Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

5503results about "Internal/peripheral component protection" patented technology

Method and system for realizing USB flash disk equipment interaction based on flash memory encryption technology

The invention relates to the technical field of cores, and discloses a method and a system for realizing USB flash disk equipment interaction based on a flash memory encryption technology, which comprises the following steps of: dividing an encryptable data block of a flash memory controller, and determining a dynamic entropy weight of the encryptable data block by utilizing an equipment interaction instruction and a random noise characteristic signal; generating a self-adaptive key generation sequence capable of encrypting data blocks through an address allocation mode and a dynamic entropy weight of a flash memory controller; calculating a side channel leakage risk index of the flash memory controller, and setting a security level label of an encryptable data block in combination with a self-adaptive key generation sequence; the method comprises the following steps: setting a differentiated security protection mechanism of an encipherable data block by constructing an access control matrix of the encipherable data block and an encryption risk area of a flash memory controller; and generating a secure interaction scheme of the USB flash disk equipment based on the self-adaptive key generation sequence in combination with the differential security protection mechanism and the access control matrix. According to the invention, the interaction safety and reliability of the USB flash disk equipment can be improved.
Owner:SHENZHEN LINGCHUANG IND CO LTD

Cryptocurrency hardware wallet on monolithic chip with common physical countermeasures and secure memory

An electronic hardware wallet for conducting cryptocurrency transactions, blockchain transactions, or other secure communications is embodied on a monolithic integrated circuit (IC) die supported on a single substrate. The monolithic semiconductor device can include a non-volatile data store for storing application software executable by the multi-core processor, and the secure element can include a secure data store for storing secret data (e.g., a private key) for use in a secure electronic transaction. In some embodiments, the secure element can include hardware logic embodying a cryptocurrency algorithm associated with executing the secure electronic transaction and can have a limited and selective communication bus between the secure element and the multi-core processor. The electronic hardware wallet can communicatively couple with one or more other devices to facilitate a multi-party computation (MPC) algorithm for authenticating the cryptocurrency algorithm and validating the secure electronic transaction.
Owner:CROSSBAR INC

Systems and methods for autonomous intelligence

Systems, methods, and apparatus are disclosed for omnimodal sensing, data fusion, and autonomous decision-making across physical and digital domains and further integrates a Multimodal Diagnostic System (MDS) and Impairment Recognition and Intervention System (IRIS) with defense architecture or a system architecture that can be compliant with the Modular Open Systems Approach (MOSA) and Sensor Open Systems Architecture (SOSA) to ensure interoperability. The system can utilize real-time multisensory fusion, cryptographic provenance via blockchain, and resilient magnetoelectric communication to support mission-critical decision-making across manned and unmanned platforms in denied or contested environments.
Owner:XGENESIS

Utilizing two-terminal resistive switching memory to store validation data of an integrated circuit device

An electronic device can be validated at a circuit-level or device-level to provide supply chain verification of an integrated circuit (IC) product. A modern integrated circuit package can comprise multiple dies, systems and circuitry built from a variety of device-level structures. Device-level verification disclosed herein can confirm that a device-level (sub-) component of an integrated circuit product is sourced by a known or otherwise valid manufacturer. This serves to mitigate or avoid a hacking attempt involving illicit replacement of a component of an IC product by an intermediate handler of the IC product within a supply chain.
Owner:CROSSBAR INC

Multimodal transport trusted data space construction method based on privacy calculation and block chain

The invention belongs to the technical field of logistics information, and discloses a multimodal transport trusted data space construction method based on privacy calculation and a block chain. The method comprises the following steps: deploying a modular intelligent data gateway at a core node of a multimodal transport line, unifying the format of multi-source heterogeneous original data, and chaining a hash value; after the multi-source heterogeneous data is subjected to customization processing, key metadata attributes of all the data are registered and linked in real time; constructing a core ontology model, and establishing a cross-domain semantic interoperation capability; establishing a privacy calculation and block chain collaborative dual-channel architecture, and cooperatively training an ETA prediction model in a local data isolation environment by adopting transverse federal learning to ensure that original trajectory data is not out of a domain; constructing a dispute arbitration and credible verification system, and realizing an arbitration process of judicial verification when a transportation dispute occurs; data minimization disclosure and compliance sharing are achieved through dynamic access control. According to the method, multimodal transport data can be available and invisible, and the whole operation process can be audited.
Owner:NANJING UNIV OF SCI & TECH +1

Distributed data security storage and encryption system based on AI technology

The invention relates to a distributed data security storage and encryption system based on an AI technology. The system comprises a data acquisition and preprocessing layer used for acquiring original data and preprocessing the original data to obtain an identifiable data object; the AI identification and strategy decision layer is used for identifying data features of identifiable data objects based on an interpretable AI model to obtain an encrypted instruction packet; the encryption execution and distributed storage layer is used for performing encryption storage processing on the original data content according to an encryption instruction packet to obtain data access interface information; and the dynamic access control layer is used for obtaining user information in response to a data access request instruction of a user, recombining and decrypting the data by using the data distribution mapping index based on the access control strategy table, and returning a plaintext data fragment. By adopting the system, a high-strength, differentiated and multi-level security mechanism can be realized through the AI, intelligent encryption strategy decision is carried out, and the security requirements of multiple scenes and multiple types of data are met.
Owner:HEFEI CITY UNIV

Apparatus and method for secure communication and integration with secure and non-secure root ports

Secure communication provided with secure and non-secure root ports. One embodiment comprises: a plurality of cores; a memory controller to couple to a memory; an interconnect fabric coupled to the plurality of cores and the memory controller; and a root complex to support end-to-end encrypted channels between devices, the root complex comprising: a root port to receive non-posted requests from a requestor device, the root port to associate a first tag value with a non-posted request to indicate whether the non-posted request is received over an end-to-end encrypted channel; and a bridge device to transmit the non-posted request with the first tag value and to subsequently receive a completion message including the first tag value, wherein the root port is to determine whether the completion message is to be encrypted in accordance with the end-to-end encrypted channel based on the first tag value.
Owner:INTEL CORP

User Behavior Modeling for Detecting and Containing Malicious Activity in a Storage System

An illustrative method includes monitoring operations performed with respect to a storage system by an entity using an identity associated with a particular role, the particular role providing the entity with a set of permissions associated with the storage system; determining, based on the monitoring, that one or more operations of the operations deviate from an expected activity profile associated with the role by more than a threshold; and performing, based on the determining that the one or more operations deviate from the expected activity by more than the threshold, a remedial action with respect to the entity.
Owner:PURE STORAGE INC

Solid-state electronic disk soft destruction method, device and system

The invention relates to the technical field of storage, and particularly discloses a solid-state electronic disk soft destruction method, device and system, which are mainly used for solving the systematic vulnerability problems of key metadata single-point failure, power-on deadlock, single recovery strategy, insufficient core component redundancy protection and the like of the existing solid-state electronic disk in an extreme application scene. The method comprises the following steps: monitoring metadata integrity, PCIe links and power-on progress in real time by anomaly perception, and generating an abnormal data packet; the decision arbitration generates an instruction packet according to an abnormal matching recovery strategy; and the execution layer dispatches hardware to complete repairing or clearing operation and feeds back a result. According to the scheme, the deep fault of the solid-state electronic disk can be intelligently sensed, accurately arbitrated and effectively recovered without physical intervention, and the reliability, availability and safety of the solid-state electronic disk are remarkably improved.
Owner:SICHUAN WEIXIN TECH CO LTD

Intelligent customer acquisition and user behavior analysis system based on AI full ecology

The invention discloses an intelligent customer acquisition and user behavior analysis system based on AI full ecology, and relates to the technical field of artificial intelligence and big data marketing, and the system comprises a multi-source data collection module which collects internal and external multi-channel data of an enterprise; the data cleaning module processes abnormal and missing values and unifies data formats; the user portrait construction module extracts multi-dimensional labels to describe user features; the intelligent customer obtaining module uses transfer learning to screen high-potential customers, and the user behavior analysis module mines behavior logic by means of Transform; the intelligent recommendation engine is fused with multiple algorithms to realize personalized recommendation, and the real-time decision module is combined with rules and reinforcement learning to optimize marketing. According to the method, multi-source data integration and deep analysis are realized, clients are accurately identified, behavior requirements are mined, the client obtaining efficiency and the conversion rate are improved, the marketing effect is optimized through personalized recommendation and intelligent decision, and a whole-process intelligent marketing solution from data acquisition to decision execution is provided for enterprises.
Owner:NINGBO JIAYUAN TECHNOLOGY CO LTD

Method and system for encrypting and isolating storage data of credential mobile terminal

The invention relates to a method and system for encrypting and isolating storage data of a credential mobile terminal, and belongs to the technical field of information. The method comprises the following steps: encrypting and partitioning the whole storage area, and setting an access strategy according to user permission; when a user requests to access, executing multi-factor authentication containing a password and an external hardware certificate, and adding biological characteristic authentication; after the authentication is passed, an encryption key is taken from the domestic security chip; and encrypting and decrypting data by using the secret key, and opening corresponding partition access according to authority. The system comprises a storage partition module, an identity authentication module, a key management module, an encryption and decryption module and an authority control module and is used for executing the method. The method also comprises the steps of equipment startup trusted boot and firmware upgrade verification, is based on a custom curing system, and is compatible with Android 10 +. The problems of poor hardware controllability and positioning security risk of the creative mobile terminal are solved, and full-link data security protection is realized.
Owner:JINAN UNIV IND TECH RES INST CO LTD +1

Cryptographic system for post-quantum cryptographic operations

Certain examples described herein relate to at least a cryptographic system and a method of operating a cryptographic system. The cryptographic system may be implemented as a co-processor for performing post-quantum cryptographic functions. The cryptographic system has a set of bus interfaces for coupling to an external computing system, a cryptographic math unit and a control unit. The cryptographic math unit in certain examples is adapted to provide one or more masked modes of operation that secure the cryptographic operations against side-channel and non-invasive attacks. The method of operating a cryptographic system involves annotating secret data and tracking those annotations through one or more arithmetic operations.
Owner:PQSHIELD LTD

Security protection method for power mobile application based on swan-gap microkernel

The invention relates to an electric power mobile application security protection method based on a swan gap microkernel, which comprises the following steps of: S1, establishing a hardware trust root, and storing a device root key and a certificate chain by utilizing a non-tampering storage area built in a chip; s2, establishing a complete trusted boot chain based on a hardware root of trust, and verifying the integrity and credibility of the next layer by each layer from Bootloader to a swan microkernel and then to an application program; s3, constructing a triple authentication system based on user identity, equipment identity and biological characteristics, and performing user authentication; s4, according to a user authentication result, realizing fine-grained authority control based on an RBAC model and ABAC, and ensuring that authority check can be executed during resource access every time by utilizing an IPC security mechanism of a swan micro kernel; and S5, creating an independent execution environment for each power application according to the process isolation capability of the swan microkernel, and ensuring that memories among the applications cannot be mutually accessed through virtual address space isolation. The reliability of power mobile application safety protection is effectively improved.
Owner:STATE GRID INFORMATION & TELECOMM GRP CO LTD +1

Fused secure storage system, electronic equipment, data management method and computer readable storage medium

The invention provides a fusion type secure storage system, electronic equipment, a data management method and a computer readable storage medium. The system comprises a hardware security layer, an encryption processing layer, a verification error correction layer, a data stream processing layer and an intelligent management layer which are in communication connection, the hardware security layer provides a physical trusted root for the system and executes a security policy; the encryption processing layer is used for carrying out encryption processing on data based on the security service provided by the physical trusted root; the verification and error correction layer is used for carrying out integrity verification and self-adaptive error correction coding on the encrypted data; the data stream processing layer is used for executing a near data calculation task on the data subjected to verification and error correction; and the intelligent management layer collects real-time state data from the hardware security layer, the encryption processing layer, the check error correction layer and the data stream processing layer, and performs dynamic strategy configuration and global optimization decision, thereby improving the active calculation, dynamic adaptation and intelligent optimization capabilities of the system.
Owner:深圳华芯星半导体有限公司

Large model corpus data interaction system and interaction method based on trusted execution environment, terminal and medium

The invention discloses a large model corpus data interaction system and method based on a trusted execution environment, a terminal and a medium. The system comprises a data provider, a data demander and a trusted data space service platform. And the data provider is used for encrypting the corpus data, and performing preprocessing, directory sorting and packaging on the corpus data in the data provider connector to obtain the data capsule. And the data demander is used for submitting a calculation task in the data demander connector and obtaining corpus data of the data capsule for calculation after authorization. And the trusted data space service platform is used for storing the encrypted corpus data, controlling access of a data user, scheduling a calculation task, managing a key and generating an audit log. Through trusted execution environment hardware isolation and full-link encryption, it is ensured that corpus data only exists in a plaintext form in the trusted execution environment in the full life cycle from access to destruction, and unauthorized access and leakage are completely eradicated.
Owner:SHENZHEN CONFIDENTIAL COMPUTING TECH CO LTD

System and method for routing-based internet security

Method and system for improving the security of storing digital data in a memory or its delivery as a message over the Internet from a sender to a receiver using one or more hops is disclosed. The message is split at the sender into multiple overlapping or non-overlapping slices according to a slicing scheme, and the slices are encapsulated in packets each destined to a different relay server as an intermediate node according to a delivery scheme. The relay servers relay the received slices to another other relay server or to the receiver. Upon receiving all the packets containing all the slices, the receiver combines the slices reversing the slicing scheme, whereby reconstructing the message sent.
Owner:MAY PATENTS LTD

Data storage security protection method and system based on solid state disk

The invention relates to the field of computer security, and discloses a data storage security protection method and system based on a solid-state hard disk, which comprises the following steps: identifying the inherent physical difference of a flash memory chip in the solid-state hard disk so as to calculate the read-write time sequence micro-deviation of the solid-state hard disk; performing hash operation on the device root key and the unique identifier of the controller corresponding to the solid state disk to obtain a bound master control key; generating a temporary encryption key of the write-in operation to encrypt plaintext data of the host system to obtain ciphertext data; writing the ciphertext data into a flash memory physical page corresponding to the physical page address to obtain a ciphertext physical page address; when the access mode is a hostile attack mode, secretly updating the ciphertext physical page address into a new physical page address, and deleting the ciphertext physical page address; and when the access mode is a secure access mode and the verification key is consistent with the bound master control key, normal loading and data access requests of the solid state disk are allowed. According to the invention, the security and integrity of data storage can be improved.
Owner:深圳市彦胜科技有限公司

Rear-end system creativity transformation method and device, electronic equipment and storage medium

The invention relates to the technical field of computers, can be applied to the field of science and technology finance / digital medical treatment, and discloses a back-end system creativity transformation method and device, electronic equipment and a storage medium. The method comprises the following steps: deploying a credential back-end system environment by using a credential server and credential middleware, and physically isolating credential traffic and non-credential traffic; carrying out dynamic segmentation scheduling on the traffic of the credential and credential gateway in the credential and credential environment and the traffic of the non-credential and credential gateway in the non-credential and credential environment; deploying a domestic database, and finishing data migration from the original database to the domestic database through an automatic tool chain; segmenting the traffic to a credential and credential gateway in the credential and credential environment for gray verification, and switching a back-end service chain of the credential and credential environment to a domestic database after the verification is passed; and monitoring the operation performance data of the credential environment in real time, and switching the traffic to the non-credential environment and the original database through the global traffic management tool if an exception occurs. According to the method, the risk controllability and smooth transition of creative transformation are realized.
Owner:CHINA PING AN LIFE INSURANCE CO LTD

Communication system for a vehicle

In certain embodiments, a communication system includes a network server configured to provide a secure data fabric, a network device connected to the secure data fabric, and a vehicle in communication with the network and connected to the secure data fabric. The secure data fabric includes cell modules, and each cell module includes a fabric hub, a vehicle model, a signal model, and a first protocol with publication and subscription. The vehicle includes electronic control units (ECUs) connected to an ECU bus. One of the ECUs includes a fabric node, and is configured to exchange messages, including the data from the vehicle model, with the fabric hub according to the first protocol, convert the data from the vehicle model to data from the signal model, and exchange messages, including the data from the signal model, with the ECUs according to a second protocol.
Owner:RIVIAN HOLDINGS LLC

Sparse and dense state calculation method, device and equipment and readable storage medium

The invention provides a sparse and dense state calculation method, device and equipment and a readable storage medium, and the method comprises the steps: receiving an input data stream, analyzing the feature information of the input data stream, and marking a sensitivity level for the data stream; according to the sensitivity level of the data stream, a corresponding calculation strategy is called, and the calculation strategy at least comprises secret state calculation, hybrid calculation and plaintext calculation; and executing a calculation strategy for calculation associated with the data stream according to the calculation strategy corresponding to the data stream in AI training and / or AI reasoning. Through the technical scheme of the specification, the sensitivity level is marked for the data stream, and the secret state, mixing or plaintext calculation strategy is dynamically matched, so that the overall calculation overhead is remarkably reduced while the high-sensitivity data security is ensured, and the AI training and reasoning efficiency is improved.
Owner:XINHUASAN INFORMATION TECH CO LTD

Secure hardware signature and related methods and applications

This disclosure provides techniques for recovering a root key from measurement of a circuit function. In some embodiments, a checkpointing feature is used to periodically mark measurements of this function and thereby track drift in the value of the root key over the life of a digital device; the checkpointing feature permits rollback of any measurement of the function in a manner that negates incremental drift and permits recovery of the root key for the life of a device (e.g., an IC circuit or product in which the IC is embedded). This disclosure also provides novel PUF designs and applications.
Owner:JONETIX CORP

Multi-level security protection method taking persistent memory as core level

The invention discloses a multi-level security protection method taking a persistent memory as a core level, and relates to the technical field of computer storage security. The method comprises the following steps: constructing a cross-level security abstract model, and implementing NUMA perception encryption on the basis of the cross-level security abstract model, including a localization encryption strategy and an intelligent key distribution system; based on a cross-hierarchy security abstract model and NUMA perception encryption, dynamic key hierarchical derivation is realized, a tree topology structure is adopted in the derivation process, generation of a root key and sub-keys of each hierarchy depends on a hierarchical key derivation engine, and cross-node synchronization is completed through an intelligent key distribution system during key cascade update; a side channel attack resisting system is constructed, support for CXL equipment is matched with establishment of a CXL metadata consistency group in NUMA perception encryption, and the security of data transmission and storage of the CXL equipment is guaranteed. According to the invention, the encryption performance is obviously improved.
Owner:Shanxi Taihang Laboratory Co., Ltd.

Access reminding method and electronic equipment

The embodiment of the invention provides an access reminding method which comprises the steps that when it is detected that a first application accesses a sensitive resource, a display object is displayed on a display interface of electronic equipment, the display object is used for reminding a user that the first application is accessing the sensitive resource, the display object is drawn through a trusted execution environment (TEE), in the process that the first application accesses the sensitive resource, the display object is always displayed on the current display interface of the electronic equipment. Through the method, in the process that the application accesses the sensitive resource, the access behavior of the application can be explicitly and clearly presented on the display interface of the electronic equipment, and the presentation is always displayed on the upper layer and is not shielded by other display contents. The perception degree of a user on sensitive access behaviors of an application can be enhanced.
Owner:HUAWEI TECH CO LTD

Financial audit system based on artificial intelligence

The invention discloses a financial auditing system based on artificial intelligence, which belongs to the technical field of artificial intelligence and comprises a heterogeneous data dynamic adaptation device, a trusted data pipeline system and a central auditing processing unit. The heterogeneous data dynamic adaptation device comprises a multi-protocol PHY chip set, an FPGA programmable logic array, a protocol sensing antenna array and an AI coprocessor. The protocol sensing antenna array is annularly arranged on the inner wall of the device shell and comprises at least 12 miniature receiving and transmitting modules with adjustable directions; a protocol reverse learning model is arranged in the AI coprocessor, and a protocol analysis scheme is dynamically generated by analyzing electromagnetic radiation characteristics of an interface. According to the financial auditing system based on artificial intelligence, real-time dynamic data adaptation and credible traceability of a cross-heterogeneous financial system can be achieved, the problems of format conflict, semantic ambiguity and transmission delay of multi-source heterogeneous data in the auditing process are solved, and meanwhile verifiability and non-tampering performance of the data extraction process are ensured.
Owner:GUOYI TIANCHENG CONSTR ENG TECH CO LTD

Equipment panel loading method and system based on Qiankun framework and electronic equipment

The invention discloses an equipment panel loading method and system based on a Qiankun framework and electronic equipment, the method is applied to an Internet of Things platform comprising a main application, the method comprises the following steps: S1, a registration step: based on an application container framework, the main application registers a plurality of sub-applications, and each sub-application corresponds to one piece of equipment; s2, a loading step: in response to an operation for a target device, dynamically acquiring and loading a corresponding registered sub-application by the main application according to the device identifier of the target device; s3, an isolation running step: creating an isolation environment for the loaded sub-application by the application container framework, and running the sub-application in the isolation environment to render a control panel interface of the target equipment, so that the system can ensure the independence of the control panel of each equipment, and the control panel interface of the target equipment can be rendered. The efficient utilization of resources and the effective isolation of operating environments are realized, and the maintainability, the expansibility and the operating stability of the Internet of Things platform are improved.
Owner:深圳市力合微电子股份有限公司

Method and system for FPGA-based encrypted VPN

A system and methods are provided for encrypting and decrypting data payloads, receiving an unencrypted data payload; generating a random seed value; generating in FPGA firmware an encryption hash key from seed parameters including the seed value, XORing the encryption hash key with the unencrypted data payload to generate an encrypted data payload; transmitting the encrypted data packet with the seed value and the encrypted data payload to a second FPGA that regenerates the hash key from the see parameters and XORing the hash key with the encrypted data payload to regenerate an unencrypted data payload.
Owner:ENQUANTUM LTD

Mobile solid state disk data encryption storage method based on trusted computing module

The invention relates to the technical field of data security, in particular to a mobile solid state disk data encryption storage method based on a trusted computing module. According to the method, integrity measurement is carried out on an operating environment through a trusted computing module, and a trusted measurement value is generated; generating a session-level encryption key based on the trusted magnitude; encrypting data using the key and storing key metadata; during data reading, correlation verification is carried out to determine whether decryption is authorized or not; and baseline adjustment can be triggered according to the measurement deviation. According to the invention, the data security of the mobile storage device is improved, and an environment-aware dynamic key management mechanism is realized.
Owner:BEIJING XINXUN XINAN TECH CO LTD

Dynamic access control method, device and equipment of baseboard management controller, and storage medium

The invention discloses a dynamic access control method and device of a baseboard management controller, equipment and a storage medium, and relates to the technical field of server hardware security management.The method comprises the steps that when an access request is detected in a trusted operation environment, multi-dimensional context attributes associated with the access request are collected; performing dynamic trust evaluation based on the multi-dimensional context attribute, and generating a dynamic trust score corresponding to the access request; and executing an access control decision corresponding to the access request according to the dynamic trust score. Compared with a traditional static trust model, the dynamic trust evaluation is carried out based on the multi-dimensional context attribute under the trusted operation environment of starting verification of the baseboard management controller, and the differentiated access control decision is executed according to the dynamic trust score, so that the access risk is accurately identified, and the reliability of the system is improved. The security vulnerability of'permanent trust in one-time authentication 'in the prior art is avoided, and the access security of the substrate management controller is improved.
Owner:中电长城科技有限公司

Techniques for implementing customized image privacy zones

This disclosure describes, in part, techniques for implementing customized privacy zones for security monitoring. In embodiments, such techniques may comprise receiving first data defining a first area associated with a privacy zone, receiving image data generated by a camera, the image data encompassing at least a portion of the first area, determining a position of an object detected within the image data, and determining, based on the first data and the position of the object, that the object is outside of the first area associated with the privacy zone, The techniques may further comprise defining a portion of image data that corresponds to the first area less a second area associated with the object detected within the image data, applying at least one obfuscation technique to the portion of image data, and sending the image data having the applied obfuscation technique to at least one second electronic device.
Owner:AMAZON TECH INC