Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

66 results about "Root certificate" patented technology

In cryptography and computer security, a root certificate is a public key certificate that identifies a root certificate authority (CA). Root certificates are self-signed and form the basis of an X.509-based public key infrastructure (PKI). Either it has matched Authority Key Identifier with Subject Key Identifier, in some cases there is no Authority Key identifier, then Issuer string should match with Subject string (RFC5280). For instance, the PKIs supporting HTTPS for secure web browsing and electronic signature schemes depend on a set of root certificates.

Real estate full life cycle intelligent management method and system based on Internet of Things perception

The invention provides a real estate full life cycle intelligent management method and system based on Internet of Things perception, and the method comprises the steps: distributing a unique hardware identifier of equipment, combining a lightweight digital certificate with a pre-shared key to achieve two-factor authentication, and storing a root certificate in a cloud end; an access authentication process is optimized, an identity label and a certificate signature request need to be submitted when a node accesses for the first time, a temporary session key is generated after the gateway verifies, and abnormal access is immediately isolated and reported; data integrity verification is implemented, and after a sensor collects data, an abstract is generated and data encryption transmission is carried out; after decryption, the receiving end recalculates the abstract for comparison, and if not, the abstract is discarded and nodes are marked to be abnormal; a data anomaly detection model is constructed, energy consumption fluctuation is determined based on historical data, a frequency baseline is collected, data reasonability is monitored in real time, secondary authentication is triggered when the data is abnormal, and node data access is suspended if the data fails; a hierarchical key system is established, hardware is solidified by a root key, session keys are alternated for 24 hours, and data encryption keys are dynamically derived and distributed through encryption channels.
Owner:LERUAN CENTURY (BEIJING) INFORMATION TECHNOLOGY CO LTD

Document printing and traceability tracking system based on block chain

The invention relates to the technical field of block chain data storage and traceability tracking, in particular to a document printing and traceability tracking system based on a block chain. Comprising an off-line certificate generation unit used for generating an off-line cryptographic certificate based on technical parameters analyzed from an external printing request; the dynamic anchoring control unit is used for monitoring system state parameters and carrying out dynamic anchoring strategy calculation based on the system state parameters so as to generate an anchoring triggering decision; the aggregation anchoring unit is used for responding to the anchoring triggering decision, aggregating a plurality of offline cryptographic certificates to generate an aggregation root certificate, and broadcasting a block chain transaction containing the aggregation root certificate; and the verification traceability unit is used for acquiring the aggregation root certification on the block chain and executing cryptographic verification in combination with the offline data to obtain a final verification result. According to the invention, the core pain point that the system is unavailable due to the performance bottleneck of the block chain in a high-concurrency scene in the prior art is solved, and the continuity and reliability of services are ensured.
Owner:北京微点科学技术有限公司

Systems and methods for streamlined platform component attestation

Systems and methods for streamlined platform attestation are described. In an illustrative, non-limiting embodiment, an Information Handling System (IHS) may include a processor and a memory coupled to the processor. The memory may have program instructions stored thereon that, upon execution, cause the IHS to: read root certificates for a plurality of components of the IHS; and embed the root certificates for the plurality of components into a platform certificate.
Owner:DELL PROD LP

Network access control method, apparatus and device, and storage medium

Embodiments of the present disclosure relate to a network access control method, apparatus and device, and a storage medium. The network access control method includes: receiving a certificate verification request sent by a terminal, and returning a certificate verification response to the terminal, wherein the certificate verification response carries a preset server certificate, the certificate verification response is used for instructing the terminal to verify the preset server certificate based on a root certificate installed in the terminal, and identity verification information of the root certificate is partially or fully different from identity verification information of the preset server certificate; and receiving a verification result returned by the terminal for the preset server certificate, and in a case where the verification result indicates that certificate verification succeeds, determining that the terminal has a security risk and interrupting a network access communication link of the terminal. In the embodiments of the present disclosure, when the terminal successfully verifies the preset server certificate, the terminal may be prevented from accessing a network by interrupting the network access communication link with the terminal, thereby improving the security of the network.
Owner:DOUYIN VISION CO LTD

Ca consensus method, apparatus, and node

Provided are a CA consensus method, an apparatus, and a node. The method comprises: obtaining a final voting result for a voting event on the basis of voting results of a plurality of first CAs; and when the final voting result indicates that the voting event passes, executing a first operation, wherein the first operation comprises registration of a CA, revocation of a CA, or update of a root certificate. In this way, a decision can be jointly made by a plurality of CAs without relying on a central CA, thereby improving the degree of decentralization of DPKI systems, and thus improving the overall security of the DPKI systems.
Owner:HUAWEI TECH CO LTD

Hierarchical certificate issuing system, method, device and equipment

PendingCN121864327AUser identity/authority verificationRoot certificateCertificate signing request
The invention provides a hierarchical certificate issuing system, method, device and equipment, and the system comprises root CA equipment, strategy CA equipment and certificate issuing CA equipment: the root CA equipment is used for generating a self-signature root CA certificate based on a root CA key pair, and carrying out the signature of a strategy CA certificate signature request of the strategy CA equipment through employing a root CA private key, and obtaining the strategy CA certificate; the policy CA equipment is used for acquiring a policy CA certificate from the root CA equipment and signing a certificate issuing CA certificate signature request of the certificate issuing CA equipment by adopting a policy CA private key to obtain the certificate issuing CA certificate; the certificate issuing CA equipment is used for acquiring a certificate issuing CA certificate from the policy CA equipment and signing a terminal certificate signature request of the terminal equipment by adopting a certificate issuing CA private key to obtain a terminal entity certificate; and the certificate issuing CA equipment is also used for sending a certificate chain to the terminal equipment, and the certificate chain comprises a self-signature root CA certificate, a policy CA certificate, a certificate issuing CA certificate and a terminal entity certificate.
Owner:BEIJING CHUANGRUI HONGKE TECHNOLOGY CO LTD

Real estate registration method and system based on block chain

The invention relates to the technical field of real estate registration, and discloses a real estate registration method and system based on a blockchain, and the system comprises a data collection module, a data encryption module, a blockchain storage module, and an information verification module.In the aspect of data security, public key encryption and private key decryption mechanisms effectively guarantee data privacy and security, and the data security is improved. Stealing and tampering are prevented; in terms of data integrity, block hash values are compared through an information verification module, whether transmission data are changed or not is accurately judged, and completeness and reliability of the transmission data are ensured; the identity verification checks the signature validity by means of a digital certificate and a root certificate, constructs a security trust system, and prevents illegal operation; the multi-node alliance reduces the single-point fault risk, and the data change history can be checked to facilitate audit supervision; on the whole, the transparency, the fairness and the credibility of real estate registration are improved, the registration process is optimized, the processing capacity and the response speed are improved, the pain point of a traditional mode is solved, and efficient and healthy development of real estate registration business is promoted.
Owner:临沂润恒信息科技有限公司

WAPI identification method and device for multiple root certificates, computer equipment, readable storage medium and program product

The invention relates to a WAPI identification method and device for multiple root certificates, computer equipment, a readable storage medium and a program product. The method comprises the following steps: receiving a certificate authentication request message; carrying out certificate authentication on the digital certificate of each WAPI wireless network device to generate a certificate authentication result; under the condition that the AS root certificates corresponding to the digital certificates of the WAPI wireless network devices are different, private keys corresponding to the AS root certificates corresponding to the digital certificates of the WAPI wireless network devices are obtained, and according to the private keys corresponding to the WAPI wireless network devices, double signature is carried out on the certificate identification result, and double signature information of the certificate identification result is generated; and sending an identification response message to the WAPI wireless network equipment. By adopting the method, wireless access authentication can be successfully completed under the condition that different AS root certificates are installed on different WAPI wireless network devices, so that the WAPI wireless network can be successfully accessed.
Owner:SHENZHEN ZHIKAI TECH CO LTD

CA root certificate issuing method or device based on block chain

The invention discloses a block chain-based CA root certificate issuing method or device, and the method comprises the steps: carrying out the registration or maintenance of a CA mechanism with an electronic authentication permission through a registration ECP method; then, certificate data are written in batches through a certificate writing method, certificate content and an electronic authentication license number ECP to which the certificate content belongs are stored by taking a CA root certificate serial number SN as a unique index, and the global certificate number, the certificate number under the ECP and an SN list are synchronously maintained when the certificate is written for the first time; the CA root certificate revocation state is independently managed through a revocation management method, revocation information is only recorded in state mapping, certificate main body data is not affected, and therefore efficient state change is achieved. In the query stage, the certificate content, the affiliated ECP and the CA name can be obtained based on the SN, the CA root certificate serial number set, the certificate number and the global ECP number corresponding to the ECP can also be queried based on the ECP, and the whole process does not need to traverse data on the chain.
Owner:CHENGDU BITWELL TECH CO LTD

Certificate query method and device based on edge node, equipment, medium and product

The invention relates to the field of block chains, and provides a certificate query method and device based on edge nodes, equipment, a medium and a product. The method comprises the following steps: receiving registration transaction information initiated by an authoritative certification authority; under the condition that the pre-verification of the registration transaction information is passed, sending the root certificate to the distributed public key infrastructure block chain, and receiving a registration completion response fed back by the distributed public key infrastructure block chain; under the condition that the registration completion response passes verification, after the registration completion response is fed back to the authority authentication mechanism, the authority authentication mechanism issues an entity certificate and feeds the entity certificate back to the network element; receiving a certificate verification request sent by the network element; and carrying out certificate query according to the certificate verification request, and determining a certificate query result. According to the certificate query method based on the edge node, a bridge is built through the edge node, and during certificate query, the network element securely accesses the distributed public key infrastructure through the edge node, so that the query efficiency is improved.
Owner:CHINA MOBILE COMM LTD RES INST +1

CA consensus method, device and node

The invention provides a CA consensus method, a CA consensus device and a node. Wherein the final voting result of the voting event is obtained based on the voting results of the plurality of first CAs; under the condition that the final voting result indicates that the voting event passes, executing a first operation; wherein the first operation comprises CA registration, CA logout or root certificate updating. Thus, the decentralization degree of the DPKI system can be improved through co-determination of a plurality of CAs without relying on a central CA, and the overall safety of the DPKI system is further improved.
Owner:HUAWEI TECH CO LTD

Methods and systems for ensuring trust between entities

This technology simplifies the management of information used to authenticate communication partners. [Solution] The first entity possesses a first identity certificate, and the second entity possesses a second identity certificate. The root certificate authority generates a first relationship certificate between the first entity and the first group. The first entity stores the first relationship certificate. The first entity sends the first identity certificate and the first relationship certificate to the second entity as a first communication. The second entity verifies that the first identity certificate and the first relationship certificate were legitimately created by the root certificate authority. Based on the verification of the first identity certificate and the first relationship certificate by the second entity, the second entity or the first entity activates a predetermined function.
Owner:DENSO CORP

Certificate issuing method and device of PKI trust model, equipment and medium

The invention discloses a certificate issuing method and device of a PKI trust model, equipment and a medium, and relates to the technical field of information security, and the method comprises the steps: determining a target signature algorithm of each certificate authority according to the business characteristics of the certificate authority and the position of the certificate authority in the trust level of the PKI trust model; generating a self-signature root certificate based on a target signature algorithm through the root certificate issuing mechanism; when a certificate is applied to a parent certificate issuing mechanism, a first signature public key determined based on a target signature algorithm is sent to the parent certificate issuing mechanism through an intermediate certificate issuing mechanism, so that the first signature public key is authenticated and signed to complete certificate issuing; and the information of the terminal user is authenticated and signed through the final-stage certificate issuing mechanism, and a second signature public key generated based on the target signature algorithm is sent to the intermediate certificate issuing mechanism, so that the second signature public key is authenticated and signed, and certificate issuing is completed. Therefore, the certificate can be signed and issued conveniently and flexibly.
Owner:CETC CYBERSPACE SECURITY TECH CO LTD

An efficient generation and synchronization method of multi-node Kubernetes cluster self-sign root certificate based on Etcd distributed lock

The application relates to the field of cloud native technology, in particular to a multi-node Kubernetes cluster self-signed root certificate efficient generation and synchronization method and system based on an Etcd distributed lock, which comprises the following steps: an Etcd service, a certificate synchronization component service, certificate generation and synchronization, generating certificate content according to configuration and storing the certificate content in an Etcd database in an encrypted mode, and listening to Etcd database changes, synchronously updating certificate data and storing the certificate data in a local mode in a decrypted mode; beneficial effects are that through the introduction of the Etcd distributed lock technology, the generation and synchronization of the multi-node concurrent self-signed root certificate are realized. Multiple nodes can simultaneously generate the certificate, and the generated certificate information can be shared and synchronized in real time through the Etcd database. The parallel processing mode greatly shortens the waiting time of cluster deployment and significantly improves the deployment efficiency.
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

Role-based authorization for wireless network management services

Technology for mesh network management including role-based authorization for wireless network management services is described. In one embodiment, a wireless mesh device receives, from a requesting device, a request to establish a secure communication session, authenticates the client certificate and establishes the secure communication session. The wireless mesh device further receives, from the requesting device via the secure communication session, a request directed to a service of a plurality of services provided by the wireless mesh device, where the request comprises the client certificate associated with the requesting device, identifies a root certificate used to cryptographically sign the client certificate, wherein the root certificate is associated with a role assigned to the requesting device, identifies role information associated with the requesting device and the client certificate, and responsive to determining that the role information indicates that the requesting device has permission to access the service, forwards the request to the service.
Owner:AMAZON TECH INC

Electronic device, control method, and non-transitory computer-readable storage medium

An electronic device includes a control unit configured to, in a case where connection between the electronic device and a first server outside the electronic device is to be started, control to execute first transmission processing of transmitting, to the first server, information for requesting start of communication by a predetermined protocol for performing encrypted communication, and if the communication by the predetermined protocol is started between the electronic device and the first server based on the first transmission processing, control to execute first reception processing of receiving, from the first server, second root certificate data for verifying certificate data from a second server different from the first server even without an operation from a user after execution of the first transmission processing.
Owner:CANON KK

Method and device for flashing upgrade package of vehicle

The invention provides a method and a device for flashing an upgrade package of a vehicle, and relates to the technical field of vehicles, in response to the condition that a supplier passes multiple authentications, vulnerability scanning is performed on the upgrade package uploaded by the supplier, if the vulnerability scanning is not abnormal, encryption processing is performed on the upgrade package through a random secret key to obtain encrypted upgrade content, and the encrypted upgrade content is sent to the vehicle. The upgrade package and the random secret key are signed based on a Hash algorithm and a PKI system to obtain an abstract value, an encryption secret key and an upgrade package certificate; transmitting an encrypted upgrade package formed by combining the encrypted upgrade content, the abstract value, the encryption key and the upgrade package certificate to a main node corresponding to the upgrade scene, so that the main node performs certificate chain verification based on a preset root certificate and the upgrade package certificate; and if the hash algorithm verifies that the corresponding first hash value after the abstract value is unsigned is consistent with the second hash value corresponding to the original upgrading content, executing upgrading. Therefore, reliable updating of the vehicle system in a complex upgrading environment is guaranteed.
Owner:LIUZHOU WULING NEW ENERGY VEHICLE CO LTD

Postponed certificate credential installation to wireless devices

This application describes techniques for postponed certificate credential installation to wireless devices, including generation and storage of secured scripts to be used for subsequent certificate credential installation on an eUICC of a wireless device after manufacturing. Management of certificate credentials, including installation on, modification to, and removal from, an eUICC can occur post-manufacturing, such as during a device activation procedure or as part of remote electronic subscriber identity module (eSIM) provisioning to the eUICC of the wireless device. Updating certificate credentials on an eUICC can allow for wireless device operation in different geographic regions that use different public key infrastructures (PKIs) with distinct root certificate issuers. The secured scripts can be pre-generated by an eUICC manufacturer (EUM) for the particular eUICC and stored at an OEM networked server and later used to install the certificate credentials on the eUICC of the wireless device.
Owner:APPLE INC

Call method and device of bluetooth device, bluetooth device and medium

The application discloses a call method and device of a Bluetooth device, the Bluetooth device and a medium. Through application of the technical solution of the application, after two Bluetooth devices establish a voice connection, the two Bluetooth devices do not transmit audio data at the first time, but verify the authenticity of device information and user information of the other party according to the pre-stored device manufacturer root certificate and service provider root certificate of each Bluetooth device. And only in the case of determining the authenticity, the encrypted audio data is transmitted to the other party to formally start the call function of the two parties. Further, on the one hand, the purpose of detecting the authenticity of the identity of the user at the other end by using a multi-channel mode is achieved. On the other hand, the problem that security information is stolen due to malicious user attacks in Bluetooth call technology existing in the related art is avoided.
Owner:BEIJING WATCH DATA SYSTEM CO LTD

Lightweight authentication method for quantum digital certificate

The invention discloses a lightweight authentication method for a quantum digital certificate, which comprises the following steps: S1, a client initiates an authentication request to a unified authentication service, and the authentication request contains authentication information based on the quantum digital certificate; s2, the unified authentication service receives the authentication request, and sends the ciphertext or signature data needing key operation and the quantum key identifier to a quantum secret service system; s3, according to the received quantum key identifier, the quantum secret service system indexes and calls a corresponding quantum key in a safe internal environment, and performs decryption or signature verification operation on the ciphertext or signature data; the method has the beneficial effects that the true random key is generated by using the quantum key entropy source, the quantum computing-resistant trust chain is constructed from the root certificate level, and in the authentication process, the transmitted quantum key identifier is not the key itself but has no computing significance, so that the risk that the key is intercepted in transmission and is used for reverse cracking is avoided.
Owner:FUJIAN NEW WORLD HUICHUANG TECH CO LTD

Distributed security authentication method and device for device identity, device and storage medium

The invention provides a distributed security authentication method and device for an equipment identity, equipment and a storage medium, and the method comprises the steps: determining that a first manufacturer to which the own equipment belongs and a second manufacturer to which the to-be-authenticated equipment belong have accessed the same decentralized identity platform in response to an instruction that the own equipment performs identity authentication on the to-be-authenticated equipment; obtaining a to-be-authenticated device certificate corresponding to a to-be-authenticated device and a root decentration identifier registered in the decentration identity platform by a second manufacturer in advance; and based on the root decentration identifier and the decentration identity platform, authenticating the certificate of the to-be-authenticated device. According to the method and the device, the corresponding root decentration identifier is only registered for the root certificate issuing mechanism of the second manufacturer corresponding to the to-be-authenticated device, and the decentration identifier does not need to be issued to each device, so that the complexity of device identity operation and maintenance is reduced.
Owner:深圳开鸿数字产业发展有限公司

Secure starting method and related equipment

The invention discloses a safe starting method and related equipment, and the safe starting method comprises the steps: responding to a detected preset safe starting condition, employing a national root certificate preset in a processor to carry out the trusted measurement of an intermediate root certificate, and enabling the intermediate root certificate to be stored in an external storage space of the processor; when the trusted measurement of the intermediate root certificate is passed, the intermediate root certificate is adopted to carry out trusted measurement on an intermediate application certificate, and the intermediate application certificate is stored in an external storage space of the processor; when the trusted measurement of the intermediate application certificate is passed, the intermediate application certificate is adopted to carry out trusted measurement on the user certificate, and the user certificate is stored in an external storage space of the processor; when the trusted measurement of the user certificate is passed, adopting the user certificate to carry out trusted measurement on the basic input / output system; and when the trusted measurement of the basic input and output system passes, running the basic input and output system. According to the technical scheme of the invention, the reliability, credibility and authority of trust chain verification can be improved.
Owner:HYGON YUNXIN INTEGRATED CIRCUIT DESIGN (SHANGHAI) CO LTD

A communication encryption method, system, storage medium and electronic device

The present disclosure belongs to the technical field of communication, and provides a communication encryption method, system, storage medium and electronic device. The method comprises the following steps: taking a TPM chip as a root of trust, and establishing a root CA certificate; establishing a sub-CA under the root CA; creating a symmetric key by using the TPM chip, and calculating an HMAC value of the root CA and HMAC values of all sub-CAs; according to a sub-CA to which a management and control system or a device belongs, sending a corresponding terminal certificate and an HMAC value of the terminal certificate to the management and control system or the device; receiving an HMAC value of a device certificate required to establish a connection, and comparing the HMAC value with a theoretical HMAC value of the device certificate calculated or saved; when a comparison result meets a preset condition, sending a management and control system certificate and an HMAC value of the management and control system certificate to the device; receiving an HMAC value of the management and control system certificate returned by the management and control system, and comparing the HMAC value with a theoretical HMAC value of the management and control system certificate calculated or saved; and when a comparison result meets a preset condition, the device successfully establishes a connection. The above method improves security and connection efficiency.
Owner:FIBERHOME TELECOMMUNICATION TECHNOLOGIES CO LTD

Securing communication with security processors using platform keys

A computer platform comprises a security processor, at least one hardware processor, and memory. The security processor stores data representing a private platform key. The private platform key is part of an asymmetric key pair, and the asymmetric key pair contains a public platform key. The memory stores a firmware image. The firmware image contains data representing a root certificate of a public key infrastructure that signs a second certificate associated with the computer platform. The second certificate contains the public platform key and binding information that binds the second certificate to the computer platform.The firmware image contains instructions that, when executed by the hardware processor(s), cause the hardware processor(s) to access data representing the second certificate and, based on the root certificate and binding information, determine whether the second certificate is valid. Furthermore, when executed by the hardware processor(s), these instructions, in response to the determination that the second certificate is valid, cause the hardware processor(s) to use the public platform key to secure communication with the security processor.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Modbus serial link secure communication method, device and equipment

The invention relates to the technical field of link communication, and discloses a Modbus serial link safety communication method, device and equipment, and the method comprises the steps: receiving a first certificate chain of slave station equipment, verifying a slave station brand certificate in the first certificate chain according to a first root certificate, and when the verification result is that the slave station brand certificate in the first certificate chain passes, carrying out the verification of the slave station brand certificate based on the slave station equipment certificate in the first certificate chain; generating a master key and a corresponding encapsulation key ciphertext; sending the encapsulation key ciphertext, the encryption and decryption mode of the master station equipment and the second certificate chain to slave station equipment, so that the slave station equipment verifies the second certificate chain, and decrypts the encapsulation key ciphertext based on a private key of the slave station equipment to obtain a master key; and encrypting the protocol data unit based on the master key, and sending the encrypted protocol data unit to the slave station equipment. A two-way verification mechanism based on a certificate chain is introduced into a Modbus serial link, a security sublayer can be embedded on the premise of not changing an original frame structure and a communication process, the security of the Modbus serial link is improved, and the cost is low.
Owner:PENG CHENG LAB

Web portal service that supports establishing and maintaining a websocket connection

PCT designated stageWO2026137376A1Root certificateWebSocket
A method and computer program product provide operations for establishing and maintaining a WebSocket connection. A web portal receives a uniform resource locator (URL) from a system management application (SMA), provides the URL to the BMC, and exchanges the root certificates of the BMC and SMA, provides the same Time-based One-Time Password (TOTP) algorithm and TOTP key to both the BMC and SMA, and supports synchronization of clocks maintained by the BMC and SMA. Both the BMC and SMA use the TOTP algorithm to compute a TOTP value as a function of the TOTP key and a current time value. If the BMC and SMA pass mutual authentication and TOTP value verification, then the WebSocket connection is established. The web portal periodically replaces the TOTP algorithm and key, such that the WebSocket connection is maintained by periodically performing the TOTP value verification.
Owner:LENOVO GLOBAL TECH (TAIWAN) LTD

Secure onboarding of a component in a network

A method for providing a secure onboarding of a component from at least one first host device into a second host device includes verifying the integrity, authenticity and / or execution environment of the first host device by an orchestrator; providing a trusted root certificate to the second host device by the orchestrator; providing an onboarding identity by the orchestrator to the first host device, when the integrity, the authenticity and / or the execution environment of the first host device has been verified; receiving the onboarding identity from the orchestrator by the first host device and assigning the onboarding identity to the component; providing the assigned onboarding identity to the second host device; and securely onboarding the component from the first host device into the second host device based on the assigned onboarding identity and the provided trusted root certificate.
Owner:ABB (SCHWEIZ) AG

Wireless ad hoc network quantum security authentication method and related device

The invention belongs to the field of wireless ad hoc networks, and discloses a wireless ad hoc network quantum security authentication method and a related device, in a master station mode, a quantum protection key is written into equipment offline and is used for encrypting a one-time quantum authentication key, and symmetric challenge-response authentication is realized through ciphertext transmission and decryption; in the independent mode of the device, the device generates quantum random public and private keys and requests for a digital certificate, the server signs with a root certificate and then distributes, and certificate exchange and challenge-response authentication are supported. By adopting the method, the network security is remarkably improved, illegal access and data leakage are effectively prevented, stable operation of the key information infrastructure is ensured, the authentication reliability is enhanced, and different deployment requirements are met.
Owner:ZHONGSHAN XINTONG COMM CO LTD

Methods for encrypting data transmission

The present invention relates to a method for encrypting the transmission (10) of data between terminals (14, 16), wherein, before transmitting the data, a verification certificate (Z*) is created and transmitted to a backend (12), and the verification certificate is signed by a root certificate (Z) in the backend (12), the signed verification certificate (Z**) is sent back to a second terminal (16), the public second digital key of the signed verification certificate (Z**) is transmitted to a first terminal (14), and verification is performed using the public second digital key (S2), wherein, during the verification, an encrypted unique symmetric session key (S*) is generated, which is transmitted to the second terminal (16) and decrypted using the private key of the signed verification certificate (Z**), wherein, in the event of verification failure, the first terminal (14) is notified, or in the event of successful verification, the data is decrypted using the session key (S*).
Owner:MERCEDES BENZ GRP

Cryptographically authenticated database representing a multiple-key-pair root certificate authority

In a general aspect, a cryptography system includes a multiple-key pair root certificate authority. In some aspects, a plurality of distinct cryptographic pairs of public keys and private keys of a root certificate authority are generated. A plurality of distinct self-signed root certificates of the root certificate authority are generated. The plurality of distinct self-signed root certificates are each based on and correspond to a respective one of plurality of distinct cryptographic key pairs. A cryptographically authenticated database is generated that includes the plurality of distinct self-signed root certificates and represents the root certificate authority. The cryptographically authenticated database includes validity information of each of the plurality of self-signed root certificates. The cryptographically authenticated database is distributed to entities in a public key infrastructure. The entities can use the validity information to cryptographically verify the validity or invalidity of each of the plurality of distinct self-signed root certificate.
Owner:ISARA CORP