Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

12 results about "Revocation" patented technology

Revocation is the act of recall or annulment. It is the cancelling of an act, the recalling of a grant or privilege, or the making void of some deed previously existing. A temporary revocation of a grant or privilege is called a suspension.

Operational permit-receipt gate (ORPRG): non-bypassable permit-before-commit control of external effects at effect boundaries

Systems and methods enforce non-bypassable, fail-closed permit-before-commit control of external-effect requests at an effect boundary between an execution substrate and one or more external interfaces. An interceptor captures each request, deterministically canonicalizes it, computes an action digest, and obtains a machine-verifiable permit receipt bound to a policy digest and epoch identifier with a time-bounded validity. Prior to commitment, the interceptor verifies receipt authenticity, authorization by digest match and / or cryptographic commitment verification, epoch-compatibility, and revocation status using signed revocation data and / or transparency-log proofs subject to policy-defined recency, including in intermittently connected environments, and may enforce scope and permit-provenance constraints. If required verification evidence is missing, stale, conflicting, or indeterminate, the external effect is denied. Optional embodiments use trusted execution boundaries, capability tokens for dual enforcement, and machine-verifiable decision, audit, and denial receipts.
Owner:GATE OF REMEMBRANCE LLC

Anonymous certificate entrusting method supporting revocation and attribute selective disclosure

The invention discloses an anonymous certificate entrusting method supporting revocation and attribute selective disclosure. The method comprises the following steps: generating system parameters; generating a user key; a user registers in a trusted revocation center TRA; constructing and sending a delegation voucher; the entrusted issuer verifies the received anonymous certificate; the user proves the authenticity of the attribute to the entrusted issuer; issuing a certificate to the user by the entrusted issuer; the user selects part of attribute information to be disclosed, a corresponding commitment value is generated for undisclosed attribute information, and the user sends the part of attribute information, the commitment value and the anonymous certificate to a verification party together; and the verifier verifies the legality of the user attribute. According to the invention, through a chain type randomization structure and a public key generation mechanism, a issuer is prevented from tracking and associating a user identity fundamentally, and anonymity is ensured. A user can flexibly and controllably disclose attributes, and information leakage is minimized while anonymity is guaranteed.
Owner:SHAANXI NORMAL UNIV

Multi-group data security sharing method and system supporting traceability and revocation

The invention discloses a multi-group data security sharing method and system supporting traceability and revocation. A trusted key generation center generates parameters required by system operation; generating an attribute private key and a puncturable private key; the data owner uses a pre-formulated access control strategy to encrypt data to be shared by adopting puncturable attribute-based encryption; the group administrator formulates a new access control strategy, and generates a re-encryption key based on an attribute private key of the group administrator; the cloud server performs re-encryption on the original ciphertext according to the proxy re-encryption key; and the group administrator decrypts the original ciphertext according to the attribute private key and the puncturable private key, and the user in the group decrypts the re-encrypted ciphertext according to the attribute private key, the puncturable private key and the authorized private key to obtain the plaintext of the data to be shared. According to the method, the user decryption key is divided into the attribute private key, the puncturable private key and the authorized private key, the group user identity can be uniquely determined through combination of the three types of keys, and refined tracing is achieved.
Owner:WUHAN UNIV

Attribute signature-based distributed supervision anonymous certificate method and system

PendingCN121283636AUser identity/authority verificationRegulatory authorityEngineering
The invention discloses a distributed supervision anonymous certificate method and system based on an attribute signature, and the method comprises the steps: a user submits an attribute application to a distributed attribute mechanism, and the attribute mechanism issues an attribute private key to the user through a chain type authorization method after the authentication is passed; the user submits a revocation right application to the supervision mechanism, and the supervision mechanism generates a revocation right for the user and publishes a certificate white list; the user uses the attribute private key and the revoked right to generate an anonymous certificate, and the anonymous certificate is shown to the verifier; the verifier verifies the attribute signature and certificate validity of the anonymous certificate; when a dispute occurs, the verifier can request arbitration, and the supervision mechanism recovers the real identity of the user or revokes the anonymous certificate of the user according to the dispute degree. Compared with the prior art, the anonymous certificate revocation method has the advantages that double decentration of the attribute mechanism and the supervision mechanism is realized, and the anonymous certificate revocation method is efficient.
Owner:ZHEJIANG UNIV

Digital car key sharing and revocation method, system and equipment and computer medium

The invention provides a digital car key sharing and revocation method, system and device and a computer medium. The method comprises the following steps: establishing a state synchronization channel among a car end, a cloud end and at least two terminal devices; a first terminal device sends a sharing request to a cloud end, and the cloud end generates an intermediate voucher with a first life cycle; the first terminal device calls a vehicle owner private key stored locally to sign the intermediate voucher, and sends the signed intermediate voucher to the cloud; after the cloud verifies that the signed intermediate voucher is valid, a sub-voucher with a second life cycle is signed and issued to the second terminal equipment; when the first terminal device, the second terminal device, the vehicle end or the cloud end triggers a revocation event, the cloud end generates a revocation instruction and broadcasts the revocation instruction to the vehicle end and all the terminal devices through the state synchronization channel, and the vehicle end and all the terminal devices synchronously delete the digital vehicle key object corresponding to the sub-voucher after receiving the revocation instruction. And the respective local digital car key state is updated.
Owner:DONGFENG MOTOR GRP

Distributed digital identity supervision and revocation method and system based on block chain

The invention relates to a distributed digital identity supervision and revocation method and system based on a block chain, and belongs to the field of distributed digital identity management. The system comprises an identity subsystem and a revocation subsystem, and the identity subsystem is responsible for DID registration, VC signing and issuing, identity verification and transaction block upper chain storage and relates to entities such as a user, a certificate issuer, a service provider and a block chain committee; and the revocation subsystem runs an XGBoost model through a malicious detection node, analyzes multi-dimensional features on a chain to identify malicious users, and realizes three types of fine-grained operations of malicious detection forced revocation, user voluntary logout and issuer VC revocation in combination with a DID management center, a block chain committee and a chameleon hash technology. According to the system, a deep learning model is introduced, multi-dimensional features on a chain are analyzed to recognize malicious behaviors, and the recognition ability of the system to abnormal users is improved; autonomous identities are recorded depending on the block chain, and fine-grained revocation management of digital identities is realized in combination with a chameleon hash technology.
Owner:BEIJING INST OF TECH

Authorization system and method supporting dynamic permission revocation

The invention discloses an authorization system and method supporting dynamic permission revocation. The method comprises the steps that an authorization strategy for a third-party application is defined based on attributes; generating a signature voucher based on a BBS + signature algorithm; according to the authorization strategy and metadata corresponding to the signature voucher, establishing an intelligent contract of an authority authorization state of the third-party application, monitoring whether a revocation condition is met or not in real time through the intelligent contract, and setting the authority authorization state to be revoked when the revocation condition is met; and when the third-party application accesses the resource through the signature voucher, carrying out validity verification on the signature voucher, querying the smart contract, confirming a permission authorization state, and refusing an access request of the third-party application when the permission authorization state is revoked. According to the invention, three core technologies of BBS + signature algorithm, attribute-based encryption and block chain smart contract are fused, a novel authorization architecture separating identity verification and authority management is constructed, and dynamic revocation, fine-grained control and real-time risk response of authority are realized.
Owner:HENAN INFORMATIZATION GRP CO LTD

Verifiable revocation multi-authority attribute-based encryption method and system

PendingCN122640110ACiphertextEngineering
The application discloses a verifiable revocation multi-authority attribute-based encryption and decryption method and system, which comprises the following steps: when any data user is revoked, a corresponding authority attribute institution updates a revocation list and a verifiable commitment and publishes them; a data owner updates an aggregated revocation state according to the latest verifiable commitment, generates an update key based on the aggregated revocation state before and after the update, and sends the update key to a cloud server; the cloud server updates a ciphertext package according to the update key and generates a cryptographic proof for proving the correctness of the update operation of the ciphertext; any data user verifies the consistency of the revocation state and the correctness of the update operation according to the latest verifiable commitment and the cryptographic proof before decrypting the latest ciphertext package; and the data user decrypts the latest ciphertext package after the verification. Therefore, the data user can verify the correctness of the update operation of the cloud server before decryption.
Owner:WUHAN UNIV

Attribute revocation encryption access control method and system based on time label

The invention relates to an attribute revocation encryption access control method and system based on a time label, and the system is characterized in that a time label definition module achieves the precise pre-judgment of authority failure time through constructing a three-stage constraint structure of an early warning window, an intervention window and an execution window; the alarm triggering judgment module dynamically generates graded alarm signals based on the time window inclusion relation, and the problem of manual response lag is solved. The dynamic optimization module adaptively adjusts a scanning strategy in combination with a system load state, and eliminates resource waste of a fixed scanning mechanism; the disaster recovery path configuration module guarantees reliable execution of a revocation instruction in a high-concurrency scene through a main-standby dual-path design; and the encryption revocation execution module adopts a key update factor injection technology to thoroughly eliminate the historical key decryption capability, under the cooperation of the data communication module, triple improvement of the timeliness, resource efficiency and cryptography security of permission revocation is realized, and the core contradiction between the service continuity and the data residual risk is effectively solved.
Owner:SHANGHAI UNIVERSITY OF ELECTRIC POWER

Method for performing automated systematic entitlement review

A system and method for performing automated systematic entitlement review comprising a data store tracking one or more entitlements available to one or more users. A server enforces the one or more entitlements by permitting or denying access to the one or more users to perform one or more given tasks. Non-transitory memory storing instructions that, when executed by a computer processor, cause the computer processor to: retrieve the one or more entitlements and the one or more users having those entitlements, select a first one or more instances of an entitlement and its user for revocation, based on a probability of revocation per unit of time for each entitlement, select a second one or more instances of an entitlement and its user to be retained without revocation, and automatically revoke access of the entitlements in the first one or more instances.
Owner:MORGAN STANLEY SERVICES GROUP INC

Method for performing automated systematic entitlement review

A computer-implemented method and system for performing automated systematic entitlement review is disclosed. The method comprises retrieving metadata concerning the one or more entitlements and the one or more users having those entitlements; selecting a first one or more instances of an entitlement and its user for revocation, and a second one or more instances of an entitlement and its user to be retained without revocation; automatically revoking access of the entitlements in the first one or more instances; and automatically notifying the users in the first one or more instances of the automatic revocation. In one family of variants, revocations are performed via probabilistic sampling, while in another family of variants, revocation are performed based on a “use it or lose it” scheme.
Owner:MORGAN STANLEY SERVICES GROUP INC