Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

50 results about "Trusted hardware" patented technology

Multi-dimensional credit asset traceability system and method

The invention discloses a multi-dimensional credit asset traceability system and method. The system comprises a data acquisition and encryption module (10) which is used for performing encryption and digital signature on credit asset data based on a trusted execution environment (TEE) and a hardware security module (HSM) at a data generation end; the parallel Hash processing module (20) is used for performing parallel Hash operation on the encrypted data and generating leaf node Hash values based on GPU acceleration and a multi-thread technology; the nested hash and zero-knowledge proof module (30) constructs leaf node hash values into a compression type Merkle tree and generates a zero-knowledge proof (ZKP), so that a third party can verify the authenticity and consistency of data without accessing full data; the on-chain evidence storage module (40) is used for recording root Hash (RootHash) and zero knowledge proof of the compression type Merkle tree to the block chain; the dynamic authorization and secure multi-party computing module (50) performs access clipping on the credit asset data based on the access intention and realizes verification of the minimum data dimension through secure multi-party computing (SMPC). Through combination of technical means such as trusted hardware acquisition, parallel hash calculation and privacy protection verification, rapid verification is realized on the premise of not exposing original data, and verification performance, data security and privacy protection capability are remarkably improved.
Owner:北京娱广科技有限公司

Large model privacy reasoning method and device based on trusted hardware and electronic equipment

The invention relates to the technical field of security calculation and privacy protection, in particular to a large model privacy reasoning method and device based on trusted hardware and electronic device.The method comprises the steps that before a large model reasoning task is executed, a client and a server initialize respective pseudo-random number generators based on information interaction so as to synchronize initial seeds, and the pseudo-random number generators are initialized; generating a random number based on the seed; in the reasoning execution process, homomorphic encryption is used for completing word embedding of large model reasoning, a reasoning instruction set is used for converting all operators into instruction combinations, privacy reasoning is carried out based on a privacy reasoning protocol and a random number generated by a pseudo-random number, and the random number is used for masking privacy data; and after the task is completed, obtaining an execution result and proof information provided by the server, performing verification, and refusing to receive the result if verification fails. Therefore, the problems of data leakage risk, difficulty in considering safety and efficiency and the like existing in related technologies are solved.
Owner:TSINGHUA UNIVERSITY

A data verification system implementation method based on blockchain and zero-knowledge proof

The application discloses a data verification system implementation method based on a block chain and zero-knowledge proof. In the data verification stage, the data use end pays the corresponding data verification fee to the on-chain smart contract according to the verification requirement, and the demand satisfaction and data real possession are verified through the interaction with the smart contract; in the data declaration stage, the data owner carries out the Merkle tree on the data and generates the characteristic zero-knowledge proof, and the on-chain verification and evidence storage of the data are completed through the interaction with the smart contract, and in the data verification stage, the data owner responds to the challenge of the data real possession, generates the existence proof of the challenge data block set and carries out the on-chain verification and evidence storage, so that the data verification can be independently executed without relying on the third-party service executable environment or the trusted hardware, the independence and safety of the data verification are ensured, and in the whole data real possession verification process, the data is always saved in the local security environment of the data owner, and the complete non-flow of the data is realized.
Owner:SOUTH CHINA NORMAL UNIV

Health data asset governance method, system, and program product

The application is suitable for the technical field of health data asset governance, and provides a health data asset governance method, system and program product. The method comprises the following steps: collecting six-dimensional original metadata corresponding to health data assets, performing cross-dimension entanglement suppression mapping by a distributed mathematical engine, and generating a category entanglement tensor; taking the tensor as an initialization parameter, constructing and synchronously evolving a three-manifold of space-time value, semantic association and security risk to generate a joint entanglement manifold, performing topological region division and threshold-free judgment on the joint entanglement manifold, and outputting an entanglement state judgment result; performing an archiving or destroying operation according to the judgment result by a trusted hardware base, and generating an entanglement archiving fingerprint or an entanglement destroying fingerprint; obtaining an entanglement manifold thermodynamic deviation according to the difference between the fingerprint and a theoretical entanglement state entropy, and updating the joint entanglement manifold based on the deviation; synchronizing the fingerprint to a cross-domain node, and writing audit information into an unalterable distributed audit ledger. The application can realize dynamic adaptation, safe controllability, adaptive optimization without shutdown and full-link trusted traceability of health data assets.
Owner:PEIANMEI (ZHEJIANG) TECHNOLOGY CO LTD

Trust-chain based adaptable telemetry

Method and systems are provided for adaptive collection of telemetry by an Information Handling System (IHS). A validation failure of a hardware component of the IHS is detected, where the hardware component is part a chain of trusted hardware components of the IHS. A position of the hardware component is determined within the chain of trusted hardware components of the IHS. The collection of telemetry by the IHS is adjusted based on the position of the hardware component within the chain of trusted hardware components of the IHS.
Owner:DELL PROD LP

Systems and methods for using internal memory of a system on chip in a security boot

A computing system is provided. The computing system includes a system on a chip. The system on a chip includes a processor and an internal memory. The computing system further includes a root of trust hardware connected to the internal memory and configured to intercept commands from the processor to the internal memory.
Owner:QUANTA COMPUTER INC

Safe storage method and system for intelligent operation and maintenance data in credential field

The invention discloses a secure storage method and system for intelligent operation and maintenance data in the credential field, and the method comprises the steps: deploying an end-to-end intelligent operation and maintenance all-in-one machine embedded with a GPU and an NPU, and monitoring a resource state in real time; encrypting the original operation and maintenance data by using an encryption engine, and analyzing memory access characteristics of the encrypted data in the neural network model through an NPU storage encryption engine performance evaluation platform; classifying the data into hot, warm and cold data according to memory access characteristics; a trusted execution environment based on trusted hardware is constructed to form a trust chain, and calculation tasks are dynamically scheduled according to resource states and memory access characteristics; and embedding life cycle labels containing sources and sensitivity into all encrypted data, and recording a full life cycle audit log. The system comprises a resource sensing and monitoring module, an encryption and memory access analysis module, an intelligent hierarchical storage module, an intelligent scheduling and trusted computing module and a data security management module. According to the method, safe storage, efficient processing and whole-course tracing of the operation and maintenance data in the credential environment are realized.
Owner:CHINA TELECOM DIGITAL INTELLIGENCE TECH CO LTD

Secure dynamic threshold signature scheme employing trusted hardware

Methods and devices for generating an elliptic curve digital signature algorithm signature (r, w) are described. In one embodiment, a method includes: i) forming, by a node, a signing group with other nodes; ii) obtaining, by the node, based on a secure random number: a) a multiplicative inverse of the secure random number; and b) the first signature component, r, wherein the first signature component is determined based on the secure random number and an elliptic curve generator point; iii) determining, by the node, a partial signature based on a private secret share, the multiplicative inverse of the secure random number and the first signature component; iv) receiving, by the node, partial signatures from other nodes of the signing group; and v) generating, by the node, the second signature component, w, based on determined and received partial signatures.
Owner:NCHAIN LICENSING AG

Calculation method of single cloud architecture threshold multi-party privacy set intersection depending on trusted hardware and homomorphic encryption

The invention discloses a computing method of a single cloud architecture threshold multi-party privacy set intersection depending on trusted hardware and homomorphic encryption. The method relates to a task requester, a cloud server supporting the Intel SGX technology and a plurality of task participants. The cloud server is logically divided into a rich execution environment (REE) and a trusted execution environment (TEE) isolated by CPU hardware. The method comprises the steps that a task requester securely deploys private key fragments to a TEE through remote authentication; establishing secure connection between each participant and the server, and directly uploading the encrypted Bloom filter to the REE; performing homomorphic aggregation on the ciphertext by the REE, and calling an internal function of the TEE through a secure interface (ECALL) to jointly execute security comparison; and the TEE completes decryption and threshold comparison by using the private key fragmentation in the isolation region, and encrypts and returns a result. According to the method, the TEE is used for replacing a cooperation server in a traditional architecture, network communication is converted into memory interaction, the collusion risk of the server is eliminated, meanwhile, the communication overhead is remarkably reduced, and the calculation efficiency and privacy security are improved.
Owner:GUANGZHOU INSTITUTE OF TECHNOLOY XIDIAN UNIVERSITY

Electronic voting casual shuffling method based on semi-trusted hardware

The invention discloses an electronic voting casual shuffling method based on semi-trusted hardware, trusted execution environments of a first participant and a second participant are mutually verified through a remote authentication protocol, and after authentication is passed, the trusted execution environments of the first participant and the second participant negotiate to generate a shared random seed; constructing a permutation matrix based on the random seeds and the trusted execution environments of the two participants, generating a secret share of the permutation matrix, and sending the secret share to the corresponding participants according to a distribution rule of copy secret sharing; the voter generates a secret share of voting data by using the trusted execution environment of each participant, and sends the secret share to the corresponding participant according to a distribution rule of copy secret sharing; and the two participants respectively use the locally held voting data and the secret share of the permutation matrix to carry out casual shuffling calculation, and the secret share of the position permutation voting data is obtained and disclosed, so that any third party can obtain a voting result after casual shuffling through the secret share of the position permutation voting data.
Owner:CSG EHV POWER TRANSMISSION

A blockchain-based data credibility processing method and system

This invention discloses a data credibility processing method and system based on blockchain, comprising the following steps: acquiring device data, verifying the device data, generating an encrypted verification signature through a trusted execution environment device, and merging the verification signature with the original data and uploading it to the blockchain; based on the device data, using smart contracts for data verification rule judgment and filtering, the smart contracts responding to preset standards to judge the data, or using machine learning to predict and analyze the quality of uploaded data to determine the quality of the data on the chain; this invention proposes to encrypt and sign the data source through trusted hardware and store it on the blockchain, providing higher data source credibility and preventing single-point tampering. Multiple verification mechanisms: combining smart contracts, blockchain consensus mechanisms, and off-chain data verification, ensuring multi-dimensional verification of blockchain data and avoiding the limitations of a single verification method.
Owner:SHICHUAN DIGITAL TECH (SHENZHEN) CO LTD

Resource providing method and device

The invention provides a resource providing method and device which can be applied to the technical field of cloud computing. The resource providing method comprises the steps that at least one trusted node is generated on a cloud computing platform according to a hardware layer and a virtualization layer, the hardware layer comprises multiple pieces of trusted hardware, and the virtualization layer comprises a virtual machine monitor for managing the trusted hardware; in response to a received resource acquisition request sent by a user to the cloud computing platform, determining at least one to-be-allocated trusted node according to resource demand information in the resource acquisition request; and distributing at least one trusted node to be distributed to the user.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Generating and managing encrypted non-fungible tokenized assets

Techniques are described relating to the ownership and management of digital assets that are represented by non-fungible tokens (or “NFTs”) on a blockchain. Trusted hardware is used to enable encrypted digital assets to be consumed solely by the owners of the encrypted digital assets and further to enable the transfer of ownership in the digital asset to a new owner using a blockchain. An owner of a digital asset controls access to and consumption of the digital asset via the trusted hardware to which the asset is cryptographically bound. The legal ownership of the digital asset is represented on the blockchain via an NFT. When an NFT changes ownership (e.g., when it is sold to a new owner) on the blockchain, a secure hardware-to-hardware asset transfer protocol is used (off-chain).
Owner:NUMERAIRE FINANCIAL INC

Tea industry tracing method and equipment based on mixed chain and trusted hardware

The invention discloses a tea industry tracing method and equipment based on a mixed chain and trusted hardware. The method comprises the following steps: packaging tea garden trusted hardware; anchoring the identity of tea garden equipment; performing backup on a root key chain; carrying out tea garden sensing data credible signature; transmitting and preprocessing tea data; verifying the authenticity of the tea data; evaluating a tea data trust model; grading and chaining the tea data; the consumer scans the code for verification; and performing feedback closed loop on the tea data trust model. According to the invention, through physical fusing destruction and cryptographic chip encryption binding, the identity of the device is ensured not to be cloned, and the source data is ensured to be true and credible. Based on the dynamic trust score, high-score data is automatically routed to an efficient private chain and a low-score data storage public chain, invalid data is discarded, and accurate matching of resources and risks is achieved. A data processing result is fed back in real time to update equipment reputation, and time decay and DAO treatment are combined, so that the system is more and more accurate in use, and a virtuous circle is formed.
Owner:HEFEI INSTITUTE OF PHYSICAL SCIENCE CHINESE ACADEMY OF SCIENCES +2

Multi-level access control and crowd search method and system based on trusted hardware

PendingCN122087838Aprevent unauthorized accessguaranteed non-repudiationDigital data protectionDigital data authenticationComputer hardwareData stream
The invention discloses a multi-level access control and crowd search method and system based on trusted hardware, and relates to the technical field of energy power. According to the invention, a multi-level access control mechanism based on trusted hardware is constructed, so that authority isolation between different levels of data such as power generation, power transmission and power utilization and personnel is realized, and unauthorized access to core power data is prevented; the security of a query mode and an access mode is protected through a hidden search technology, and an attacker is prevented from deducing sensitive information such as a power grid operation state and load characteristics by analyzing search behaviors; dynamic authority management is used for blocking the search authority of revoked personnel to the data of the power monitoring system, so that the non-repudiation of data operation and the anonymity of user identity are ensured; mode leakage in a storage access process is eliminated through an ORAM mechanism, a cloud malicious agent is prevented from obtaining key data flow tracks such as a power equipment state and a fault record through flow analysis, and the data protection strength and the privacy guarantee capability of the energy power cloud storage system are comprehensively improved.
Owner:SHENYANG INST OF ENG

A remote image feature extraction and retrieval method based on sgx

ActiveCN115935426BThird partyTrusted hardware
This invention provides a remote image feature extraction and retrieval method based on SGX, relating to the field of encrypted image retrieval technology. This method utilizes trusted hardware SGX to offload computational operations such as image feature extraction and index construction to a trusted execution environment (enclave) on a cloud server. Within this trusted execution environment, a secret sharing scheme is used for key distribution, and access control lists are implemented to control access for third-party users. Compared to traditional encrypted image retrieval schemes, this invention effectively reduces the computational power requirements for data owners and enables precise access control for third-party users during the retrieval process.
Owner:NORTHEASTERN UNIV CHINA

Laboratory digital safety workspace management method, system and equipment based on trusted computing and medium

The invention discloses a laboratory digital safety workspace management method, system and device based on trusted computing and a medium, and belongs to the technical field of laboratory information safety management, and the method comprises the steps: measuring a starting chain through trusted hardware, uploading a measurement value after verification, completing multi-factor authentication and encryption channel establishment, and carrying out strategy conformity check; creating a resource isolated working space, loading a security policy in real time, and monitoring user behaviors and peripheral access; carrying out enhanced authentication and encryption verification transmission; and generating a tamper-proof chained auditing log, and automatically starting hierarchical response and joint treatment based on the log and a monitoring result to form a traceable responsibility judgment link. According to the invention, the operation environment of the terminal system is ensured to be credible based on the trusted computing root, multi-task isolation and data leakage prevention are realized by adopting a containerized digital workspace, authority control is implemented through an identity and task adaptive security policy, and the security event response capability and operation traceability are improved by means of real-time monitoring and auditing a log library.
Owner:YUNNAN ELECTRIC POWER TESTING & RES INST (GRP) CO LTD +1

A digital certificate making method, system and application thereof

The embodiment of the application discloses a digital certificate manufacturing method and system and application thereof, and the method comprises the following steps: cross authentication of a third-party platform is utilized, and a cross-platform autonomous identity of a user is generated in combination with trusted hardware; cross authentication of the third-party platform is utilized, and cross-platform autonomous identity login of the user is generated in combination with the trusted hardware; cross authentication of the third-party platform is utilized, and a digital certificate certification authority certificate of the user is generated in combination with the trusted hardware. The blockchain is utilized to manage the issuance and application of the digital certificate, so that the security is ensured and traceability is possessed.
Owner:ADVANCED INST OF INFORMATION TECH (AIIT) PEKING UNIV +1

Trusted measurement method and equipment for power utilization acquisition system terminal and power utilization acquisition system

The invention discloses a trusted measurement method and equipment for a power utilization acquisition system terminal and a power utilization acquisition system, a master station sends a trusted connection request carrying a random number and an AIK requirement to the terminal, and the terminal responds to the trusted connection request, obtains trusted verification data based on a trusted hardware module and feeds back the trusted verification data to the master station; the credible verification data comprises a current PCR value of the terminal, a combined information signature value, a measurement event log with an AIK signature and a terminal security attribute value, and the combined information signature value is obtained by signing a random number and the current PCR signature value through a credible hardware module by using a private key meeting the AIK requirement; the master station performs log integrity verification based on the measurement event log with the AIK signature; based on a preset trusted measurement strategy, performing attribute compliance verification of the terminal according to the terminal security attribute value; and terminal security verification is carried out based on the current PCR value and the combined information signature value, so that the security protection level of the electricity utilization acquisition system is effectively improved.
Owner:CHINA SOUTHERN POWER GRID COMPANY

A privacy-preserving vector database query method

This invention discloses a privacy-preserving vector database query method, comprising: each server obtaining a query vector secret share and performing a linear transformation to obtain a transformed query vector secret share; sending the locally held transformed vector data secret share and the transformed query vector secret share to semi-trusted hardware; the semi-trusted hardware performing a nearest neighbor search to obtain the nearest neighbor vector and its corresponding index; sharing the nearest neighbor vector and the one-hot vector corresponding to the index with each server; each server performing a dot product calculation between the one-hot vector secret share and the locally held label secret share to obtain a query result label secret share; performing an inverse linear transformation on the nearest neighbor vector secret share to obtain a query result vector secret share; and sending the query result label secret share and the query result vector secret share to the user terminal; the user terminal reconstructing the query result vector and the query result label.
Owner:CSG EHV POWER TRANSMISSION

Storage method, query method and device for encrypted data based on trusted hardware

This application provides a method, method, and apparatus for storing and querying encrypted data based on trusted hardware. By generating random query tokens and encrypted query formulas, this application prevents the server from associating query content with specific data records, thus avoiding the leakage of specific query relationships and improving security. This solves the problem of leaking access patterns in existing solutions. Furthermore, the computation of query relationships is performed in trusted hardware, with the server only handling storage, achieving separation of storage and computation and reducing server resource consumption.
Owner:HANGZHOU HIKVISION DIGITAL TECHNOLOGY CO LTD

Block chain privacy protection query method based on distributed point function

The invention discloses a block chain privacy protection query method based on a distributed point function. The block chain privacy protection query method comprises the following steps: completing system participant definition, threat model setting and preprocessing work of a consensus node end; generating a query request through a distributed point function (DPF) and distributing the query request; performing share evaluation, multi-block processing and parallel optimization; and obtaining and verifying a final result. According to the method, a privacy query mechanism and a garrison mechanism based on the distributed point function are introduced, so that the privacy protection capability on query keywords in a blockchain light node outsourcing query scene is remarkably improved, and the correctness and credibility of a query result are effectively guaranteed in an untrusted full-node environment. According to the method, the computing and communication burden is obviously reduced while privacy protection is achieved, the trust premise can be met only by deploying Intel SGX in a small number of all nodes, and the trusted hardware deployment threshold is obviously reduced.
Owner:CHANGAN UNIV

Video content security distribution system and method based on trusted hardware and distributed sharding streaming

The application discloses a video content security distribution system and method based on trusted hardware and distributed sharding streaming. The system comprises a cloud processing subsystem, a distributed storage network, an authorization management server and a trusted hardware terminal device. The cloud processing subsystem divides an original video into multiple physical shards, independently encrypts each shard and distributes the shards; meanwhile, a logical play list is generated to describe the mapping relationship between a timeline and the physical shards. The terminal device is provided with a security chip and a security play engine, receives the logical play list after authorization verification, obtains corresponding physical shards on demand, decrypts, assembles and plays in real time in a secure memory, and immediately clears the decrypted data after playing. The application realizes that the video content does not exist in a complete form in a permanent storage medium at any moment, supports high-definition streaming media playing and various business modes, and has high security, good user experience and business flexibility.
Owner:林建国

Block chain credible evidence storage and AI auditing system

The invention relates to the technical field of block chains, and discloses a block chain credible evidence storage and AI auditing system, which comprises a credible hardware module used for receiving a data hash value and a dynamic consensus variable obtained from a block chain network, and generating a dynamic data fingerprint; the terminal equipment is used for acquiring the dynamic consensus variable from the block chain network and sending the dynamic consensus variable to the trusted hardware module; the block chain platform is used for recording the transaction broadcasted by the terminal equipment; the AI auditing module is used for obtaining the recorded transaction data from the block chain platform for analysis and generating an auditing conclusion; and updating the trusted state corresponding to the trusted hardware module. According to the method, data hash and dynamic consensus variables are combined and signed through the trusted hardware module, and the data and the block chain state are subjected to cryptographic binding by utilizing the global uniqueness of the dynamic consensus variables, so that the dependence on a local clock is eliminated, and the time credibility of data storage is improved.
Owner:CHONGQING COLLEGE OF ELECTRONICS ENG

Heterogeneous trusted hardware cross authentication implementation method based on block chain

The invention discloses a heterogeneous trusted hardware cross authentication implementation method based on a block chain, and the method comprises the steps: carrying out the system initialization and contract deployment, carrying out the authentication processing of a to-be-proved party device, carrying out the bidirectional authentication after a TEE device inquires a verification result on a chain, and building a secure channel. Safe mutual recognition of heterogeneous trusted hardware is realized; an extensible and upgradable contract architecture is provided, and dynamic access of new type trusted hardware is supported; merkel tree existence proof and Hash mask technology are introduced, authentication result authenticity and trusted application identity privacy are guaranteed, and safety, expansibility and efficiency of heterogeneous trusted hardware cross authentication are improved.
Owner:SHANGHAI JIAOTONG UNIV +1

Externally held account discovery and aggregation

Apparatuses, systems, methods, and computer program products are disclosed for externally held account discovery and aggregation. A method includes aggregating transactions of a first service provider from one or more servers to a trusted hardware device. A method includes identifying, on a trusted hardware device, one or more transactions of a first service provider between an account of a user with the first service provider and an account of the user with a second service provider. A method includes prompting a user for electronic credentials for an account of the user with a second service provider. A method includes accessing data of a user from a second service provider on behalf of the user using electronic credentials.
Owner:MX TECHNOLOGIES INC

Verifiable secure multi-party computing method based on improved lattice commitment

The invention relates to the technical field of information security and cryptography, and discloses a verifiable secure multi-party computing method based on improved lattice commitment, comprising the following steps: constructing a system model comprising a data owner, a cloud service provider and a honesty verifier; in the offline preprocessing stage, a cloud service provider collaboratively generates cryptographic parameters, a global authentication key, a multiplication triple and an input commitment, and stores auditing transaction records; in the online stage, a data owner submits secret input, a cloud service provider executes secure multi-party calculation based on a pre-calculation material, and an intermediate process and a result commitment are recorded in a case; according to the method, a lattice commitment scheme of post-quantum security is adopted, and an independent verification mechanism based on trusted hardware is introduced, so that high verifiable security capable of resisting quantum attacks is realized while high calculation efficiency and multi-party expansibility are guaranteed, and the security of the computing process is improved. The method is suitable for cooperation scenes with high privacy requirements.
Owner:ZHEJIANG GONGSHANG UNIVERSITY

A trusted storage system and method based on a distributed storage mechanism

The application relates to the technical field of data storage and trusted computing, and provides a trusted storage system and method based on a distributed storage mechanism. The system comprises a storage resource pool, a virtualization layer, a storage engine, a function layer, interface management and trusted enhancement verification; the distributed intelligent storage system is used for realizing multi-type storage of data; a high-speed communication interconnection network is used for realizing high-speed access of data; and the fusion of trusted hardware and a trusted operating system is used for realizing safe control and whole-process trust of a data access process.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Smart contract privacy protection method and device

The invention discloses an intelligent contract privacy protection method and device, and the method is applied to a client, and comprises the steps: creating a security isolation environment through trusted hardware during starting, and carrying out the remote certification, and then carrying out the registration to a block chain node; initiating a balance withdrawal transaction request to the smart contract, so that the smart contract returns second proof information to the security isolation environment after executing chain balance destruction on the block chain account address of the client; after the second certification information is verified in the security isolation environment, updating and encrypting a local available balance to generate third certification information; and receiving a transfer transaction request of a user, and sending the transfer transaction request to the smart contract, so that the smart contract updates the on-chain balance ciphertext of the sender and the receiver after the transfer transaction request is verified based on the registration information. The method has the advantages of high expandability, privacy and deployment flexibility.
Owner:TSINGHUA UNIVERSITY +1