Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

108 results about "Transport Layer Security" patented technology

Transport Layer Security (TLS), and its now-deprecated predecessor, Secure Sockets Layer (SSL), are cryptographic protocols designed to provide communications security over a computer network. Several versions of the protocols find widespread use in applications such as web browsing, email, instant messaging, and voice over IP (VoIP). Websites can use TLS to secure all communications between their servers and web browsers.

Systems and methods for implementing a service identity platform with cloud-based Public Key Infrastructure (PKI)

Systems and methods for implementing a service identity platform with cloud-based Public Key Infrastructure (PKI) include providing security as a service via a cloud-based system for a plurality of tenants, wherein the cloud-based system includes a plurality of components communicatively coupled and adapted to communicate with one another based on mutual Transport Layer Security (mTLS) authentication; responsive to a new component requiring deployment within the cloud-based system, performing an enrollment process for the new component; and subsequent to the enrollment process, utilizing the new component within the cloud-based system for providing security as a service.
Owner:ZSCALER INC

System, method, device and equipment for safe communication between charging pile and BMS and storage medium

The invention relates to the field of electric vehicle charging control, and particularly provides a system, method, device and equipment for safe communication between a charging pile and a BMS and a storage medium, the system comprises a bidirectional authentication module, a communication encryption module, a verification module and an optimization module; the bidirectional authentication module is used for constructing a bidirectional authentication protocol between the charging pile and a battery management system (BMS) based on the hardware security module and authenticating the identity; the communication encryption module is used for customizing an integrated transport layer security protocol line through an open source tool and encrypting security communication data; the verification module is used for designing a three-level verification mechanism, blocking a malicious firmware injection path and verifying a secure communication process; and the optimization module is used for optimizing the key process by adopting a redundant backup scheme deployed in a containerization manner. Through the system, the effect of a safe communication process between the charging pile and the BMS can be realized.
Owner:CHINA FAW CO LTD

AI-driven transport layer security protocol adaptive optimization system

The invention discloses an AI-driven transport layer security protocol adaptive optimization system, which relates to the technical field of traffic data access and comprises a data access module, a state sensing module, a risk assessment module, an optimization transmission module and an adaptive encryption module. The data access module is used for capturing an original data flow from a network and a host in real time; the state sensing module is used for receiving the original data stream and setting a feature engineering state index; the risk assessment module is used for quantitatively assessing the safety score of the current state according to the current traffic environment state; the self-adaptive encryption module is used for constructing a password strategy library and generating an encryption configuration strategy according to a current traffic state; and the optimization transmission module is used for constructing a parameter intelligent optimization model and controlling algorithm interaction to generate performance scheduling optimization actions.
Owner:BEIJING XINDA WANGAN INFORMATION TECH CO LTD

API invoker authentication method and apparatus, communication device, and storage medium

A method for authenticating an application program interface (API) invoker enhances secure communication between API invokers and a Common Application Program Interface Framework (CAPIF). The method involves sending authentication information from the API invoker to the CAPIF function, which authenticates the invoker's identity. The process includes obtaining enrollment information to establish a secure transport layer security (TLS) connection with the CAPIF function. Advanced authentication mechanisms leverage an authentication and key management for applications (AKMA) anchor key, enabling secure derivation and verification of application function keys (KAF). Additionally, the CAPIF function uses received authentication data to retrieve API invoker configuration information, onboard signing keys, and certificates. These elements facilitate secure API access and interaction while ensuring compliance with authentication protocols.
Owner:BEIJING XIAOMI MOBILE SOFTWARE CO LTD

Systems and methods facilitating connection of browsers having different transport layer security versions using a reverse proxy server

Aspects of the subject disclosure may include, for example, deploying a reverse proxy server in front of a first type of web servers and a second type of web servers, where the first type of web servers is compliant with a current version of payment card industry data security standard (PCI DSS) and supports a first version of a transport layer security (TLS) protocol, and where the second type of web servers supports one or more TLS protocols that are older than the first version of TLS protocol, detecting, using the reverse proxy server, a TLS protocol version used in an incoming request, and determining, using the reverse proxy server, routing of the incoming request to one of the first type of web servers and the second type of web servers at least based on the detected TLS protocol version. Other embodiments are disclosed.
Owner:AT&T INTELLECTUAL PROPERTY I L P

Quantum-resistant security enhancement method for transport layer security protocol

A quantum-resistant security enhancement method for a transport layer security protocol, comprising: (011) acquiring a first quantum key and a quantum key identifier from a serving node; (012) performing post-quantum cryptographic encryption on the quantum key identifier to obtain a first encryption result, and sending the first encryption result to a network device; (013) decrypting a received second encryption result to obtain a second decryption result; (014) obtaining a first terminal handshake key and a first network device handshake key on the basis of the first encryption result and the second decryption result; and (015) generating a second terminal handshake key and a second network device handshake key on the basis of the first quantum key, the first terminal handshake key, the first network device handshake key, the first encryption result and the second decryption result, so as to encrypt communication between the terminal and the network device.
Owner:CHINA TELECOM QUANTUM INFORMATION TECH GRP CO LTD

Application certificate provisioning process using connected vehicle

An example operation includes one or more of establishing a secure channel between a host platform and a vehicle based on a transport layer security (TLS) handshake between the host platform and the vehicle, downloading an authorization code to the vehicle through the secure channel between the host platform and the vehicle, receiving the authorization code from a mobile application installed on a mobile device, generating a mobile application certificate for the mobile device and transmitting the mobile application certificate to the mobile application on the mobile device, and establishing a secure connection between the host platform and the mobile application on the mobile device based on the mobile application certificate.
Owner:TOYOTA MOTOR NORTH AMERICA INC +1

System and method for classification of normal encrypted network traffic and transport layer security (TLS)-based virtual private network traffic

A system for classifying network traffic retrieves first packet data from a network session between a client device and server. The first packet data includes a first set of Internet Protocol (IP) packets and timestamps, and calculates a first latency between: (i) a first timestamp of a first IP packet for initiating an encrypted connection, and (ii) a second timestamp of a second IP packet for acknowledging receipt of an IP packet. The system calculates a second latency between the first timestamp and a third timestamp of a third IP packet for establishing a connection. The system calculates a third latency between a third timestamp and a fourth timestamp of a fourth IP packet for accessing application data. The system also provides as input to machine learning model, the first, second, and third latencies, and generates and transmits an alert based upon an output of the machine learning model.
Owner:VEHERE TECHNOLOGIES PTE LTD

Methods and Devices for Supporting Authentication

Methods and devices for supporting authentication of a first Transport Layer Security (TLS) device, wherein a second TLS device receives from the first TLS device a message indicative of the credential type that the first TLS devices will provide to be authenticated, i.e., Verifiable Credential (VC)-based certificate. The second TLS device then receives, from the first TLS device, a first VC and a first Verifiable Presentation (VP) proof which the second TLS device uses for authenticating the first TLS device.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Radio authentication as root of trust for transport layer security

A converged radio device (MS) is configured to perform communication in an internet protocol (IP) based network and authenticate with a switching and management infrastructure (SwMI) of a second network by using pre-existing radio authentication as a root of trust for an unauthenticated IP session established between the MS and a server associated with the SwMI. The MS receives a first challenge from the SwMI via the server, and determines a result of the first challenge using data derived from a certificate associated with the server. The MS transmits, to the SwMI via the server, a second challenge and the result of the first challenge. The MS authenticates the SwMI by verifying a result of the second challenge received from the SwMI via the server matches an expected result of the second challenge. Responsive to a mutual authentication, the MS performs communication in the radio network via the server.
Owner:MOTOROLA SOLUTIONS INC

Secure key management for service mesh deployments

Various methods, systems, and use cases for securely managing, generating, and controlling access to keys in a service mesh are discussed herein. In various examples, key protection operations include service mesh signing key protection and service mesh communication key protection, for a secure transport session between services such as conducted with mutual transport layer security (mTLS). For instance, such key protection operations may be used to establish communications between the service host and another entity within the service mesh, in a secure transport session, based on use of a private key (secured using a confidential computing technology) in a secure enclave or other secure compute environment to sign one or more keys for the secure transport session.
Owner:INTEL CORP

Authentication method and apparatus, and communication device and storage medium

Provided in the embodiments of the present disclosure is an authentication method. The method is executed by a first root certificate authority (CA), and comprises: generating a first type of certificate on the basis of a transport layer security (TLS) protocol, wherein the first type of certificate is a certificate of an entity in a first security domain where the first root CA is located.
Owner:BEIJING XIAOMI MOBILE SOFTWARE CO LTD

Photovoltaic data transmission encryption method based on cloud computing

The invention discloses a photovoltaic data transmission encryption method based on cloud computing. The method comprises the following steps: acquiring photovoltaic data through a sensor and preprocessing the photovoltaic data; feature extraction is carried out on the preprocessed photovoltaic data, a random forest model is used for judging the sensitivity degree of different photovoltaic data, and the target is to predict the encryption requirements of the different photovoltaic data at the current moment; the method comprises the steps of encrypting power generation data by using an AES advanced encryption standard, encrypting environmental data by using a TLS transport layer security protocol, encrypting equipment state data by using RSA asymmetric encryption, and dynamically adjusting corresponding encryption levels based on encryption requirements of different photovoltaic data at the current moment; decrypting different types of photovoltaic data on the cloud platform, and storing the photovoltaic data in corresponding databases; generating a photovoltaic data correlation topological graph according to correlation strength among different statistical characteristic values in the photovoltaic data; based on the photovoltaic data correlation topological graph, analyzing the power generation data and the environmental data by using a time sequence prediction model, and predicting a future power generation amount change trend; a photovoltaic system operation optimization strategy is automatically generated according to a future power generation amount change trend and equipment state data; the method provides a scientific basis for optimizing the operation strategy of the photovoltaic system.
Owner:NARI NANJING CONTROL SYSTEM CO LTD +1

Methods and systems for client certificate extraction in device authentication

Embodiments of a device and method are disclosed. In an embodiment, a method of communications involves at a network device, receiving an authentication message from a client, at the network device, extracting a payload from the authentication message, and sending a copy of the payload to a Transport Layer Security (TLS) microserver of the network device for client certificate extraction, where the TLS microserver is implemented in a side signal channel.
Owner:NILE GLOBAL INC

Key replacement during datagram transport layer security (DTLS) connections over stream control transmission protocol (SCTP)

Embodiments include methods, electronic device, storage medium, and computer program to implement parallel Data-gram Transport Layer Security (DTLS) connections over a stream control transmission protocol (SCTP) association. In one embodiment, a method at a first network node for encoding user messages for secure transmission to a second network node comprises: initiating a Datagram Transport Layer Security (DTLS) connection over a stream control transmission protocol (SCTP) association through a DTLS handshake using an existing Authenticated Chunks for SCTP (SCTP-AUTH) key from an existing DTLS connection over the SCTP association that transmits user messages: deriving a new SCTP-AUTH key from the initiated DTLS connection: transmitting further user messages through the initiated DTLS connection with the new SCTP-AUTH key: and closing the existing DTLS connection over the SCTP association upon confirmation that SCTP packets encrypted with the existing DTLS connection and SCTP packets authenticated by the existing SCTP-AUTH key have been delivered.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

TLS connection establishment method and device for transparent encrypted database proxy

The invention discloses a TLS connection establishment method and device for a transparent encryption database proxy, and belongs to the technical field of database security and communication encryption, and the method is characterized in that a database protocol rule base is built in the proxy, so that the proxy has a protocol perception capability; simulating the server to return a positive response, and then establishing a first TLS connection as a TLS server; meanwhile, the proxy initiates TCP connection to the real database server, actively sends a negotiation request of a corresponding protocol, and serves as a TLS client to establish second TLS connection; and finally, binding the two TLS connection sessions to realize transparent forwarding of the data. The technical problem that an existing transparent encryption agent cannot work in the scene that the database forcibly opens the TLS is solved, coordination of transport layer security and field-level transparent encryption is achieved, and the security of database communication is comprehensively improved.
Owner:BEIJING SANSEC TECH DEV

Enrollment over secure transport

An apparatus comprises an Enrollment over Secure Transport (EST) client, the EST client being configured to: store a trust anchor; initiate a Transport Layer Security or Datagram Transport Layer Security (TLS / DTLS) handshake with an EST server; receive a TLS / DTLS EST server certificate from the EST server; perform validation of the TLS / DTLS EST server certificate using the trust anchor; and when validation fails, complete the TLS / DTLS handshake to establish a non-trusted TLS / DTLS session with the EST server.
Owner:LANDIS GYR TECH INC

Inter-PLMN communication

Embodiments of the present disclosure relate to inter-PLMN communications. A device is disclosed. The device includes means for initiating establishment of an N32-c transport layer security connection with an entity, the device being located in a first public land mobile network and the entity being located in a second public land mobile network; sending an N32-c handshake signaling message from the device to the entity over the N32-c transport layer security connection, the N32-c handshake signaling message including domain name information of the device to be used by the entity for establishing an N32-f transport layer security connection toward the device; receiving a reply from the entity, the reply including domain name information of the entity to be used by the device for establishing an N32-f transport layer security connection toward the entity; and establishing the N32-f transport layer security connection toward the entity using the domain name information received in the reply.
Owner:NOKIA TECHNOLOGIES OY

Remote verification method and device for confidential calculation, related equipment, storage medium and computer program product

The invention discloses a remote verification method and device for confidential calculation, a first platform, first equipment, fourth equipment, a storage medium and a computer program product. The method comprises the steps that a first platform obtains first data and obtains second data, the first data comprises first evidence data related to a first trusted execution environment (TEE) of first equipment and first related data of a first transport layer security (TLS) certificate of the first TEE, and the first equipment is used for providing confidential computing service through the first TEE; the second data comprises certificate chain related data of the first TEE; verifying the first evidence data based on certificate chain related data of the first TEE to obtain a first verification result, and packaging the first verification result, the first evidence data and the first related data by using a first protocol to obtain third data; the third data is sent to the first device and a second device, the second device being a user of the confidential computing service.
Owner:CHINA MOBILE COMM LTD RES INST +1

Methods and apparatus for a sixth generation (6G) roaming solution using protocol for n32 interconnect security (PRINS) with roaming intermediaries

Session management for a Fifth Generation (5G) roaming solution using PRotocol for N32 INterconnect Security (PRINS) with roaming intermediaries is described herein. A first network node establishes a transport layer security (TLS) connection with a second network node, wherein the TLS connection is established using hypertext transfer protocol secure (HTTPS) as a uniform resource identifier (URI). The first network node creates a security negotiation request message, including a fully qualified domain name (FQDN) of the second network node. The first network node protects information elements (IEs) in the security negotiation request message with a Javascript Object Notation (JSON) Web Signature (JWS) token, wherein the JWS token uses a digital signature and includes a public key certificate of the first network node. The first network node sends over TLS, to the second network node, an HTTPS request, including the security negotiation request message and the JWS token.
Owner:CABLE TELEVISION LAB INC

Transport layer security management using a management controller

Methods and systems for managing an endpoint device are disclosed. To do so, a key pair may be generated by a management controller of the endpoint device and a private key of the key pair may be kept secret by the management controller. A public key of the public private key pair may be provided to a first entity for use in generating a certificate for the endpoint device. The certificate may be provided to a second entity desiring a level of trust with the endpoint device. As a portion of establishing a secure connection between the second entity and the endpoint device, a TLS handshake may be performed. Performing the TLS handshake may include obtaining a TLS packet, signing the TLS packet using the private key, and providing the signed TLS packet to the second entity to demonstrate that the endpoint device is trustworthy for the level of trust.
Owner:DELL PROD LP

Procedure relating to a transport container for packages

Method for transporting an item by: - ​​bringing a transport container for parcels to a sender (V), wherein the transport container (1) for parcels (P) has a data processing device (10) and a memory (16) on which a certificate (Z1) for identifying the transport container (1) and a pair of a public and a private cryptographic key are stored, wherein the transport container has a communication interface (14a, 14b) for sending the certificate (Z1) together with the public cryptographic key to an external unit (2, 3) and for receiving messages from the external unit (2, 3) and an electrically operated locking device (12);- Performing a procedure for opening the transport container (1) for packages, comprising the steps: - Performing a Transport Layer Security (TLS) handshake between the transport container and the sender (2, 3, V) for mutual authentication; - If the authentication is successful, opening the transport container; - Placing the item (P) into the transport container (1); - Transporting the transport container (1) to a recipient (E); - Performing a procedure for opening the transport container (1) for packages, comprising the steps: - Performing a Transport Layer Security (TLS) handshake between the transport container and the recipient (2, 3, E) for mutual authentication; - If the authentication is successful, opening the transport container;- Removing the item (P) from the transport container (1), the transport container being subsequently connected to a backend server to change and / or supplement the certificate.;
Owner:CARIAD SE

Methods and systems for accessing content

An identifier, for example, an identifier of a domain and / or a host of the domain (e.g., a fully qualified domain name (FQDN), etc.), such as a service management device (e.g., a server, a web server, a computing device, a web host device, a webpage, etc.), may be modified (e.g., hashed, encrypted, etc.) by a network device (e.g., a server, a domain name system (DNS) server, a DNS over hypertext transfer protocol secure (HTTPS) server / gateway (DoH server), DNS over Transport Layer Security (TLS) server / gateway (DoT server), a network management device, a computing device, etc.), sent to a user device (e.g., a client device, a smart device, a mobile device, a content output device, a computing device, a web browser, a search engine, etc.), and reused by the user device to request a service (e.g., a web service, a webpage, a file, content, a content item, etc.).
Owner:COMCAST CABLE COMM LLC

Network request method and terminal device

PendingCN122661742AMultiplexingTransport layer
The application relates to a network request method and a terminal device, and relates to the technical field of terminals. The method comprises the following steps: when a second application initiates a network request, a terminal device sends a negotiation message to a second server, the negotiation message is used for negotiating session multiplexing information of a first application, and the second server is a server of the second application; the terminal device receives negotiation results from the second server, and the negotiation results comprise the session multiplexing information; when the first application initiates the network request, the terminal device sends a network request message to a first server, the network request message comprises the session multiplexing information, and the first server is a server of the first application; and the terminal device receives network request results from the first server, and the network request results comprise response data of a transport layer security (TLS) handshake and / or application data transmission. In this way, the time delay of the network request when the application is started can be reduced.
Owner:HONOR DEVICE CO LTD

Pre-master key generation method and device for data packet transmission layer security protocol dtls

The present disclosure provides a pre-master key generation method, device and equipment of a data packet transmission layer security protocol DTLS and a storage medium, and belongs to the technical field of communication. The method comprises receiving a DTLS message sent by a terminal device, wherein the DTLS message comprises a shared key PSK identifier supported by the terminal device; selecting a PSK identifier from the shared key PSK identifier supported by the terminal device; obtaining a key according to the selected PSK identifier; and generating a pre-master key of the DTLS according to the obtained key. The present disclosure provides a processing method for the case of "pre-master key generation of a data packet transmission layer security protocol DTLS", and generates a pre-master key corresponding to the selected PSK identifier, so that the DTLS can support the security requirements of the Ua interface for GBA and the Ua* interface for AKMA, and the security during communication can be improved.
Owner:BEIJING XIAOMI MOBILE SOFTWARE CO LTD

Security enhancement methods and systems for the IEC 104 protocol on the master station side of power monitoring systems

PendingCN122339686AIEC 62351Embedded system
This invention discloses a security enhancement method and system for the IEC 104 protocol on the master station side of a power monitoring system, comprising: generating input data, dynamically selecting a security mode and issuing configuration commands, generating original ASDU messages, calling application-layer security plugins to generate enhanced ASDU messages, encapsulating them into complete APDUs, generating security messages via transport-layer security plugins, and sending them to the station. This invention adopts a plug-in embedded architecture, integrating IEC 62351-5 application-layer and IEC 62351-3 transport-layer security plugins into the protocol processing module and communication processing module respectively, achieving decoupling of security functions and business functions; establishing a policy-driven mechanism, adding a security policy management module and an operation monitoring module, and providing port differentiation to adapt to different terminals to meet the needs of gradual transformation; controlling terminal concurrent connection latency at the millisecond level to meet the needs of large-scale high-concurrency access at the master station, and establishing a layered security protection system that coordinates the transport layer and application layer, ensuring message security even if transport layer security fails.
Owner:NARI NANJING CONTROL SYSTEM CO LTD +1

Method to migrate workload between two environments and a system thereof

ActiveUS12676835B2Transport layerWorkload
A method to migrate workload between a single node environment and a multi-node environment over a Transport Layer Security (TLS) network, the method comprises running an application on a first machine in a first environment, wherein the first environment is any one of the environments. The method further comprises generating a first file for the application running on the first machine and storing the first file and the workload created from the first file in the first machine. The method further comprises accessing a second machine that runs a container cluster in a second environment, wherein the second environment is different from the first environment. The method further comprises reading a second file from the container cluster and storing the second file in the first machine. The method further comprises connecting the first machine to the container cluster of the second machine using access information stored in the second file.
Owner:RED HAT INC

Network node and communication method

This network node comprises: a transmission unit that reports, to a security edge protection proxy (SEPP), an identifier in a first transport layer security (TLS) session for control; and a control unit that establishes, with the SEPP, a second TLS session for signal transmission to which an encryption method negotiated in the first TLS session is applied. Immediately after establishment of the second TLS session, the transmission unit reports, to the SEPP, a hypertext transfer protocol (HTTP) signal including the identifier via the second TLS session.
Owner:NTT DOCOMO INC

Cloud-native function authentication at layer 2

Example embodiments of the present disclosure relate to cloud-native function (CNF) authentication during the instantiation and bootstrapping of the CNF. According to embodiments, a method may be provided, including sending, by a supplicant to an authenticator during an instantiation and bootstrapping stage of a CNF, a message to initiate an Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) protocol sequence, wherein an EAP-TLS authentication is performed with an authentication server based on the message; receiving, by the supplicant, a result of the EAP-TLS authentication from the authenticator, wherein the result of the EAP-TLS authentication originates from the authentication server, and wherein the authenticator is configured to control traffic of the CNF based on the result of the EAP-TLS authentication.
Owner:RAKUTEN SYMPHONY INC

Apparatus, system, and method of federated authentication service (FAS) for wireless communication roaming

For example, a Federated Authentication Service (FAS) server may be configured to register the FAS server with a wireless communication roaming federation service; to authenticate a user of a mobile device according to a network authentication protocol of the wireless communication roaming federation service, e.g., over a Remote Authentication Dial-In User Service (RADIUS) over Transport Layer Security (RADSec) tunnel between the FAS server and an Access Network Provider (ANP); to identify an Identity Provider (IDP) for the user based on user information for the user received from the ANP via the RADSec tunnel; to trigger user authentication of the user with the IDP for the user via an authentication interface between the FAS server and the IDP for the user; and based on a determination that the user is successfully authenticated with the IDP for the user, to send an authentication success message to the ANP via the RADSec tunnel.
Owner:INTEL CORP