A layered security system and method against quantum, side channel, and insider photographing and memory reconstruction

By employing a layered confidentiality architecture with data fragmentation, dynamic screen marking, and a fault rollback mechanism, the system addresses issues such as insider leaks, quantum attacks, and side-channel attacks, achieving a highly available and auditable information security system.

CN122372174APending Publication Date: 2026-07-10
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Filing Date
2026-04-14
Publication Date
2026-07-10

AI Technical Summary

Technical Problem

Existing information security systems cannot effectively prevent insiders from leaking information through photography or memory reconstruction, are vulnerable to quantum computing and side-channel attacks, and cannot meet the requirements for high availability and auditability.

Method used

A layered security architecture is adopted, including an access adaptation layer, a confidentiality isolation layer, a human-machine display layer, an anti-side channel module, an anti-quantum module, a leak prevention module, a self-iteration module, and a fault rollback module. Through data fragmentation, dynamic screen marking, pseudo-operations, and fault rollback mechanisms, it prevents insider leaks and resists quantum and side channel attacks.

Benefits of technology

It achieves the goals of preventing insider leaks, resisting quantum computing and side-channel attacks, meeting regulatory audit requirements, and ensuring system operability and security without compromising system availability and compliance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure FT_1
    Figure FT_1
  • Figure FT_2
    Figure FT_2
  • Figure FT_3
    Figure FT_3
Patent Text Reader

Abstract

This invention discloses a layered security system and method resistant to quantum attacks, side-channel attacks, and insider filming / memory reconstruction. The system includes an access adaptation layer, a confidentiality isolation layer, a human-machine interface layer, an anti-side-channel module, an anti-quantum module, an anti-leakage module, a self-iterative module, and a fault rollback module. Real data is fragmented, encrypted, and written to an audit black box; the human-machine interface maintains stable semantics for critical operations, while non-critical attributes change dynamically and are overlaid with screen markers; operators can use the system normally, but filming or memorizing data cannot restore the real data. The system periodically performs self-attack simulations, and vulnerabilities are reinforced after manual approval; in the event of a security layer failure, the original service is automatically rolled back. This invention effectively combats quantum attacks, side-channel attacks, and insider filming / memory reconstruction leaks while maintaining availability and auditability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of information security technology, specifically relating to a high-level confidentiality system applicable to financial transactions, military command, and protection of core corporate intellectual property rights. In particular, it relates to a layered security architecture that, while maintaining operability and auditability, combats quantum attacks and side-channel attacks, and prevents insiders from reconstructing real data through photography or memory. Background Technology

[0002] Existing information security systems generally suffer from the following fundamental flaws.

[0003] First, an insider can use a mobile phone to photograph the screen, memorize key information, and reconstruct it afterward, causing a serious leak. Traditional security systems only protect the network and storage, failing to address the core issue that what the human eye sees is what they get, and what they get can be leaked.

[0004] Second, fixed cryptographic algorithms and mathematical structures are vulnerable to quantum computing. Shor's algorithm can break public-key cryptosystems such as RSA and ECC in polynomial time, and Grover's algorithm can perform quadratic speedup attacks on symmetric cryptosystems.

[0005] Third, side-channel attacks include power consumption analysis, timing analysis, electromagnetic acquisition, and cache attacks, which can bypass upper-layer encryption algorithms and directly extract keys from the physical layer.

[0006] Fourth, security module failures often lead to business interruptions, and there is a lack of rapid rollback mechanisms. Existing high-security systems often sacrifice availability and cannot meet financial-grade high-availability requirements.

[0007] Fifth, high-security systems often sacrifice auditability and operability, failing to meet regulatory requirements for transaction retention and post-event traceability.

[0008] To overcome the above-mentioned shortcomings, this invention proposes a layered confidentiality architecture that significantly improves actual security without sacrificing core availability and compliance. Summary of the Invention

[0009] The technical problem this invention aims to solve is: how to effectively prevent insiders from leaking information through filming or memory reconstruction without reducing system availability or violating audit compliance requirements, while also resisting quantum attacks and side-channel attacks. Technical solution

[0010] This invention discloses a layered security system and method that is resistant to quantum computing, side-channel attacks, and insider filming, and enables memory reconstruction. Its core idea is to allow operators to use and memorize operating procedures normally, but to prevent the memorized or filmed content from being reconstructed from the actual data.

[0011] The system consists of the following components.

[0012] First, the access adaptation layer. The access adaptation layer adopts a bypass transparent proxy, without modifying the original business system interfaces, processes, and hardware, and supports dual-link hot standby.

[0013] Second, the confidentiality isolation layer. This layer divides the real data into multiple fragments, making it impossible to reconstruct the complete information from any single fragment. Each fragment is independently encrypted and processed instantaneously, with the processing recorded in an immutable audit log. The data is divided into at least 16 fragments, each independently encrypted, and reassembled instantaneously only within a trusted execution environment or hardware security module.

[0014] Third, the human-machine interface layer. This layer maintains the semantics and spatial location of critical operations, dynamically changes non-critical attributes, and overlays traceable screen markers. Critical operations include confirmation, cancellation, transfer, sending, and authorization, and their screen coordinates and interaction logic remain consistent across different sessions.

[0015] Fourth, the anti-side-channel module. The anti-side-channel module hides the true computational characteristics through one or more of the following methods: pseudo-operations, timing perturbations, and power leveling. The pseudo-operation injection ratio is 1:1 to 1:5, the timing randomization range is ±30%, and power leveling is achieved through virtual load.

[0016] Fifth, the quantum-resistant module. The quantum-resistant module employs quantum-resistant cryptographic schemes, including true random entropy sources, one-time pad, or post-quantum cryptographic algorithms.

[0017] Sixth, the data leakage prevention module. This module prevents the reconstruction of real data from screen captures or personal memory. It includes a dynamic screen watermark containing user identity and timestamps, rotating color decorations for non-critical attributes, and random noise patterns in the background.

[0018] Seventh, the self-iterative module. The self-iterative module is used to periodically simulate attacks to detect vulnerabilities, and after vulnerability confirmation, it undergoes manual approval for hardening. Simulated attack types include traditional network attacks, side-channel attacks, quantum attack simulations, social engineering and insider behavior simulations, and fault injection attacks. Hardening strategies require joint approval from security, business, and operations departments, and are distributed in a phased, gradual, and gradual manner (5%, 20%, and 100%), and must not be automatically deployed to the entire network.

[0019] Eighth, the fault rollback module. The fault rollback module automatically switches to the original business system when the security layer fails, with the switchover time meeting business continuity requirements. The fault rollback module supports three levels of degradation. Level 1 degradation involves automatic retries and enhanced verification in case of a single timeout or verification failure. Level 2 degradation involves shutting down a single defense module and issuing an alarm when it crashes, resulting in degraded business operation. Level 3 degradation involves automatically or manually triggering a hardware bypass switch to switch to the original business system when the entire security layer fails, with a switchover time of less than 1 second.

[0020] The workflow is as follows: Step A: Bypass and intercept business requests through the access adaptation layer without blocking the original business. Step B: Divide the real data into multiple fragments in the confidentiality isolation layer, ensuring that no single fragment can reconstruct the complete information. Each fragment is independently encrypted, instantaneously processed, and simultaneously written to the audit log. Step C: Maintain the semantic and spatial stability of critical operations in the human-machine interface layer, dynamically change non-critical attributes, and overlay screen markers. Step D: Operators make decisions and confirmations based on the stable operation area. Step E: The system periodically performs self-attack simulations, and hardens the system after manual approval upon discovering vulnerabilities. Step F: When an anomaly occurs in the security layer, automatically switch back to the original business system. Beneficial effects

[0021] Compared with existing technologies, this invention has the following beneficial effects: First, it prevents being photographed and reconstructed from memory. Even if the screen is photographed or someone intentionally memorizes the data, the complete and true data cannot be restored, thus solving the problem of insider leaks at its root. Second, it resists quantum computing by employing information-theoretic security or post-quantum cryptographic algorithms to resist known quantum attacks. Third, it resists side-channel attacks by hiding the true computational characteristics through mechanisms such as pseudo-operations, temporal randomization, and power flatness. Fourth, it provides high availability, with a fault rollback mechanism that meets the requirements for continuous business availability. Fifth, it is compliant and auditable, with the audit black box storing complete encrypted logs, meeting the regulatory requirements for transaction retention and post-event traceability. Sixth, it is trainable and operable, with stable semantics and locations for key operations, allowing personnel to use it normally, train on it, and explain the operation process. Seventh, it continuously improves security by combining self-attack, manual approval, and gray-scale iteration to avoid the production risks brought by automatic upgrades. Eighth, it allows for bypass deployment without modifying existing business systems, ensuring compatibility with existing hardware and processes, and reducing deployment risks and costs. Attached Figure Description

[0022] Figure 1 This is the overall system architecture diagram.

[0023] Figure 2 It is a cross-scenario workflow diagram.

[0024] Figure 3 This is a flowchart of self-attack and self-iteration.

[0025] Figure 4This is a flowchart of fault degradation and physical rollback. Detailed Implementation

[0026] Example 1: Financial transaction scenario.

[0027] A bank has deployed this invention's system. In the teller's interface, the transfer confirmation button is always located in a fixed position in the lower right corner of the screen to ensure operational efficiency, but the button color, background decoration, and screen watermark change randomly with each login. The real account number, amount, and key are stored in a hardware security module with encrypted segments in the background; only a partial mask is displayed on the screen, such as the account number displayed as 6222 asterisks 1234. Tellers can complete transfer operations normally, but even if they use a mobile phone to photograph the screen, the obtained image cannot be used directly due to the watermark and dynamic background, and the missing account information cannot be recovered from a single photograph. The audit black box records all original transaction data, meeting regulatory requirements. When the anti-side-channel module malfunctions, the system automatically shuts down the module and issues an alarm, degrading business operations without interruption. When the security layer main process crashes, the hardware watchdog triggers a bypass switch within 500 milliseconds, allowing the signal to directly reach the original business system, restoring teller operations without any noticeable disruption.

[0028] Example 2: Military command scenario.

[0029] This invention is deployed in a command system. In the situation map seen by the commander, the positions of enemy and friendly targets are stable, ensuring rapid decision-making; however, the marker colors, added noise symbols, and background grid dynamically change. The actual coordinates, frequencies, and numbers are stored separately in the background and reassembled only within a trusted execution environment. The commander can issue attack commands normally, but even if they memorize or capture the screen, they cannot obtain precise parameters. Between different tasks, non-critical attribute rule pools are randomly re-selected, further reducing cross-task information correlation.

[0030] Example 3: Core Intellectual Property Scenarios for Enterprises.

[0031] A chip design company deployed this invention. When R&D personnel viewed register-transfer level code snippets, the key algorithm structure was displayed as a stable block diagram to ensure logical understanding; however, variable names and constant values ​​were dynamically replaced with unpredictable aliases, such as `key1` and `const a`. A watermark containing employee identification and a timestamp was overlaid on the screen. R&D personnel could conduct code reviews normally, but could not reconstruct the actual code from memory or by taking a photo. Even after leaving the company, they could not reconstruct valid intellectual property from memory.

[0032] Example 4: Detailed implementation of self-attack and self-iteration.

[0033] The system performs attack simulations daily at 2 AM in an isolated sandbox. Traditional attacks include simulating unauthorized access, SQL injection, and database breaches. Side-channel attacks involve collecting power consumption curves and timing characteristics under the simulation environment to analyze for potential leaks. Quantum attack simulations assess the theoretical security strength of existing cryptographic algorithms under Shor's and Grover's algorithms. Social engineering simulations simulate insider attempts to memorize or capture screen data to test the effectiveness of the data leakage prevention module. Fault injection simulations include memory overflows, deadlocks, and abnormal power outages. Upon vulnerability discovery, the system automatically generates a hardening draft and submits it to the security committee, including the security manager, business manager, and operations manager. After approval by all three parties, the hardening strategy is rolled out in a phased manner, initially enabled in 5% of sessions. After 24 hours of observation without anomalies, it is expanded to 20%, and then fully deployed after another 48 hours of observation. The entire iteration cycle takes approximately one week, and the security strength can be quantitatively assessed.

[0034] Example 5: Detailed implementation of fault degradation.

[0035] The system continuously monitors the health status of each module. For Level 1 anomalies, such as single timeouts or verification failures, the system automatically increases the number of retries and extends the timeout threshold, ensuring normal service operation and continued security layer functionality. For Level 2 anomalies, such as a side-channel protection module crash, the system shuts down the module, logs an alarm, degrades service operation, and allows other security modules to continue functioning. Maintenance personnel intervene to investigate after receiving the alarm. For Level 3 anomalies, such as a deadlock in the security layer's main process, or a hardware watchdog detecting a lost heartbeat within 500 milliseconds, the system automatically triggers a hardware bypass switch, physically disconnecting the security enhancement layer and allowing direct signal transmission to the original service system. Service recovery occurs within 1 second. After the security layer is repaired, manual switchback by maintenance personnel is required; automatic switchback is prohibited.

[0036] Example 6: Ensuring the security of core bank accounts and resolving discrepancies between the actual balance sheet and the actual account, where funds are available but cannot be withdrawn.

[0037] A provincial commercial bank deployed this system to prevent insider tampering with accounts and falsifying records. The bank had previously experienced a serious incident where a user's balance inquiry showed a deposit, but the actual withdrawal showed insufficient funds; investigation revealed this was due to direct database modification by an insider. After deployment, this system stores real account data in encrypted segments within a confidential isolation layer. Each segment is independently encrypted and stored only within the hardware security module. When tellers or back-office staff inquire about a user's balance, the human-machine interface (HMI) reassembles and displays the balance information from these segments. However, the displayed content is overlaid with a dynamic watermark and random shifts in non-critical attributes, such as the background color of the balance number changing randomly with each query. When a teller initiates a withdrawal transaction, the system automatically executes the following verification process: First, it retrieves and compares the account's three most recent account snapshots from the audit black box. Second, it cross-validates the displayed balance with the actual account balance. Third, if an inconsistency is found, an alarm is immediately triggered, the difference is recorded, the withdrawal operation for that account is locked, and the security audit department is notified. An iterative module simulates a discrepancy attack every morning at midnight to automatically detect unauthorized tampering. If a vulnerability is discovered, the system automatically generates a hardening report, which is then approved by the bank's security, business, and operations departments before being rolled out in a phased manner. The implementation results in discrepancies between the system's records and actual data being automatically detected and alerted before user complaints. Any single point of attack yields only invalid fragments, preventing simultaneous modification of both the display layer and the actual data layer. The audit black box records all query and modification operations, meeting the audit retention requirements of the China Banking and Insurance Regulatory Commission.

[0038] Example 7: The polymer material formula is kept confidential for a long time to prevent researchers from memorizing or photographing it and leaking the information.

[0039] A polymer materials company possesses the core formula and synthesis process for a novel polymer, which is a core trade secret. R&D personnel, production managers, and quality control staff frequently need to access the formula parameters, but the company cannot prevent leaks through memorization or mobile phone photography. After deploying this invention's system, the core formula data is stored in fragments within a confidential isolation layer, not displayed completely on any terminal. When R&D personnel view the formula, the human-machine interface exhibits the following characteristics: First, critical operations, such as viewing the formula, modifying parameters, and exporting reports, maintain stable semantics and spatial location, ensuring normal work efficiency. Second, specific proportions, such as 35.2% for component A, undergo dynamic changes in non-critical attributes each time the formula is viewed, such as random changes in font, color, and background, but the numerical value itself remains accurate. Third, an invisible digital watermark is overlaid on the screen, containing employee identification, timestamps, and device serial numbers, allowing traceability of any screen capture. Fourth, the anti-leakage module runs continuously in the background; if multiple consecutive screenshots or abnormally high viewing frequency are detected, an alarm is automatically triggered and the account is temporarily locked. Companies can choose to disclose the core structure of their patents while protecting the specific synthesis processes as trade secrets. Under this system, even if R&D personnel leave the company, the fragmented formula memories they retain cannot be pieced together completely due to fragmented storage and dynamic obfuscation. Any photographic activity can be traced back to the specific person and time. The long-term effect is that no formula leaks have occurred due to personnel memory or photographic recordings. Companies can continue R&D, production, and quality control normally. The audit black box records all formula access activities, meeting internal audit and compliance requirements. Industrial applicability

[0040] This invention can be used in scenarios requiring high-level security protection, such as financial transaction systems, military command systems, enterprise intellectual property protection systems, government confidential information systems, and critical infrastructure control systems, and has good industrial applicability.

Claims

1. A layered security system resistant to quantum computing, side-channel attacks, and insider filming, and capable of memory reconstruction, characterized in that: include: It includes an access adaptation layer, a confidentiality isolation layer, a human-machine display layer, an anti-side channel module, an anti-quantum module, an anti-leakage module, a self-iteration module, and a fault rollback module.

2. The access adaptation layer is used to bypass existing business systems without blocking the original business processes.

3. The confidential isolation layer is used to divide real data into multiple fragments, so that no single fragment can restore the complete information, and to encrypt each fragment independently and perform instantaneous calculations, while writing the calculation process into an unalterable audit record.

4. The human-machine display layer maintains the semantics and spatial position of key operations, dynamically changes non-key attributes, and overlays traceable screen markers.

5. The anti-side channel module is used to hide the true computational characteristics through one or more of the following methods: pseudo-operation, timing disturbance, and power consumption balancing.

6. The quantum-resistant module adopts a quantum-resistant cryptographic scheme, including a true random entropy source, one-time pad, or post-quantum cryptography algorithm.

7. The anti-leakage module is used to prevent the real data from being recovered from screen captures or personal memory.

8. The self-iterative module is used to periodically simulate attacks to detect vulnerabilities, and hardening is carried out after manual approval after the vulnerability is confirmed.

9. The fault rollback module is used to automatically switch to the original business system when the security layer is abnormal, and the switching time meets the business continuity requirements.

10. The system according to claim 1, characterized in that, The confidential isolation layer contains 16 or more data fragments, each of which is independently encrypted and is only momentarily reassembled within a trusted execution environment or hardware security module.

11. The system according to claim 1, characterized in that, In the human-machine display layer, key operations include confirmation, cancellation, transfer, launch, and authorization, and their screen coordinates and interaction logic remain consistent across different sessions.

12. The system according to claim 1, characterized in that, The anti-leakage module includes a dynamic screen watermark containing user identity and timestamp, color decoration rotation for non-critical attributes, and random noise patterns in the background.

13. The system according to claim 1, characterized in that, The pseudo-operation injection ratio of the anti-side channel module is 1:1 to 1:5, the timing randomization range is ±30%, and the power consumption flattening is achieved through virtual load.

14. The system according to claim 1, characterized in that, The self-iterative module simulates attack types including traditional network attacks, side-channel attacks, quantum attack simulations, social engineering and insider behavior simulations, and fault injection attacks.

15. The system according to claim 1, characterized in that, The hardening strategy of the self-iterative module must be jointly approved by the security, business, and operation and maintenance parties, and shall be distributed in a gray-scale manner, i.e., 5%, 20%, and 100%, and shall not be automatically deployed to the full extent.

16. The system according to claim 1, characterized in that, The fault rollback module supports three levels of degradation. Level 1 degradation is automatic retry and enhanced verification when a single timeout or verification failure occurs. Level 2 degradation is shutting down a single defense module and issuing an alarm when it crashes, and the business is degraded. Level 3 degradation is automatically or manually triggering a hardware bypass switch and switching back to the original business system when the entire security layer crashes, with a switching time of less than 1 second.

17. A layered security method resistant to quantum computing, side-channel attacks, and insider filming, and capable of memory reconstruction, characterized in that, Includes the following steps: Step A: Bypass business requests through the access adaptation layer to avoid blocking the original business; Step B: Divide real data into multiple fragments in the confidentiality isolation layer, making it impossible to reconstruct complete information from any single fragment, and independently encrypt and instantaneously process each fragment, while writing it into the audit log; Step C: Maintain the semantic and spatial stability of key operations in the human-machine display layer, dynamically change non-key attributes, and overlay screen markers; Step D: Operators make decisions and confirmations based on the stable operation area; Step E: The system periodically performs self-attack simulations, and hardens the system after manual approval upon discovering vulnerabilities; Step F: When an anomaly occurs in the security layer, automatically switch back to the original business system.

18. The method according to claim 9, characterized in that, The ultimate technical effects are as follows: operators can operate normally, can be trained, and can relay the operating procedures; no single photograph or memory can reconstruct the complete and true data; and the requirements for audit and regulatory retention are met. Security layer failures do not affect business continuity and availability.