation stage, a random extraction stage and a key derivation stage which are executed in sequence. In the sharing stage, an asynchronous complete secret sharing protocol is adopted, and secret share distribution is achieved through the steps of sending, confirmation, preparation and amplification; in the negotiation stage, consensus screening is carried out on terminated secret sharing instances based on a multi-valued verification Byzantine negotiation protocol; in the random extraction stage, a negotiation result is operated by using an ultra-reversible matrix to generate an intermediate parameter; and in the key derivation stage, a key related result is finally output through an online error correction algorithm and Lagrange interpolation calculation. The method gets rid of dependence on public key infrastructure and credible setting, relieves the contradiction between throughput and delay, improves the security, reliability and anti-review performance of the system, and is suitable for a large-scale distributed system or a resource limited environment.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Vehicle safety access system and method based on Lifi technology

The invention discloses a vehicle safety access system and method based on Lifi technology, and belongs to the technical field of automobile electronic architecture. The system comprises a PKI public key infrastructure, a vehicle management platform, a Lifi host, a Lifi server, a communication management system, a TBOX, a central computing gateway and a Lifi communicator, and the vehicle management platform is connected with the PKI public key infrastructure, the Lifi server and the communication management system; the Lifi server is connected with the Lifi host computer; and the communication management system is connected with the Lifi communicator through the TBOX and the central computing gateway in sequence. According to the invention, secure communication between the vehicle and the external equipment based on the Lifi technology is realized.
Owner:CHERY COMMERCIAL VEHICLE (SHANDONG) TECHNOLOGY CO LTD

A computer remote control method and system

The application discloses a kind of computer remote control method and system, belong to computer remote control technical field, its method specifically includes: using public key infrastructure to control equipment and computer are authenticated;Control equipment sends connection request to computer through Internet of Things platform, computer verifies the digital signature of control equipment, and returns confirmation information, establishes secure communication channel;Control equipment generates and sends remote control instruction, encrypts remote control instruction, scores the priority of communication channel by time delay, and carries out real-time update, and the highest priority communication channel is selected to transmit;Computer receives remote control instruction sent by control equipment, decrypts and executes corresponding instruction, and records the operation log of each remote control;Through the encryption operation of remote control instruction and the selection of optimal communication channel, the security and efficiency of command transmission are greatly improved.
Owner:NANTONG INST OF TECH

Certificate query method and device based on edge node, equipment, medium and product

The invention relates to the field of block chains, and provides a certificate query method and device based on edge nodes, equipment, a medium and a product. The method comprises the following steps: receiving registration transaction information initiated by an authoritative certification authority; under the condition that the pre-verification of the registration transaction information is passed, sending the root certificate to the distributed public key infrastructure block chain, and receiving a registration completion response fed back by the distributed public key infrastructure block chain; under the condition that the registration completion response passes verification, after the registration completion response is fed back to the authority authentication mechanism, the authority authentication mechanism issues an entity certificate and feeds the entity certificate back to the network element; receiving a certificate verification request sent by the network element; and carrying out certificate query according to the certificate verification request, and determining a certificate query result. According to the certificate query method based on the edge node, a bridge is built through the edge node, and during certificate query, the network element securely accesses the distributed public key infrastructure through the edge node, so that the query efficiency is improved.
Owner:CHINA MOBILE COMM LTD RES INST +1

Consideration is given to a method of authenticating an access layer based on a public key infrastructure in a handover in a next generation wireless communication system

This disclosure relates to 5G or 6G communication systems for supporting higher data transmission rates than 4G communication systems such as LTE. In a wireless communication system according to an embodiment of the invention, a method for operating a serving base station for mutual authentication in the access layer (AS) portion during handover includes the following steps: receiving a measurement report from a terminal; determining, based on the measurement report, whether the terminal meets handover conditions; if the terminal meets the handover conditions, determining whether the target base station to which the terminal will connect during handover and the serving base station belong to the same authentication area (AA); and sending a handover command to the terminal, the handover command being configured differently depending on whether the target base station and the serving base station belong to the same AA.
Owner:SAMSUNG ELECTRONICS CO LTD

User authentication method, system, medium and equipment

The invention provides a user authentication method and system, a medium and equipment, and the method comprises the steps: a service portal and a private network authentication agent pre-install a root certificate based on a standard public key infrastructure, and establish a safety message channel through the mutual verification of digital certificates; a user sends an authentication request to a service portal through a client, the service portal forwards authentication information to an authentication agent through a secure channel, and the authentication agent submits the authentication information to a private network LDAP server after protocol conversion; the LDAP server verifies the identity and returns a result, the result is transmitted back to the service portal through the authentication agent and the secure channel, and the service portal generates a short-term token or a black hole cache and feeds back the short-term token or the black hole cache to the client; and the client accesses the service site by the token. According to the invention, the deployment process is simplified, the existing network architecture and security rules of an enterprise are prevented from being changed, the pressure of a private network LDAP server is reduced, and the security, efficiency and system stability of cross-domain authentication are improved.
Owner:CHINA TOWER CO LTD

Computer-readable medium relating to trust relationships between a first party and a second party, search method, computer program for an electronic device, electronic device, and first vehicle, in particular utility vehicle

A computer-readable medium includes a mesh with a public key infrastructure relating to trust relationships between a first party and a second party. The mesh includes: a first chain representing the first party and including a first root element, mesh element and element; a second chain representing the second party and including a second root element and element. The first element includes a signature by the first party mesh certification authority, the mesh public key, a predecessor sibling hash of a preceding element in the first chain, and a neighbor link to a second linked element of the second chain; the second element includes a neighbor link to a first linked element of the first chain. The second chain includes a self-revocation element, a successor of the second linked element, and a self-revocation property and / or the first chain includes a revocation element, a first element successor, and a revocation property.
Owner:ZF CV SYST GLOBAL GMBH

Serial number generation for stateless cloud certificate authority

A system associated with a public key infrastructure certificate framework in a cloud computing environment may include a certificate authority data store that contains information about a plurality of certificate authority instances (with each certificate authority instance being associated with an instance index and an instance deployment time). A certificate authority server, coupled to the certificate authority data store, may retrieve an instance index and instance deployment time from the certificate authority data store. The certificate authority server may then determine a current certificate identifier generation timestamp. A unique certificate identifier for a public key certificate is generated by the certificate authority server based on a deterministic creation algorithm, the instance index, the instance deployment time, and the certificate identifier generation timestamp. The public key certificate can then be issued using the unique certificate identifier.
Owner:SAP SE

Web application dynamic key encryption method based on SM3 and SM4

The invention relates to a Web application dynamic secret key encryption method based on SM3 and SM4, and relates to the technical field of data security. According to the method, a dynamic symmetric secret key is cooperatively generated at a front end and a rear end, a secret key seed is generated by utilizing an SM3 Hash algorithm, and sensitive data is encrypted and transmitted by combining an SM4 symmetric encryption algorithm, so that the secret key is not hard-coded and not transmitted; the session key is dynamically changed each time, the algorithm support can be completely localized, the encryption and decryption process is simple and efficient, a complicated certificate system or public key infrastructure is not needed, the front and rear ends only need to synchronize the key generation rule, and the method is suitable for an offline or weak network environment, does not depend on real-time network verification, and is easy to implement. The method can be used for offline or weak network environments such as an intranet and a government affair private network, and can effectively prevent historical data from being replayed by introducing factors such as dates and timestamps, so that sensitive data is effectively prevented from being stolen or tampered in the transmission process, and the overall security protection capability of Web application is improved.
Owner:BEIJING CATHAY INTERNET INFORMATION TECH CO LTD +1

Symmetric encryption for private smart contracts among multiple parties in a private peer-to-peer network

Features for providing a secure method of symmetric encryption for private smart contacts among multiple parties in a private peer-to-peer network. The features include a master key representing a unique blockchain ledger. The master key may be shared among multiple participants in a private peer-to-peer network. Sharing of the master key may include communicating the master key in an encrypted message (e.g., email) using public key infrastructure (PKI). In some implementations, more complex distribution features may be includes such as quantum entanglement. The features support instantiation of a smart contract using a specific master key. The request may be submitted as an entry to the ledger with appropriate metadata and / or payload information for identifying and processing the request.
Owner:EXPERIAN INFORMATION SOLUTIONS INC

Control method and system for remote power-on and power-off of new energy automobile

The invention discloses a control method and system for remote power-on and power-off of a new energy vehicle, and the method comprises the steps: carrying out the bidirectional identity authentication of a cloud server and a vehicle-mounted TBOX based on a certificate authentication mechanism of a public key infrastructure (PKI), and building MQTT long connection and subscription Topic between the cloud server and the vehicle-mounted TBOX; when a user initiates a remote power-on and power-off request, a cloud server attaches a timestamp and a random number to each remote power-on and power-off instruction, and end-to-end encryption is performed by using TLS 1.3 and AES-256 to ensure instruction transmission security; when the vehicle-mounted TBOX receives the remote power-on and power-off instruction, the instruction is decrypted and verified, if verification fails, the remote power-on and power-off request is refused, and a log is recorded; if the verification is successful, a power-on and power-off instruction is sent to the VCU, and then the VCU executes power-on and power-off operation. According to the invention, the safety and intelligence of vehicle remote control can be improved, and the use safety of a user is improved.
Owner:ANHUI JIANGHUAI AUTOMOBILE GRP CORP LTD

A Ship Virtual Test Platform Identity Authentication System

This invention proposes an identity authentication system for a ship virtual testing platform. The system comprises four parts: an application layer, a business layer, a smart contract layer, and a data storage layer. The system improves upon traditional public key infrastructure (PKI) technology by leveraging the security, irreversibility, immutability, and transparency of blockchain. It timestamps the blocks storing digital certificates, creating a continuous and interconnected honest data record structure, effectively enhancing the transparency of the PKI system and strengthening the credibility of identity authentication.
Owner:HARBIN ENG UNIV

Set of Servers for "Machine-to-Machine" Communications Using Public Key Infrastructure

A set of servers can support secure and efficient ā€œMachine to Machineā€ communications using an application interface and a module controller. The set of servers can record data for a plurality of modules in a shared module database. The set of servers can (i) access the Internet to communicate with a module using a module identity, (i) receive server instructions, and (iii) send module instructions. Data can be encrypted and decrypted using a set of cryptographic algorithms and a set of cryptographic parameters. The set of servers can (i) receive a module public key with a module identity, (ii) authenticate the module public key, and (iii) receive a subsequent series of module public keys derived by the module with a module identity. The application interface can use a first server private key and the module controller can use a second server private key.
Owner:NETWORK 1 TECH

Construction design data management method and system

The invention discloses a construction design data management method and system, and relates to the technical field of data management, and the method comprises the steps: obtaining construction design data, employing a standardization conversion engine to unify the format and verify the integrity, and outputting the standardization design data; performing access control on the standardized design data by adopting multi-level authority management, and outputting an operation auditing record in combination with a digital signature method of Hash calculation and public key infrastructure; based on the change data in the operation auditing record, utilizing a dynamic data flow updating mechanism to adjust an entity relationship in the construction knowledge graph in real time, and generating a digital twinborn synchronization instruction; and performing security evidence storage on the operation audit record and the digital twinborn synchronization instruction through a quantum encryption protocol, performing data consistency verification in combination with multi-dimensional distributed AI cooperative computing, and outputting an audit closed-loop management report. According to the method, dual verification of dominant rule check and implicit semantic analysis is realized through combination of the dynamic mapping table and deterministic logic.
Owner:JIANGSU SMART WORKSHOP TECHNOLOGY RESEARCH INSTITUTE CO LTD