Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

16 results about "Trusted authority" patented technology

High-performance multi-keyword sorting query privacy computing system for secret state big data

The invention discloses a high-performance multi-keyword sorting query privacy computing system oriented to secret state big data. Comprising four participants including a trusted authority, a data owner, a query user and a cloud server, and seven functional modules including a system initialization module, a key generation module, a data encryption module, a query token generation module, a security query module, a data decryption module and a key tracking module. On the basis of deeply researching and analyzing existing searchable encryption, access control based on attribute-based encryption and high-performance index technology research results, the invention provides a high-performance multi-keyword sorting query privacy calculation scheme and an application system oriented to secret state big data. The invention provides a high-performance safe multi-keyword sorting query scheme for realizing access control for the first time, and has the capabilities of high-performance multi-keyword sorting query, fine-grained ciphertext access control, malicious user tracking and dynamic data updating at the same time on the premise of protecting data privacy.
Owner:EAST CHINA NORMAL UNIV +2

Trusted tokenized asset transactions

In one or more embodiments, the present invention provide a system that uses two unique and random codes based on cryptographic blockchain key pairs to represent both the physical asset (private code) and the digital or virtual asset (public code) as a token. In various embodiments, these codes are initially recoded and associated to assets by a known trusted authority and all subsequent data generated by the movement, use, manipulation, and exchange of the asset during its whole lifecycle can be trust-linked (forwards and backwards) using either the tokenized digital version or the physical version, independently from the SAME trust-chain of data recorded on blockchains.
Owner:INTEGRATED MANAGEMENT SYSTEMS HONG KONG LTD

Internet of vehicles cross-domain authentication and key agreement method based on double-chain structure

The invention discloses an Internet of Vehicles cross-domain authentication and key agreement method based on a double-chain structure. The method comprises the following steps: generating system public parameters based on a trusted authority and writing the system public parameters into a main chain; generating a corresponding identity encryption value, a reputation value, an area number and a vehicle and road side unit binding value based on the road side unit registration information; generating a virtual identity, a secret value and a binding parameter of the vehicle based on the vehicle user registration information; the vehicle obtains a binding value of the vehicle and the roadside unit based on the binding parameter and initiates authentication to the roadside unit to obtain an area number; when the vehicle needs cross-domain communication, the vehicle generates a hidden identity and a cross-domain request based on target area verification node information, and a verification node generates an aggregation signature and an encryption seed after verifying the cross-domain request; the main node verifies the legality of the vehicle based on the aggregation signature, and decrypts the encrypted seed to obtain a seed; and the main node queries in the main chain based on the area number and the virtual identity of the vehicle to obtain a secret value, and verifies the session key based on the secret value and the seed.
Owner:ANQING NORMAL UNIV

Privacy protection and verifiable federated learning method based on hyper-incremental sequence

PendingCN121835947ADigital data protectionMachine learningTrusted authorityData set
The invention discloses a privacy protection and verifiable federated learning method based on a hyper-incremental sequence, and aims to improve data security and calculation efficiency in a federated learning process. The method comprises the following steps: (1) system initialization: a trusted authority (TA) generates key parameters required by the system, and distributes related parameters to a client to support subsequent encryption and verification processes; (2) training a model by the clients: training the model by each client based on a local data set, encoding and encrypting gradient data by using a hyper-incremental sequence, and then uploading the gradient data to a cloud for aggregation; (3) central server aggregation: the server aggregates the encrypted gradient data uploaded by the client by using an addition homomorphic encryption technology, returns an aggregation result to the client, and ensures that the gradient information is always kept in an encrypted state at the server side; and (4) local model updating and verification: the client decrypts and decodes the aggregation result, verifies the correctness of the aggregation result, and updates local model parameters based on the aggregation gradient. According to the invention, an efficient encryption and verification mechanism is designed, so that collusion attacks can be resisted, flexible exit of the client is supported, the security, verifiability and calculation efficiency of the system are ensured, and the method is suitable for various privacy protection federated learning application scenes.
Owner:HUNAN UNIV OF SCI & TECH

An anonymous dynamic authentication and key agreement method based on certificateless signature

This invention discloses an anonymous dynamic authentication and key negotiation method based on certificateless signatures. This method is based on a system model operating in an edge intelligent IoT environment, consisting of four entities: intelligent nodes, a key generation center, edge nodes, and a trusted authority. The method comprises five stages: system initialization performed by the key generation center; pseudo-identities assigned to system entities and public-private key pairs generated through entity registration involving intelligent nodes, edge nodes, and the trusted authority; mutual authentication and key negotiation between intelligent nodes and edge nodes; batch authentication; and encryption transmission of intelligent IoT data using a symmetric encryption algorithm based on the negotiated session key. This invention, based on a certificateless signature mechanism, avoids the complexity of certificate management and key escrow, while eliminating high-overhead operations such as bilinear pairing and exponential operations, effectively reducing the computational burden on resource-constrained terminals.
Owner:GUIZHOU NORMAL UNIVERSITY

Remote access via system-level trusted authorities

Methods and systems for establishing a system specific trust system are provided. The methods and systems establish a secure channel between a first device and a second device using a system specific trusted authority. The methods and systems determine, by the first device, using a first certificate associated with the second device, a first set of access rights of the second device and determine, by the second device, using a credential associated with the first device, a second set of access rights of the first device.
Owner:ASSA ABLOY AB

Implicit attack resistant medical tactile internet security authentication system and method

The invention belongs to the technical field of communication, and provides an implicit-attack-resistant medical tactile internet security authentication system and an implicit-attack-resistant medical tactile internet security authentication method. The system comprises a trusted authority (TA), a remote doctor (RDs), a medical robot (MRs) and a gateway (GW). The TA is responsible for registration of all remote doctors, medical robots and gateways in the medical tactile internet. After a remote doctor registers on the TA, remote touch control over the medical robot can be achieved through the gateway by means of mutual authentication with the gateway and the medical robot. The medical robot is deployed in a hospital and supports inquiry and operation. The gateway serves as an incompletely credible relay device and is responsible for assisting identity authentication and shared key negotiation between a remote doctor and the medical robot, and safe communication is ensured.
Owner:ZHONGNAN UNIVERSITY OF ECONOMICS AND LAW

A two-way verifiable secure aggregation method for federated learning

PendingCN122316633ATrusted authorityData set
This invention discloses a bidirectional, verifiable, and secure aggregation method for federated learning, comprising three entities: a trusted authority, a client, and a server. Bidirectional verification is achieved through verifiable secret sharing and homomorphic encryption: the server verifies the legitimacy of the client's identity before aggregation, and the client independently verifies the correctness of the server's aggregation result before updating. The specific process includes five stages: initialization, key distribution, masking and sharing, verification and aggregation, and checking and updating. The protocol uses Paillier homomorphic encryption to protect model gradient privacy, avoids high-complexity operations such as bilinear pairing, and reduces verification computational overhead. Experiments on the MNIST and CIFAR-100 datasets verify the correctness and efficiency of the protocol. Compared with existing schemes, it has advantages in computational and communication costs, while enhancing the robustness and security of federated learning.
Owner:NANJING UNIV OF POSTS & TELECOMM

Offline certificate authority renewal for medical devices

PendingUS20260046146A1User identity/authority verificationSecure communicationTrusted authority
In a system where secure communication relies on device certificates issued by an authority having its own certificate, a first device can transmit an update message to a second device based on determining that the most recent certificate available to the first device is newer than the most recent certificate available to the second device. In various examples, the update message includes the newer certificate and is digitally signed by a mutually trusted authority.The update message can be transmitted during a time when one or both devices are unable to communicate with the mutually trusted authority. In this way, the second device can obtain the newer certificate through an offline update process and use the newer certificate to validate a device certificate of the first device, e.g., as a prerequisite for establishing a communication channel to the first device.
Owner:MEDTRONIC MINIMED INC

Non-transitory computer readable medium and device

A non-transitory machine-readable medium including machine-readable instructions is provided. The machine-readable instructions, when executed on a device, cause the device to receive, by a trusted institution, an access request for user data stored on a distributed network. The machine-readable instructions further cause the apparatus to search for entries related to the user data in the immutable ledger by the trusted institution. The machine-readable instructions further cause the apparatus to selectively decide whether to grant access to the user data by the trusted authority and based on an access policy for the user data indicated by the entry.
Owner:INTEL CORP

Method and system for adaptive authentication and key agreement in cloud-edge-device environments

A method and system for adaptive authentication and key agreement in cloud-edge-device environments are provided. The method includes: utilizing a trust authority to perform identity registration for users, devices, edge servers, and cloud servers; after identity registration is completed, a user logs into a device and sends the user's request information to edge servers within range through the logged-in device; upon receiving the request information, the edge server provides service to the user: determining whether the edge server's service capability satisfies the request information; if yes, performing authentication and key agreement between the edge server and the user's logged-in device, and providing service to the user after completion; if no, selecting a cloud server to perform authentication and key agreement with the user's logged-in device, and providing service to the user after completion. The disclosure can adaptively execute different authentication methods, devices only need to send one authentication request to satisfy requirements, reducing redundant authentication of devices, reducing the load on Trust Authority (TA) while protecting device privacy.
Owner:BEIJING UNIV OF POSTS & TELECOMM

An authenticable high-efficient n-of-k oblivious transfer method and system

ActiveCN116015658BPublic key for secure communicationTrusted authorityCiphertext
The application discloses an authentic high-efficiency n-taken-k careless transmission method and system, and the method comprises the following steps: S1, a system establishment step, wherein a trusted authority KGC outputs system public parameters mpk and a secret master private key msk based on input security parameters; S2, a key generation step, wherein the trusted authority KGC outputs a public-private key pair corresponding to the identity of the sender and the receiver to the sender and the receiver based on the identity information of the accepted sender and receiver; S3, a careless transmission step, wherein the receiver encrypts k own keys and sends them to the sender; the sender converts the k keys and encrypts n information to generate n ciphertexts, and then sends the k converted keys and the n ciphertexts to the receiver; and S4, a decryption step, wherein the receiver uses the k converted keys to decrypt the n ciphertexts to obtain k desired information. The identity authentication problem of the sender and the receiver in the careless transmission process is solved, and efficient encryption and decryption are realized.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

Internet of Things data sharing method and system based on threshold signature

PendingCN122027234AUser identity/authority verificationTrusted authorityEdge server
The invention discloses an Internet of Things data sharing method and system based on a threshold signature. The method comprises four types of participants: a trusted authority TA, an edge server ES, Internet of Things equipment and a data aggregation node. The TA is responsible for registration and management of the Internet of Things equipment, the edge server ES and the data aggregation node; the ES cooperatively signs the broadcast message of the data aggregation node; the data aggregation node is used as an aggregator, and an aggregation signature is generated by using the ES signature; and the Internet of Things equipment realizes authentication of the data aggregation node through signature verification. And the data aggregation node aggregates the signature of the ES, so that the communication and calculation overhead between the data aggregation node and the Internet of Things equipment is remarkably reduced. The registration and management work of the TA can be executed in an offline state, so that the efficiency and safety of the system are further improved. A threshold cryptography mechanism is introduced, a plurality of ESs are required to collaboratively sign the same message, and the system can still ensure the authenticity of the message even if a part of ESs are broken through.
Owner:WUHAN UNIV

Cloud service-oriented on-lattice attribute-based connection keyword search method

The invention provides a cloud service-oriented on-lattice attribute-based connection keyword search method. The method comprises the following steps of: initializing parameters by a trusted authority center, calling a trap door generation algorithm in a lattice password and selecting a random matrix to construct public parameters and a main private key; for the data owner, the trusted authority center calculates a public key and a private key of the data owner by using a trap door generation algorithm, and for the data user, the trusted authority center calculates a private key of the data user by using a lattice basis generation algorithm; the data owner constructs an access strategy, selects a random encryption vector and a plurality of disturbance parameters to generate a data ciphertext, and uploads the data ciphertext to the cloud server; the data user selects a polynomial, calculates a first intermediate vector and a second intermediate vector, calls a generalized lattice-based sampling algorithm in the lattice password to generate a search trap door, and uploads the search trap door to the cloud server; after the data ciphertext and the search trap door are received, the cloud server sets a fourth ciphertext, calculates a third intermediate vector and judges whether the attribute of the user meets the access strategy or not, and if yes, search is carried out, and a search result is returned. According to the method, a lattice password technology is adopted, connection keyword search is supported while data access control is achieved, and high post-quantum security is achieved.
Owner:NORTH CHINA UNIVERSITY OF TECHNOLOGY

An aircraft anonymous authentication method based on pseudonym aggregation index

The application discloses an aircraft anonymous authentication method based on pseudonym aggregation index, and the method constructs a hierarchical collaborative architecture of a trusted authority center, a regional management agency, a low-altitude base station and an unmanned aircraft, completes system initialization, strong authentication and key negotiation based on an elliptic curve cryptography system, generates an aircraft pseudonym by the regional management agency, and generates a unique index through aggregation operation, and the index is chained together with a certificate, and the trusted authority center stores the mapping relationship between the index and the real identity. The aircraft initiates an anonymous authentication request through additive homomorphic encryption, and the index level fast authentication is completed by a calculation node after verification by the base station; in a malicious scene, the ciphertext pseudonym is aggregated, and the real identity is traced back by controlled decryption of the trusted authority center, and the whole life cycle management of the certificate is realized, forming a 'one-time strong authentication and multiple fast authentication' mode. The method reduces authentication complexity and time delay, improves high-concurrency processing capacity, and realizes privacy protection and security supervision.
Owner:JIANGSU UNIV OF TECH

Cross-domain authentication and key agreement method and system for unmanned aerial vehicle assisted internet of vehicles

The invention relates to a cross-domain authentication and key agreement method and system for an unmanned aerial vehicle assisted Internet of Vehicles. The method is applied to an emergency rescue system comprising an unmanned aerial vehicle, a vehicle, a trusted authority (TA) and an alliance chain. A TA is deployed in each communication domain to serve as an alliance chain consensus node, the node obtains a core parameter after TA dual verification registration, the node generates a temporary parameter to initiate an authentication request during cross-domain rescue, a cross-domain voucher uplink consensus is generated after TA verification, and the three parties collaboratively negotiate a session key based on a Chebyshev Diffie-Hellman problem and perform uplink evidence storage. According to the scheme, the Chebyshev mapping lightweight characteristic and the alliance chain distributed trust advantage are fused, privacy and responsibility traceability are guaranteed, various attacks are resisted, the whole process is low in time consumption, the emergency rescue real-time requirement is met, and safety guarantee is provided for key data interaction.
Owner:NANYANG NORMAL UNIV