Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

6 results about "Revocation" patented technology

Revocation is the act of recall or annulment. It is the cancelling of an act, the recalling of a grant or privilege, or the making void of some deed previously existing. A temporary revocation of a grant or privilege is called a suspension.

Operational permit-receipt gate (ORPRG): non-bypassable permit-before-commit control of external effects at effect boundaries

Systems and methods enforce non-bypassable, fail-closed permit-before-commit control of external-effect requests at an effect boundary between an execution substrate and one or more external interfaces. An interceptor captures each request, deterministically canonicalizes it, computes an action digest, and obtains a machine-verifiable permit receipt bound to a policy digest and epoch identifier with a time-bounded validity. Prior to commitment, the interceptor verifies receipt authenticity, authorization by digest match and / or cryptographic commitment verification, epoch-compatibility, and revocation status using signed revocation data and / or transparency-log proofs subject to policy-defined recency, including in intermittently connected environments, and may enforce scope and permit-provenance constraints. If required verification evidence is missing, stale, conflicting, or indeterminate, the external effect is denied. Optional embodiments use trusted execution boundaries, capability tokens for dual enforcement, and machine-verifiable decision, audit, and denial receipts.
Owner:GATE OF REMEMBRANCE LLC

Multi-group data security sharing method and system supporting traceability and revocation

The invention discloses a multi-group data security sharing method and system supporting traceability and revocation. A trusted key generation center generates parameters required by system operation; generating an attribute private key and a puncturable private key; the data owner uses a pre-formulated access control strategy to encrypt data to be shared by adopting puncturable attribute-based encryption; the group administrator formulates a new access control strategy, and generates a re-encryption key based on an attribute private key of the group administrator; the cloud server performs re-encryption on the original ciphertext according to the proxy re-encryption key; and the group administrator decrypts the original ciphertext according to the attribute private key and the puncturable private key, and the user in the group decrypts the re-encrypted ciphertext according to the attribute private key, the puncturable private key and the authorized private key to obtain the plaintext of the data to be shared. According to the method, the user decryption key is divided into the attribute private key, the puncturable private key and the authorized private key, the group user identity can be uniquely determined through combination of the three types of keys, and refined tracing is achieved.
Owner:WUHAN UNIV

Digital car key sharing and revocation method, system and equipment and computer medium

The invention provides a digital car key sharing and revocation method, system and device and a computer medium. The method comprises the following steps: establishing a state synchronization channel among a car end, a cloud end and at least two terminal devices; a first terminal device sends a sharing request to a cloud end, and the cloud end generates an intermediate voucher with a first life cycle; the first terminal device calls a vehicle owner private key stored locally to sign the intermediate voucher, and sends the signed intermediate voucher to the cloud; after the cloud verifies that the signed intermediate voucher is valid, a sub-voucher with a second life cycle is signed and issued to the second terminal equipment; when the first terminal device, the second terminal device, the vehicle end or the cloud end triggers a revocation event, the cloud end generates a revocation instruction and broadcasts the revocation instruction to the vehicle end and all the terminal devices through the state synchronization channel, and the vehicle end and all the terminal devices synchronously delete the digital vehicle key object corresponding to the sub-voucher after receiving the revocation instruction. And the respective local digital car key state is updated.
Owner:DONGFENG MOTOR GRP

Distributed digital identity supervision and revocation method and system based on block chain

The invention relates to a distributed digital identity supervision and revocation method and system based on a block chain, and belongs to the field of distributed digital identity management. The system comprises an identity subsystem and a revocation subsystem, and the identity subsystem is responsible for DID registration, VC signing and issuing, identity verification and transaction block upper chain storage and relates to entities such as a user, a certificate issuer, a service provider and a block chain committee; and the revocation subsystem runs an XGBoost model through a malicious detection node, analyzes multi-dimensional features on a chain to identify malicious users, and realizes three types of fine-grained operations of malicious detection forced revocation, user voluntary logout and issuer VC revocation in combination with a DID management center, a block chain committee and a chameleon hash technology. According to the system, a deep learning model is introduced, multi-dimensional features on a chain are analyzed to recognize malicious behaviors, and the recognition ability of the system to abnormal users is improved; autonomous identities are recorded depending on the block chain, and fine-grained revocation management of digital identities is realized in combination with a chameleon hash technology.
Owner:BEIJING INST OF TECH

Method for performing automated systematic entitlement review

A system and method for performing automated systematic entitlement review comprising a data store tracking one or more entitlements available to one or more users. A server enforces the one or more entitlements by permitting or denying access to the one or more users to perform one or more given tasks. Non-transitory memory storing instructions that, when executed by a computer processor, cause the computer processor to: retrieve the one or more entitlements and the one or more users having those entitlements, select a first one or more instances of an entitlement and its user for revocation, based on a probability of revocation per unit of time for each entitlement, select a second one or more instances of an entitlement and its user to be retained without revocation, and automatically revoke access of the entitlements in the first one or more instances.
Owner:MORGAN STANLEY SERVICES GROUP INC