Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

380results about "Cryptographic attack countermeasures" patented technology

Control method of multi-protocol switching anti-quantum security gateway

The invention relates to a control method for a multi-protocol switching anti-quantum security gateway, and the method comprises the steps: carrying out the safety self-inspection of a hardware environment after the security gateway is powered on, generating a unique root key of equipment based on a physical unclonable function, continuously collecting and analyzing the network traffic characteristics, and carrying out the self-inspection of the hardware environment. Based on a machine learning model, a quantum attack mode is identified and an encryption algorithm mode is dynamically decided, protocol analysis is carried out on a communication data packet, dynamic conversion and adaptation are carried out between a traditional protocol and an anti-quantum cryptography protocol according to an instruction and a preset rule, and an anti-quantum cryptography engine is called to carry out encryption or signature operation. And dynamically deriving and managing a session key in a complete period based on a root key, switching an algorithm mode, a communication protocol and a key in a linkage manner according to a quantum attack detection result, and starting anti-side channel attack protection and hardware security response. According to the method, active protection of the security gateway on quantum attacks, multi-protocol seamless compatibility and full-life-cycle security management of keys are realized.
Owner:WEIDE GUANGDONG INFORMATION TECH CO LTD

Reconfigurable multi-channel polynomial multiplier architecture and implementation method thereof

The invention relates to a reconfigurable multi-channel polynomial multiplier architecture and an implementation method thereof, and belongs to the technical field of post-quantum cryptography hardware acceleration. The architecture comprises a scheduler, a twiddle factor memory bank, a bank address routing module, a bank array and a reconfigurable butterfly unit array. According to the architecture, a cyclic decoupling multi-channel NTT / INTT / PWM algorithm is used, flexible configuration of the degree of parallelism and the flow line depth can be supported, and the adaptability of a memory access control strategy is improved; a conflict-free memory mapping scheme based on interleaved storage is adopted, so that storage and read-write of polynomial coefficients are irrelevant to polynomial length and a calculation stage, NTT / INTT / PWM access modes are unified, and hardware resource overhead is greatly reduced; and a conflict-free detection algorithm oriented to multi-channel assembly line design is adopted, so that the utilization rate of hardware resources is remarkably improved.
Owner:NAT UNIV OF DEFENSE TECH

Data security protection method and system for large model training

The invention discloses a data security protection method and system for large model training. The core of the method is that a data safe box trusted application (TA application) is deployed in a trusted execution environment (TEE) and cooperatively works with a user-defined virtual file system driver at a host machine side, so that an end-to-end secret state data access control link is constructed. Before encryption protection of sensitive data, a measurement value (including code hash, configuration parameters and a runtime state) of a current TEE instance is submitted to a remote verification service through a data safe box TA application, and the verification service only sends the measurement value (including code hash, configuration parameters and a runtime state) of the current TEE instance to the remote verification service after confirming that the TEE environment meets a preset security policy (such as a kernel version, a software version and configuration parameter compliance). And generating a secret key encrypted by a custom virtual file system on a host machine side through derivation. And malicious copying of a system memory and a storage medium is prevented, so that the traditional attack defense capability is effectively improved.
Owner:PANOVASIC TECHNOLOGY CO LTD

Zero-knowledge-proof-oriented CPU-GPU data processing and transmission optimization system and method

Disclosed in the present invention is a zero-knowledge-proof-oriented CPU-GPU data processing and transmission optimization system, which is used for executing multi-scalar multiplication operations on the basis of elliptic curve cryptography, so as to generate zero-knowledge proofs. The system comprises a CPU and a GPU, wherein a data transmission channel is provided between the CPU and the GPU; the CPU is used for acquiring and storing point sets and scalar sets that are involved in multi-scalar multiplication operations, and using a set parallelized data transmission mechanism to communicate with the GPU; and the GPU executes multi-scalar multiplication computation on the basis of the point sets and the scalar sets, and returns a computation result to the CPU. By means of the coordinated effect of a plurality of technical features, the present invention significantly improves the speed and efficiency of zero-knowledge proof generation and optimizes resource utilization efficiency.
Owner:SHENZHEN INST OF ADVANCED TECH CHINESE ACAD OF SCI

Digital signature generation and authentication system and method

The invention discloses a digital signature generation and authentication system and method. The system comprises a first terminal and a second terminal, the first terminal comprises a first acquisition module for generating a first graphical interface, responding to a signature executed by a user on the first graphical interface, and acquiring first vector coordinate data signed on the first graphical interface; the second acquisition module is used for sampling facial features of the user; the data processing module is used for extracting a first secret key parameter from the first vector coordinate data, taking the facial feature as a second secret key parameter, and encrypting the first vector coordinate data through the first secret key parameter and the second secret key parameter to obtain secret key data; the storage module is used for storing key data; the communication module is used for transmitting the key data to a second terminal; the second terminal comprises a third acquisition module for verifying the facial features of the user; and the generation module verifies the facial features, decrypts the key data by using the second key parameter, and requests the first terminal to generate a digital copy to the second graphical interface.
Owner:HUNAN VOCATIONAL COLLEGE OF SCI & TECH

Lightweight, blockchain-based reputation system for unmanned aerial vehicle networks

A system includes: one or more each of UAVs; UAV service requestors; UAV service providers; and ground stations. Using an identity authentication module, a reputation system module, and a blockchain fabric module, the UAVs, the UAV service requestors, the UAV service providers, and the ground stations are capable of sending and receiving electronic data via one or more remote connections, the identity authentication module identifies and authenticates UAVs such that only verified and authenticated UAVs can access the UAV network; the reputation system module evaluates and maintains a reputation of the UAV service requestors and the UAV service providers and assigns a reputation; and the blockchain fabric module implements a blockchain with respect to the UAV network to securely record flight data of the UAVs on the UAV network, which flight data includes one or more of a location, altitude, and one or more mission parameters of the UAV.
Owner:THE GOVERNMENT OF THE UNITED STATES AS REPRESENTED BY THE SECRETARY OF THE AIR FORCE

Anti-quantum security enhancement method for SSL VPN protocol

An anti-quantum security enhancement method for an SSL VPN protocol of a communication network. The method comprises: (011) acquiring a first quantum key and a quantum key identifier from a first network node that has accessed a network device; (012) performing post-quantum cryptographic encryption processing on the quantum key identifier, and sending a first encryption result of the post-quantum cryptographic encryption processing to a terminal; (013) decrypting a received second encryption result sent by the terminal, so as to obtain a second decryption result; (014) obtaining a first master key on the basis of the first encryption result and the second decryption result; and (015) generating and obtaining a second master key on the basis of the first master key, the first encryption result, the second decryption result, and the first quantum key, so as to encrypt communication between the network device and the terminal.
Owner:CHINA TELECOM QUANTUM INFORMATION TECH GRP CO LTD

Intelligent household equipment communication method driven by physical unclonable function

The invention relates to the technical field of smart home devices, in particular to a smart home device communication method driven by a physical unclonable function, which is used for establishing a secure session between a resource-limited initiating device and a resource-limited receiving device, and comprises the following steps: A, generating a physical unclonable function key; b, anti-quantum key negotiation; c, combining identity authentication and signature; d, establishing a secure session key; and E, safely transmitting the instruction. According to the method, the non-persistent key is generated and established through the physical unclonable function key, so that the problems of physical attack and key stealing are solved; anti-quantum key negotiation and lattice ciphertext de-encapsulation provide anti-quantum security, and the problem of future calculation threats is solved; identity authentication and signature are combined to realize single handshake, delay and power consumption are reduced, and the requirements of low power consumption and high efficiency are met; drift calibration is implemented, so that the stability of the key of the physical unclonable function is guaranteed, and the reliability is improved; and the confidentiality and the integrity of the instruction are ensured by the final secure transmission of the instruction.
Owner:DONGGUAN LAIMSEN TECH BUILDING MATERIAL CO LTD

Node injection attack method based on adaptive target selection

The invention relates to a node injection attack method based on adaptive target selection, and the method comprises the following steps: S1, target node selection: calculating a comprehensive score of a node based on uncertainty and topology centrality, and dynamically selecting a target node set of a current attack round; s2, feature generation: using an adaptive feature generator to generate node features which are similar to target node distribution and have strong aggressiveness; and S3, disturbance edge construction: selecting an optimal disturbance edge connection mode for the injection node according to strategy network output in reinforcement learning. According to the method, the attack flexibility can be improved through dynamic target selection, the attack performance can be remarkably enhanced through combination of disturbance characteristics and structures, and the method has good concealment, expandability and generalization ability. The method is widely applied to security evaluation and defense research fields related to graph neural networks, such as social network analysis, recommendation systems, knowledge graphs and the like.
Owner:BEIJING JIAOTONG UNIV

ASIL-D vehicle-mounted intelligent battery replacement method and system based on edge calculation

The invention belongs to the technical field of intelligent network connection automobiles and edge calculation, and particularly relates to an ASIL-D vehicle-mounted intelligent battery replacement method and system based on edge calculation. The method comprises the following steps: establishing a lightweight security channel optimized based on a national cryptographic SM4 algorithm between a vehicle-mounted edge computing unit and a battery swap station edge node; the vehicle-mounted edge calculation unit collects physical state parameters of a battery pack, vehicle running state data and a battery replacement task instruction in real time; performing functional security integrity verification on the physical state parameters; triggering a preset security authentication triggering condition based on the state credibility label and a battery replacement task instruction; and when the security authentication triggering condition is met, starting a dynamic key fragment generation mechanism. According to the system, the resource consumption of a traditional encryption algorithm is reduced to be less than 40% of the original level by constructing a lightweight security communication protocol, and the calculation pressure of edge equipment in an ASIL-D authentication scene is effectively relieved.
Owner:FUZHOU STRAIT VOCATIONAL & TECH COLLEGE

Low-cost masking for post-quantum cryptography

Devices, systems, and methods for secure modular addition and subtraction are provided. A modular adder and subtractor circuit with masking circuit includes an arithmetic to Boolean (A2B) conversion operator configured to convert (i) a second sum and (ii) a value determined based on a first sum, to Boolean resulting in first and second Boolean values, a shifter configured to (i) make a most significant bit of the first Boolean value a least significant bit resulting in a shifted first Boolean value and (ii) make the most significant bit of the second Boolean value a least significant bit resulting in a shifted second Boolean value, and a Boolean to arithmetic (B2A) conversion operator, configured to convert a representation of the shifted first Boolean value and a representation of the shifted second Boolean value to arithmetic representation resulting in first and second arithmetic values, respectively.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Quantum key distribution system and method

The invention discloses a quantum key distribution system and method. According to the system, a phase coherence monitoring mechanism is innovatively introduced, and early attack detection is realized through a dynamic consensus sampling protocol; a zero-trust relay network is constructed by adopting a wavefront fragmentation principle, and trust dependence on relay nodes is eliminated; self-adaptive safety monitoring is realized based on a finite state automaton, and a system safety strategy is dynamically adjusted. According to the method, the problems of resource consumption type attack, relay trust dependence, static protocol limitation and the like faced by an existing QKD system are solved through a strict mathematical framework, and long-distance quantum key distribution with efficient resources, endogenous security and elasticity and physical layer security guarantee is realized. Experiments show that compared with a traditional scheme, the detection delay of the system is reduced by about 38%, the resource waste is reduced by about 40%, and the availability of the system reaches 99.995% or above.
Owner:CHIZHOU JIAYIN MOTOR & CONTROL SYSTEM CO LTD

Dynamic Cyberattack Mission Planning and Analysis

Cybersecurity mission planning and analysis uses artificial intelligence systems to make red and blue team exercises more comprehensive and effective by supplementing individual expertise, reducing reliance on intuition, and eliminating gaps in knowledge. In an embodiment, a platform for cyberattack missions planning and analysis by red and blue teams is coordinated by a control center. An incident generator generates cyberattack scenarios and events using data from external databases and an internal attack knowledge manager having a knowledge graph of data about the network under attack in conjunction with one or more machine learning algorithms configured to identify potential network vulnerabilities. Red are guided by a machine learning algorithm configured to provide suggestions as to potential successful attack paths. Blue teams are guided by a machine learning algorithm configured to provide suggestions as to potential successful attack paths.
Owner:QPX LLC

Security analysis method based on SelfTargetSIS problem

PendingCN121907424ACryptographic attack countermeasuresRandom oracleQuantum modeling
The invention provides a safety analysis method based on a SelfTargetSIS problem. The method comprises the following steps: modeling a solution target of the SelfTargetSIS problem into explicit search on a message set, an allowable vector set and a challenge vector set; estimating a first search complexity in the classic model under a random oracle model; estimating a second search complexity in the quantum model under a random oracle model; and determining the minimum value of the first search complexity and the known classical optimal attack complexity as the effective attack complexity under the classical model, and determining the minimum value of the second search complexity and the known quantum optimal attack complexity as the effective attack complexity under the quantum model, thereby performing security evaluation on the anti-quantum signature. According to the method, an explicit search path based on a message set, an allowable vector set and a challenge vector set is supplemented and quantified, and the attack cost in the real world can be reflected more comprehensively.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI

A data processing method, apparatus and device

The application provides a data processing method, device and equipment, wherein the data processing method comprises the following steps: sending a decryption request to at least two data decryption nodes respectively; the decryption request carries a data access address; receiving a decryption result and first verification parameter information for the decryption result fed back by each data decryption node; obtaining decrypted data according to each decryption result and the first verification parameter information; wherein the decryption result comprises part of the decrypted content of the ciphertext data corresponding to the decryption request. This scheme can support the implementation of data decryption by using multiple data decryption nodes, and then the complete decrypted data is obtained according to the decryption results (part of the decrypted data) obtained by each data decryption node, thereby realizing distributed delegated decryption, avoiding the problem of low security caused by single-point storage of asymmetric keys, and the problem of management difficulty caused by symmetric keys.
Owner:CHINA MOBILE COMM LTD RES INST +1

IPSec anti-replay detection method based on multiple caches

The application relates to the field of network security, in particular to an IPSec anti-replay detection method based on multiple caches. The latest window information which has not been stored in DDR is cached by means of the cache space of FPGA. When the sn window information of the previous message is not updated in the algorithm decryption stage, the un-updated sn window information is stored in the cache space of FPGA, the anti-replay detection of the next message is not affected, the processing time of two messages is shortened to the algorithm processing time, the preparation time before the algorithm decryption is greatly compressed, the method has the characteristics of fast speed, less resource occupation and the like, and is suitable for devices which have strict performance requirements and need to perform anti-replay detection.
Owner:SHANDONG HUAYI MICRO ELECTRONICS

Efficient computation of bivariate statistical moments for side channel vulnerability evaluation

Systems and methods for efficient computation of bivariate statistical moments. An example method comprises: determining exponents characterizing a bivariate mean value referenced by a definition of a statistical moment to be computed; receiving an input data set representing a plurality of observed values of one or more variables, the input data including a plurality of traces, each trace of the plurality of traces including a plurality of sample points; generating an initial matrix comprising combinations of pre-determined degrees of the sample points; producing an intermediate result matrix represented by a product of multiplying a transpose of the initial matrix by the initial matrix; retrieving an element of the intermediate result matrix, wherein indices of the element are defined based on the exponents; and using the retrieved element of the intermediate result matrix to compute the statistical moment.
Owner:CRYPTOGRAPHY RESEARCH INC

Method and system for resisting side channel attack

In one embodiment, a method for combating side channel attacks in a system comprising a neural network comprising a block of processing elements is described. The method includes spatially disrupting an assignment map of an output of the neural network to the block of processing elements using a first random sequence generator, where the output of the neural network includes a series of multiply-accumulate (MAC) operations, and using a second random sequence generator to temporally disrupt the product of a series of MAC operations in a run sequence. A system for combating side channel attacks is also described in one embodiment.
Owner:NATIONAL UNIVERSITY OF SINGAPORE

Secure encryption using tokenized data

In some implementations, a device may receive a request for cryptographic transmission of payload data. The device may obtain the payload data for encryption. The device may encrypt the payload data, to generate encrypted payload data, using a first encryption key, wherein the first encryption key is configured such that the encrypted payload data is decryptable using a second encryption key that corresponds to the first encryption key. The device may generate tokenized data. The device may combine, using a combining algorithm of a set of combining algorithms, the encrypted payload data and the tokenized data to generate combined data, wherein the combined data is not directly decryptable using the second encryption key. The device may provide the combined data and an indicator of the combining algorithm as a response to the request.
Owner:CAPITAL ONE SERVICES LLC

A signal rate splitting transmission method and receiving method suitable for optical fiber communication

The application discloses a signal rate splitting transmission method and receiving method suitable for optical fiber communication, and belongs to the technical field of communication. The transmission method comprises the following steps: decomposing the information of each user into public information and private information, combining the public information of all users into a public data stream, taking the private information of each user as a private data stream, and then performing serial-parallel conversion and constellation mapping to obtain a public information constellation point and a private information constellation point of each user; loading the public information constellation point onto a first group of subcarriers, loading the private information constellation point of each user onto a second group of subcarriers whose order is disturbed by a chaotic key, assigning the public information constellation point a first power, assigning the private information constellation point a second power smaller than the first power, and superimposing to form an RSMA signal. The application solves the problem that the existing optical fiber communication system cannot utilize multiple antennas to perform layered secure transmission.
Owner:NANJING UNIV OF INFORMATION SCI & TECH

Neural network cryptography coprocessor providing countermeasture against side-channel analysis

The present invention relates to a method for securing a security device against side-channel analysis attacks while performing a sensitive operation, the method comprising: • training (401) an attack neural network to perform a side-channel attack against the security device while performing a sensitive operation; • creating (403) a training data set for a protective neural network by applying a plurality of elementary protection combinations to the sensitive operation while performing the sensitive operation using a plurality of values for the piece of sensitive information, and for each elementary protection combination and sensitive information value, recording in the training data set whether the elementary protection combination prevented the attack neural network from discerning the sensitive information value; • training (405) a protective neural network executing on a coprocessor of the security device using the training data set for the protective neural network such that an input to the protective neural network is a sensitive information value to be protected and an output of the protective neural network is an indicator of which combination of elementary protections to apply to protect the piece of information from being detectable using the attack neural network thereby producing a set of parameters for the protective neural network; and • Programming (407) the coprocessor of the security device with the set of parameters for the protective neural network.
Owner:THALES DIS FRANCE SA

Malicious attack protection circuit, system-on-chip including the same, and operating method thereof

Provided are a malicious attack protection circuit, a system-on-chip including the same, and an operating method thereof. The malicious attack protection circuit includes a reference interrupt generator to output a reference interrupt signal every reference interrupt period, a variable clock manager for outputting an operating clock signal to a logic circuit outside the malicious attack protection circuit and a variable clock signal having a variable period, a variable interrupt generator to output an interrupt signal every variable interrupt period based on the variable clock signal, a comparison circuit to compare the reference interrupt signal with the interrupt signal and output a comparison result signal, and a controller that interrupts the output of the operating clock signal input to the logic circuit, according to the comparison result signal.
Owner:SAMSUNG ELECTRONICS CO LTD

Binomial sampling circuit for side-channel attack resistance in post-quantum cryptography

The application discloses a binomial sampling circuit applied to post-quantum cryptographic algorithm and resisting side channel attacks, comprising a random number generation unit, a binomial sampling unit and a control logic unit; the random number generation unit is used for generating pseudo random numbers according to input data; the pseudo random numbers comprise true data and false data; the binomial sampling unit is used for synchronously performing binomial sampling on the true data and the false data; and the control logic unit is used for controlling the random number generation unit and the binomial sampling unit to operate according to external instructions. The binomial sampling circuit applied to post-quantum cryptographic algorithm and resisting side channel attacks disclosed by the application increases the difficulty of analysis of attackers by generating pseudo random numbers, synchronously samples the true data and the false data to interfere with the attackers, and jointly realizes the protection against side channel attacks, thereby effectively improving the security of a Kyber cryptographic system and reducing the risk of being attacked by side channels.
Owner:HUAZHONG UNIV OF SCI & TECH +1

An intelligent large model driven heterogeneous traffic analysis method, device and system

The application relates to the technical field of heterogeneous traffic analysis, in particular to a heterogeneous traffic analysis method, device and system driven by an intelligent large model, which comprises the following steps: collecting side channel features of encrypted traffic, correcting a static position coding mode of a Transform model based on the length of each data packet in a single session, the traffic direction and the arrival time stamp relative to the session start time, dynamically coding the side channel features to obtain a first feature vector of each data packet; constructing a second feature vector, a third feature vector and a fourth feature vector; assigning a learnable bias vector to each feature vector to form a modal bias matrix as a learnable parameter in the training process of the Transform model and correcting the attention mechanism in the Transform model; obtaining a fusion feature vector of all feature vectors to perform attack detection on the input traffic. Therefore, the accuracy of traffic detection is improved.
Owner:HEBEI INST OF MACHINERY ELECTRICITY

Root key generation method and intelligent secrecy system

The invention relates to a root key generation method and an intelligent security system, and relates to the field of intelligent security systems.The root key generation method comprises the steps that S1, a preset number of password book blocks are obtained, the password book blocks are converted into byte abstracts, and a sequence result is determined; s2, after determining a sequence result, converting a sub-block corresponding to the sequence result into a block hash value; s3, based on the common operation base point, converting the block hash value into a group point, and then converting the group point into an aggregation point; and S4, converting the aggregation point into a byte string, and performing encryption operation to generate a root key. The core of the intelligent secrecy system is security, and the security performance of the existing method has defects, so that the scheme provided by the invention not only can effectively avoid cracking by an attacker, but also can ensure the unpredictability of the password book, thereby remarkably improving the security performance of the system.
Owner:SHENZHEN RUISHI OPTOELECTRONICS TECHNOLOGY CO LTD

Secure communication method and apparatus

This application provides a secure communication method and apparatus, and relates to the field of wireless communication technologies. In the method, a communication apparatus receives an ith codeword, where the ith codeword is obtained by encoding an ith first data packet. The ith first data packet is obtained by encrypting an ith second data packet based on an ith random seed. The communication apparatus sends response information of the ith codeword based on a decoding result of the ith codeword, where the response information indicates that the ith codeword is successfully decoded or fails to be decoded.
Owner:HUAWEI TECH CO LTD

Discrete space global optimization method based on neighborhood mapping and multi-path parallel search

The invention discloses a discrete space global optimization method based on neighborhood mapping and multi-path parallel search. The method comprises the following steps: acquiring a discrete state variable to be optimized as an initial search starting point; generating an initial candidate set by applying a neighborhood mapping rule, and executing structure pre-screening; constructing a multi-path parallel computing architecture, and distributing the effective candidate states to a plurality of independent computing threads by taking the effective candidate states as local initial starting points of the independent search paths; executing deep iterative search on each search path, wherein each round of iterative search is screened according to an evaluation index system comprising a first evaluation index for macroscopic evaluation and a second evaluation index for microscopic difference distinguishing; and periodically synchronizing local optimal solutions output by all parallel search paths, and screening to obtain a global optimal solution. According to the method, the problem of search stagnation during construction of the high-performance password component is solved, and the high-security password component with both high nonlinearity and low difference uniformity can be efficiently and stably generated.
Owner:HUAZHONG AGRI UNIV

Physical side channel information confusion method and system based on heterogeneous computing and medium

The invention belongs to the technical field of computer hardware security, discloses a physical side channel information confusion method and system based on heterogeneous computing and a medium, and aims to solve the problem that security defense and system performance are difficult to cooperate in the prior art. The method is executed by a heterogeneous sensing security scheduler, and comprises the following steps: identifying core type information of a target heterogeneous multi-core processor; receiving a sensitive calculation task to be scheduled; and scheduling the sensitive computing task to a physical computing core for execution based on the judgment result of whether the sensitive computing task is decomposable and the core type information, so that physical side channel information generated in the execution process is confused. According to the invention, inherent and ubiquitous physical isomerism of hardware is used as a defense resource which can be actively scheduled and utilized. Through active scheduling and utilization of inherent physical heterogeneity of a processor, a high-quality and high-robustness side channel information confusion effect is obtained with relatively low implementation overhead.
Owner:ELECTRIC POWER RES INST OF STATE GRID ZHEJIANG ELECTRIC POWER COMAPNY