Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

26 results about "Trust certificate" patented technology

In finance, a trust certificate is a corporate bond backed by other securities, usually a parent corporation borrowing against securities of its subsidiaries.

AI model security protection system and method based on domestic cryptographic algorithm and digital certificate

The invention discloses an AI model security protection system and method based on a domestic cryptographic algorithm and a digital certificate. The system comprises a certificate management center CA, an AI model security gateway, a training terminal and a deployment server, wherein the certificate management center CA is a certificate management system of a third-party trusted certificate management center CA mechanism; the AI model security gateway is used for security access and compliance verification of training data; the training terminal is used for security initialization of the model development terminal and generation of a security model package, and is terminal equipment used by a developer for model training; and the deployment server is used for security management and control of the model operation end. The method comprises the following steps: firstly, carrying out data encryption and model certificate binding; identity authentication and transmission encryption are carried out; then, integrity verification and tampering prevention are carried out; and finally, version traceability and legality verification are carried out. According to the method, the security of the AI model and the model transmission and verification efficiency are improved, the whole-process traceability of the model is realized, the compatibility is high, and the method is easy to popularize.
Owner:JIANGSU DATA GROUP DIGITAL TECHNOLOGY CO LTD

Anti-quantum certificate signature verification method and device, equipment and storage medium

The invention discloses an anti-quantum certificate signature verification method, which comprises the following steps: signing and issuing a traditional certificate to a certificate issuing mechanism, and carrying out abstract operation processing on a serial number of the traditional certificate to obtain an abstract of the traditional certificate; issuing an anti-quantum certificate to a certificate issuing mechanism, and adding the abstract of the traditional certificate into an extension item of the anti-quantum certificate, so that the anti-quantum certificate is bound with the traditional certificate; when the security of the certificate needs to be verified in the interaction process with other application systems, performing signature verification processing on the traditional certificate; and after the signature verification of the traditional certificate is passed, carrying out signature verification processing on the countermeasure quantum certificate, and if the verification is passed, considering the certificate as a trusted certificate. The invention further discloses a device for implementing the anti-quantum certificate signature verification method, computer equipment and a storage medium. According to the method, the potential risk that a traditional digital certificate is attacked by quantum during use can be well solved, and the security of the certificate is greatly improved.
Owner:KOAL SOFTWARE CO LTD

Distributed space hiding protection method based on self-certification trust

PendingCN120455153ASecuring communicationThird partyTrust certificate
The invention relates to the technical field of network security, and discloses a distributed space hiding protection method based on self-certification trust, which comprises the following steps: a requester broadcasts a first request for constructing an anonymous area; the potential collaborator and the requester receiving the first request mutually verify historical trust certificates of each other, and judge whether the interaction is successful or invalid according to a preset interaction verification mechanism; after the interaction result is judged, one of the two interaction parties generates a trust voucher for the interaction of the other party and sends the trust voucher to the other party; and the requester selects a preset number of verified target collaborators to construct the anonymous area. According to the method, through self-certification of trust, the dependence on a trusted third party in an anonymous region construction process is avoided, so that the problems of single-point failure and the like are solved. The trust value of the user can be accurately and efficiently evaluated by combining the consistency of trust evaluation, the time attenuation of the trust value and the similarity of trust evaluation. According to the method, credible anonymous region construction can be realized, and the location privacy of the user is protected.
Owner:NORTHWESTERN POLYTECHNICAL UNIV

Safety equipment management and service system and method based on trusted scene

The invention belongs to the technical field of Internet of Things, and discloses a safety equipment management and service system and method based on a trusted scene, and the method comprises the steps: obtaining manufacturer basic information and a real-time risk signal, judging a credit level according to a four-level standard, generating a corresponding rectification work order, collecting equipment attributes, signing and issuing a trusted passport, and forming an equipment initial trusted certificate; the scene admission type is judged by combining the batch admission template and the offline rule packet, differential adaptation is executed, and a scene adaptation result is generated; historical experience labels are converted through a cross-domain label mapping table, invalid labels are cleared up, an inheritance trust state is determined, and a trust passport is updated; sandbox simulation is executed on the major strategy, conflicts are arbitrated according to mode priorities, and an arbitration strategy, an execution instruction and an audit log are generated; the trust passport and the manufacturer credit level are updated, trust approval and strategy arbitration rules are optimized, and a closed-loop auditing link is formed.
Owner:NAT CERTIFICATION TECH (HANGZHOU) CO LTD

Equipment information protection method and related device

The embodiment of the invention discloses an equipment information protection method and a related device, which are used for improving the security of hardware equipment information in a complete machine and applied to a baseboard management controller BMC, the BMC comprises a security core isolated from external environment access, and the method comprises the following steps: calling the security core, signing a firmware hash value based on a trusted certificate, and sending the signed firmware hash value to a server; generating a firmware identity certificate, wherein the firmware hash value is obtained by performing hash value calculation on the firmware information of the BMC; acquiring reference equipment information, wherein the reference equipment information is equipment information of the initial hardware equipment; a security core is called, the reference device information is signed based on the firmware identity certificate, a device identity certificate is generated, the device identity certificate is used for extracting the reference device information when the target hash value is not matched with the reference hash value, and the target hash value is obtained by performing hash value calculation on the target device information; the target equipment information is equipment information of the target hardware equipment, and the reference hash value is obtained by performing hash value calculation on the reference equipment information.
Owner:HUAWEI TECH CO LTD

Data processing method and device based on privacy protection, equipment and storage medium

The application relates to the technical field of data processing, and provides a data processing method and device based on privacy protection, equipment and a storage medium. The method comprises the following steps: generating a trusted certificate list of a signature certificate, an encryption certificate and an identity ID of each subsystem; generating a corresponding task ID and a to-be-done subtask of each subsystem according to a preset to-be-done task flow table; when it is monitored that a first subsystem acquires a first to-be-done subtask of the to-be-done task flow table from a preset address according to a first task ID and performs decryption, performing signature verification on the decrypted first to-be-done subtask according to the trusted certificate list to obtain operation content of the first to-be-done subtask; acquiring target data associated with the operation content in a data storage device of the first subsystem, encrypting and signing the target data, obtaining target data results and uploading the target data results to the preset address. The application also relates to the technical field of blockchains, and the signature certificate, the encryption certificate and the identity ID can also be stored in a node of a blockchain.
Owner:WELAB INFORMATION TECH SHENZHEN LTD

Network node, terminal, and communication method

A network node according to the present invention comprises a reception unit that receives a trust evaluation request message that includes a trust certificate for a terminal or a user from a specific network node that has received a message that includes the trust certificate from the terminal, a control unit that executes trust evaluation processing that uses the trust certificate, and a transmission unit that transmits trust evaluation results to the specific network node.
Owner:NTT DOCOMO INC +1

An online POS application signature method based on ukey communication data security protection.

This invention relates to the field of information processing technology, specifically an online POS application signing method based on ukey communication data security protection, comprising the following steps: S1: generating a certificate request file for the Ukey device and issuing a trusted certificate to it; S2: using the Ukey for identity authentication and obtaining a list of signing private keys; S3: after identity authentication, using the Ukey to sign and reassemble the application package; The online POS application signing method based on ukey communication data security protection provided by this invention can reduce the cost of manufacturing security devices. Relatively speaking, the manufacturing cost of ukey is one-tenth of the cost of security devices, which is more user-friendly for customers with small demand. Small customers generally do not build their own signature security system, and this solution can be used immediately; In addition, the Ukey device performs identity authentication, which, while balancing convenience and security, prevents the possibility of signing private key leakage and provides the convenience of being carried around, making it suitable for further promotion and application.
Owner:FUJIAN NEWLAND PAYMENT TECH

Verification of certificate packages with asymmetric keys

Operations of a certificate package verification service may include receiving a first certificate package including a first set of one or more digital certificates, and a digital signature associated with the first certificate package; determining, using a public key of an asymmetric key pair associated with a second set of the one or more digital certificates, that the digital signature is generated using a private key of the asymmetric key pair; and in response to determining that the digital signature is generated using the private key, storing the first certificate packet as a trusted certificate packet in a certificate repository.
Owner:ORACLE INT CORP

Network node, terminal, and communication method

PendingCN122122951ASecurity arrangementComputer networkTrust certificate
A network node includes a reception unit that receives a trust evaluation request message including a trust certificate of a terminal or a user from a specific network node that has received a message including the trust certificate from the terminal, a control unit that performs a trust evaluation process using the trust certificate, and a transmission unit that transmits a trust evaluation result to the specific network node.
Owner:NTT DOCOMO INC +1

Rapid lightweight network trust method suitable for vehicle-road cooperation of expressway

The invention discloses a rapid lightweight network trust method suitable for highway vehicle-road cooperation, and the method comprises the steps: carrying out the identity authentication of a target intelligent network connection vehicle through a digital certificate-based strong identity authentication technology at an entrance of a highway, and generating a lightweight network trust certificate of the vehicle; pre-transmitting the lightweight network trust certificate to the intelligent roadside equipment on a subsequent path through the intelligent roadside equipment on the entrance side according to the linear closing characteristic of the expressway; and in the vehicle driving process, information interaction with the intelligent roadside equipment on the subsequent path is carried out in sequence, and the intelligent roadside equipment on the subsequent path carries out identity authentication on the target intelligent network connection vehicle by using the pre-obtained lightweight network trust repertoire verification. According to the method, the identity authentication of the vehicle can be quickly completed during high-speed driving of the vehicle, the authentication efficiency is remarkably improved, meanwhile, the occupied authentication computing resources are small, the network load is greatly reduced, the system safety is enhanced, and the system reliability is improved.
Owner:RES INST OF HIGHWAY MINIST OF TRANSPORT

Second-hand goods online transaction system and method

InactiveCN121937190AProduct appraisalTrust certificateUnique identifier
The invention provides a second-hand cargo online transaction system and method. The method comprises the following steps: determining a credible evaluation report; binding the credibility evaluation report with the unique identifier of the second-hand commodity, generating a non-tampering digital credibility certificate, and storing the digital credibility certificate and an out-of-chain storage address index in an alliance chain in an associated manner; when a transaction request is received, providing an estimation confidence interval as a transaction reference based on the digital credible voucher, automatically executing fund trusteeship and on-chain material right circulation record registration after a buyer and a seller confirm a reference opinion, and further generating a new transaction circulation node and writing the new transaction circulation node into a life cycle tracing chain; and when a query request of an authorized user is received, retrieving all transaction transfer nodes in the alliance chain, assembling the transaction transfer nodes to obtain life cycle traceability information, and returning the life cycle traceability information to the authorized user. By adopting the scheme of the invention, full-life-cycle tamper-proof traceability from commodity multi-mode intelligent evaluation to credible automatic transaction execution can be realized.
Owner:GUANGZHOU KUSHANG CULTURE MEDIA TECH CO LTD

Communication method and apparatus

PCT designated stageWO2026001734A1Security arrangementInternet privacyTrust certificate
The embodiments of the present application relate to the technical field of communications. Provided are a communication method and apparatus, which can determine the security of a network element used for implementing communication between a relying party and a verifier. The method comprises: a first network element receiving first request information; determining a trust certificate on the basis of the first request information; and sending second request information, wherein the first request information is used for requesting the measurement of a trusted status of a target network element, the trust certificate is used for indicating that the first network element has the permission to query the trusted status of the target network element, the second request information is used for requesting the trusted status of the target network element, and the second request information is further used for indicating the trust certificate.
Owner:HUAWEI TECH CO LTD

Generating trust certificates for ai with black and whitebox verification

PendingUS20250300842A1User identity/authority verificationTrust certificateWhite box
Described herein are systems and methods for generating Trust Certificates for AI with Black and WhiteBox Verification via a principled, multi-modal, causality-based composable certification method to benefit especially trust-sensitive real-world applications like health and food wherein the certificates created by the method can also facilitate appropriate regulation needs and are compatible with NIST's AI risk mitigation framework.
Owner:UNIVERSITY OF SOUTH CAROLINA

Network node, terminal, and communication method

The network node has a reception section that receives a trust evaluation request message from a specific network node in a case where authentication using a user's attribute / eligibility certificate is successful, the trust evaluation request message including a terminal or the user's trust certificate, a control section that performs a trust evaluation process using the trust certificate, and a transmission section that transmits a trust evaluation result to the specific network node.
Owner:NTT DOCOMO INC +1

Tamper protection for the clock of a field device

PCT designated stageWO2026032895A1Programme controlUser identity/authority verificationTrust certificatePublic key certificate
The invention relates to a method (100) for operating a field device (1), which has an adjustable clock (2), at least one non-volatile CA memory (3) having a public key certificate (3a) from a trusted certificate authority, CA, at least one non-volatile time memory (4) for storing a date and / or a time (4a), and at least one interface (5), the method comprising the following steps: - a current date and / or a current time (7a) is received (170) via the interface (5); - said current date or said current time (7a) is compared (180) with the date or the time (4a) in the time memory (4); and - in response to the current date or the current time (7a) being later (190) than the date or the time (4a) in the time memory (4), the adjustable clock (2) of the field device (1) is set (200) to the current date or to the current time (7a).
Owner:VEGA GRIESHABER GMBH & CO

Device information protection method and related apparatus

Disclosed in embodiments of the present application are a device information protection method and a related apparatus, used for improving the security of hardware device information in the entire device, and applied to a baseboard management controller (BMC), the BMC comprising a security kernel isolated from external environment access. The method comprises: calling a security kernel, signing a firmware hash value on the basis of a trusted certificate, and generating a firmware identity certificate, wherein the firmware hash value is obtained by performing hash value calculation on firmware information of a BMC; acquiring reference device information, wherein the reference device information is device information of an initial hardware device; and calling the security kernel, signing the reference device information on the basis of the firmware identity certificate, and generating a device identity certificate, wherein the device identity certificate is used for extracting the reference device information when a target hash value does not match a reference hash value, the target hash value is obtained by performing hash value calculation on target device information, the target device information is device information of a target hardware device, and the reference hash value is obtained by performing hash value calculation on the reference device information.
Owner:HUAWEI TECH CO LTD

Consumable identification method and device, medium and product

The invention provides a consumable identification method and device, a medium and a product, and relates to the technical field of electrical digital data processing, and the method comprises the following steps: firstly, a host and a consumable use a pre-stored root public key to mutually verify a consumable credible certificate and a host credible certificate; and after passing, the host and the consumable use the consumable public key and the host public key to mutually verify the first signature file and the second signature file, and then the host generates and sends a symmetric communication key. Then, the host generates a verification code according to the consumable parameters, encrypts the verification code by using the symmetric communication key, and sends the verification code to the consumable for timing; finally, the host receives and decrypts the operation result, and when the verification duration is smaller than the preset duration and the operation result passes verification, it is confirmed that the consumable is a certified consumable. According to the scheme, the technical problem that true and false consumables are difficult to discriminate effectively in the prior art is solved.
Owner:BEIJING SHUOFANG INFORMATION TECH CO LTD

Website access control method, device, computer equipment and readable storage medium

Embodiments of the present application provide a website access control method, apparatus, computer device, and readable storage medium. The method comprises: obtaining a website access request sent by a user browser to a target website, forwarding the website access request to the target website via a remote browser proxy service, and receiving a target certificate returned by the target website; verifying the target certificate via the remote browser proxy service to obtain a verification result; when the verification result indicates that the verification status of the target certificate is an error, querying the target certificate according to a pre-set security policy data table to obtain a query result; when the query result indicates that the target certificate is a trusted certificate, controlling the remote browser proxy service to access the target website, obtaining access data corresponding to the website access request; and returning the access data to the user's browser. This effectively improves the stability of browser website access.
Owner:PENG CHENG LAB

Method, device, equipment and medium for being compatible with post quantum and traditional public key

PendingCN121333583AUser identity/authority verificationAlgorithmCritical information infrastructure
The embodiment of the invention discloses a post quantum and traditional public key compatible method, device and equipment and a medium, and relates to the technical field of password application, and the method comprises the steps: generating a trusted certificate which comprises additional public key information extension, additional signature algorithm extension and additional signature value extension; when the credible certificate is verified, judging whether the verification system supports a post quantum cryptography algorithm or not; if not, verifying a certificate signature value of a preset traditional cryptographic algorithm in the credible certificate; and if yes, verifying a certificate signature value of a traditional cryptographic algorithm preset in the credible certificate, and verifying a certificate signature value of the post-quantum cryptographic algorithm based on the additional public key information extension, the additional signature algorithm extension and the additional signature value extension. According to the method, a powerful post-quantum cryptographic algorithm is introduced and supported to cope with quantum threats, seamless compatibility with existing systems and equipment depending on a traditional public key cryptographic algorithm is ensured, and destructive influence on existing huge and key information infrastructures is avoided.
Owner:WEIWEI SHANGHAI NETWORK TECH CO LTD +1

Network node, terminal, and communication method

PCT designated stageWO2025169344A1Security arrangementTrust certificateEngineering
A network node disclosed herein comprises: a reception unit that, when authentication using an attribute / qualification certificate of a user is successful, receives a trust evaluation request message, including a trust certificate of a terminal or the user, from a specific network node; a control unit that executes a trust evaluation procedure using the trust certificate; and a transmission unit that transmits a trust evaluation result to the specific network node.
Owner:NTT DOCOMO INC +1

UE onboarding and provisioning using one way authentication

An apparatus and system for onboarding based on UE default manufacturer credentials are described. A UE sends default manufacturer credentials and an indication to proceed with restricted onboarding to an onboarding non-public network (O-SNPN). An Onboarding Server validates the authenticity of the UE based on the manufacturer credentials and sends a certificate. The UE is provisioned with a set of roots of trust certificate information to use to authenticate the certificate using one way authentication. After authentication, the UE receives network credentials and performs mutual authentication to register with a NPN while being authenticated by a home network. The UE identity is indicated as anonymous in response to an indication by the O-SNPN for subscriber identifier privacy.
Owner:INTEL CORP

Consensus method and device based on negotiation-free high-throughput block-out strategy

PendingCN120729524AUser identity/authority verificationComputer networkTrust certificate
The invention provides a consensus method and device based on a negotiation-free high-throughput block-out strategy. The method comprises the following steps: determining the selection qualification of nodes of received blocks according to a whole network trust certificate, and collecting the priority block number of the nodes at the same time; voting is carried out on the nodes with the election qualification, a block-out node sequence of this round is obtained, and voting can be carried out only by the nodes elected as voters; an unfixed node block-out sequence is obtained after voting, and a block-out node sends a pre-out block and collects an endorsement within a specific time; after receiving the endorsement request, the endorsement node verifies the legality of the pre-output block and signs the pre-output block; and when the out-block node collects more than half of endorsement signatures, adding the signatures to the pre-out block to form a formal block, and broadcasting the formal block to the whole network. The block-out sequence is not fixed, so that malicious nodes are prevented from operating the block-out sequence, and the security of the block chain is ensured; on the other hand, a priority block output strategy is added, and the flexibility of block output is improved.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI

Managing stores of trusted certificates for data processing systems

PendingUS20260252739A1Data processing systemTrust certificate
Methods and systems for managing operation of a data processing system are disclosed. To manage operation of the data processing system, after a startup of the data processing system and while in operable communication with a vendor certificate repository, a management agent may determine that a store of trusted certificates is to be updated. The management agent may perform a synchronization process to obtain an updated store of trusted certificates, the updated store of trusted certificates being accessible by a startup manager of the data processing system while the startup manager is not in operable communication with the vendor certificate repository. Therefore, during a future startup of the data processing system, a security posture of the data processing system may be evaluated using the store of trusted certificates and operation of the data processing system may be managed based on the security posture to facilitate provisioning of desired computer-implemented services.
Owner:DELL PROD LP

Drive installation method, apparatus, and cloud service system

Embodiments of the present application disclose a drive installation method, device and cloud service system. A specific embodiment of the method comprises: in response to detecting that a trust certificate of a to-be-installed drive is not stored in a to-be-installed system, obtaining the trust certificate of the to-be-installed drive; importing the trust certificate into the to-be-installed system; and executing an installation command of the to-be-installed drive corresponding to the trust certificate. The embodiment can be applied to the field of cloud computing, and by pre-importing the trust certificate, the occurrence of a trust warning during Windows drive installation is prevented, so that the drive can be automatically installed through the installation command. As a necessary step for making a Windows image, the automatic installation of the Windows drive provides a prerequisite for the automation of the entire Windows image making process.
Owner:BEIJING BAIDU NETCOM SCI & TECH CO LTD

Securing communication between a PMU and a PDC

A method and system for securing communication between a Phasor Measurement Unit (PMU) and a Phasor Data Concentrator (PDC) in accordance with IEEE C37.118.2-2024. The method includes receiving, at the PMU, a command frame requesting an authentication certificate, receiving a configuration frame comprising an X.509 certificate of the PDC, generating a public-private key pair, and transmitting a configuration frame comprising an X.509 certificate of the PMU. Mutual authentication is performed by verifying received certificates using a trusted Certificate Authority. Upon successful authentication, the PMU transmits synchrophasor data messages formatted per IEEE C37.118.2-2024, each appended with a security algorithm field and a FALCON-512 digital signature generated over defined message fields. The PDC verifies signatures using the PMU's public key and authenticates messages only upon successful verification. Replay protection is achieved through SOC timestamp comparison, rendering quantum-resistant, authenticated, and integrity-protected synchrophasor communication without altering the original IEEE C37.118.2 frame structure.
Owner:KING FAHD UNIVERSITY OF PETROLEUM AND MINERALS