Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

53 results about "Trusted authority" patented technology

Attestation-as-a-service for confidential computing

Various systems and methods are described for implementing trust authority or trust attestation verification operations, including for Trust-as-a-Service or Attestation-as-a-Service implementations, in accordance with the techniques discussed herein. In various examples, operations and configurations are described to enable service-to-service attestation using a trust authority, to operate an attestation service, and to coordinate trust operations between relying and requesting parties.
Owner:INTEL CORP

System and Method for Digital Identity Authorization

A system including a mobile communication device configured to communicate with a secure element is disclosed herein. The mobile communication device is equipped with a secure element for improving an authorization process, comprising interface circuitry configured to communicate with a trusted authority, and processing circuitry configured to control the interface circuitry and to receive a signal from the trusted authority. The signal comprises information indicative of a user binding to the secure element.
Owner:BAYERISCHE MOTOREN WERKE AG

Data uplink method and system based on government affair data sharing platform

The invention relates to the technical field of computers, in particular to a data uploading method and system based on a government affair data sharing platform, and the method comprises a data directory uploading step, a data resource uploading step, an application record uploading step, a calling record uploading step and a calling record on-chain checking step. The method has the beneficial effects that the block chain is combined with the government affair data sharing platform, the data catalog, the data resource, the application record and the calling record of the government affair data sharing platform are chained, and credibility, authority and high efficiency of data sharing are realized.
Owner:SHANGHAI INSPUR CLOUD COMPUTING SERVICE CO LTD

Blockchain-based anonymous authentication method for cross-trusted authority in internet of vehicles

The invention belongs to the field of computer security and discloses a blockchain-based anonymous authentication method for the Internet of Vehicles across trusted authorities, including registering the vehicle (with onboard unit) and roadside unit in their respective trusted authorities. When the vehicle enters different trusted authority domains, both the onboard unit and roadside unit generate corresponding authentication parameters and transmit them to the consortium blockchain of the Internet of Vehicles for verification and signature, obtaining authenticated data signed by the consortium blockchain. The onboard unit and roadside unit receive and verify the authenticated data, and upon successful verification, the onboard unit calculates a session key. The onboard unit uses the session key to sequentially transmit data with the roadside unit and the consortium blockchain. This technical solution allows vehicles from any trusted authority domain to authenticate and negotiate session keys with roadside units from different trusted authority domains.
Owner:HANGZHOU NORMAL UNIVERSITY

Verifiable searchable encryption method and system with flexible access control in cloud environment, and storage medium

The invention discloses a verifiable searchable encryption method and system with flexible access control in a cloud environment, and a storage medium. The method comprises the following steps: a trusted authority calculates and generates a system public key and a system master key; the trusted authority obtains a pre-access list containing data owner information, and respectively calculates a public key and a private key of the cloud server, a public-private key pair of the data owner and a private key of the data user, and the management of the owner-level authority is independent of the cloud server; through a lightweight permission updating method, not only can unauthorized search and attack be resisted, but also fine-grained access control on encrypted data can be realized under the condition of not sacrificing privacy; according to the method, the function of verifying the search result is added, the integrity and authenticity of the search result are ensured, and data security and access control can be ensured even if the server is possibly dishonest for the problem of cooperation depending on honest cloud servers.
Owner:NANJING UNIV OF SCI & TECH

High-performance multi-keyword sorting query privacy computing system for secret state big data

The invention discloses a high-performance multi-keyword sorting query privacy computing system oriented to secret state big data. Comprising four participants including a trusted authority, a data owner, a query user and a cloud server, and seven functional modules including a system initialization module, a key generation module, a data encryption module, a query token generation module, a security query module, a data decryption module and a key tracking module. On the basis of deeply researching and analyzing existing searchable encryption, access control based on attribute-based encryption and high-performance index technology research results, the invention provides a high-performance multi-keyword sorting query privacy calculation scheme and an application system oriented to secret state big data. The invention provides a high-performance safe multi-keyword sorting query scheme for realizing access control for the first time, and has the capabilities of high-performance multi-keyword sorting query, fine-grained ciphertext access control, malicious user tracking and dynamic data updating at the same time on the premise of protecting data privacy.
Owner:EAST CHINA NORMAL UNIV +2

Internet of vehicles cross-domain authentication method based on block chain and certificateless ECC

The invention discloses an Internet of Vehicles cross-domain authentication method based on a block chain and a certificateless ECC (Elliptic Curve Code), and the method comprises the following steps: a trusted mechanism generates and discloses global parameters of a certificateless elliptic curve password, and deploys a block chain network; all the road side units and the vehicles sequentially initiate registration requests to the trusted mechanism, legal road side units receive pseudonyms returned by the trusted mechanism, and legal vehicles receive secret keys returned by the trusted mechanism; mutual authentication and key negotiation are carried out between the registered vehicle and the road side unit, the vehicle sends a signed authentication request packet to the road side unit, the road side unit verifies the freshness of the request and verifies the validity of the signature through a block chain smart contract, and then a data packet is returned to the vehicle through a secure channel for verification; and when the position of the vehicle changes, the vehicle is re-authenticated. According to the method, a certificateless elliptic curve cryptosystem is adopted, so that the transmission and verification overhead of a traditional certificate is saved, and the communication time delay is reduced.
Owner:HUNAN UNIV OF SCI & TECH

Identity management method and apparatus

An identity management method, wherein the method includes: A trusted authority (TA) device determines a pseudonymous identity (PID) of a terminal device i, and sends a first parameter to the terminal device i, where the first parameter indicates the PID of the terminal device i, and the PID of the terminal device i is determined based on a real identity (RID) of the terminal device i. Based on this, the TA device may determine the PID for the terminal device, to protect the RID of the terminal device. In addition, the PID of the terminal device is associated with the RID of the terminal device, so that the TA device can determine the RID of the terminal device based on the PID of the terminal device, and can determine the real identity of the terminal device when the terminal device performs a malicious operation or an unauthorized operation.
Owner:HUAWEI TECH CO LTD

Trusted tokenized asset transactions

In one or more embodiments, the present invention provide a system that uses two unique and random codes based on cryptographic blockchain key pairs to represent both the physical asset (private code) and the digital or virtual asset (public code) as a token. In various embodiments, these codes are initially recoded and associated to assets by a known trusted authority and all subsequent data generated by the movement, use, manipulation, and exchange of the asset during its whole lifecycle can be trust-linked (forwards and backwards) using either the tokenized digital version or the physical version, independently from the SAME trust-chain of data recorded on blockchains.
Owner:INTEGRATED MANAGEMENT SYSTEMS HONG KONG LTD

Privacy-preserving dynamic vehicle platooning management methods and systems

This invention discloses a privacy-preserving dynamic vehicle platooning management method and system, comprising: a lead vehicle broadcasting a vehicle platooning recruitment message and transmitting the message to cloud server A; simultaneously, member vehicles generating request messages containing location information and digital signatures, which are forwarded to cloud server A via roadside units (RSUs); cloud server A, with the assistance of cloud server B, calculating the encrypted spatial distance between the lead vehicle and the requesting vehicle using the encrypted Manhattan distance calculation method, and finally outputting a trusted vehicle platooning decision; after the platooning trip is completed, member vehicles generating feedback scores and digital signatures, which are sent to cloud server A via roadside units (RSUs); cloud server A sending aggregated reputation encrypted messages to a trusted authority; and calculating the new reputation value of the lead vehicle from the aggregated reputation encrypted messages received from cloud server A. Using the technical solution of this invention, dynamic platoon disbanding in platooning management is achieved, while effectively protecting privacy and resisting various attacks.
Owner:JINAN UNIVERSITY

Cross trusted authorities identity authentication and message publishing method based on redactable blockchain

The invention discloses a cross trusted authority identity authentication and message publishing method based on redactable blockchain, adopts a redactable blockchain based on chameleon hash function to replace the traditional blockchain, and the trusted authority can use the private key of the chameleon hash function to edit the block content on the blockchain, so that only legal, valid and timely information is stored on the blockchain. In addition, the trusted authority can also edit the vehicle authentication information stored on the blockchain, easily updating the vehicle information credentials or revoking the information credentials of illegal vehicles. In the process of authentication and key negotiation, cryptography tools are used to ensure the confidentiality, integrity and availability of messages, and can effectively resist various known attacks.
Owner:HANGZHOU NORMAL UNIVERSITY

Internet of vehicles cross-domain authentication and key agreement method based on double-chain structure

The invention discloses an Internet of Vehicles cross-domain authentication and key agreement method based on a double-chain structure. The method comprises the following steps: generating system public parameters based on a trusted authority and writing the system public parameters into a main chain; generating a corresponding identity encryption value, a reputation value, an area number and a vehicle and road side unit binding value based on the road side unit registration information; generating a virtual identity, a secret value and a binding parameter of the vehicle based on the vehicle user registration information; the vehicle obtains a binding value of the vehicle and the roadside unit based on the binding parameter and initiates authentication to the roadside unit to obtain an area number; when the vehicle needs cross-domain communication, the vehicle generates a hidden identity and a cross-domain request based on target area verification node information, and a verification node generates an aggregation signature and an encryption seed after verifying the cross-domain request; the main node verifies the legality of the vehicle based on the aggregation signature, and decrypts the encrypted seed to obtain a seed; and the main node queries in the main chain based on the area number and the virtual identity of the vehicle to obtain a secret value, and verifies the session key based on the secret value and the seed.
Owner:ANQING NORMAL UNIV

Secure transfer of blockchain-based tokens

PCT designated stage expiredWO2025038261A9Database updatingFinanceTrusted authorityComputer network
An example may involve receiving, by a computing system configured as a node of a network of nodes operating a distributed storage structure, a request message for placing an entry on the distributed storage structure, wherein the entry contains or refers to a digital token; making a first determination that the request message or the entry is digitally signed by a trusted authority and digitally signed by a previous owner of the digital token; making a second determination that the entry is requesting transfer of the digital token from a putative owner of the digital token to the trusted authority; and, based on the first determination and the second determination, submitting the entry for block processing to be added to the distributed storage structure.
Owner:KANOVITZ MICHAEL IRA +1

A reliable and fair attribute encryption outsourcing decryption method based on smart contracts

The present invention discloses a reliable and fair attribute encryption outsourcing decryption method based on smart contracts, comprising the following steps: a master key and public parameters are output by a trusted authority; the trusted authority then calculates and outputs a private key; a sender obtains a ciphertext and transmits it to a storage cloud server; the sender obtains a conversion key and a corresponding retrieval key; the sender obtains a set W, the storage cloud server sends the ciphertext to the smart contract in segments, and the sender sends the conversion key and the set W to the smart contract in segments; a node calculates and outputs a meta-element, the node issues a transaction, uploads the meta-element to the smart contract, and the smart contract calculates and outputs a conversion ciphertext; the sender obtains the encapsulated key through the public parameters, the conversion ciphertext and the retrieval key; the present invention does not introduce redundant information, thus avoiding placing an additional burden on the decryption cloud server and the user to check the validity of the converted ciphertext.
Owner:HANGZHOU POST QUANTUM CRYPTOGRAPHY TECH CO LTD

A cross-domain authentication method and system in a vehicle-mounted ad hoc network

The present invention relates to the field of network security and communication technologies, specifically disclosing a cross-domain authentication method and system for a vehicle-mounted ad hoc network. The method is implemented based on a cross-domain authentication system for the vehicle-mounted ad hoc network, which includes a key generation center, a trusted authority within at least one domain corresponding to each area, and several roadside units and vehicles within each area. The method includes the following steps: system initialization, vehicle initialization, roadside unit initialization, construction of a threshold group signature, identity update, intra-domain identity authentication, inter-domain identity authentication, identification of illegal users, and deregistration of illegal users. The present invention provides a cross-domain authentication method that effectively addresses issues such as privacy protection, cross-domain device collaboration, and malicious entity tracking in vehicle networks, promoting the rapid development of smart transportation.
Owner:XIAN UNIV OF POSTS & TELECOMM

Blockchain-assisted conditional privacy protection method and system based on ring signcryption

The present invention discloses a blockchain-assisted conditional privacy protection method and system based on ring signcryption, belonging to the field of blockchain technology. The method comprises: protecting the vehicle network by embedding a first blockchain and a second blockchain in a vehicle network consisting of a trusted authority (TA), a roadside unit (RSU), and vehicles equipped with an OBU. The first blockchain is used to store the identity and public key information of the vehicle user. When a vehicle engages in malicious behavior, the TA removes the malicious vehicle from the first blockchain and stores it in the second blockchain. The present invention can be used to maintain the security and data integrity of vehicle communications through blockchain. By storing traffic data on the blockchain, it can ensure that the data is not tampered with or forged, helping to prevent the spread of false information and increase the credibility of vehicle communications, thereby reducing the threat of false and malicious vehicles.
Owner:LANZHOU JIAOTONG UNIV

Privacy protection and verifiable federated learning method based on hyper-incremental sequence

The invention discloses a privacy protection and verifiable federated learning method based on a hyper-incremental sequence, and aims to improve data security and calculation efficiency in a federated learning process. The method comprises the following steps: (1) system initialization: a trusted authority (TA) generates key parameters required by the system, and distributes related parameters to a client to support subsequent encryption and verification processes; (2) training a model by the clients: training the model by each client based on a local data set, encoding and encrypting gradient data by using a hyper-incremental sequence, and then uploading the gradient data to a cloud for aggregation; (3) central server aggregation: the server aggregates the encrypted gradient data uploaded by the client by using an addition homomorphic encryption technology, returns an aggregation result to the client, and ensures that the gradient information is always kept in an encrypted state at the server side; and (4) local model updating and verification: the client decrypts and decodes the aggregation result, verifies the correctness of the aggregation result, and updates local model parameters based on the aggregation gradient. According to the invention, an efficient encryption and verification mechanism is designed, so that collusion attacks can be resisted, flexible exit of the client is supported, the security, verifiability and calculation efficiency of the system are ensured, and the method is suitable for various privacy protection federated learning application scenes.
Owner:HUNAN UNIV OF SCI & TECH

Medical data security system and method based on attribute-based signcryption ABSC

The invention belongs to the technical field of medical data security, and particularly discloses a medical data security system and method based on attribute-based signcryption ABSC, and the system comprises a system initialization module which generates a public key and a master key of the system through a trusted authority TA, and is responsible for participating in identity verification and key distribution of entities; the key generation and registration module is used for generating a random value for a participating entity through a trusted institution TA and obtaining a signature key, a verification key and a decryption key; the data encryption and storage module encrypts the medical data collected by the intelligent device SD, and stores the encrypted data on a block chain through an edge node ED; and the data access and decryption module is used for decrypting the data stored on the block chain and is internally provided with a predefined access control strategy. By the adoption of the medical data security system and method based on the attribute-based signcryption ABSC, the performance of the system in the aspects of data security, privacy protection, calculation efficiency and expandability can be comprehensively improved.
Owner:BINZHOU MEDICAL COLLEGE

Vehicle Opportunistic Computing Attribute Encryption Method and System Based on Dual Hybrid Ciphertext Strategy

The present invention provides a vehicle opportunity computing encryption method and system based on dual hybrid ciphertext policy attributes, which relates to the field of vehicle network construction technology. It includes: a dual hybrid attribute-based encryption algorithm DH-CPABE scheme tailored for vehicle opportunity computing (VOC), which fixes the shortcomings of the existing ciphertext policy attribute-based encryption algorithm CP-ABE forward security. The data sharing tool encrypts the data twice using a symmetric key, and the key is encrypted by CP-ABE. Once the computing tool or VOC is revoked, the storage service provider and the data sharing tool will re-encrypt the shared data and symmetric key. Due to the intermittent connection of the VOC, the function of the trusted authority TA is transferred to the data sharing vehicle, thereby eliminating the TA. The generation of keys and parameters is performed by the data sharing tool, rather than by a third party that must be assumed to be completely secure. Compared with existing similar schemes, the DH-CPABE scheme has lower computational cost in encryption, proxy decryption, and decryption under the same conditions.
Owner:UNIV OF SCI & TECH BEIJING

A non-interactive instant identity verification and secure data transmission method

The application discloses a non-interactive instant identity authentication and secure data transmission method, which generates global parameters through a trust authority and distributes them to edge terminals, an authentication center and an edge computing server, and adopts a non-interactive identity authentication technology to perform edge terminal authentication. In the authentication process, the edge terminal generates and sends instant authentication credentials to realize secure connection with the edge computing server. Hash functions and public key cryptography technology are adopted to ensure the security of communication, and a non-member proof and revocation list mechanism are adopted to prevent illegal terminals from accessing the system. Temporary symmetric keys are used for encryption between the edge terminal and the server to ensure the confidentiality and integrity of data transmission. The application has efficient identity authentication, reliable data transmission security and optimized computing and bandwidth utilization, is suitable for resource-limited edge computing scenarios, and has good security, efficiency and scalability.
Owner:SHANGHAI MARITIME UNIVERSITY +1

Authenticating Transactions Using Biometric Authentication

A system and method for authenticating transactions using biometric authentication is disclosed. The method includes receiving a message for a transaction from one of a user device and a trusted authority server. The message is generated on receiving preconfigured biometric data for the transaction on the user device. The message is verified in order to retrieve a prestored second Personal Identification Number (PIN) fragment associated with a PIN of the user. The second PIN fragment is transmitted to one of the user device and the trusted authority server in order to determine the PIN by using the second PIN fragment and a first PIN fragment received from the user device. In an alternate implementation, the method includes determining an authorized token using one or more token fragments stored on a plurality of entities.
Owner:MINKASU INC

An anonymous dynamic authentication and key agreement method based on certificateless signature

This invention discloses an anonymous dynamic authentication and key negotiation method based on certificateless signatures. This method is based on a system model operating in an edge intelligent IoT environment, consisting of four entities: intelligent nodes, a key generation center, edge nodes, and a trusted authority. The method comprises five stages: system initialization performed by the key generation center; pseudo-identities assigned to system entities and public-private key pairs generated through entity registration involving intelligent nodes, edge nodes, and the trusted authority; mutual authentication and key negotiation between intelligent nodes and edge nodes; batch authentication; and encryption transmission of intelligent IoT data using a symmetric encryption algorithm based on the negotiated session key. This invention, based on a certificateless signature mechanism, avoids the complexity of certificate management and key escrow, while eliminating high-overhead operations such as bilinear pairing and exponential operations, effectively reducing the computational burden on resource-constrained terminals.
Owner:GUIZHOU NORMAL UNIVERSITY

Efficient privacy protection authentication scheme for edge-assisted Internet of Things security warning system

The invention discloses an efficient privacy protection authentication scheme for an edge-assisted Internet of Things security warning system, belongs to the technical field of Internet of Things privacy protection, and is based on an improved linkable group signature mechanism and a security warning system architecture. The security warning system architecture comprises a trusted authorization mechanism TA, edge nodes ENs and equipment. Comprising a system initialization stage, an equipment registration stage, a message transmission stage, a verification and decryption stage and a malicious tracing stage. According to the efficient privacy protection authentication scheme for the edge-assisted Internet of Things security warning system, balance between anonymity and responsibility of the edge nodes can be realized, key challenges of maintaining privacy while ensuring security early warning integrity are completed, Sybil attacks are effectively resisted, and the security early warning system has the advantages that the security early warning integrity is ensured, the security early warning safety is ensured, and the security early warning safety is ensured. And safety measures in the system are further enhanced.
Owner:BEIJING INST OF TECH

Cryptographic systems and methods using distributed ledgers

The disclosure relates to, among other things, systems and methods for facilitating the secure recording of assertions made by entities tied to identities. Embodiments of the disclosed systems and methods may allow users to make non-revocable, difficult to forge, cryptographic assertions tied to their identities through the posting of entries in an immutable ledger. In certain embodiments, a user's cryptographic assertions may be preceded by ledger entries which feature certificates from trusted authorities that tie the keys used for making assertions to the user's identity. Further embodiments provide for a mechanism for disabling further entries posted under a user's key, either automatically or at the user's initiation.
Owner:INTERTRUST TECH CORP

Remote access via system-level trusted authorities

Methods and systems for establishing a system specific trust system are provided. The methods and systems establish a secure channel between a first device and a second device using a system specific trusted authority. The methods and systems determine, by the first device, using a first certificate associated with the second device, a first set of access rights of the second device and determine, by the second device, using a credential associated with the first device, a second set of access rights of the first device.
Owner:ASSA ABLOY AB

Implicit attack resistant medical tactile internet security authentication system and method

The invention belongs to the technical field of communication, and provides an implicit-attack-resistant medical tactile internet security authentication system and an implicit-attack-resistant medical tactile internet security authentication method. The system comprises a trusted authority (TA), a remote doctor (RDs), a medical robot (MRs) and a gateway (GW). The TA is responsible for registration of all remote doctors, medical robots and gateways in the medical tactile internet. After a remote doctor registers on the TA, remote touch control over the medical robot can be achieved through the gateway by means of mutual authentication with the gateway and the medical robot. The medical robot is deployed in a hospital and supports inquiry and operation. The gateway serves as an incompletely credible relay device and is responsible for assisting identity authentication and shared key negotiation between a remote doctor and the medical robot, and safe communication is ensured.
Owner:ZHONGNAN UNIVERSITY OF ECONOMICS AND LAW

A two-way verifiable secure aggregation method for federated learning

PendingCN122316633ATrusted authorityData set
This invention discloses a bidirectional, verifiable, and secure aggregation method for federated learning, comprising three entities: a trusted authority, a client, and a server. Bidirectional verification is achieved through verifiable secret sharing and homomorphic encryption: the server verifies the legitimacy of the client's identity before aggregation, and the client independently verifies the correctness of the server's aggregation result before updating. The specific process includes five stages: initialization, key distribution, masking and sharing, verification and aggregation, and checking and updating. The protocol uses Paillier homomorphic encryption to protect model gradient privacy, avoids high-complexity operations such as bilinear pairing, and reduces verification computational overhead. Experiments on the MNIST and CIFAR-100 datasets verify the correctness and efficiency of the protocol. Compared with existing schemes, it has advantages in computational and communication costs, while enhancing the robustness and security of federated learning.
Owner:NANJING UNIV OF POSTS & TELECOMM

Privacy-preserving and efficient low-altitude route authentication method

PendingUS20260253503A1Trusted authorityUncrewed vehicle
A privacy-preserving and efficient low-altitude route authentication method. In the route verification information generation phase, the trusted authority center defines the legal routes of UAVs for each sentry station and generates a Bloom filter. The trusted authority center uses this filter to generate elements and send them to the sentry stations to prepare for subsequent verification. In the route verification phase, the sentry stations receive the real-time flight data of UAVs, use the Bloom filter to screen out elements of illegal routes, process them, and then send them to the trusted authority center. The trusted authority center verifies the received elements, and if the verification is successful, the corresponding routes are confirmed as legal. This method ensures that only UAVs flying on legal routes can pass the verification, protects the privacy of route information, and reduces computing and communication overheads at the same time.
Owner:HARBIN INST OF TECH (SHENZHEN) (HARBIN INST OF TECH SHENZHEN INST OF SCI & TECH INNO)

Offline certificate authority renewal for medical devices

In a system where secure communication relies on device certificates issued by an authority having its own certificate, a first device can transmit an update message to a second device based on determining that the most recent certificate available to the first device is newer than the most recent certificate available to the second device. In various examples, the update message includes the newer certificate and is digitally signed by a mutually trusted authority.The update message can be transmitted during a time when one or both devices are unable to communicate with the mutually trusted authority. In this way, the second device can obtain the newer certificate through an offline update process and use the newer certificate to validate a device certificate of the first device, e.g., as a prerequisite for establishing a communication channel to the first device.
Owner:MEDTRONIC MINIMED INC

A vehicle-to-infrastructure (v2i) authentication key exchange protocol and a fast handover authentication method thereof

A vehicle-to-everything (V2I) authentication key exchange protocol and a fast switching authentication method thereof include the following steps: step one, the system selects and sets elliptic curve parameters for authentication and encryption, and configures the hardware security module of each node and the trusted platform module of the vehicle; step two, the vehicle and the driver's information are securely registered in the system, the vehicle registers its real identity by generating a unique public-private key pair and registering with the trusted authority center (TA), the TA generates a pseudo identity of the vehicle after verification and sends it back to the vehicle through a secure channel; step three, the RSU generates and registers its unique identity with the TA, the TA generates the relevant authentication information of the RSU after verification and stores it in the block chain; step four, the initial authentication and key exchange between the vehicle and the RSU are completed; and step five, the switching authentication with the new RSU is completed. The application has the characteristics of high efficiency, low calculation cost and communication overhead, strong security and privacy protection.
Owner:GANSU INST OF POLITICAL SCI & LAW