Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

147 results about "Rekeying" patented technology

Rekeying a lock is replacing the old lock pins with new lock pins.

Data encryption method and device, equipment and medium

The invention relates to the technical field of data security, can be applied to business scenes of financial science and technology, medical health and the like, and discloses a data encryption method, device, equipment and medium, comprising: acquiring a real-time state vector representing a running state of a chaotic neural network processing unit, monitoring a chaotic characteristic of the real-time state vector to generate a chaotic intensity index, and comparing the chaos intensity index with a preset chaos threshold value, generating an original key based on the real-time state vector when a key updating condition is met, dynamically adjusting a weight matrix of the chaos neural network processing unit according to the chaos intensity index, and performing cryptographic processing on the original key to generate a final key. And performing encryption processing on the target data by using the final key to generate target encrypted data. According to the method, the internal state of the chaotic neural network is used as a dynamic key generation basis, so that the dependence on an external entropy source and fixed parameters is eliminated, and the security and real-time performance of a data encryption process are improved.
Owner:PING AN TECH (SHENZHEN) CO LTD

Secret communication system of unmanned aerial vehicle

The invention discloses a secret communication system of an unmanned aerial vehicle, which relates to the technical field of secret communication of the unmanned aerial vehicle and comprises a secret key generation and distributed storage unit, a dynamic secret key updating unit, a secret key destruction and tracing unit, a multi-band sensing and interference identification unit and a combined regulation and control unit. A dynamic key is generated through a chaos algorithm, and the security of the key is ensured in combination with block chain fragmentation storage and GPS binding encryption; updating the key according to the risk level, and transmitting the fragments by using an anti-quantum channel; after the communication is finished, the secret key fragments are invalidated, and anomaly detection and traceability are realized; scanning a multi-band frequency spectrum in real time, identifying an interference type and optimizing the model; and according to the interference intensity and the energy efficiency demand, dynamically switching the frequency bands, adjusting the power and enhancing the anti-interception capability. The problems that an existing unmanned aerial vehicle communication system is insufficient in safety, weak in anti-interference capacity, incomplete in key management mechanism and the like are effectively solved, and the safety, the anti-interference performance and the energy efficiency performance of unmanned aerial vehicle communication are remarkably improved.
Owner:CHINA TOWER CO LTD

Intelligent data security encryption method in edge computing environment

The invention relates to the technical field of data encryption, and discloses an intelligent data security encryption method in an edge computing environment. The method comprises the following steps: acquiring an original data stream, decomposing through discrete wavelet transform, and adding a random disturbance sequence; constructing a dynamic encryption strategy network, generating a dynamic key matrix and distributing an access control strategy; according to the data security level and the node load, adaptively selecting an encryption algorithm and generating an encrypted metadata label; verifying data integrity by using a decentralized consensus mechanism and a zero-knowledge proof algorithm; a key is updated through a key updating model based on a time decay function, and the key is stored in combination with a block chain technology. According to the method, the problems of data encryption, access control, key management and the like in the edge computing environment are solved, the security and integrity of the data are guaranteed, and the security and reliability of data processing in the edge computing environment are improved.
Owner:冯梓原

Charging user portrait data security management system and method

The invention relates to the technical field of data security management, in particular to a charging user portrait data security management system and method, and the system comprises a channel state sensing module, a key updating control module, a behavior sequence evaluation module, a data exception recognition module and a key scheduling encryption module. In the invention, active perception of communication quality change is realized, agility and protection of data transmission are enhanced, and signal attenuation and equipment number labels are extracted for secret key updating judgment by comparing communication link quality with a user positioning data sequence, capturing a hopping trend of signal intensity and a noise ratio and mapping an abnormal fluctuation segment to an equipment identifier. The pertinence and efficiency of an encryption strategy are improved, a portrait feature deviation behavior is recognized by combining a user charging behavior and a frequency sequence, a specific user number is positioned, the anomaly recognition precision is improved, a path encryption strategy is dynamically generated according to behavior deviation and access path information, and a flexible and efficient data protection system is constructed.
Owner:STATE GRID HUBEI MARKETING SERVICE CENT (MEASUREMENT CENT)

Secure communication method and system based on QRNG and Beidou positioning terminal

The invention provides a secure communication method and system based on a QRNG and a Beidou positioning terminal. A sending end and a receiving end of communication preset a pre-shared initial key, and a space-time reference parameter group is obtained through Beidou positioning; a secret key packaging secret key is generated by using a national secret SM4 algorithm; monitoring time-space parameter deviation in a communication process in real time, and triggering a key updating protocol when the time-space parameter deviation exceeds a threshold value; and after the receiving end verifies the Hash verification value, decrypting to obtain the primary encryption key, and restoring the plaintext data. According to the system, the generated true random number sequence is used as an encryption key, so that the unpredictability and randomness of the key are fundamentally enhanced, and quantum computing attack and man-in-the-middle attack are effectively resisted. The use of the pre-shared key mechanism and the key packaging key improves the response speed and efficiency of the communication system. And meanwhile, the position parameter and the timestamp are deeply fused to the key generation process, so that the spatio-temporal information is more difficult to counterfeit, and the defense capability of the system is further improved.
Owner:YIXUNTONG TECH CO LTD

Security operation and maintenance management method for power production management system based on national secret algorithm

The invention discloses an electric power production management system safety operation and maintenance management method based on a national secret algorithm. According to the method, the key and the real-time running state of the equipment are deeply bound through a dynamic key derivation mechanism, so that the key is dynamically adjusted along with parameters such as the load rate, the temperature and the bit error rate, state change, namely key updating, is realized, and the anti-cracking capability of the key is greatly improved; the SM2, SM3, SM4 and other national cryptographic standards are adopted from root key generation, identity authentication, data transmission encryption and log tampering prevention of the full-link application of the national cryptographic algorithm system, it is ensured that the encryption strength meets the national password management requirement, and the overall encryption protection level of the system is improved. Closed-loop protection is formed through deep linkage among multiple steps, fragmentation of a safety mechanism is avoided, meanwhile, the traceability and the fault recovery efficiency of system operation are further improved through the whole-process encryption archiving and emergency response rapid recovery process of audit logs, and transmission and storage safety of power production core data is guaranteed.
Owner:GUIZHOU WUJIANG HYDROPOWER DEV

Rekeying end-to-end efficient encryption with security chaining

Rekeying an Information Handling System (IHS) network End-to-End Efficient Encryption (E2EEE) with security chaining includes locking an encrypted data volume, preventing reading of, and writing to, the encrypted data volume by applications. A data source IHS may request a new key from a key management system and write new metadata in a trailer of the encrypted data block using a different key slot than a currently used and active metadata key slot, wherein the different key slot is updated with the with the new key. The data source IHS then sends an out-of-data signal to change the use key slot from the currently used key slot to the different key slot. Thereafter, the data source IHS unlocks the encrypted data volume, enabling writing and / or reading user data by the data source IHS and encryption and decryption in all IHS E2EEE data connection segment interfaces.
Owner:DELL PROD LP

Rekeyable lock cylinder

A rekeyable lock cylinder with a cylinder body, an inner sleeve, and a plug assembly is provided. The plug assembly includes a plurality of key followers and a corresponding plurality of first racks and second racks disposed in carriers. The first racks correspond to operation of a user key and the second racks correspond to operation of a master key. As such, the lock cylinder is usable in a user / master key system. Disengaging either of the first or second racks from the key followers allows rekeying of the lock cylinder for the user key or the master key.
Owner:ASSA ABLOY AMERICAS RESIDENTIAL INC

Dynamic encryption and security level adaptive adjustment method for flight data

The invention discloses a dynamic encryption and security level adaptive adjustment method for flight data, particularly relates to the field of data security, and is used for solving the security and integrity problems of the flight data in an unstable network environment. According to the method, the mass of random seeds is quantified in real time in the mixing process, incremental seeds are added once the dispersion is reduced, and weak random source transmission is blocked; the historical track continuously provides threshold correction, so that the secret key updating rhythm and the link fluctuation are kept at the same frequency; a new secret key with sufficient safety margin is output by depending on a structured spin mixing and real-time source supplementing mechanism, and a secret key material keeps double characteristics of high discretization and high independence, so that randomness attenuation caused by packet missing, retransmission or node out-of-step is avoided; meanwhile, security level adjustment logic is deeply coupled with a key generation process, so that adaptive balance of encryption strength and operation load is realized, and the flight data is enabled to maintain collaborative excellent performance of confidentiality, integrity and real-time performance in a complex environment.
Owner:CHANGZHOU JIANGNAN GENERAL AVIATION CO LTD

Double-dynamic key encryption circuit and method capable of dynamically changing after dynamic key interpretation

The invention belongs to the technical field of integrated circuit hardware security, and discloses a double-dynamic key encryption circuit and method for dynamically changing dynamic keys after interpretation, and the circuit comprises an external dynamic key module, an internal dynamic key module and a circuit original logic module. And the external dynamic key module generates a dynamic key signal through the linear feedback shift register unit, and the internal dynamic key module generates a D / T selection signal according to a parity check result of the dynamic key signal to dynamically change the type of a trigger in the state machine. The state machine is divided into a group A and a group B, key updating is triggered at an entrance state through a state detection unit, and it is ensured that the key is still dynamically changed after being interpreted. Through a double-dynamic key mechanism and state machine jump confusion, probe detection and bypass attacks are effectively resisted, and the safety of the circuit is remarkably improved. And when the initial key is wrong, circuit jump is abnormal, so that IP protection is realized. The method has the advantages of high attack resistance, dynamic key change, high security and the like.
Owner:ZHEJIANG UNIV

Secure data transmission over constrained one-way channel

The sender stores a pair of sender's public and private keys and a public key of the receiver, and carries out the steps of:A—generating a master key, that is a secret shared with the receiver, by key derivation from a current root key and using the sender's private key and the receiver's public key, and updating the root key with the generated master key;B—generating, by key derivation from said master key, a chain of message keys for securing messages to communicate to the receiver;C—generating a next pair of sender's public and private keys, sending the next sender's public key to the receiver and executing again the steps A andB using the next sender's private key and the same receiver's public key;wherein the current root key used in the step A isat a first iteration of step A, an initial root key prestored in the sender, said initial root key being a secret shared with the receiver, andat each subsequent iteration of the step A, the root key that has been updated at the preceding iteration of step A.
Owner:NAGRAVISION SRL

A new physical layer encryption and authentication cooperation security method

The application provides a new physical layer encryption and authentication cooperation security method, solves the problem that the ability of encryption technology to resist differential attack depends on the rapid update of a key; at a sending end, a hash function is used to generate an encryption sequence by using the key and the digital features of information, and the information is subjected to the action of the encryption sequence; the encryption sequence will greatly change when the key is unchanged and the information changes, and the digital features of the information before and after encryption remain unchanged; at a receiving end, the received information can be used to regenerate a decryption sequence by using the digital features of the information and the key before decryption, and the decryption sequence is used for decryption; the requirement of key update is greatly reduced, and the rate requirement and the cost of key generation and distribution are reduced. The generation of the digital label required by the authentication does not depend on the ciphertext itself or the plaintext itself, but uses the same signal digital features, the key and the hash function as when the encryption sequence is generated, and better cooperation is achieved, that is, the cooperation realizes the physical layer security, prevents eavesdropping and attack.
Owner:ZHENGZHOU UNIV

Key update using relationship between keys for extended reality privacy

Systems and methods are provided herein for providing privacy while allowing interactions with virtual representations of sensitive objects. This may be accomplished by an extended reality (XR) system receiving information associated with a real-world environment of a user. The XR system may transmit the received information to one or more devices (e.g., server, XR device, etc.) for processing. Before transmitting the received information, the XR system can use the received information to identify and categorize objects in the real-world environment to identify sensitive objects. To protect the privacy of the sensitive objects, the XR system transforms features of the sensitive objects using one or more transform keys prior to transmitting the information to the one or more devices. The XR system may also update the transform keys after a first time period to further protect the privacy of the sensitive objects.
Owner:ADEIA GUIDES INC

Computer network data storage encryption method and system based on artificial intelligence

The invention discloses a computer network data storage encryption method and system based on artificial intelligence, and relates to the technical field of computer data storage, the system comprises an acquisition component, a processing component, a calculation component and an encryption management component, the calculation component comprises a data risk assessment unit, a key update adjustment unit and a dynamic key encryption unit, the security of the storage system is improved through the three core units, the data risk assessment unit integrates multi-dimensional parameters and fuses hardware features, AI anomaly confidence and the like, the blank of hidden anomaly perception is filled up, the security of the storage system is improved, the security of the storage system is improved, the security of the storage system is improved, and the security of the storage system is improved. The key updating and adjusting unit is coupled with physical space abnormity, authentication strength and performance risks, a self-adaptive period is achieved to balance safety and efficiency, the dynamic key encryption unit fuses hardware fingerprints, data versions and AI disturbance, a scenarized anti-attack key is generated, and the anti-cracking capacity is improved.
Owner:SHENZHEN LEIMENG NASHUN TECHNOLOGY CO LTD

Internet of vehicles heterogeneous signcryption communication system and method based on double-layer block chain

The invention discloses an Internet of Vehicles heterogeneous signcryption communication system and method based on a double-layer block chain, relates to the technical field of Internet of Vehicles, and solves the technical problems that the Internet of Vehicles technology is insufficient in expansibility and poor in compatibility, safety and efficiency are difficult to consider, and use requirements are difficult to meet. The system comprises a private key generation center PKG, a secret key generation center KGC, an on-board unit OBU, a roadside unit RSU and a double-layer block chain device. The private key generation center PKG is used for generating and distributing a public key and private key pair of the identity signcryption IBC; the key generation center KGC is used for key updating and management of the certificateless signcryption CLC; the OBU is used for performing communication between the vehicle and other vehicles or the road side unit; the roadside unit RSU is used for communication support and data forwarding; and the double-layer block chain equipment is used for carrying out data storage and security verification in the communication system. According to the invention, the calculation overhead and communication cost of the system are obviously reduced, and safe, efficient and extensible authentication and data transmission in a high-dynamic and large-scale V2X environment is realized.
Owner:SHENZHEN SEG SCI NAVIGATIONS CO LTD

Security key distribution

Communications between computing devices connected via a network can be secured with digital keys (e.g., encryption keys). The key may be updated based on states of a state machine. The computing device may receive a key update command to update a key value. In response to the key update command, the computing device may update the key value upon determining that the computing device is in a first state based on state data defining the first state, the state data including the key value, a machine mode specifying a current operating environment, and a lock value specifying that memory storing the key value is one of locked or unlocked.
Owner:FORD GLOBAL TECH LLC

Power distribution terminal key management method and system based on trusted computing

The invention provides a power distribution terminal key management method and system based on trusted computing, and relates to the field of power system management.The method comprises the following steps that key strength is determined according to risk indexes; encrypting the real-time data of the power distribution terminal by using the encryption key; transmitting to a key management center through a preset security access gateway; performing integrity verification on the encrypted real-time data, and associatively storing a verification result, a security risk index and a transmission timestamp to a block chain evidence storage node to form a tampering-free encryption key operation context record; and dynamically optimizing an encryption key updating strategy in combination with the historical change trend of the security risk index so as to realize closed-loop security management and control of the whole life cycle of the encryption key. According to the invention, the active immunity and the overall safety management and control level of the power distribution Internet of Things in a complex environment are significantly improved.
Owner:HEFEI ZHONGNENG POWER TECH

Multi-device communication key negotiation method based on V2X vehicle formation

The invention provides a multi-device communication key negotiation method, and the method comprises the steps: generating a corresponding private key and a scalar multiplication point for each device, the scalar multiplication point being a product of the private key and an elliptic curve base point; each device broadcasts a scalar multiplication point corresponding to the device and receives scalar multiplication points of other devices, and each device calculates a shared key by using a private key of the device and the received scalar multiplication point based on a pairing strategy; encrypted communication between the devices is performed using the shared key. The method has the beneficial effects that the authenticity and integrity of the message are verified by fusing and using certificate signature, the confidentiality of the message is ensured by using the secret key negotiation based on the scalar multiplication point and the private key, the dynamic secret key updating is realized, and the communication security is ensured in multiple aspects.
Owner:BEIJING RENXINZHENG TECH CO LTD

High-speed encryption and decryption engine and encryption and decryption implementation method

The application relates to a high-speed encryption and decryption engine and an encryption and decryption implementation method, wherein a plurality of physical channels are provided to provide a plurality of service processing modules with cryptographic services, the problem that a cryptographic card can only provide a single service channel is solved, secondary keys are imported into an FPGA chip for buffering, a session key is managed in a life cycle by the FPGA chip, the time cost of key updating required by cryptographic operation can be reduced, and the processing delay of the cryptographic service can be obviously reduced; the FPGA chip is used as a cryptographic operation processing core unit, multi-stage parallel pipeline processing is realized, and the processing performance is effectively improved.
Owner:QUANTUMCTEK CO LTD +1

Internet of Things equipment encryption method and device and electronic equipment

The invention relates to the technical field of Internet of Things equipment encryption, and discloses an Internet of Things equipment encryption method and device and electronic equipment, and the method comprises the steps of secret key level-to-level management, dynamic secret key updating, hierarchical encryption communication, and secret key revocation and recovery. According to the invention, a three-level architecture of the master key, the regional key and the equipment key is adopted, hierarchical isolation management of the keys is realized, and the key leakage risk is effectively reduced; a dynamic key updating mechanism can automatically identify and update expired or abnormal keys, so that the flexibility of the system is improved; equipment-level, area-level and core-level data isolation protection is realized through a layered encryption communication strategy, and cross-level attacks are prevented; by quickly identifying abnormal equipment and executing key revocation and recovery, safe operation of the system is ensured; a verification mechanism is introduced to guarantee the integrity and reliability of data transmission. The method is suitable for various scenes such as smart cities and industrial Internet of Things, and provides all-around safety guarantee for Internet of Things equipment.
Owner:JINING POLYTECHNIC

Rekeyable lock cylinder

A rekeyable lock cylinder with a cylinder body, an inner sleeve, and a plug assembly is provided. The plug assembly includes a plurality of key followers and a corresponding plurality of first racks and second racks disposed in carriers. The first racks correspond to operation of a user key and the second racks correspond to operation of a master key. As such, the lock cylinder is usable in a user / master key system. Disengaging either of the first or second racks from the key followers allows rekeying of the lock cylinder for the user key or the master key.
Owner:ASSA ABLOY AMERICAS RESIDENTIAL INC

Dynamic and verifiable searchable encryption method and system based on updatable encryption and blockchain

A dynamic and verifiable searchable encryption method based on updatable encryption and blockchain and a system thereof are provided. The method is suitable for the real scene where the data user and the data owner are not the same party. The method adopts the updatable technology to update the secret key in the searchable encryption, and the security of the key update could achieve Chosen Ciphertext Security (CCA) and Ciphertext Integrity (CTXT) security. In addition, the method is used to judge whether the cloud server is “trustworthy” by verifying the search results publicly based on the blockchain. Therefore, the verifiable dynamic searchable encryption method based on updatable encryption and blockchain has been greatly improved in terms of practicability and security.
Owner:HANGZHOU CITY UNIV

Work key updating method, communication device, readable medium and program product

The invention provides a working key updating method for a national secret I PSec tunnel, and the method is used for an initiator communication device, and comprises the steps: generating a first updating message comprising an initiator key updating material according to a pre-stored security alliance parameter, an integrity working key, a pre-stored responder encryption certificate public key, and an initiator signature certificate private key, sending a first update message to the responder communication device; receiving a second update message which is sent by the responder communication equipment and comprises a responder key update material; wherein the integrity work key, the initiator encryption certificate public key and the responder signature certificate private key are used for ensuring the security of the second update message; and verifying the second update message at least by using the integrity work key, the initiator encryption certificate private key and the pre-stored responder signature certificate public key according to the security alliance parameter. The invention further provides a communication device, a computer readable medium and a computer program product.
Owner:ZTE CORP

Low-voltage distribution line information safety acquisition control method adaptive to multi-load characteristic

The invention discloses a low-voltage distribution line information safety acquisition control method adaptive to multi-load characteristics, and aims to solve the problems that key updating depends on a central server, the response delay is high, and dynamic load change is difficult to adapt in the prior art. The method specifically comprises the following steps: triggering transient impedance characteristic acquisition when a load monitoring unit detects that a current change rate exceeds a threshold value in real time; the impedance feature extraction module calculates a specific frequency band phase angle and an amplitude to form a feature vector; the physical unclonable function generator binarizes the physical unclonable function and generates an encryption seed; the key synchronization module encrypts the root key and then broadcasts the encrypted root key to an adjacent node; and the security chip executes atomic operation to complete seamless key switching. By adopting the technical scheme, the generation and synchronization of the localized self-triggering key can be realized, the key updating delay time is shortened, and the safety response capability and the attack resistance of the low-voltage distribution line under the dynamic load are remarkably improved.
Owner:JINZHOU ELECTRIC POWER SUPPLY COMPANY OF STATE GRID LIAONING ELECTRIC POWER SUPPLY +1

Managing key rotation for endpoint devices using re-keying rules

Methods and systems for validating key rotation requests for endpoint devices are disclosed. The key rotation requests may be signed by one or more signing systems according to a set of re-keying rules for the endpoint device. The set of the re-keying rules may indicate that key rotation requests may be valid if signed using at least two different keys. The set of the re-keying rules may also indicate that each of the at least the two different keys be from a different grouping of keys of multiple groupings of keys included in a secure key repository. Each grouping of keys may be associated with a different organization. Therefore, key rotation requests may be serviced if signatures associated with the key rotation requests meet the re-keying rules thereby decreasing a likelihood of compromise of the endpoint devices via compromise of a key.
Owner:DELL PROD LP

A dynamic encryption method and system for secure transmission

This invention relates to the field of data encryption transmission technology, specifically disclosing a dynamic encryption method and system for secure transmission. The method includes: first, acquiring input parameters of the data to be transmitted and generating an initial encryption key; processing the data to be transmitted in blocks and determining the importance level of each data block; performing layered initial encryption transmission on each data block according to its importance level; collecting dynamic status parameters of the transmission link to generate key update parameters, adjusting the current encryption key to obtain an updated encryption key; detecting whether there are security risks in the transmission link, and if so, using an upgraded encryption algorithm and an updated encryption key to re-encrypt the incomplete data blocks and continue transmission through a backup encryption link; finally, decrypting the encrypted data blocks to obtain the original data blocks and performing integrity verification. This invention effectively solves the problems of easy key leakage, insufficient security, and low encryption efficiency in traditional static encryption methods.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

Intelligent data security encryption method in edge computing environment

The invention relates to the technical field of data encryption, and discloses an intelligent data security encryption method in an edge computing environment. The method comprises the following steps: acquiring an original data stream, decomposing through discrete wavelet transform, and adding a random disturbance sequence; constructing a dynamic encryption strategy network, generating a dynamic key matrix and distributing an access control strategy; according to the data security level and the node load, adaptively selecting an encryption algorithm and generating an encrypted metadata label; verifying data integrity by using a decentralized consensus mechanism and a zero-knowledge proof algorithm; a key is updated through a key updating model based on a time decay function, and the key is stored in combination with a block chain technology. According to the method, the problems of data encryption, access control, key management and the like in the edge computing environment are solved, the security and integrity of the data are guaranteed, and the security and reliability of data processing in the edge computing environment are improved.
Owner:NANJING UNIV OF SCI & TECH

Key updating method and device, storage medium, terminal and system

The invention discloses a secret key updating method and device, a storage medium, a terminal and a system, relates to the technical field of data encryption transmission, and mainly aims to solve the problem of low timeliness and safety of existing secret key updating. The method mainly comprises the steps of determining key use state parameters according to key associated data; under the condition that the key use state parameter is greater than a preset use state parameter threshold, generating a quantum key updating request according to the key associated data, and generating an encryption key through a physical unclonable security component; encrypting the quantum key updating request according to the encryption key, and sending the encrypted quantum key updating request to the server, so that the server generates and returns a newly added key according to the quantum key updating request; and receiving a key update reply sent by the server in an encrypted manner, decrypting the key update reply through the physical unclonable security component, and storing the newly-added key obtained by decryption to the trusted platform module. The method is mainly used for key updating.
Owner:BEIJING XUEDIRUANJIAN DEVELOPMENT CO LTD

Key update methods, key management systems, devices, storage media and products

This application provides a key update method, a key management system, a device, a storage medium, and a product, relating to the field of information security. The method includes: a POS terminal backend management system calling the POS terminal's key generation interface to generate a public-private key pair via the POS terminal's PIN pad and returning the public key; forwarding the public key to a hardware security module and calling the hardware security module to generate a first working key; the hardware security module encrypting the first working key based on the public key to generate a first ciphertext and a corresponding key verification value, and sending them to the POS terminal; upon receiving the first ciphertext and the key verification value, the POS terminal obtains the first working key based on its private key and updates its current working key to the first working key. In this application, the POS terminal backend management system is used for instruction scheduling, and the encryption and decryption of information are configured in the POS terminal and the hardware security module, enabling remote and efficient updating of the POS terminal's working key.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Key updating method and device for full-mesh database, equipment and storage medium

The application discloses a key updating method, device and equipment of a full-mechanism database and a storage medium. The method comprises the following steps: creating a target client master key; using an initial client master key stored locally by a client to decrypt an initial column encryption key ciphertext, and obtaining column encryption key plaintext; using the target client master key to encrypt the column encryption key plaintext, and obtaining target column encryption key ciphertext; updating the target column encryption key ciphertext to a system table of a server, and using the target client master key to update the initial client master key stored locally by the client, so that the updating of the client master key in the full-mechanism database is realized, the security of a key storage device is ensured, and the consistency of the key of the client and the server is ensured during the updating of the client master key, so that the continuous availability of the key is ensured.
Owner:WUHAN DAMENG DATABASE