Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

58 results about "Revocation list" patented technology

In cryptography, a certificate revocation list (or CRL) is "a list of digital certificates that have been revoked by the issuing certificate authority (CA) before their scheduled expiration date and should no longer be trusted".

Secure dynamic loading method for peripheral adapter plug-in in embedded low-resource environment

The invention relates to a safe dynamic loading method for a peripheral adaptive plug-in in an embedded low-resource environment, and belongs to the technical field of plug-in loading. The method comprises the following steps: executing digital signature identity authentication and lightweight increment integrity verification; analyzing the metadata, and distributing a physical isolation memory area by utilizing a memory management unit; initializing and analyzing the peripheral dependency list in the isolation memory, dynamically generating an encryption capability token bound with an isolation domain identifier, and embedding a monitoring hook to verify the authority of the token; performing lightweight behavior auditing during operation, triggering a response mechanism based on a result, and checking a certificate state by using a pre-downloaded certificate revocation list incremental data packet when the system is idle; verifying the new-version plug-in independently, pausing the old-version capture state snapshot, switching the peripheral control right to the new-version plug-in through the atomic operation sequence, recovering the token and safely erasing the memory. The whole mechanism ensures high-security isolation and dynamic protection. The efficient and safe loading and operation of the peripheral adaptive plug-in under the embedded low-resource environment are realized.
Owner:SHANGHAI TUYOU INFORMATION TECH CO LTD

Management method and device for preventing BMS firmware from being flashed

The invention provides a management method and device for preventing BMS firmware from being flashed, and relates to the technical field of asymmetric encryption, and the method comprises the steps: generating a unique response, and reconstructing an equipment root key, so as to establish a trusted firmware execution environment and complete firmware digital signature verification; digital certificate exchange and bidirectional verification of the BMS and the diagnostic instrument are carried out in the trusted firmware execution environment, a dynamic session key is generated, and a challenge response mechanism is executed to ensure that firmware flashing operation is only authorized in the trusted communication environment; performing hash check, control flow monitoring and access auditing by using the security reference data based on the dynamic session key, performing real-time hardware processing when an exception is detected, and recording a security event at the same time; and the BMS uploads the log and attack behavior characteristics corresponding to the security event to a cloud platform, and the cloud platform analyzes and generates a detection rule or certificate revocation list and issues and updates the detection rule or certificate revocation list. Through the dynamic BMS firmware flashing protection method, the safety of the BMS firmware is improved.
Owner:XIAOGAN CORNEX NEW ENERGY INNOVATION TECHNOLOGY CO LTD

Vehicle and roadside unit mutual trust authentication and key negotiation method and device

The invention discloses a mutual trust authentication and key negotiation method for a vehicle and a roadside unit, relates to identity authentication of a communication entity of the Internet of Vehicles, and belongs to the field of information security of the Internet of Vehicles. The method comprises the following steps: presetting a trusted center key, and embedding an unclonable device into the communication entity; after the registration response is received, the communication entity stores the triad in a memory of the communication entity; the method comprises the following steps: constructing authentication messages based on an identity label, a password, a timestamp and an elliptic curve public key cryptographic algorithm of a communication entity, and realizing communication entity identity mutual trust authentication and session key negotiation through interaction of the authentication messages and verification of a to-be-verified parameter; after the identity mutual trust authentication is passed, the receiving communication entity verifies the integrity of the received key message; the trusted center can track the identity of a false message sender; and the communication entity adds the false identity of the false message sender to the incremental false identity revocation list of the false message sender to complete revocation of the false message sender, so that the authentication efficiency of the vehicle and the road side unit is improved.
Owner:CHANGZHOU INST OF TECH

Secure certificate chain transition

Some embodiments provide proxies or other servers in a computing network with independent certificate chains which facilitate mitigation of certificate problems. Independence criteria are enforced against two or more installed certificate chains on a given server, identifying and avoiding dependencies such as cross-certification, shared certificate authorities, shared revocation lists, or shared certificate status protocol endpoints between the certificate chains. Some embodiments serve independent certificates concurrently in an active-active certificate server configuration. The certificate chains' coexistence and their independence from one another facilitates transitioning the network from a failing issuer or a failed chain to a chain that works better, thereby improving network resilience and limiting damage from certificate problems. By dynamically updating certificate bindings, some embodiments also facilitate safe deployment of new certificates during migration from one issuer to another. Certificate distributions are computed from issuer ratios, network topology, or both.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Network node and control method

This network node comprises: a reception unit that acquires a certificate revocation list (CRL); a control unit that identifies a device in which a certificate has expired on the basis of the CRL, and identifies an opposing entity having said device as a communication destination; and a transmission unit that transmits, to the opposing entity, a setting for excluding said device from the communication destination.
Owner:NTT DOCOMO INC

A secure and revocable anonymous authentication method for internet of things

The application discloses a kind of enhanced security revocable anonymous authentication method of Internet of Things, including the following steps, S1: system initialization, for generating public parameters and user registration;S2: authentication between user and gateway, for identity authentication and session key establishment;S3: password update and revocation, authorized user can update password, gateway can revoke malicious user.It is beneficial to generate a pseudonym using the random number of gateway, provide a safe and effective identity privacy protection scheme, perfectly solve the problem of anonymity and message unlinkability.Add an effective revocation mechanism, when malicious user appears, gateway will record it to revocation list, and gateway does not provide key generation service for the user, so as to realize user revocation, realize identity authentication, anonymity, unlinkability, password update and revocation, etc.Security requirements such as.
Owner:ANHUI AGRICULTURAL UNIVERSITY

Revocation determination method, certificate-revocation-list creation method, non-transitory computer-readable recording medium, revocation determination system, and certificate-revocation-list creation system

A revocation determination method involves acquiring an electronic certificate, acquiring a certificate revocation list including one or more invalid certificates that are revoked electronic certificate, and determining, based on a serial number and one or more condition information items, whether the acquired electronic certificate is valid or invalid, the serial number being included in the acquired certificate revocation list, the one or more condition information items being indicated in one or more extension regions included in the acquired certificate revocation list.
Owner:PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD

Method and system for a secure platform driven root of trust (ROT) for information handling system components

A method for securely updating a firmware (FW) of a component of an information handling system (IHS) includes: receiving an update package for the component; analyzing the update package to extract at least a manifest and an FW update file associated with the component; making a first determination that the manifest is authenticated; making, based on the first determination, a second determination that a key revocation criterion is met, in which the key revocation criterion specifies that a certificate revocation list (CRL) does not specify an authentication key to be used to authenticate an updated FW of the component; updating, based on the second determination, the FW of the component using the FW update file, in which, after being updated, the component has the updated FW; and initiating notification of a user of the IHS about the updated FW of the component.
Owner:DELL PROD LP

X.509-compatible anonymous identity authentication and supervision method on a blockchain

The application provides a kind of anonymous identity authentication and supervision method on X.509 compatible blockchain, and each user party calculates the middleware that is legally held according to its own private key and the legal certificate held by itself and generates the first zero-knowledge proof;Combined with Merkle tree and accumulator, the identity certificate identification number of itself is proved to the service party that it is not in the revocation list of service party to obtain the second zero-knowledge proof, and multiple secret values and public values are generated;Request is sent to the service party and the first zero-knowledge proof, the second zero-knowledge proof and the public value are provided, and the service party is authenticated, if the three are verified, the request sent by the user party is responded to.The application uses standard X.509 specification certificate anonymous access service party Various services provide basic privacy protection, while designing a proof scheme supporting large-scale certificate revocation, greatly reducing the zero-knowledge proof overhead of generating proof not in the revocation list.
Owner:XIDIAN UNIV

Revocable attribute-based encryption method based on block chain and policy hiding

The embodiment of the invention provides a revocable attribute-based encryption method based on a block chain and policy hiding, and belongs to the technical field of data security. Comprising the following steps: constructing an access strategy, generating a symmetric key, encrypting a data file and the symmetric key, and outputting an intermediate ciphertext; replacing an access strategy in the intermediate ciphertext through a Bloom filter, outputting a final ciphertext and a ciphertext header component, and storing a hash value of the final ciphertext to a block chain BC; verifying a decryption token for applying for accessing the data file by the data user DU; if the verification is passed, judging whether the attribute set of the data user DU is in a revocation list; under the condition that the attribute set is not in the revocation list, verifying whether the attribute meets an access strategy or not; if yes, executing an outsourcing decryption operation, and returning a part of decryption result to the data user DU; verifying the correctness of the partial decryption result according to a hash value stored on the block chain BC; and if the verification is passed, final decryption is carried out to obtain a plaintext data file.
Owner:ANHUI RUIXIN SOFTWARE CO LTD +1

Revokeable access control method based on cloud-edge collaboration

The application relates to a revocable access control method based on cloud edge cooperation, which comprises the following steps: a blockchain execution system is set, and global parameters are generated; a data owner is set, and a public key and a master key are generated; an edge node executes a setting algorithm, and outputs a public key and a master key of the edge node; a user decryption key is composed of the key of the data owner and the key of the edge node; the data owner firstly executes partial encryption of data according to an access strategy and plaintext information, generates partial ciphertext, and then the edge node performs secondary encryption on the partial ciphertext to obtain final ciphertext; the blockchain performs key legality checking on the user decryption key, and the user with the key passing the checking can continue to access the data; the edge node firstly performs semi-decryption on the final ciphertext to obtain semi-decrypted ciphertext, and then the user performs final decryption on the semi-decrypted ciphertext to obtain correct plaintext; after the revocation operation is executed, the ciphertext is updated by using an updated revocation list and the key, and the updated ciphertext is stored in the cloud.
Owner:HEBEI UNIVERSITY

Mobile intelligent node dynamic networking safety control system

The invention relates to the technical field of secure communication, and discloses a mobile intelligent node dynamic networking security control system, which comprises a group division module, a key management module, a member access module, a secure communication module, a tracking and revocation module and a controller module. The group division module realizes self-adaptive stable clustering by adopting a K-Means algorithm and combining Z-score standardization on the basis of feature vectors of the speed, the position, the type and the direction of the mobile node; the key management module initializes and maintains a post-quantum lattice base group public key, a member private key and a tracking key in each cluster; the member access module completes hardware identity binding and distributes signature private keys through PUF challenge-response and zero-knowledge proof; the secure communication module performs anonymous signature and verification on the service message by adopting a quantum group signature scheme after the lattice difficulty problem; and the tracking and revocation module opens a group signature to position a signer by using the tracking key, and maintains a revocation list to timely eliminate failure nodes.
Owner:CHANGCHUN UNIV OF SCI & TECH

Method and system for safely sharing data in untrusted cloud environment

The invention discloses a method and a system for safely sharing data in an untrusted cloud environment. The method comprises the following steps: 1) when a trusted program is started for the first time, initializing a service key RKEY and a revocation list in a trusted execution environment TEE memory; encrypting the RKEY and storing the encrypted RKEY in a storage program; loading the encrypted RKEY into the TEE memory and decrypting the RKEY when the RKEY is not started for the first time, and loading the revocation list into the TEE memory and decrypting the revocation list; 2) the trusted program generates an identity ID, an identity key IKEY and an authentication report TCERT for a to-be-registered user; encrypting the IKEY by using the RKEY, and storing the encrypted IKEY in a storage program; 3) the trusted program generates an ABE master key pair for the user, and binds the MSK with the ID of the user; 4) the trusted program generates a private key SK for the user and binds the private key SK with the ID of the user; and 5) the trusted program decrypts the ciphertext by using the SK after receiving the data decryption request of the user.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

Distributed anonymous certificate authentication method supporting multiple CAs

The invention discloses a distributed anonymous certificate authentication method and device supporting multiple CAs, a medium and equipment, and the method comprises the steps: sending the identity attribute of a user to each certificate issuing mechanism, and receiving corresponding anonymous certificates generated after each distributed certificate issuing mechanism signs the identity attribute of the user which does not belong to a revocation list; sending the identity identifier of the user to a supervision mechanism, and encrypting the identity identifier by using the public key according to the supervision mechanism to determine an identity escrow ciphertext; sending each anonymous voucher to a verifier, and completing batch legality verification of each anonymous voucher together with the verifier in a zero-knowledge certification environment to obtain a message verification result of each anonymous voucher; sending the identity trusteeship ciphertext to a supervision mechanism, and determining a decryption plaintext of the supervision mechanism to the identity trusteeship ciphertext; according to the method, a distributed signing and issuing mechanism which does not need credible initialization is designed, multi-CA cooperative work is supported, a single-point fault is avoided, and the decentralization degree and robustness of the system are improved.
Owner:XIDIAN UNIV

Fine-grained data dynamic access control method based on attribute-based encryption

The invention relates to a fine-grained data dynamic access control method based on attribute-based encryption. The method comprises the steps of obtaining to-be-shared data, and performing symmetric encryption on the to-be-shared data according to a randomly generated symmetric encryption key to obtain a data ciphertext; based on an access control strategy, encrypting the symmetric encryption key by using an ABE encryption algorithm to obtain a convertible ciphertext header; in response to the obtained data access request, performing user identity verification according to a user identity public key and an access data identifier in the data access request based on a current system state version number, a revocation list and metadata of to-be-shared data in the smart contract of the block chain to obtain a verification result; and if the verification result is that the verification is passed, obtaining a corresponding convertible ciphertext header according to the access data identifier, and performing re-encryption processing on the convertible ciphertext header according to the proxy re-encryption private key, the current system state version number and the revocation list to obtain a new ciphertext header. By adopting the method, large-scale and frequent permission change can be dealt with.
Owner:侯金轩

Privacy enhancement access control method for medical data sharing

The invention discloses a privacy-enhanced access control method for medical data sharing, which is characterized in that an efficient and privacy-protected attribute revocation mechanism is innovatively added on the basis of an original decentralized multi-authority attribute verification and strategy hiding mechanism, and an attribute revocation list (ARL) based on a Merkle tree and corresponding ZKP constraints are introduced, so that the privacy-protected access control method for medical data sharing is realized. Fine-grained dynamic authorization is supported, the security problem that user permission changes along with time in a medical environment is effectively solved, and triple privacy security of user attributes, access strategies and attribute validity states is ensured. Through cooperative work of a system initialization stage, a strategy deployment stage, an access request submission stage, an access control decision stage and a data access stage, strong privacy protection, decentralized architecture, fine-grained control and dynamic authorization in medical data sharing are realized; the problems of single-point failure, privacy disclosure and strategy stiffness in a traditional scheme are effectively solved, and a safe and reliable technical basis is provided for cross-institution medical cooperation.
Owner:XINJIANG UNIVERSITY

Remote key injection method and system based on asymmetric cryptography

The invention discloses a remote key injection method and system based on asymmetric cryptography. The method comprises the following steps: establishing a three-level CA system, presetting a certificate, and strictly defining a theme identifier and an expansion key usage of the terminal certificate; both the device side and the server side verify the certificate chain and the extended key usage of the opposite side, actively acquire and verify the certificate revocation list of the intermediate CA of the opposite side, and perform anti-replay certificate state verification in combination with the OCSP; the two parties are bound with a specified communication party by comparing the certificate theme identifier with a preset authorization list; the two parties generate a temporary key pair, and an initial key is securely transmitted by adopting an asymmetric cryptography mechanism; and S4, the device end decrypts to obtain the initial key and securely stores the initial key. Through bidirectional peer-to-peer deep verification, service binding and forward security key negotiation mechanisms, the problems of insufficient authentication strength, easy replay attack, lack of forward security and poor flexibility in the prior art are solved.
Owner:FUJIAN MOREFUN ELECTRONICS TECH CO LTD

Certificate Revocation List Management Services

Operations may include receiving, from a first network entity, a first request for a first certificate revocation list (CRL) that identifies a first CRL distribution point (CDP) corresponding to the first CRL; mapping the first CDP to a first CRL identifier of a set of available CRL identifiers; locating, in a CRL repository, a first CRL based on the first CRL identifier; and transmitting the first CRL to the first network entity.
Owner:ORACLE INT CORP

Power system digital certificate state synchronization method, system and device and medium

The invention relates to the technical field of network security, and discloses an electric power system digital certificate state synchronization method, system and device and a medium, and the method comprises the steps: representing a trust list and a revoked list of an electric power system digital certificate through an OR-Set type conflict-free complex data structure, forming a trust OR-Set and a revoked OR-Set, each node in the power system network stores a corresponding copy; when the concurrent operation of adding the certificate trust and revoking the certificate exists, enabling the revoking operation to take effect preferentially; the certificate state change operation is signed and authorized through a plurality of pre-trusted authority subjects, and then is broadcasted in the power system network; and each node exchanges an incremental log of a certificate state change operation through a peer-to-peer network, so that the trust OR-Set and the revoked OR-Set of each node are kept consistent in state. According to the method, centerless and high-fault-tolerance certificate revocation and trust list synchronization can be realized in the power control network.
Owner:GUO JIA DIAN WANG YOU XIAN GONG SI XI NAN FEN BU

A method for automatic key negotiation and management of a link-layer transparent encryption device based on an identifier algorithm

This invention discloses a method for automatic key negotiation and management of link-layer transparent encryption devices based on the SM9 identifier cryptography algorithm. Addressing the problem of extremely high certificate management costs in existing link-layer transparent encryption devices that use a PKI system for key negotiation, this invention proposes a certificateless key negotiation scheme based on the SM9 identifier cryptography algorithm. This method uses a Key Generation Center (KGC) to pre-configure a private key generated from the node's identity identifier. When the sending node detects raw data packets flowing to the target intranet, it directly extracts the receiving node's identity identifier (such as the device serial number) as the public key to initiate SM9 negotiation. This invention eliminates the cumbersome certificate exchange, revocation list maintenance, and verification steps of traditional PKI systems, significantly reducing certificate management costs and negotiation message overhead while achieving implicit authentication.
Owner:BEIJING GUOLING TECH CO LTD

A non-interactive instant identity verification and secure data transmission method

The application discloses a non-interactive instant identity authentication and secure data transmission method, which generates global parameters through a trust authority and distributes them to edge terminals, an authentication center and an edge computing server, and adopts a non-interactive identity authentication technology to perform edge terminal authentication. In the authentication process, the edge terminal generates and sends instant authentication credentials to realize secure connection with the edge computing server. Hash functions and public key cryptography technology are adopted to ensure the security of communication, and a non-member proof and revocation list mechanism are adopted to prevent illegal terminals from accessing the system. Temporary symmetric keys are used for encryption between the edge terminal and the server to ensure the confidentiality and integrity of data transmission. The application has efficient identity authentication, reliable data transmission security and optimized computing and bandwidth utilization, is suitable for resource-limited edge computing scenarios, and has good security, efficiency and scalability.
Owner:SHANGHAI MARITIME UNIVERSITY +1

Cloud storage data sharing method and system supporting dynamic user group and outsourcing decryption

The invention relates to a cloud storage data sharing method and system supporting dynamic user groups and outsourcing decryption, and belongs to the technical field of information security. According to the method, a key generation center selects system security parameters, outputs system public parameters and the number of users at the same time, and generates a system main public key, a main private key, state information and a revocation list; the data user generates a public key and a private key by using a key generator (KeyGen), and sends the public key to the key generation center; the key generation center generates a conversion key according to the public key and the attribute information of the data user, and sends the conversion key to the cloud server through a public channel; meanwhile, a key updating algorithm is operated, and key updating information is broadcasted; the data owner encrypts the data, generates a ciphertext and uploads the ciphertext to the cloud server; the cloud server performs calculation outsourcing processing on the ciphertext by using the conversion key and the key updating information, and outputs the converted ciphertext; and the data user completes final decryption of the converted ciphertext by using the private key.
Owner:FUJIAN NORMAL UNIV

Management method and device for revoked certificate information, and certificate management system

The present application discloses a method and device for managing revoked certificate information, and a certificate management system. The method is applied to a certificate management system and includes: based on a streaming processing mechanism, receiving and parsing a certificate revocation list file to obtain multiple sets of corresponding organization information and revoked certificate information; converting each revoked certificate information into a specified format and storing it in a non-relational database; receiving and responding to a revoked certificate status query request sent by an application service, loading the non-relational database, retrieving and reading the target revoked certificate information corresponding to the revoked certificate status query request, and determining a query result for the target revoked certificate based on the target revoked certificate information, and returning the result to the application service, wherein the query result includes at least the certificate status of the target revoked certificate. The present application avoids the memory overflow problem caused by an overly large certificate revocation list file; improves the speed and efficiency of revoked certificate status queries; and improves the reference value of the query results.
Owner:KANG JIAN INFORMATION TECH (SHENZHEN) CO LTD

An attribute-based dual access control data sharing method for internet of vehicles

The application discloses a kind of attribute-based Internet of Vehicles dual access control data sharing methods, user generates attribute key, and proxy key is generated using attribute key;Data owner is encrypted to data using attribute-based encryption algorithm according to defined semi-hidden access structure, considering the limited computing capacity of vehicle end, and the encryption process is divided into offline and online two stages;Cloud server filters out the false information sent by malicious user;(Access control is carried out to the download request sent by the user who wants to access data, so as to refuse EDOS attack;Only the user who satisfies access policy can decrypt ciphertext, and the decryption stage is also divided into two stages of outsourcing decryption and user decryption;Malicious user is revoked, and after malicious user is revoked, only the ciphertext related to revocation list needs to be updated, without updating the entire ciphertext.The application can realize the safe data sharing in Internet of Vehicles, and promotes the wide application of vehicle network.
Owner:ANHUI UNIV

Vehicle and certificate validation method of vehicle

A certificate validation method of a vehicle may include: receiving, by a controller of a vehicle and from an external device, a certificate for authenticating the external device; and based on a determination that wireless communication is available between the controller and a certificate validation server: sending, by the controller and to the certificate validation server, the certificate without a certificate revocation list (CRL) for verification of validity of the certificate; and requesting the certificate validation server to validate the certificate without the CRL.
Owner:HYUNDAI MOTOR CO LTD +1

Industrial Internet of Things anonymous responsibility-traceable data editing method and system based on block chain

PendingCN121967028APut an end to illegal exchangesPrevent permission abuseKey distribution for secure communicationUser identity/authority verificationComputer networkEngineering
The invention belongs to the technical field of blockchain security, and discloses an industrial Internet of Things anonymous responsibility-traceable data editing method and system based on a blockchain. The method comprises the following steps: generating a chameleon Hash trap door by a trusted mechanism, splitting the chameleon Hash trap door into shares by using threshold secret sharing, distributing the shares to verifier nodes, and initializing a dynamic accumulator; the owner encrypts the production data and formulates a modification strategy, and generates a hash value and an initial voucher by using chameleon hash and uploads the hash value and the initial voucher to a chain; the modifier initiates a request containing zero-knowledge proof, after verification is passed, the verifier node generates partial vouchers by using the trap door share, and the modifier aggregates the partial vouchers into a one-time voucher to complete editing; and the trusted mechanism decrypts the identity of the malicious modifier, moves the malicious modifier out of the dynamic accumulator and updates the revocation list. According to the method, trap door leakage is prevented through a threshold sharing mechanism, zero knowledge proof and a dynamic accumulator are combined, and effective tracking and permission revocation of malicious behaviors are realized while identity privacy of a modifier is guaranteed.
Owner:ANHUI UNIV

Lattice-based fine-grained attribute encryption method supporting user and attribute double revocation

The invention discloses a lattice-based fine-grained attribute encryption method supporting user and attribute double revocation, and belongs to the technical field of information security and cryptography. The method comprises the following steps: S1, initializing a system; s2, public key distribution; s3, generating a private key; s4, encrypting and uploading the data; s5, requesting and decrypting data; s6, releasing the user revocation list; and S7, distributing the attribute revocation list. According to the method, fine-grained access control on encrypted data in a cloud environment is realized, user revocation and attribute revocation are supported at the same time, the attribute revocation does not need to re-execute a discrete Gaussian sampling algorithm to generate a user private key, and ciphertext updating is realized by cloud service without participation of an encryptor; the user revocation only needs to regenerate the ciphertext component related to the user revocation by the encryption party, and any user private key does not need to be updated; according to the double revocation mechanism, the system calculation amount and the communication burden are effectively reduced, and low-overhead and dynamic fine-grained authority management facing the cloud environment is realized.
Owner:NANJING UNIV OF SCI & TECH

A time-limited group signature method with double privacy

The application provides a time-limited group signature method with double privacy. The method comprises the following steps: a system initialization operation: generating system parameters and creating a time tree; an administrator initialization operation: the administrator generates his own public and private keys, pseudonym parameters, a register and a revocation list; a user joining a group operation: the user generates his own public and private keys, generates his own pseudonym and applies to join a group; a group certificate generation operation: the administrator issues a group certificate to the user who is approved and makes the user a group member; a group revocation operation: the administrator uses the time tree to obtain the current encryption time and verifies, and adds the group member whose time limit is invalid to the revocation list; a group signature generation operation: a message is sent to the group member, the group member signs the message and sends it to a signature verifier; a signature verification operation: the signature verifier verifies the group signature; and a signature tracker operation: if there is a dispute between the signature verifiers, the administrator is requested to arbitrate, and the administrator tracks the real identity of the corresponding group member.
Owner:HENAN UNIVERSITY

Encrypted OTA upgrading method for air conditioner controller

The invention relates to the technical field of air conditioner upgrading, and provides an encrypted OTA upgrading method for an air conditioner controller, which comprises the following steps: generating model keys corresponding to different model identifiers, constructing a multi-level intermediate key corresponding to different area identifiers and upgrading batch identifiers, pre-encrypting an original firmware package layer by layer, and updating the firmware package layer by layer; generating batch-level encrypted packets stored in a classified manner; receiving an upgrade request carrying equipment identity information, matching a target batch-level encrypted packet, issuing a dynamic revocation list abstract, generating a unique session key of a single session based on joint negotiation of an equipment random number and a cloud random number, performing block encryption on the batch-level encrypted packet, and issuing the encrypted packet; decrypting the received encrypted blocks layer by layer by using the session key and a locally stored key of a corresponding level, and restoring to obtain original firmware blocks; and writing the restored firmware into a backup partition, and executing partition switching update after determining that the new firmware has a starting condition.
Owner:GUANGDONG SANHUA VANADIUM SOUND TECH CO LTD

Vehicle and roadside unit mutual authentication and key agreement method and device

ActiveCN120378875BKey (cryptography)Password
The application discloses a vehicle and roadside unit mutual trust authentication and key negotiation method, relates to vehicle networking communication entity identity authentication, and belongs to the field of vehicle networking information security. The method pre-sets a trusted center key, and embeds an unclonable device into a communication entity. After receiving a registration response, the communication entity stores a three-tuple in a memory thereof. An authentication message is constructed based on the identity identification of the communication entity, a password, a time stamp and an elliptic curve public key cryptography algorithm. The mutual trust authentication of the identity of the communication entity and the session key negotiation are realized through the interaction of the authentication message and the verification of the to-be-verified parameters. After the mutual trust authentication of the identity is passed, the received key message is verified by the receiving communication entity. The trusted center can track the identity of a false message sender. The communication entity adds the pseudo identity identification of the false message sender to an incremental pseudo identity identification revocation list, and completes the revocation of the false message sender, thereby improving the authentication efficiency of the vehicle and the roadside unit.
Owner:CHANGZHOU INST OF TECH