Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

20 results about "Revocation list" patented technology

In cryptography, a certificate revocation list (or CRL) is "a list of digital certificates that have been revoked by the issuing certificate authority (CA) before their scheduled expiration date and should no longer be trusted".

A secure and revocable anonymous authentication method for internet of things

The application discloses a kind of enhanced security revocable anonymous authentication method of Internet of Things, including the following steps, S1: system initialization, for generating public parameters and user registration;S2: authentication between user and gateway, for identity authentication and session key establishment;S3: password update and revocation, authorized user can update password, gateway can revoke malicious user.It is beneficial to generate a pseudonym using the random number of gateway, provide a safe and effective identity privacy protection scheme, perfectly solve the problem of anonymity and message unlinkability.Add an effective revocation mechanism, when malicious user appears, gateway will record it to revocation list, and gateway does not provide key generation service for the user, so as to realize user revocation, realize identity authentication, anonymity, unlinkability, password update and revocation, etc.Security requirements such as.
Owner:ANHUI AGRICULTURAL UNIVERSITY

Method and system for a secure platform driven root of trust (ROT) for information handling system components

A method for securely updating a firmware (FW) of a component of an information handling system (IHS) includes: receiving an update package for the component; analyzing the update package to extract at least a manifest and an FW update file associated with the component; making a first determination that the manifest is authenticated; making, based on the first determination, a second determination that a key revocation criterion is met, in which the key revocation criterion specifies that a certificate revocation list (CRL) does not specify an authentication key to be used to authenticate an updated FW of the component; updating, based on the second determination, the FW of the component using the FW update file, in which, after being updated, the component has the updated FW; and initiating notification of a user of the IHS about the updated FW of the component.
Owner:DELL PROD LP

Revocable attribute-based encryption method based on block chain and policy hiding

The embodiment of the invention provides a revocable attribute-based encryption method based on a block chain and policy hiding, and belongs to the technical field of data security. Comprising the following steps: constructing an access strategy, generating a symmetric key, encrypting a data file and the symmetric key, and outputting an intermediate ciphertext; replacing an access strategy in the intermediate ciphertext through a Bloom filter, outputting a final ciphertext and a ciphertext header component, and storing a hash value of the final ciphertext to a block chain BC; verifying a decryption token for applying for accessing the data file by the data user DU; if the verification is passed, judging whether the attribute set of the data user DU is in a revocation list; under the condition that the attribute set is not in the revocation list, verifying whether the attribute meets an access strategy or not; if yes, executing an outsourcing decryption operation, and returning a part of decryption result to the data user DU; verifying the correctness of the partial decryption result according to a hash value stored on the block chain BC; and if the verification is passed, final decryption is carried out to obtain a plaintext data file.
Owner:ANHUI RUIXIN SOFTWARE CO LTD +1

Revokeable access control method based on cloud-edge collaboration

The application relates to a revocable access control method based on cloud edge cooperation, which comprises the following steps: a blockchain execution system is set, and global parameters are generated; a data owner is set, and a public key and a master key are generated; an edge node executes a setting algorithm, and outputs a public key and a master key of the edge node; a user decryption key is composed of the key of the data owner and the key of the edge node; the data owner firstly executes partial encryption of data according to an access strategy and plaintext information, generates partial ciphertext, and then the edge node performs secondary encryption on the partial ciphertext to obtain final ciphertext; the blockchain performs key legality checking on the user decryption key, and the user with the key passing the checking can continue to access the data; the edge node firstly performs semi-decryption on the final ciphertext to obtain semi-decrypted ciphertext, and then the user performs final decryption on the semi-decrypted ciphertext to obtain correct plaintext; after the revocation operation is executed, the ciphertext is updated by using an updated revocation list and the key, and the updated ciphertext is stored in the cloud.
Owner:HEBEI UNIVERSITY

Fine-grained data dynamic access control method based on attribute-based encryption

The invention relates to a fine-grained data dynamic access control method based on attribute-based encryption. The method comprises the steps of obtaining to-be-shared data, and performing symmetric encryption on the to-be-shared data according to a randomly generated symmetric encryption key to obtain a data ciphertext; based on an access control strategy, encrypting the symmetric encryption key by using an ABE encryption algorithm to obtain a convertible ciphertext header; in response to the obtained data access request, performing user identity verification according to a user identity public key and an access data identifier in the data access request based on a current system state version number, a revocation list and metadata of to-be-shared data in the smart contract of the block chain to obtain a verification result; and if the verification result is that the verification is passed, obtaining a corresponding convertible ciphertext header according to the access data identifier, and performing re-encryption processing on the convertible ciphertext header according to the proxy re-encryption private key, the current system state version number and the revocation list to obtain a new ciphertext header. By adopting the method, large-scale and frequent permission change can be dealt with.
Owner:侯金轩

Privacy enhancement access control method for medical data sharing

The invention discloses a privacy-enhanced access control method for medical data sharing, which is characterized in that an efficient and privacy-protected attribute revocation mechanism is innovatively added on the basis of an original decentralized multi-authority attribute verification and strategy hiding mechanism, and an attribute revocation list (ARL) based on a Merkle tree and corresponding ZKP constraints are introduced, so that the privacy-protected access control method for medical data sharing is realized. Fine-grained dynamic authorization is supported, the security problem that user permission changes along with time in a medical environment is effectively solved, and triple privacy security of user attributes, access strategies and attribute validity states is ensured. Through cooperative work of a system initialization stage, a strategy deployment stage, an access request submission stage, an access control decision stage and a data access stage, strong privacy protection, decentralized architecture, fine-grained control and dynamic authorization in medical data sharing are realized; the problems of single-point failure, privacy disclosure and strategy stiffness in a traditional scheme are effectively solved, and a safe and reliable technical basis is provided for cross-institution medical cooperation.
Owner:XINJIANG UNIVERSITY

Remote key injection method and system based on asymmetric cryptography

The invention discloses a remote key injection method and system based on asymmetric cryptography. The method comprises the following steps: establishing a three-level CA system, presetting a certificate, and strictly defining a theme identifier and an expansion key usage of the terminal certificate; both the device side and the server side verify the certificate chain and the extended key usage of the opposite side, actively acquire and verify the certificate revocation list of the intermediate CA of the opposite side, and perform anti-replay certificate state verification in combination with the OCSP; the two parties are bound with a specified communication party by comparing the certificate theme identifier with a preset authorization list; the two parties generate a temporary key pair, and an initial key is securely transmitted by adopting an asymmetric cryptography mechanism; and S4, the device end decrypts to obtain the initial key and securely stores the initial key. Through bidirectional peer-to-peer deep verification, service binding and forward security key negotiation mechanisms, the problems of insufficient authentication strength, easy replay attack, lack of forward security and poor flexibility in the prior art are solved.
Owner:FUJIAN MOREFUN ELECTRONICS TECH CO LTD

A method for automatic key negotiation and management of a link-layer transparent encryption device based on an identifier algorithm

This invention discloses a method for automatic key negotiation and management of link-layer transparent encryption devices based on the SM9 identifier cryptography algorithm. Addressing the problem of extremely high certificate management costs in existing link-layer transparent encryption devices that use a PKI system for key negotiation, this invention proposes a certificateless key negotiation scheme based on the SM9 identifier cryptography algorithm. This method uses a Key Generation Center (KGC) to pre-configure a private key generated from the node's identity identifier. When the sending node detects raw data packets flowing to the target intranet, it directly extracts the receiving node's identity identifier (such as the device serial number) as the public key to initiate SM9 negotiation. This invention eliminates the cumbersome certificate exchange, revocation list maintenance, and verification steps of traditional PKI systems, significantly reducing certificate management costs and negotiation message overhead while achieving implicit authentication.
Owner:BEIJING GUOLING TECH CO LTD

An attribute-based dual access control data sharing method for internet of vehicles

The application discloses a kind of attribute-based Internet of Vehicles dual access control data sharing methods, user generates attribute key, and proxy key is generated using attribute key;Data owner is encrypted to data using attribute-based encryption algorithm according to defined semi-hidden access structure, considering the limited computing capacity of vehicle end, and the encryption process is divided into offline and online two stages;Cloud server filters out the false information sent by malicious user;(Access control is carried out to the download request sent by the user who wants to access data, so as to refuse EDOS attack;Only the user who satisfies access policy can decrypt ciphertext, and the decryption stage is also divided into two stages of outsourcing decryption and user decryption;Malicious user is revoked, and after malicious user is revoked, only the ciphertext related to revocation list needs to be updated, without updating the entire ciphertext.The application can realize the safe data sharing in Internet of Vehicles, and promotes the wide application of vehicle network.
Owner:ANHUI UNIV

Vehicle and certificate validation method of vehicle

A certificate validation method of a vehicle may include: receiving, by a controller of a vehicle and from an external device, a certificate for authenticating the external device; and based on a determination that wireless communication is available between the controller and a certificate validation server: sending, by the controller and to the certificate validation server, the certificate without a certificate revocation list (CRL) for verification of validity of the certificate; and requesting the certificate validation server to validate the certificate without the CRL.
Owner:HYUNDAI MOTOR CO LTD +1

Industrial Internet of Things anonymous responsibility-traceable data editing method and system based on block chain

PendingCN121967028APut an end to illegal exchangesPrevent permission abuseKey distribution for secure communicationUser identity/authority verificationComputer networkEngineering
The invention belongs to the technical field of blockchain security, and discloses an industrial Internet of Things anonymous responsibility-traceable data editing method and system based on a blockchain. The method comprises the following steps: generating a chameleon Hash trap door by a trusted mechanism, splitting the chameleon Hash trap door into shares by using threshold secret sharing, distributing the shares to verifier nodes, and initializing a dynamic accumulator; the owner encrypts the production data and formulates a modification strategy, and generates a hash value and an initial voucher by using chameleon hash and uploads the hash value and the initial voucher to a chain; the modifier initiates a request containing zero-knowledge proof, after verification is passed, the verifier node generates partial vouchers by using the trap door share, and the modifier aggregates the partial vouchers into a one-time voucher to complete editing; and the trusted mechanism decrypts the identity of the malicious modifier, moves the malicious modifier out of the dynamic accumulator and updates the revocation list. According to the method, trap door leakage is prevented through a threshold sharing mechanism, zero knowledge proof and a dynamic accumulator are combined, and effective tracking and permission revocation of malicious behaviors are realized while identity privacy of a modifier is guaranteed.
Owner:ANHUI UNIV

A time-limited group signature method with double privacy

The application provides a time-limited group signature method with double privacy. The method comprises the following steps: a system initialization operation: generating system parameters and creating a time tree; an administrator initialization operation: the administrator generates his own public and private keys, pseudonym parameters, a register and a revocation list; a user joining a group operation: the user generates his own public and private keys, generates his own pseudonym and applies to join a group; a group certificate generation operation: the administrator issues a group certificate to the user who is approved and makes the user a group member; a group revocation operation: the administrator uses the time tree to obtain the current encryption time and verifies, and adds the group member whose time limit is invalid to the revocation list; a group signature generation operation: a message is sent to the group member, the group member signs the message and sends it to a signature verifier; a signature verification operation: the signature verifier verifies the group signature; and a signature tracker operation: if there is a dispute between the signature verifiers, the administrator is requested to arbitrate, and the administrator tracks the real identity of the corresponding group member.
Owner:HENAN UNIVERSITY

Encrypted OTA upgrading method for air conditioner controller

The invention relates to the technical field of air conditioner upgrading, and provides an encrypted OTA upgrading method for an air conditioner controller, which comprises the following steps: generating model keys corresponding to different model identifiers, constructing a multi-level intermediate key corresponding to different area identifiers and upgrading batch identifiers, pre-encrypting an original firmware package layer by layer, and updating the firmware package layer by layer; generating batch-level encrypted packets stored in a classified manner; receiving an upgrade request carrying equipment identity information, matching a target batch-level encrypted packet, issuing a dynamic revocation list abstract, generating a unique session key of a single session based on joint negotiation of an equipment random number and a cloud random number, performing block encryption on the batch-level encrypted packet, and issuing the encrypted packet; decrypting the received encrypted blocks layer by layer by using the session key and a locally stored key of a corresponding level, and restoring to obtain original firmware blocks; and writing the restored firmware into a backup partition, and executing partition switching update after determining that the new firmware has a starting condition.
Owner:GUANGDONG SANHUA VANADIUM SOUND TECH CO LTD

Gateway admission determination method and device, client device and storage medium

The embodiment of the invention discloses a gateway admission determination method and device, client equipment and a storage medium, and the method comprises the steps: transmitting a gateway admission request and a verification certificate to a verification end through a gateway admission program, and enabling the verification end to continuously use a certificate authority to verify the real-time validity of the verification certificate, the verification certificate is obtained from the server side by using a gateway access program, the verification certificate is activated by the server side in a certificate issuing mechanism according to a local feature code sent by the client device, and the local feature code is obtained by encrypting user information and device information one by one by the client device by using cascade key derivation; when the target user continuously surfs the Internet, continuously receiving a real-time validity verification result determined by the verification end according to the certificate revocation list; when the real-time validity verification result is an admission instruction, determining that the gateway admission request is admission; and when the real-time validity verification result is a security protocol alarm, determining that the real-time validity of the verification certificate is invalid, and determining that the gateway admission request is failed.
Owner:DIGITAL GUANGDONG NETWORK CONSTR CO LTD

Methods and devices for authentication and verification of non-revocation

Method and device for authentication of non-revocation. A revocation list includes at least one pair extracted from a signature generated by a revoked entity, where hi is an element of a mathematical group and ki=hixi, where xi is a secret of the revoked entity. A first entity sends, to a second entity, to authenticate itself therewith: a signature generated by the first entity for this authentication; a character string; an element of the group for each pair in the revocation list; and a zero-knowledge proof that the first entity used a secret of this first entity and the character string to obtain the group element for each pair. The second entity rejects the first entity if the zero-knowledge proof is not valid or if, for at least one the pair, the group element is such that Ci=hiA, where A is a known value.
Owner:ORANGE SA

Network security password verification method and system

The invention provides a network security password verification method and system. The method comprises the following steps: acquiring a revocation list when group members sign; determining a secret revocation voucher and a personal key pair of each group member; in response to a plurality of signature requests of any group member for the plurality of event topics, performing anti-quantum attack processing on each event topic and the personal key pair to obtain an anonymous identifier for identity authorization when the group member is signed; carrying out anti-quantum encryption on the secret revocation voucher, and carrying out zero-knowledge proof on the anonymous identifier and the legality of the encryption process based on an encryption form to obtain a group signature of a hidden group member identity; and performing revocation detection on the group signature according to the anonymous identifier and the revocation list, and revoking the signer identity when the anonymous identifier corresponds to different signature messages under the same event theme based on a revocation detection result. By adopting the scheme of the invention, group signature verification of user privacy protection can be realized under the condition of resisting quantum computing attacks.
Owner:GUANGZHOU SHENGTONG QUALITY TESTING OF CONSTR

Digital certificate verification method and system based on BBS signature

The invention relates to the technical field of information security, in particular to a digital certificate verification method and system based on a BBS signature, and is used for solving the problem that the security is reduced due to the fact that a certificate system based on the BBS signature does not support certificate revocation defects in related technologies. Querying a certificate revocation list issued by the certificate issuing end, and obtaining a user identifier of a revoked certificate and a current accumulator value from the certificate revocation list; generating a certificate state proof based on the obtained user identifier of the revoked certificate, the current accumulator value and the user identifier of the holder, and sending the certificate state proof and the current accumulator value to a verification party, so that the verification party verifies the validity of the digital certificate of the holder; therefore, the validity of the digital certificate of the holder can be verified through the certificate state certification, so that the revoked certificate can be identified in time, the system security is improved, and the certificate verification reliability is improved.
Owner:BEIJING PUSH TIMES TECH CO LTD +1

An efficient data sharing method and system supporting user revocation and key tracking

This invention belongs to, but is not limited to, the field of information security technology, and particularly relates to an efficient data sharing method and system supporting user revocation and key tracking, comprising: system initialization, where an attribute authority generates a master public key and a master private key; attribute key generation, where a data user sends a key request to the authority and receives the corresponding attribute key; data encryption, where the data owner formulates an access policy for their data and encrypts the data accordingly, then uploads the ciphertext to the cloud; update key generation, where the attribute authority generates an update key for its maintained revocation list; decryption key generation, where the data user executes to obtain the decryption key; ciphertext decryption, where users who meet the policy and have not been revoked can decrypt the data; and tracking data encryption and malicious user tracking, where any user can perform tracking encryption to complete malicious user tracking.
Owner:王文丽

A distributed anonymous credential authentication method supporting multi-ca

The application discloses a kind of distributed anonymous credential authentication methods, devices, media and equipment supporting multi-CA, by sending the identity attribute of user to each certificate issuing agency, receiving the identity attribute of user not belonging to revocation list is signed by each distributed certificate issuing agency, to generate corresponding each anonymous credential;Send the identity identifier of user to supervisory agency, determine identity hosting ciphertext according to the encryption of identity identifier using public key of supervisory agency;Send each anonymous credential to verifier, complete the batch legality verification of each anonymous credential in zero-knowledge proof environment with verifier, obtain each anonymous credential message verification result;Send identity hosting ciphertext to supervisory agency, determine the decryption plaintext of identity hosting ciphertext of supervisory agency;Finally determine whether verification passes, the application is designed without trusted initialization distributed issuing mechanism, supports multi-CA collaborative work, avoids single point failure, improves system decentralization degree and robustness.
Owner:XIDIAN UNIV

Group management method, device and electronic equipment

The application relates to a group management method and device and electronic equipment, wherein the method comprises the following steps: after a group message is published, signature information of any group member is received; the group message and the signature information are verified to obtain a first verification result, and whether fraud exists in the signature process is determined in combination with the first verification result and the group message of the group; if fraud exists, the group member corresponding to the signature information is determined, the group member is added to a revocation list, and the group member is deleted from the group. Thus, the technical problems that, in the related art, the trend of decentralized privacy protection is contrary, it is inconvenient to combine with technologies such as blockchains, the revocation cost is high, and it is difficult to trace, and the like are solved.
Owner:WUHAN UNIV