Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

19 results about "Revocation" patented technology

Revocation is the act of recall or annulment. It is the cancelling of an act, the recalling of a grant or privilege, or the making void of some deed previously existing. A temporary revocation of a grant or privilege is called a suspension.

Multi-level revocation recovery method and device of CAD system and storage medium

The invention relates to the technical field of computer aided design, and provides a multi-level revocation recovery method of a CAD system, the method comprises the following steps: receiving a user operation instruction through a transaction management module and generating a corresponding operation set, the operation set comprising a plurality of atomic operation units; analyzing geometric objects related to the operation set and the incidence relation of the geometric objects, and constructing a directed dependency graph with the geometric objects as nodes and the dependency relation between the objects as edges; according to the topological structure of the directed dependency graph, sequence adjustment and operation filling are carried out on the atomic operation units in the operation set, and an operation sequence conforming to dependency constraints is generated; and when the revocation or recovery operation is executed, executing the atomic operation units in the operation sequence according to the reverse topological sequence or the forward topological sequence. According to the technical scheme, high efficiency and consistency of revocation and recovery operation can be guaranteed, and the performance and reliability of the system are remarkably improved.
Owner:SHENZHEN POISSON SOFTWARE TECH CO LTD

Operational permit-receipt gate (ORPRG): non-bypassable permit-before-commit control of external effects at effect boundaries

Systems and methods enforce non-bypassable, fail-closed permit-before-commit control of external-effect requests at an effect boundary between an execution substrate and one or more external interfaces. An interceptor captures each request, deterministically canonicalizes it, computes an action digest, and obtains a machine-verifiable permit receipt bound to a policy digest and epoch identifier with a time-bounded validity. Prior to commitment, the interceptor verifies receipt authenticity, authorization by digest match and / or cryptographic commitment verification, epoch-compatibility, and revocation status using signed revocation data and / or transparency-log proofs subject to policy-defined recency, including in intermittently connected environments, and may enforce scope and permit-provenance constraints. If required verification evidence is missing, stale, conflicting, or indeterminate, the external effect is denied. Optional embodiments use trusted execution boundaries, capability tokens for dual enforcement, and machine-verifiable decision, audit, and denial receipts.
Owner:GATE OF REMEMBRANCE LLC

Anonymous certificate entrusting method supporting revocation and attribute selective disclosure

The invention discloses an anonymous certificate entrusting method supporting revocation and attribute selective disclosure. The method comprises the following steps: generating system parameters; generating a user key; a user registers in a trusted revocation center TRA; constructing and sending a delegation voucher; the entrusted issuer verifies the received anonymous certificate; the user proves the authenticity of the attribute to the entrusted issuer; issuing a certificate to the user by the entrusted issuer; the user selects part of attribute information to be disclosed, a corresponding commitment value is generated for undisclosed attribute information, and the user sends the part of attribute information, the commitment value and the anonymous certificate to a verification party together; and the verifier verifies the legality of the user attribute. According to the invention, through a chain type randomization structure and a public key generation mechanism, a issuer is prevented from tracking and associating a user identity fundamentally, and anonymity is ensured. A user can flexibly and controllably disclose attributes, and information leakage is minimized while anonymity is guaranteed.
Owner:SHAANXI NORMAL UNIV

Multi-group data security sharing method and system supporting traceability and revocation

The invention discloses a multi-group data security sharing method and system supporting traceability and revocation. A trusted key generation center generates parameters required by system operation; generating an attribute private key and a puncturable private key; the data owner uses a pre-formulated access control strategy to encrypt data to be shared by adopting puncturable attribute-based encryption; the group administrator formulates a new access control strategy, and generates a re-encryption key based on an attribute private key of the group administrator; the cloud server performs re-encryption on the original ciphertext according to the proxy re-encryption key; and the group administrator decrypts the original ciphertext according to the attribute private key and the puncturable private key, and the user in the group decrypts the re-encrypted ciphertext according to the attribute private key, the puncturable private key and the authorized private key to obtain the plaintext of the data to be shared. According to the method, the user decryption key is divided into the attribute private key, the puncturable private key and the authorized private key, the group user identity can be uniquely determined through combination of the three types of keys, and refined tracing is achieved.
Owner:WUHAN UNIV

Certificate revocation list updating method and related apparatus

PCT designated stage expiredWO2025138106A1User identity/authority verificationEngineeringDatabase
Disclosed in the present application are a certificate revocation list (CRL) updating method and a related apparatus. The method comprises: acquiring reference information, wherein the reference information comprises at least one of revocation records to be processed of a first CRL, certificate types of revoked certificates, the number of times the first CRL is accessed, a preset update cycle of the first CRL, and an update timeliness level of the first CRL that is configured by a user, and each revocation record comprises a certificate revoked after the first CRL is issued; and when the reference information satisfies update conditions, updating the first CRL to obtain a second CRL. The flexibility of certificate revocation list updating is improved. In addition, the interval between an issuance moment of the first CRL and an issuance moment of the second CRL is less than the preset update cycle of the first CRL, thereby improving the timeliness of certificate revocation list updating, and helping to improve the security of communication.
Owner:YINWANG INTELLIGENT TECHNOLOGIES CO LTD

Digital Certificate Verification Method, Device, Computer Equipment and Storage Medium

The present application relates to a digital certificate verification method, apparatus, computer device, and storage medium. The method includes: in response to a digital certificate verification request sent by a terminal, confirming the revocation status of the digital certificate in the digital certificate verification request; verifying the digital certificate according to the revocation status of the digital certificate to obtain a verification result; and returning the verification result to the terminal. The server of the present application determines the revocation status of the digital certificate by responding to the digital certificate verification request sent by the terminal, performs corresponding verification according to different revocation statuses, obtains the verification result and returns it to the terminal; that is, the server can perform corresponding processing on the digital certificate according to the revocation status of the digital certificate to obtain the verification result, thereby improving the efficiency of digital certificate verification.
Owner:SHENZHEN COMTOP INFORMATION TECH

Attribute signature-based distributed supervision anonymous certificate method and system

PendingCN121283636AUser identity/authority verificationRegulatory authorityEngineering
The invention discloses a distributed supervision anonymous certificate method and system based on an attribute signature, and the method comprises the steps: a user submits an attribute application to a distributed attribute mechanism, and the attribute mechanism issues an attribute private key to the user through a chain type authorization method after the authentication is passed; the user submits a revocation right application to the supervision mechanism, and the supervision mechanism generates a revocation right for the user and publishes a certificate white list; the user uses the attribute private key and the revoked right to generate an anonymous certificate, and the anonymous certificate is shown to the verifier; the verifier verifies the attribute signature and certificate validity of the anonymous certificate; when a dispute occurs, the verifier can request arbitration, and the supervision mechanism recovers the real identity of the user or revokes the anonymous certificate of the user according to the dispute degree. Compared with the prior art, the anonymous certificate revocation method has the advantages that double decentration of the attribute mechanism and the supervision mechanism is realized, and the anonymous certificate revocation method is efficient.
Owner:ZHEJIANG UNIV

Digital car key sharing and revocation method, system and equipment and computer medium

The invention provides a digital car key sharing and revocation method, system and device and a computer medium. The method comprises the following steps: establishing a state synchronization channel among a car end, a cloud end and at least two terminal devices; a first terminal device sends a sharing request to a cloud end, and the cloud end generates an intermediate voucher with a first life cycle; the first terminal device calls a vehicle owner private key stored locally to sign the intermediate voucher, and sends the signed intermediate voucher to the cloud; after the cloud verifies that the signed intermediate voucher is valid, a sub-voucher with a second life cycle is signed and issued to the second terminal equipment; when the first terminal device, the second terminal device, the vehicle end or the cloud end triggers a revocation event, the cloud end generates a revocation instruction and broadcasts the revocation instruction to the vehicle end and all the terminal devices through the state synchronization channel, and the vehicle end and all the terminal devices synchronously delete the digital vehicle key object corresponding to the sub-voucher after receiving the revocation instruction. And the respective local digital car key state is updated.
Owner:DONGFENG MOTOR GRP

Distributed digital identity supervision and revocation method and system based on block chain

The invention relates to a distributed digital identity supervision and revocation method and system based on a block chain, and belongs to the field of distributed digital identity management. The system comprises an identity subsystem and a revocation subsystem, and the identity subsystem is responsible for DID registration, VC signing and issuing, identity verification and transaction block upper chain storage and relates to entities such as a user, a certificate issuer, a service provider and a block chain committee; and the revocation subsystem runs an XGBoost model through a malicious detection node, analyzes multi-dimensional features on a chain to identify malicious users, and realizes three types of fine-grained operations of malicious detection forced revocation, user voluntary logout and issuer VC revocation in combination with a DID management center, a block chain committee and a chameleon hash technology. According to the system, a deep learning model is introduced, multi-dimensional features on a chain are analyzed to recognize malicious behaviors, and the recognition ability of the system to abnormal users is improved; autonomous identities are recorded depending on the block chain, and fine-grained revocation management of digital identities is realized in combination with a chameleon hash technology.
Owner:BEIJING INST OF TECH

Authorization system and method supporting dynamic permission revocation

The invention discloses an authorization system and method supporting dynamic permission revocation. The method comprises the steps that an authorization strategy for a third-party application is defined based on attributes; generating a signature voucher based on a BBS + signature algorithm; according to the authorization strategy and metadata corresponding to the signature voucher, establishing an intelligent contract of an authority authorization state of the third-party application, monitoring whether a revocation condition is met or not in real time through the intelligent contract, and setting the authority authorization state to be revoked when the revocation condition is met; and when the third-party application accesses the resource through the signature voucher, carrying out validity verification on the signature voucher, querying the smart contract, confirming a permission authorization state, and refusing an access request of the third-party application when the permission authorization state is revoked. According to the invention, three core technologies of BBS + signature algorithm, attribute-based encryption and block chain smart contract are fused, a novel authorization architecture separating identity verification and authority management is constructed, and dynamic revocation, fine-grained control and real-time risk response of authority are realized.
Owner:HENAN INFORMATIZATION GRP CO LTD

Method and system for traceable anonymous voucher revocation of limited equipment

The invention aims to provide a traceable anonymous certificate revocation method and system for limited equipment. The method comprises the following steps: the system generates global parameters and sends the global parameters to an authority, a certificate issuing mechanism, a user and a service provider; the certificate issuing mechanism and the user generate corresponding public and private keys according to the global parameters; the user sends the public key and the tracking key to the authority for registration; the certificate issuing mechanism generates a certificate according to the user public key and the attribute; the service provider returns service authority to the user according to the user registration condition, the user attribute and the user certificate; the authority tracks the identity public key of the user; and the authority revokes the identity public key of the user. According to the method, an authority is introduced, and registration, tracking and revocation functions are added, so that a limited equipment scene can be supported, and rapid tracking and millisecond-level revocation are realized on the premise of ensuring that the calculation burden of the voucher does not change along with the quantity of attributes any more.
Owner:JINAN UNIVERSITY

Multi-mechanism attribute access control method supporting authority entrustment and revocation

The invention discloses a multi-mechanism attribute access control method supporting authority entrustment and revocation, which realizes fine-grained authority control, cross-domain collaborative management and efficient and safe revocation through distributed attribute management, dynamic policy entrustment and an incremental revocation mechanism. The defects of a traditional CP-ABE system in the aspects of expandability, delegation flexibility and revocation efficiency are overcome.
Owner:GUANGZHOU UNIVERSITY

Verifiable revocation multi-authority attribute-based encryption method and system

PendingCN122640110ACiphertextEngineering
The application discloses a verifiable revocation multi-authority attribute-based encryption and decryption method and system, which comprises the following steps: when any data user is revoked, a corresponding authority attribute institution updates a revocation list and a verifiable commitment and publishes them; a data owner updates an aggregated revocation state according to the latest verifiable commitment, generates an update key based on the aggregated revocation state before and after the update, and sends the update key to a cloud server; the cloud server updates a ciphertext package according to the update key and generates a cryptographic proof for proving the correctness of the update operation of the ciphertext; any data user verifies the consistency of the revocation state and the correctness of the update operation according to the latest verifiable commitment and the cryptographic proof before decrypting the latest ciphertext package; and the data user decrypts the latest ciphertext package after the verification. Therefore, the data user can verify the correctness of the update operation of the cloud server before decryption.
Owner:WUHAN UNIV

Authorization revocation method and apparatus, and storage medium

The present disclosure provides an authorization revocation method and apparatus, and a storage medium. The authorization revocation method comprises: sending to a general API architecture CAPIF authentication authorization function a first revocation request message for requesting to revoke a specified authorization, wherein the specified authorization is an authorization corresponding to a target resource of a UE; and receiving a first revocation response message returned by the CAPIF authentication authorization function, wherein the first revocation response message is used for indicating that revocation of the specified authorization has been completed. In the present disclosure, the revocation of the specified authorization can be initiated by the UE, so that the objective of enabling user authorization revocation in the invocation process of an API is achieved, and the availability is high.
Owner:BEIJING XIAOMI MOBILE SOFTWARE CO LTD

Attribute revocation encryption access control method and system based on time label

The invention relates to an attribute revocation encryption access control method and system based on a time label, and the system is characterized in that a time label definition module achieves the precise pre-judgment of authority failure time through constructing a three-stage constraint structure of an early warning window, an intervention window and an execution window; the alarm triggering judgment module dynamically generates graded alarm signals based on the time window inclusion relation, and the problem of manual response lag is solved. The dynamic optimization module adaptively adjusts a scanning strategy in combination with a system load state, and eliminates resource waste of a fixed scanning mechanism; the disaster recovery path configuration module guarantees reliable execution of a revocation instruction in a high-concurrency scene through a main-standby dual-path design; and the encryption revocation execution module adopts a key update factor injection technology to thoroughly eliminate the historical key decryption capability, under the cooperation of the data communication module, triple improvement of the timeliness, resource efficiency and cryptography security of permission revocation is realized, and the core contradiction between the service continuity and the data residual risk is effectively solved.
Owner:SHANGHAI UNIVERSITY OF ELECTRIC POWER

Method for performing automated systematic entitlement review

A system and method for performing automated systematic entitlement review comprising a data store tracking one or more entitlements available to one or more users. A server enforces the one or more entitlements by permitting or denying access to the one or more users to perform one or more given tasks. Non-transitory memory storing instructions that, when executed by a computer processor, cause the computer processor to: retrieve the one or more entitlements and the one or more users having those entitlements, select a first one or more instances of an entitlement and its user for revocation, based on a probability of revocation per unit of time for each entitlement, select a second one or more instances of an entitlement and its user to be retained without revocation, and automatically revoke access of the entitlements in the first one or more instances.
Owner:MORGAN STANLEY SERVICES GROUP INC

Method for performing automated systematic entitlement review

A computer-implemented method and system for performing automated systematic entitlement review is disclosed. The method comprises retrieving metadata concerning the one or more entitlements and the one or more users having those entitlements; selecting a first one or more instances of an entitlement and its user for revocation, and a second one or more instances of an entitlement and its user to be retained without revocation; automatically revoking access of the entitlements in the first one or more instances; and automatically notifying the users in the first one or more instances of the automatic revocation. In one family of variants, revocations are performed via probabilistic sampling, while in another family of variants, revocation are performed based on a “use it or lose it” scheme.
Owner:MORGAN STANLEY SERVICES GROUP INC

Certificate information processing method and device and computer equipment

The invention relates to the technical field of information security, and discloses a certificate information processing method and device and computer equipment, and the method comprises the steps: receiving a certificate revocation instruction which carries a certificate serial number of a revoked certificate; hash operation is carried out on the certificate serial number to obtain compressed data, the compressed data comprises a first sequence and a second sequence, the first sequence is used for being stored in a bucket data list, and the second sequence is used for updating a revocation bitmap; on the basis of the compressed data, revoked cache information is updated, the revoked cache information is used for representing all revoked certificate information, and the revoked cache information comprises the bucket data list and the revoked bitmap. Therefore, the certificate serial number is reasonably compressed and cached, and the resource consumption for caching the revoked certificate is effectively reduced.
Owner:JINGWEI HIRAIN (TIANJIN) RES&DEV CO LTD