Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

6results about How to "Reduce attack surface" patented technology

Sensitive data access method and device, electronic equipment and computer program product

The invention provides a sensitive data access method and system, electronic equipment and a computer program product, belongs to the technical field of computers, and aims to solve the problems of existing sensitive data in aspects of data protection, sharing and the like. The method is used for supporting a computing platform of a first execution mode and a second execution mode and comprises the following steps that trusted firmware is operated in the first execution mode, a user program is operated in the second execution mode, and a secure storage area where sensitive data are located is set to be inaccessible to the second execution mode through the trusted firmware; in response to a hardware exception triggered by an access instruction of the user program to the secure storage area, interrupting execution of the user program, entering an exception handling program in a first execution mode, and executing an access agent operation in the exception handling program through trusted firmware; and after the trusted firmware completes the proxy access operation, triggering an exception return instruction to recover the execution of the user program.
Owner:XINSHENG TECHNOLOGY CO LTD +2

Method, device and medium for implementing secure socket communication in operating system kernel

PendingCN122293388AObtain automatic encryption and decryption communication capabilitiesAvoid frequent data copiesSecure communicationOperational system
This application discloses a method, apparatus, and medium for implementing secure socket communication within the operating system kernel, belonging to the field of computer systems and network communication technology. This method registers a new secure socket type at the socket layer of the operating system kernel and associates it with a customized set of operation functions. Applications only need to create sockets of this type and inject cryptographic parameters through standard system calls to establish a connection, thereby obtaining transparent, end-to-end automatic encrypted communication capabilities. During transmission, data is encrypted in kernel mode by calling the native crypto subsystem API through a rewritten send function and an authentication tag is attached. During reception, the rewritten receive function automatically performs decryption and integrity verification. This scheme avoids reliance on large external security libraries, improves security and performance, and decentralizes encryption / decryption, resource management, and other processes to the kernel mode, providing upper-layer applications with easy-to-use, lightweight, high-performance, and highly secure kernel-level transparent secure communication.
Owner:TRAVELSKY TECHNOLOGY LIMITED

One-way safe content distribution and tamper-proof display method and system

The invention relates to a one-way secure content distribution and tamper-proof display method and system, and belongs to the field of information security. The method comprises the steps that terminal identity authentication is carried out, an identity label is generated for each terminal, and the identity label comprises a device fingerprint, a root key, a public key, a private key and a digital certificate; by establishing a one-way content pulling mechanism, one-way content pulling between a terminal and a platform is realized; the platform prepares to issue content and performs content integrity protection to obtain root hash, a ciphertext and a digital signature; the platform packs and issues the ciphertext, the root hash, the digital signature and the necessary Merkle hash tree branches to the terminal, and the terminal performs verification and decryption; a closed display environment is created on the terminal, and tamper-proof display is achieved. According to the method, the security and tamper-proof capability of content distribution are systematically improved through fusion of multiple technologies such as hardware feature fingerprints, chaos random pulling, dynamic environment key binding, closed display environment and the like.
Owner:SHANGHAI SHUXI TECH CO LTD

Method and system for supporting security monitoring and cloud synchronization of edge service equipment

PendingCN121807646ASolving accessibility issuesIsolated synchronization across networksHardware monitoringEdge nodeData store
The invention discloses a method and a system for supporting security monitoring and cloud synchronization of edge service equipment, and relates to the technical field of cloud computing. The method comprises the following steps: deploying a local monitoring module at an edge node to carry out index acquisition and temporary storage; a data transfer module is deployed to pull data from a federated interface of the local monitoring module; the data transfer module actively pushes the data to a cloud time sequence database through secure connection after preprocessing such as adding an identity tag to the data; and the cloud provides unified visualization and alarm based on the stored data. According to the method, cloud pulling is converted into edge pushing, the monitoring data collection problem caused by the fact that the cloud cannot directly access the edge nodes is solved, and reliable convergence and unified operation and maintenance management of the edge monitoring data are achieved on the premise that network safety is guaranteed.
Owner:SHENZHEN SNOWBALL TECHNOLOGY CO LTD

A signaling conversion method and system based on telephone interaction

The application discloses a signaling conversion method and system based on telephone interaction, which is applied between a service domain and an operator access domain, and the method comprises the following steps: on the service domain side, receiving original signaling messages from an internal service system, performing signaling desensitization mapping processing on the original signaling messages, generating abstract metadata containing only service logic identification, and transmitting the abstract metadata to the access domain side across the domain through a kernel-level communication interface; on the access domain side, converting the abstract metadata into an identifiable signaling format of an operator, and sending the abstract metadata to an operator network; establishing a media stream transmission tunnel at an operating system kernel layer, and monitoring transmission quality indexes of the media stream transmission tunnel in real time; continuously monitoring a signaling registration transaction log on the service domain side through an independent relay state maintenance module running independently of the internal service system, caching complete parameters of the latest successful registration to the operator network based on the log, and realizing high-safety, high-reliability and high-compatibility signaling conversion.
Owner:GUANGDONG CHAOTENG INFORMATION TECHNOLOGY CO LTD

A DPDK-based virtual rdma device and method of using the same

The application discloses a virtual RDMA device based on DPDK and a use method thereof. The virtual RDMA device based on DPDK comprises a front-end virtio-rdma device, which is used for receiving an RDMA device operation request initiated by an application program in a virtual machine, encapsulating the request as an instruction conforming to a virtio protocol, and sending the instruction to a back-end vhost-user- rdma device through a vring; and the back-end vhost-user- rdma device is used for simulating the function of a real RDMA network card, the device can acquire and analyze the instruction conforming to the virtio protocol from a circular queue vring, execute corresponding RDMA device operations, and return the operation results to the front-end virtio-rdma device through the vring. The application can get rid of the dependence on the real RDMA device, and can improve the resource utilization, system flexibility and safety.
Owner:KYLIN CORP