Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

4 results about "Revocation list" patented technology

In cryptography, a certificate revocation list (or CRL) is "a list of digital certificates that have been revoked by the issuing certificate authority (CA) before their scheduled expiration date and should no longer be trusted".

Method and system for a secure platform driven root of trust (ROT) for information handling system components

A method for securely updating a firmware (FW) of a component of an information handling system (IHS) includes: receiving an update package for the component; analyzing the update package to extract at least a manifest and an FW update file associated with the component; making a first determination that the manifest is authenticated; making, based on the first determination, a second determination that a key revocation criterion is met, in which the key revocation criterion specifies that a certificate revocation list (CRL) does not specify an authentication key to be used to authenticate an updated FW of the component; updating, based on the second determination, the FW of the component using the FW update file, in which, after being updated, the component has the updated FW; and initiating notification of a user of the IHS about the updated FW of the component.
Owner:DELL PROD LP

A method for automatic key negotiation and management of a link-layer transparent encryption device based on an identifier algorithm

This invention discloses a method for automatic key negotiation and management of link-layer transparent encryption devices based on the SM9 identifier cryptography algorithm. Addressing the problem of extremely high certificate management costs in existing link-layer transparent encryption devices that use a PKI system for key negotiation, this invention proposes a certificateless key negotiation scheme based on the SM9 identifier cryptography algorithm. This method uses a Key Generation Center (KGC) to pre-configure a private key generated from the node's identity identifier. When the sending node detects raw data packets flowing to the target intranet, it directly extracts the receiving node's identity identifier (such as the device serial number) as the public key to initiate SM9 negotiation. This invention eliminates the cumbersome certificate exchange, revocation list maintenance, and verification steps of traditional PKI systems, significantly reducing certificate management costs and negotiation message overhead while achieving implicit authentication.
Owner:BEIJING GUOLING TECH CO LTD

Digital certificate verification method and system based on BBS signature

The invention relates to the technical field of information security, in particular to a digital certificate verification method and system based on a BBS signature, and is used for solving the problem that the security is reduced due to the fact that a certificate system based on the BBS signature does not support certificate revocation defects in related technologies. Querying a certificate revocation list issued by the certificate issuing end, and obtaining a user identifier of a revoked certificate and a current accumulator value from the certificate revocation list; generating a certificate state proof based on the obtained user identifier of the revoked certificate, the current accumulator value and the user identifier of the holder, and sending the certificate state proof and the current accumulator value to a verification party, so that the verification party verifies the validity of the digital certificate of the holder; therefore, the validity of the digital certificate of the holder can be verified through the certificate state certification, so that the revoked certificate can be identified in time, the system security is improved, and the certificate verification reliability is improved.
Owner:BEIJING PUSH TIMES TECH CO LTD +1

An efficient data sharing method and system supporting user revocation and key tracking

PendingCN122293361AGuaranteed traceabilitytraceableInternet privacyEngineering
This invention belongs to, but is not limited to, the field of information security technology, and particularly relates to an efficient data sharing method and system supporting user revocation and key tracking, comprising: system initialization, where an attribute authority generates a master public key and a master private key; attribute key generation, where a data user sends a key request to the authority and receives the corresponding attribute key; data encryption, where the data owner formulates an access policy for their data and encrypts the data accordingly, then uploads the ciphertext to the cloud; update key generation, where the attribute authority generates an update key for its maintained revocation list; decryption key generation, where the data user executes to obtain the decryption key; ciphertext decryption, where users who meet the policy and have not been revoked can decrypt the data; and tracking data encryption and malicious user tracking, where any user can perform tracking encryption to complete malicious user tracking.
Owner:王文丽