Patents by Inventor Jiwu Jing

Jiwu Jing has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 10313111
    Abstract: An embodiment of the present disclosure provide a key protection method, via setting that each core of the multi-core process may have one symmetric master key, dynamically obtaining the plaintext private key of the asymmetric algorithm via a decryption operation and using the Intel TSX, it may be ensured that the private key and the intermediate variables used in the computation process may be stored in the cache occupied by the operation core only in terms of the hardware level, which may prevent the attackers from stealing the private key from the physical memory and ensure the security of the implementation of the public-key cryptographic algorithm in the computer system.
    Type: Grant
    Filed: August 27, 2014
    Date of Patent: June 4, 2019
    Assignee: DATA ASSURANCE AND COMMUNICATION SECURITY RESEARCH CENTER, CHINESE ACADEMY OF SCIENCES
    Inventors: Jingqiang Lin, Le Guan, Qiongxiao Wang, Jing Wang, Jiwu Jing
  • Patent number: 10262130
    Abstract: A system and method for providing cryptographic operation service in a virtualization environment. In the system, a configuration subsystem provides an interface for an administrator and a common user to input information about a virtual cryptographic device. A key file storage subsystem stores a key file and protects it with the protection password. A virtual machine operating subsystem obtains a corresponding key file from the storage subsystem according to the input of the configuration subsystem, creates a virtual device for a guest virtual machine, and finally operates the guest virtual machine to provide cryptographic computing service for the guest virtual machine. Thus the administrator/the common user can specify a key file and input a protection password for a guest virtual machine via the corresponding interface to facilitate the creation of a virtual cryptographic device, and can manage the virtual cryptographic device in a user-friendly and centralized manner.
    Type: Grant
    Filed: October 22, 2015
    Date of Patent: April 16, 2019
    Assignee: DATA ASSURANCE & COMMUNICATION SECURITY CENTER, CHINESE ACADEMY OF SCIENCES
    Inventors: Jingqiang Lin, Kaijie Zhu, Lingchen Zhang, Bo Luo, Quanwei Cai, Congwu Li, Jiwu Jing, Wuqiong Pan
  • Patent number: 10135623
    Abstract: The present invention discloses a method and a system for checking revocation status of digital certificates in a virtualization environment.
    Type: Grant
    Filed: July 15, 2015
    Date of Patent: November 20, 2018
    Assignee: Institute of Information Engineering, Data Assurance & Communication Security Center, Chinese Academy of Sciences
    Inventors: Jingqiang Lin, Bingyu Li, Zhan Wang, Jiwu Jing, Congwu Li, Luning Xia, Qiongqiao Wang
  • Publication number: 20180232519
    Abstract: A system and method for providing cryptographic operation service in a virtualization environment. In the system, a configuration subsystem provides an interface for an administrator and a common user to input information about a virtual cryptographic device. A key file storage subsystem stores a key file and protects it with the protection password. A virtual machine operating subsystem obtains a corresponding key file from the storage subsystem according to the input of the configuration subsystem, creates a virtual device for a guest virtual machine, and finally operates the guest virtual machine to provide cryptographic computing service for the guest virtual machine. Thus the administrator/the common user can specify a key file and input a protection password for a guest virtual machine via the corresponding interface to facilitate the creation of a virtual cryptographic device, and can manage the virtual cryptographic device in a user-friendly and centralized manner.
    Type: Application
    Filed: October 22, 2015
    Publication date: August 16, 2018
    Inventors: Jingqiang Lin, Kaijie Zhu, Lingchen Zhang, Bo Luo, Quanwei Cai, Congwu Li, Jiwu Jing, Wuqiong Pan
  • Publication number: 20180102904
    Abstract: The present invention discloses a method and a system for checking revocation status of digital certificates in a virtualization environment.
    Type: Application
    Filed: July 15, 2015
    Publication date: April 12, 2018
    Inventors: Jingqiang Lin, Bingyu Li, Zhan Wang, Jiwu Jing, Congwu Li, Luning Xia, Qiongqiao Wang
  • Patent number: 9898624
    Abstract: A multi-core processor based key protection method and system is described. An Operating System (OS) supporting Symmetric Multi-Processing (SMP) is set up on a multi-core processor. One core of the multi-core processor is configured as a cryptographic operation core, which is prohibited from running other processes of the OS and dedicated to perform a public-key cryptographic operation. The private key and an intermediate variable in a process of the public-key cryptographic operation are stored in a cache exclusively occupied by the cryptographic operation core.
    Type: Grant
    Filed: June 19, 2015
    Date of Patent: February 20, 2018
    Assignees: Data Assurance and Communication Security Center, Chinese Academy of Sciencess, Institute of Information Engineering, Chinese Academy of Sciences
    Inventors: Jingqiang Lin, Le Guan, Jing Wang, Qiongxiao Wang, Jiwu Jing, Bao Li
  • Patent number: 9819496
    Abstract: The present invention discloses a method and a system for protecting root CA certificates in a virtualization environment. The method installs a root CA certificate security manager on a host computer. The root CA certificate security manager stores the lists of root CA certificates and provides certificate validation service to virtual machines via a read-only interface. When a virtual machine needs the verification of a certificate, it sends a certificate validation service request to the root CA security manager. The root CA certificate security manager provides certificate validation services to the virtual machine in response to the request.
    Type: Grant
    Filed: January 16, 2015
    Date of Patent: November 14, 2017
    Assignees: Institute of Information Engineering, Chinese Academy of Sciences, Data Assurance & Communications Security Center, Chinese Academy of Sciences
    Inventors: Jingqiang Lin, Jiwu Jing, Le Guan, Bingyu Li, Jing Wang, Wuqiong Pan, Yuewu Wang
  • Publication number: 20170295024
    Abstract: The present invention discloses a method and a system for protecting root CA certificates in a virtualization environment. The method installs a root CA certificate security manager on a host computer. The root CA certificate security manager stores the lists of root CA certificates and provides certificate validation service to virtual machines via a read-only interface. When a virtual machine needs the verification of a certificate, it sends a certificate validation service request to the root CA security manager. The root CA certificate security manager provides certificate validation services to the virtual machine in response to the request.
    Type: Application
    Filed: January 16, 2015
    Publication date: October 12, 2017
    Inventors: Jingqiang Lin, Jiwu Jing, Le Guan, Bingyu Li, Jing Wang, Wuqiong Pan, Yuewu Wang
  • Publication number: 20160359621
    Abstract: An embodiment of the present disclosure provide a key protection method, via setting that each core of the multi-core process may have one symmetric master key, dynamically obtaining the plaintext private key of the asymmetric algorithm via a decryption operation and using the Intel TSX, it may be ensured that the private key and the intermediate variables used in the computation process may be stored in the cache occupied by the operation core only in terms of the hardware level, which may prevent the attackers from stealing the private key from the physical memory and ensure the security of the implementation of the public-key cryptographic algorithm in the computer system.
    Type: Application
    Filed: August 27, 2014
    Publication date: December 8, 2016
    Applicant: DATA ASSURANCE AND COMMUNICATION SECURITY RESEARCH CENTER, CHINESE ACADEMY OF SCIENCES
    Inventors: Jingqiang LIN, Le GUAN, Qiongxiao WANG, Jing WANG, Jiwu JING
  • Publication number: 20150310231
    Abstract: A multi-core processor based key protection method and system is described. An Operating System (OS) supporting Symmetric Multi-Processing (SMP) is set up on a multi-core processor. One core of the multi-core processor is configured as a cryptographic operation core, which is prohibited from running other processes of the OS and dedicated to perform a public-key cryptographic operation. The private key and an intermediate variable in a process of the public-key cryptographic operation are stored in a cache exclusively occupied by the cryptographic operation core.
    Type: Application
    Filed: June 19, 2015
    Publication date: October 29, 2015
    Inventors: Jingqiang LIN, Le GUAN, Jing WANG, Qiongxiao WANG, Jiwu JING, Bao LI
  • Patent number: 7386131
    Abstract: A digital certificate issuing system with intrusion tolerance ability and the issuing method thereof are disclosed. The system comprises an offline secret key distributor, at least one online task distributor, k online secret share calculators and m online secret share combiners.
    Type: Grant
    Filed: November 5, 2003
    Date of Patent: June 10, 2008
    Assignee: Graduate School of Chinese Academy of Sciences
    Inventors: Jiwu Jing, Dengguo Feng
  • Publication number: 20040103276
    Abstract: Disclosed is a digital certificate issuing system with intrusion tolerance ability and the issuing method thereof. The system comprises a task distributor, k calculators, m combiners and a sub-secret-key distributor. The processing of distributing a private key of a Certificate Authority comprises the steps of: the sub-secret-key distributor expressing a private key d as a sum of t sub-secret-keys dji and one sub-secret-key ca, and t<k; the distributor distributing k×l random numbers dji into i dji per calculator and sends them to k calculators, obtaining a set of ca and their equation combination representations and sending them to m combiners for pre-storage according to the combiner security condition.
    Type: Application
    Filed: November 5, 2003
    Publication date: May 27, 2004
    Inventors: Jiwu Jing, Dengguo Feng