Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

37 results about "Trusted authority" patented technology

System and Method for Digital Identity Authorization

A system including a mobile communication device configured to communicate with a secure element is disclosed herein. The mobile communication device is equipped with a secure element for improving an authorization process, comprising interface circuitry configured to communicate with a trusted authority, and processing circuitry configured to control the interface circuitry and to receive a signal from the trusted authority. The signal comprises information indicative of a user binding to the secure element.
Owner:BAYERISCHE MOTOREN WERKE AG

Blockchain-based anonymous authentication method for cross-trusted authority in internet of vehicles

PendingUS20260012346A1User identity/authority verificationTrusted authorityInternet privacy
The invention belongs to the field of computer security and discloses a blockchain-based anonymous authentication method for the Internet of Vehicles across trusted authorities, including registering the vehicle (with onboard unit) and roadside unit in their respective trusted authorities. When the vehicle enters different trusted authority domains, both the onboard unit and roadside unit generate corresponding authentication parameters and transmit them to the consortium blockchain of the Internet of Vehicles for verification and signature, obtaining authenticated data signed by the consortium blockchain. The onboard unit and roadside unit receive and verify the authenticated data, and upon successful verification, the onboard unit calculates a session key. The onboard unit uses the session key to sequentially transmit data with the roadside unit and the consortium blockchain. This technical solution allows vehicles from any trusted authority domain to authenticate and negotiate session keys with roadside units from different trusted authority domains.
Owner:HANGZHOU NORMAL UNIVERSITY

High-performance multi-keyword sorting query privacy computing system for secret state big data

The invention discloses a high-performance multi-keyword sorting query privacy computing system oriented to secret state big data. Comprising four participants including a trusted authority, a data owner, a query user and a cloud server, and seven functional modules including a system initialization module, a key generation module, a data encryption module, a query token generation module, a security query module, a data decryption module and a key tracking module. On the basis of deeply researching and analyzing existing searchable encryption, access control based on attribute-based encryption and high-performance index technology research results, the invention provides a high-performance multi-keyword sorting query privacy calculation scheme and an application system oriented to secret state big data. The invention provides a high-performance safe multi-keyword sorting query scheme for realizing access control for the first time, and has the capabilities of high-performance multi-keyword sorting query, fine-grained ciphertext access control, malicious user tracking and dynamic data updating at the same time on the premise of protecting data privacy.
Owner:EAST CHINA NORMAL UNIV +2

Identity management method and apparatus

An identity management method, wherein the method includes: A trusted authority (TA) device determines a pseudonymous identity (PID) of a terminal device i, and sends a first parameter to the terminal device i, where the first parameter indicates the PID of the terminal device i, and the PID of the terminal device i is determined based on a real identity (RID) of the terminal device i. Based on this, the TA device may determine the PID for the terminal device, to protect the RID of the terminal device. In addition, the PID of the terminal device is associated with the RID of the terminal device, so that the TA device can determine the RID of the terminal device based on the PID of the terminal device, and can determine the real identity of the terminal device when the terminal device performs a malicious operation or an unauthorized operation.
Owner:HUAWEI TECH CO LTD

Trusted tokenized asset transactions

In one or more embodiments, the present invention provide a system that uses two unique and random codes based on cryptographic blockchain key pairs to represent both the physical asset (private code) and the digital or virtual asset (public code) as a token. In various embodiments, these codes are initially recoded and associated to assets by a known trusted authority and all subsequent data generated by the movement, use, manipulation, and exchange of the asset during its whole lifecycle can be trust-linked (forwards and backwards) using either the tokenized digital version or the physical version, independently from the SAME trust-chain of data recorded on blockchains.
Owner:INTEGRATED MANAGEMENT SYSTEMS HONG KONG LTD

Privacy-preserving dynamic vehicle platooning management methods and systems

ActiveCN120415904BPlatooningSecuring communicationTrusted authorityAttack
This invention discloses a privacy-preserving dynamic vehicle platooning management method and system, comprising: a lead vehicle broadcasting a vehicle platooning recruitment message and transmitting the message to cloud server A; simultaneously, member vehicles generating request messages containing location information and digital signatures, which are forwarded to cloud server A via roadside units (RSUs); cloud server A, with the assistance of cloud server B, calculating the encrypted spatial distance between the lead vehicle and the requesting vehicle using the encrypted Manhattan distance calculation method, and finally outputting a trusted vehicle platooning decision; after the platooning trip is completed, member vehicles generating feedback scores and digital signatures, which are sent to cloud server A via roadside units (RSUs); cloud server A sending aggregated reputation encrypted messages to a trusted authority; and calculating the new reputation value of the lead vehicle from the aggregated reputation encrypted messages received from cloud server A. Using the technical solution of this invention, dynamic platoon disbanding in platooning management is achieved, while effectively protecting privacy and resisting various attacks.
Owner:JINAN UNIVERSITY

Cross trusted authorities identity authentication and message publishing method based on redactable blockchain

The invention discloses a cross trusted authority identity authentication and message publishing method based on redactable blockchain, adopts a redactable blockchain based on chameleon hash function to replace the traditional blockchain, and the trusted authority can use the private key of the chameleon hash function to edit the block content on the blockchain, so that only legal, valid and timely information is stored on the blockchain. In addition, the trusted authority can also edit the vehicle authentication information stored on the blockchain, easily updating the vehicle information credentials or revoking the information credentials of illegal vehicles. In the process of authentication and key negotiation, cryptography tools are used to ensure the confidentiality, integrity and availability of messages, and can effectively resist various known attacks.
Owner:HANGZHOU NORMAL UNIVERSITY

Internet of vehicles cross-domain authentication and key agreement method based on double-chain structure

The invention discloses an Internet of Vehicles cross-domain authentication and key agreement method based on a double-chain structure. The method comprises the following steps: generating system public parameters based on a trusted authority and writing the system public parameters into a main chain; generating a corresponding identity encryption value, a reputation value, an area number and a vehicle and road side unit binding value based on the road side unit registration information; generating a virtual identity, a secret value and a binding parameter of the vehicle based on the vehicle user registration information; the vehicle obtains a binding value of the vehicle and the roadside unit based on the binding parameter and initiates authentication to the roadside unit to obtain an area number; when the vehicle needs cross-domain communication, the vehicle generates a hidden identity and a cross-domain request based on target area verification node information, and a verification node generates an aggregation signature and an encryption seed after verifying the cross-domain request; the main node verifies the legality of the vehicle based on the aggregation signature, and decrypts the encrypted seed to obtain a seed; and the main node queries in the main chain based on the area number and the virtual identity of the vehicle to obtain a secret value, and verifies the session key based on the secret value and the seed.
Owner:ANQING NORMAL UNIV

Secure transfer of blockchain-based tokens

PCT designated stage expiredWO2025038261A9Database updatingFinanceTrusted authorityComputer network
An example may involve receiving, by a computing system configured as a node of a network of nodes operating a distributed storage structure, a request message for placing an entry on the distributed storage structure, wherein the entry contains or refers to a digital token; making a first determination that the request message or the entry is digitally signed by a trusted authority and digitally signed by a previous owner of the digital token; making a second determination that the entry is requesting transfer of the digital token from a putative owner of the digital token to the trusted authority; and, based on the first determination and the second determination, submitting the entry for block processing to be added to the distributed storage structure.
Owner:KANOVITZ MICHAEL IRA +1

Privacy protection and verifiable federated learning method based on hyper-incremental sequence

PendingCN121835947ADigital data protectionMachine learningTrusted authorityData set
The invention discloses a privacy protection and verifiable federated learning method based on a hyper-incremental sequence, and aims to improve data security and calculation efficiency in a federated learning process. The method comprises the following steps: (1) system initialization: a trusted authority (TA) generates key parameters required by the system, and distributes related parameters to a client to support subsequent encryption and verification processes; (2) training a model by the clients: training the model by each client based on a local data set, encoding and encrypting gradient data by using a hyper-incremental sequence, and then uploading the gradient data to a cloud for aggregation; (3) central server aggregation: the server aggregates the encrypted gradient data uploaded by the client by using an addition homomorphic encryption technology, returns an aggregation result to the client, and ensures that the gradient information is always kept in an encrypted state at the server side; and (4) local model updating and verification: the client decrypts and decodes the aggregation result, verifies the correctness of the aggregation result, and updates local model parameters based on the aggregation gradient. According to the invention, an efficient encryption and verification mechanism is designed, so that collusion attacks can be resisted, flexible exit of the client is supported, the security, verifiability and calculation efficiency of the system are ensured, and the method is suitable for various privacy protection federated learning application scenes.
Owner:HUNAN UNIV OF SCI & TECH

A non-interactive instant identity verification and secure data transmission method

The application discloses a non-interactive instant identity authentication and secure data transmission method, which generates global parameters through a trust authority and distributes them to edge terminals, an authentication center and an edge computing server, and adopts a non-interactive identity authentication technology to perform edge terminal authentication. In the authentication process, the edge terminal generates and sends instant authentication credentials to realize secure connection with the edge computing server. Hash functions and public key cryptography technology are adopted to ensure the security of communication, and a non-member proof and revocation list mechanism are adopted to prevent illegal terminals from accessing the system. Temporary symmetric keys are used for encryption between the edge terminal and the server to ensure the confidentiality and integrity of data transmission. The application has efficient identity authentication, reliable data transmission security and optimized computing and bandwidth utilization, is suitable for resource-limited edge computing scenarios, and has good security, efficiency and scalability.
Owner:SHANGHAI MARITIME UNIVERSITY +1

Authenticating Transactions Using Biometric Authentication

PendingUS20250328905A1User identity/authority verificationCommerceTrusted authorityBiometric data
A system and method for authenticating transactions using biometric authentication is disclosed. The method includes receiving a message for a transaction from one of a user device and a trusted authority server. The message is generated on receiving preconfigured biometric data for the transaction on the user device. The message is verified in order to retrieve a prestored second Personal Identification Number (PIN) fragment associated with a PIN of the user. The second PIN fragment is transmitted to one of the user device and the trusted authority server in order to determine the PIN by using the second PIN fragment and a first PIN fragment received from the user device. In an alternate implementation, the method includes determining an authorized token using one or more token fragments stored on a plurality of entities.
Owner:MINKASU INC

An anonymous dynamic authentication and key agreement method based on certificateless signature

This invention discloses an anonymous dynamic authentication and key negotiation method based on certificateless signatures. This method is based on a system model operating in an edge intelligent IoT environment, consisting of four entities: intelligent nodes, a key generation center, edge nodes, and a trusted authority. The method comprises five stages: system initialization performed by the key generation center; pseudo-identities assigned to system entities and public-private key pairs generated through entity registration involving intelligent nodes, edge nodes, and the trusted authority; mutual authentication and key negotiation between intelligent nodes and edge nodes; batch authentication; and encryption transmission of intelligent IoT data using a symmetric encryption algorithm based on the negotiated session key. This invention, based on a certificateless signature mechanism, avoids the complexity of certificate management and key escrow, while eliminating high-overhead operations such as bilinear pairing and exponential operations, effectively reducing the computational burden on resource-constrained terminals.
Owner:GUIZHOU NORMAL UNIVERSITY

Efficient privacy protection authentication scheme for edge-assisted Internet of Things security warning system

The invention discloses an efficient privacy protection authentication scheme for an edge-assisted Internet of Things security warning system, belongs to the technical field of Internet of Things privacy protection, and is based on an improved linkable group signature mechanism and a security warning system architecture. The security warning system architecture comprises a trusted authorization mechanism TA, edge nodes ENs and equipment. Comprising a system initialization stage, an equipment registration stage, a message transmission stage, a verification and decryption stage and a malicious tracing stage. According to the efficient privacy protection authentication scheme for the edge-assisted Internet of Things security warning system, balance between anonymity and responsibility of the edge nodes can be realized, key challenges of maintaining privacy while ensuring security early warning integrity are completed, Sybil attacks are effectively resisted, and the security early warning system has the advantages that the security early warning integrity is ensured, the security early warning safety is ensured, and the security early warning safety is ensured. And safety measures in the system are further enhanced.
Owner:BEIJING INST OF TECH

Remote access via system-level trusted authorities

Methods and systems for establishing a system specific trust system are provided. The methods and systems establish a secure channel between a first device and a second device using a system specific trusted authority. The methods and systems determine, by the first device, using a first certificate associated with the second device, a first set of access rights of the second device and determine, by the second device, using a credential associated with the first device, a second set of access rights of the first device.
Owner:ASSA ABLOY AB

Implicit attack resistant medical tactile internet security authentication system and method

The invention belongs to the technical field of communication, and provides an implicit-attack-resistant medical tactile internet security authentication system and an implicit-attack-resistant medical tactile internet security authentication method. The system comprises a trusted authority (TA), a remote doctor (RDs), a medical robot (MRs) and a gateway (GW). The TA is responsible for registration of all remote doctors, medical robots and gateways in the medical tactile internet. After a remote doctor registers on the TA, remote touch control over the medical robot can be achieved through the gateway by means of mutual authentication with the gateway and the medical robot. The medical robot is deployed in a hospital and supports inquiry and operation. The gateway serves as an incompletely credible relay device and is responsible for assisting identity authentication and shared key negotiation between a remote doctor and the medical robot, and safe communication is ensured.
Owner:ZHONGNAN UNIVERSITY OF ECONOMICS AND LAW

A two-way verifiable secure aggregation method for federated learning

PendingCN122316633ATrusted authorityData set
This invention discloses a bidirectional, verifiable, and secure aggregation method for federated learning, comprising three entities: a trusted authority, a client, and a server. Bidirectional verification is achieved through verifiable secret sharing and homomorphic encryption: the server verifies the legitimacy of the client's identity before aggregation, and the client independently verifies the correctness of the server's aggregation result before updating. The specific process includes five stages: initialization, key distribution, masking and sharing, verification and aggregation, and checking and updating. The protocol uses Paillier homomorphic encryption to protect model gradient privacy, avoids high-complexity operations such as bilinear pairing, and reduces verification computational overhead. Experiments on the MNIST and CIFAR-100 datasets verify the correctness and efficiency of the protocol. Compared with existing schemes, it has advantages in computational and communication costs, while enhancing the robustness and security of federated learning.
Owner:NANJING UNIV OF POSTS & TELECOMM

Privacy-preserving and efficient low-altitude route authentication method

PendingUS20260253503A1Trusted authorityUncrewed vehicle
A privacy-preserving and efficient low-altitude route authentication method. In the route verification information generation phase, the trusted authority center defines the legal routes of UAVs for each sentry station and generates a Bloom filter. The trusted authority center uses this filter to generate elements and send them to the sentry stations to prepare for subsequent verification. In the route verification phase, the sentry stations receive the real-time flight data of UAVs, use the Bloom filter to screen out elements of illegal routes, process them, and then send them to the trusted authority center. The trusted authority center verifies the received elements, and if the verification is successful, the corresponding routes are confirmed as legal. This method ensures that only UAVs flying on legal routes can pass the verification, protects the privacy of route information, and reduces computing and communication overheads at the same time.
Owner:HARBIN INST OF TECH (SHENZHEN) (HARBIN INST OF TECH SHENZHEN INST OF SCI & TECH INNO)

Offline certificate authority renewal for medical devices

PendingUS20260046146A1User identity/authority verificationSecure communicationTrusted authority
In a system where secure communication relies on device certificates issued by an authority having its own certificate, a first device can transmit an update message to a second device based on determining that the most recent certificate available to the first device is newer than the most recent certificate available to the second device. In various examples, the update message includes the newer certificate and is digitally signed by a mutually trusted authority.The update message can be transmitted during a time when one or both devices are unable to communicate with the mutually trusted authority. In this way, the second device can obtain the newer certificate through an offline update process and use the newer certificate to validate a device certificate of the first device, e.g., as a prerequisite for establishing a communication channel to the first device.
Owner:MEDTRONIC MINIMED INC

A vehicle-to-infrastructure (v2i) authentication key exchange protocol and a fast handover authentication method thereof

ActiveCN119183105BPublic key for secure communicationParticular environment based servicesTrusted authorityFast handover
A vehicle-to-everything (V2I) authentication key exchange protocol and a fast switching authentication method thereof include the following steps: step one, the system selects and sets elliptic curve parameters for authentication and encryption, and configures the hardware security module of each node and the trusted platform module of the vehicle; step two, the vehicle and the driver's information are securely registered in the system, the vehicle registers its real identity by generating a unique public-private key pair and registering with the trusted authority center (TA), the TA generates a pseudo identity of the vehicle after verification and sends it back to the vehicle through a secure channel; step three, the RSU generates and registers its unique identity with the TA, the TA generates the relevant authentication information of the RSU after verification and stores it in the block chain; step four, the initial authentication and key exchange between the vehicle and the RSU are completed; and step five, the switching authentication with the new RSU is completed. The application has the characteristics of high efficiency, low calculation cost and communication overhead, strong security and privacy protection.
Owner:GANSU INST OF POLITICAL SCI & LAW

Cross-domain authentication method for Internet of Vehicles based on blockchain and certificateless ECC

The present invention discloses a cross-domain authentication method for the Internet of Vehicles (IoV) based on blockchain and certificateless ECC. The method comprises the following steps: a trusted authority generates and publishes global parameters for certificateless elliptic curve cryptography and deploys a blockchain network; all roadside units and vehicles sequentially initiate registration requests to the trusted authority; legitimate roadside units receive pseudonyms and legitimate vehicles receive keys returned by the trusted authority; registered vehicles and the roadside units perform mutual authentication and key negotiation; the vehicle sends a signed authentication request packet to the roadside unit; the roadside unit verifies the freshness of the request and the validity of the signature through a blockchain smart contract, and then returns the data packet to the vehicle via a secure channel for verification; and the vehicle is reauthenticated when its position changes. The present invention adopts a certificateless elliptic curve cryptography system, eliminating the traditional certificate transmission and verification overhead and reducing communication latency.
Owner:HUNAN UNIV OF SCI & TECH

Method for verifying execution trail of protective storage processing section, program therefor and execution trail verification device for protective storage processing section

To provide a method for verifying an execution trail of a protective storage processing section which is appropriate for utilization as a settlement processing method for digital currency and a system therefor, a program therefor and an execution trail verification device for a protective storage processing section.SOLUTION: When a verification of a first execution trail of an observer program transmitted from a user terminal 1 and installed in a protective storage processing section 2 is made successful, in a second execution trail including a blind signature which is performed on a public key transmitted from the user terminal 1 and certification information transmitted from the protective storage processing section 2 to the user terminal 1 and certifying that a private key corresponding to the public key is owned, the blind signature and the certification information are received by a reliable facility terminal 3 and it is confirmed that the blind signature and the certification information are authentic, thereby verifying that the second execution trail transmitted from the protective storage processing section 2 is authenticated.SELECTED DRAWING: Figure 1
Owner:SAKURA INFORMATION SYST +1

Multi-user dynamic authorization ciphertext retrieval method based on proxy re-encryption and Chinese remainder theorem

The invention discloses a dynamic multi-user authorization ciphertext retrieval method based on proxy re-encryption and the Chinese remainder theorem, which comprises the following steps: a data owner generates an original ciphertext, the data owner generates a global authorization factor for a data user, and the global authorization factor and the original ciphertext are stored in a cloud server; when a certain data user needs to access data, the trusted authority generates a re-encryption key and sends the re-encryption key to the cloud server to complete ciphertext conversion; the data user generates a retrieval trap door and an authentication factor and sends the retrieval trap door and the authentication factor to the cloud server for applying for retrieval; the cloud server matches the user according to the global authorization factor and the authentication factor, then executes ciphertext retrieval and returns an encrypted file; according to the method, the authorization / revocation of the single user is realized by updating the global authorization factor, the original ciphertext does not need to be updated, and the authorization / revocation does not leak the privacy of other users, so that the fine-grained control on the user permission is enhanced while the encryption overhead is reduced, and the problems that the user permission is difficult to revoke dynamically, the ciphertext updating overhead is high and the privacy is easy to leak are solved.
Owner:XIDIAN UNIV

Non-transitory computer readable medium and device

A non-transitory machine-readable medium including machine-readable instructions is provided. The machine-readable instructions, when executed on a device, cause the device to receive, by a trusted institution, an access request for user data stored on a distributed network. The machine-readable instructions further cause the apparatus to search for entries related to the user data in the immutable ledger by the trusted institution. The machine-readable instructions further cause the apparatus to selectively decide whether to grant access to the user data by the trusted authority and based on an access policy for the user data indicated by the entry.
Owner:INTEL CORP

Method and system for adaptive authentication and key agreement in cloud-edge-device environments

A method and system for adaptive authentication and key agreement in cloud-edge-device environments are provided. The method includes: utilizing a trust authority to perform identity registration for users, devices, edge servers, and cloud servers; after identity registration is completed, a user logs into a device and sends the user's request information to edge servers within range through the logged-in device; upon receiving the request information, the edge server provides service to the user: determining whether the edge server's service capability satisfies the request information; if yes, performing authentication and key agreement between the edge server and the user's logged-in device, and providing service to the user after completion; if no, selecting a cloud server to perform authentication and key agreement with the user's logged-in device, and providing service to the user after completion. The disclosure can adaptively execute different authentication methods, devices only need to send one authentication request to satisfy requirements, reducing redundant authentication of devices, reducing the load on Trust Authority (TA) while protecting device privacy.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Certificateless aggregation signature authentication method for vehicle-mounted ad hoc network

The invention discloses a certificateless aggregation signature authentication method and system for a vehicle-mounted ad hoc network, and relates to the technical field of wireless network security, and the method comprises the steps: generating a public parameter through a key generation center and a trust mechanism; generating a secret value based on the common parameter; generating a pseudonym for the vehicle; generating a partial private key of the vehicle; generating a key pair of the vehicle; generating a signature for the message; checking whether the signature is valid or not, if not, refusing the signature, and ending the program; otherwise, receiving the signature; generating an aggregation signature; verifying whether the aggregated signature is valid, if not, refusing the aggregated signature, and ending the program; otherwise, the aggregation signature is accepted. The invention provides a new aggregation algorithm, in the aggregation algorithm, only when all signatures are valid, the aggregated signature can be generated, that is, as long as an invalid signature exists, the valid aggregated signature cannot be aggregated, so that the scheme can significantly improve the security.
Owner:WESTERN CHINA SCI CITY INNOVATION CENT OF INTELLIGENT & CONNECTED VEHICLES (CHONGQING) CO LTD +1

An authenticable high-efficient n-of-k oblivious transfer method and system

ActiveCN116015658BPublic key for secure communicationTrusted authorityCiphertext
The application discloses an authentic high-efficiency n-taken-k careless transmission method and system, and the method comprises the following steps: S1, a system establishment step, wherein a trusted authority KGC outputs system public parameters mpk and a secret master private key msk based on input security parameters; S2, a key generation step, wherein the trusted authority KGC outputs a public-private key pair corresponding to the identity of the sender and the receiver to the sender and the receiver based on the identity information of the accepted sender and receiver; S3, a careless transmission step, wherein the receiver encrypts k own keys and sends them to the sender; the sender converts the k keys and encrypts n information to generate n ciphertexts, and then sends the k converted keys and the n ciphertexts to the receiver; and S4, a decryption step, wherein the receiver uses the k converted keys to decrypt the n ciphertexts to obtain k desired information. The identity authentication problem of the sender and the receiver in the careless transmission process is solved, and efficient encryption and decryption are realized.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

Internet of Things data sharing method and system based on threshold signature

PendingCN122027234AUser identity/authority verificationTrusted authorityEdge server
The invention discloses an Internet of Things data sharing method and system based on a threshold signature. The method comprises four types of participants: a trusted authority TA, an edge server ES, Internet of Things equipment and a data aggregation node. The TA is responsible for registration and management of the Internet of Things equipment, the edge server ES and the data aggregation node; the ES cooperatively signs the broadcast message of the data aggregation node; the data aggregation node is used as an aggregator, and an aggregation signature is generated by using the ES signature; and the Internet of Things equipment realizes authentication of the data aggregation node through signature verification. And the data aggregation node aggregates the signature of the ES, so that the communication and calculation overhead between the data aggregation node and the Internet of Things equipment is remarkably reduced. The registration and management work of the TA can be executed in an offline state, so that the efficiency and safety of the system are further improved. A threshold cryptography mechanism is introduced, a plurality of ESs are required to collaboratively sign the same message, and the system can still ensure the authenticity of the message even if a part of ESs are broken through.
Owner:WUHAN UNIV

A time-sensitive access control method and device based on CP-ABE in edge computing

The application belongs to the field of cloud computing mode security, and particularly relates to a time-sensitive access control method and device under edge computing based on CP-ABE. The method comprises the following steps: a trusted authority generates public parameters and a master key; the trusted authority generates corresponding user keys according to the attributes of different data users, wherein the user keys comprise a unique identifier, an attribute key and a signature key; a data user generates corresponding conversion keys according to different attribute keys; a data owner generates a ciphertext to a cloud server and generates time constraint information to a time server according to the signature private key of different data users and an access tree; the time server generates a verification result according to the time constraint information; an edge node generates a time token according to the verification result and a time trapdoor; a data user applies for decryption of the ciphertext to generate a partially decrypted ciphertext; and the partially decrypted ciphertext and the attribute key of the data user are inputted to output a plaintext.
Owner:SHANXI ELECTRIC POWER CO POWER COMM CENT

Mixers and regulated mixers

PendingUS20260253068A1Trusted authorityInternet privacy
Transferring a quantity of tokens to a withdrawing party includes receiving a deposit request from a depositing party, creating a withdrawal authorization that does not identify the depositing party, and receiving a withdrawal request that requests transfer of the quantity of tokens to the withdrawing party. A digital certificate has a signature of a trusted authority that verifies an identity of the withdrawing party. The digital certificate is verified, the indication that at least the quantity of tokens is available for withdrawal by the withdrawing party is verified, and the quantity of tokens is issued in response to confirming validity of the digital certificate and confirming the indication that at least the quantity of tokens is available for withdrawal by the withdrawing party. The withdrawing party may provide the digital certificate and / or the indication that at least the quantity of tokens is available for withdrawal by the withdrawing party.
Owner:MICALI SILVIO