Remote bid opening unattended system and working method

By shielding the CPU cache and monitoring memory and hard drive through a remote unattended bidding system, the problem of data leakage during remote unattended bidding is solved, and the security and integrity of data transmission are achieved.

CN121786859APending Publication Date: 2026-04-03JIANGSU E-TRADE INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-29
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

During remote unmanned bidding, data is easily stolen and leaked because it enters the CPU cache during transmission.

Method used

The system employs a remote, unattended bidding process. By disabling the CPU cache on the lower-level machine and using a data security module to monitor memory and hard disk, combined with the processor module to identify abnormal programs, it ensures secure data transmission.

Benefits of technology

This technology prevents data from entering the CPU cache during data transmission, thus preventing data leakage and ensuring the security and integrity of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121786859A_ABST
    Figure CN121786859A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of computing, and particularly relates to data protection, in particular to a remote bid opening unattended system and a working method.According to the remote bid opening unattended system, after communication is established between an upper computer and a lower computer, the lower computer shields a cache of a CPU and monitors an internal memory and a hard disk through a data safety module, and the data safety is improved; the method comprises the following steps that: a lower computer sends an encrypted bidding document to a processor module, whether an abnormal program exists or not is judged through the processor module, when the abnormal program does not exist, the lower computer sends a safety signal to the upper computer, the lower computer sends secret key data to the upper computer, and the upper computer decrypts the encrypted bidding document according to the secret key data, so that the cache of a CPU is shielded, and the security of the bidding document is improved. The data is prevented from entering the cache of the CPU in the data transmission process, and data leakage is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of computing technology, specifically relating to data protection, and more particularly to a remote unattended bidding system and its working method. Background Technology

[0002] Memory side-channel attacks exploit the physical characteristics of hardware such as CPU cache, memory bus, and registers (e.g., access latency, power consumption, electromagnetic radiation) to steal intermediate values ​​of sensitive data within the sandbox during computation (e.g., floating-point cache traces for user debt-to-income ratios). Traditional sandboxes (such as Docker containers and virtual machines) are vulnerable to such attacks. In remote, unmanned bidding processes, data exchange is required between the host and slave computers. For example, the slave computer needs to send a key to the host computer, which then uses the key to decrypt the encrypted bid documents. This data is confidential, but because it enters the CPU cache during data exchange, it is easily stolen, leading to data leakage.

[0003] Therefore, since data enters the CPU cache during data transmission, making it easy for data to be stolen and causing data leakage, there is a technical problem that requires the design of a remote unattended bidding system and its working method.

[0004] It should be noted that the information disclosed in this background section is only for understanding the background technology of this application concept, and therefore, the above description is not considered to constitute prior art information. Summary of the Invention

[0005] This disclosure provides at least one remote unattended bidding system and its working method.

[0006] In a first aspect, embodiments of this disclosure provide a remote unattended bidding system, including: The host computer stores the encrypted tender documents; The lower-level machine includes a data security module electrically connected to the processor module, the data security module being configured to monitor the memory and hard disk in the lower-level machine; After the host computer establishes communication with the slave computer, the slave computer is configured to disable the CPU cache and monitor the memory and hard disk through the data security module. Then, the processor module determines whether there are any abnormal programs. When it is determined that there are no abnormal programs, the slave computer sends a security signal to the host computer and sends key data to the host computer. The host computer decrypts the encrypted tender document according to the key data.

[0007] In one optional implementation, after determining that there are no abnormal programs, the processor module performs verification login between the host computer and the slave computer. After the CA certificate and / or face recognition and / or SMS verification code and / or dynamic question and answer are verified, the login is successful, and identity authentication and remote check-in are completed.

[0008] In one optional implementation, after identity authentication and remote check-in, the lower-level machine sends key data to the upper-level machine, i.e. The lower-level machine randomly splits the key data into several sub-data packets, then adds random data to each sub-data packet to make each sub-data packet the same size, and sends the sub-data packet size to the upper-level machine. The upper-level machine generates a virtual upper-level machine with the same size as the storage space of the lower-level machine. The storage space of the virtual upper-level machine is filled with padding data. The virtual upper-level machine deletes padding data of the corresponding size in its storage space according to the data packet size to form a space with the same size as a sub-data packet. Then the lower-level machine sends a sub-data packet to the virtual upper-level machine for storage until all sub-data packets have been sent to the virtual upper-level machine. The host computer is configured to delete random data from the sub-data packets after receiving all sub-data packets sent by the slave computer, in order to obtain key data, and then decrypt the encrypted tender document based on the key data.

[0009] In one optional implementation, the host computer stores backup key data corresponding to the encrypted tender document. When the key data cannot decrypt the encrypted tender document, the backup key data is used to decrypt the encrypted tender document. If the backup key data still cannot decrypt the tender document, the host computer sends a decryption failure message to the slave computer. The host computer is configured to determine that it is abnormal if the number of encrypted tender documents that fail to decrypt exceeds a preset number.

[0010] In one optional implementation, the host computer is configured to extract the bidding information from all encrypted bids after decrypting them, and then display the bidding information of each bid to complete the bid opening. The bidding information includes: bidder's name, price, construction period, and quality standards.

[0011] In one optional implementation, the host computer communicates with a monitoring terminal to monitor the bidding process.

[0012] In one optional implementation, after the lower-level machine establishes communication with the upper-level machine, the processor module disables the CPU cache in the lower-level machine and directly stores the random data sent by the upper-level machine in memory.

[0013] In one optional implementation, the data security module includes: a hard disk monitoring submodule and a memory monitoring submodule electrically connected to the processor module; The memory monitoring submodule is configured to monitor the remaining capacity of memory during the process of storing random data in memory; When the remaining memory capacity is exhausted, the lower-level processor module sends a stop signal to the upper-level computer, and the upper-level computer stops sending data to the lower-level computer. The hard disk monitoring submodule is configured to monitor whether the data in the hard disk changes after the host computer stops sending random data.

[0014] In one optional implementation, the processor module is configured such that after the host computer stops sending random data, if the hard disk monitoring submodule determines that there is a data change on the hard disk, the processor module determines that there is an abnormal program; otherwise, it determines that there is no abnormal program. Furthermore, when the data change exceeds a preset threshold range, the processor module determines that the abnormal program is on the hard disk, and when the data change is within the preset threshold range, it determines that the abnormal program is in memory.

[0015] Secondly, this disclosure also provides a working method for the above-described remote unattended bidding system, comprising: After the host computer and the slave computer establish communication, the slave computer disables the CPU cache and monitors the memory and hard disk through the data security module. Then, it uses the processor module to determine if there are any abnormal programs. When no abnormal programs are found, the slave computer sends a security signal to the host computer and sends key data to the host computer. The host computer decrypts the encrypted tender document based on the key data.

[0016] The beneficial effects of this invention are that, after establishing communication between the host computer and the slave computer, the slave computer disables the CPU cache and monitors the memory and hard disk through a data security module. The processor module then determines if there are any abnormal programs. If no abnormal programs are detected, the slave computer sends a security signal to the host computer and sends key data. The host computer then decrypts the encrypted bid document based on the key data. This effectively disables the CPU cache, preventing data from entering the CPU cache during data transmission and thus avoiding data leakage.

[0017] Other features and advantages of the invention will be set forth in the following description, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention are realized and obtained through the structures particularly pointed out in the description and the drawings.

[0018] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, preferred embodiments are described in detail below with reference to the accompanying drawings. Attached Figure Description

[0019] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0020] Figure 1 A flowchart illustrating the workflow of a remote unattended bidding system provided in this embodiment of the present disclosure; Figure 2 A schematic diagram of a remote unattended bidding system provided in this embodiment of the present disclosure; Figure 3 This is a security verification flowchart provided for an embodiment of the present disclosure. Detailed Implementation

[0021] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0022] As used herein, the phrases “in one embodiment,” “according to one embodiment,” “in some embodiments,” etc., generally refer to the fact that a particular feature, structure, or characteristic following the phrase can be included in at least one embodiment of this disclosure. Therefore, a particular feature, structure, or characteristic can be included in more than one embodiment of this disclosure, such that these phrases do not necessarily refer to the same embodiment. As used herein, the terms “example,” “exemplary,” etc., are used to “serve as an example, instance, or illustration.” Any implementation, aspect, or design described herein as “example” or “exemplary” is not necessarily to be construed as preferred or superior to other implementations, aspects, or designs. Rather, the use of the terms “example,” “exemplary,” etc., is intended to present concepts in a specific manner.

[0023] Memory side-channel attacks exploit the physical characteristics of hardware such as CPU cache, memory bus, and registers (e.g., access latency, power consumption, electromagnetic radiation) to steal intermediate values ​​of sensitive data within the sandbox during computation (e.g., floating-point cache traces for user debt-to-income ratios). Traditional sandboxes (such as Docker containers and virtual machines) are vulnerable to such attacks. In remote, unmanned bidding processes, data exchange is required between the host and slave computers. For example, the slave computer needs to send a key to the host computer, which then uses the key to decrypt the encrypted bid documents. This data is confidential, but because it enters the CPU cache during data exchange, it is easily stolen, leading to data leakage.

[0024] It should be noted that similar labels and letters in the following figures indicate similar items. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.

[0025] The following detailed description of some embodiments of the present invention is provided in conjunction with the accompanying drawings. Unless otherwise specified, the following embodiments and features can be combined with each other.

[0026] like Figure 1 and Figure 2 As shown, at least one disclosed embodiment provides a remote unattended bidding system, comprising: a host computer storing encrypted bid documents; and a slave computer, wherein a data security module electrically connected to a processor module is provided, the data security module being configured to monitor the memory and hard disk in the slave computer; after the host computer and the slave computer establish communication, the slave computer is configured to disable the CPU cache and monitor the memory and hard disk through the data security module, and then determine whether there are any abnormal programs through the processor module. When it is determined that there are no abnormal programs, the slave computer sends a security signal to the host computer and sends key data to the host computer. The host computer decrypts the encrypted bid documents according to the key data, thereby disabling the CPU cache, preventing data from entering the CPU cache during data transmission, and preventing data leakage.

[0027] In this embodiment, the host computer can be a server or the like.

[0028] In one optional implementation, after determining that there are no abnormal programs, the processor module performs verification login between the host computer and the slave computer. After the CA certificate and / or face recognition and / or SMS verification code and / or dynamic question and answer are verified, the login is successful, and identity authentication and remote check-in are completed.

[0029] like Figure 3As shown, in one optional implementation, after identity authentication and remote check-in, the lower-level machine sends key data to the upper-level machine. That is, the lower-level machine randomly splits the key data into several sub-data packets, and then adds random data to each sub-data packet to make the sub-data packets the same size. The size of the sub-data packets is then sent to the upper-level machine. The upper-level machine generates a virtual upper-level machine with the same size as the storage space of the lower-level machine (specifically, the space of the running memory). The storage space of the virtual upper-level machine is filled with padding data. The virtual upper-level machine deletes padding data of the corresponding size in its storage space according to the size of the data packets to form a space with the same size as a sub-data packet. Then, the lower-level machine sends a sub-data packet to the virtual upper-level machine for storage until all sub-data packets are sent to the virtual upper-level machine.

[0030] In this embodiment, the host computer generates a virtual host computer with the same storage space as the slave computer during execution, allowing the slave computer to directly send data packets to replace random data in the virtual host computer, ensuring fast and secure data transmission.

[0031] In this embodiment, each time a portion of the fill data is deleted in the virtual host computer, space equal to the size of a sub-data packet is freed up. At this time, the slave computer sends a sub-data packet to the virtual host computer for storage. This process is repeated until all sub-data packets are sent to the host computer for storage.

[0032] In one optional implementation, the host computer is configured to delete random data from the sub-data packets after receiving all sub-data packets sent by the slave computer, in order to obtain key data, and to decrypt the encrypted tender document based on the key data.

[0033] In one optional implementation, the host computer stores backup key data corresponding to the encrypted tender document. When the key data cannot decrypt the encrypted tender document, the backup key data is used to decrypt the encrypted tender document. If the backup key data still cannot decrypt the tender document, the host computer sends a decryption failure message to the slave computer.

[0034] In one optional implementation, the host computer is configured to determine that it is abnormal if the number of encrypted tender documents that fail to decrypt exceeds a preset number.

[0035] In one optional implementation, the host computer is configured to extract the bidding information from all encrypted bids after decrypting them, and then display the bidding information of each bid to complete the bid opening; the bidding information includes: bidder name, price, construction period and quality standards, etc.

[0036] In one optional implementation, the host computer communicates with a monitoring terminal to monitor the bidding process.

[0037] In one optional implementation, after the lower-level machine establishes communication with the upper-level machine, the processor module disables the CPU cache in the lower-level machine and directly stores the random data sent by the upper-level machine in memory.

[0038] In this embodiment, the CPU cache is the CPU's L1, L2, and L3 caches. After the cache is disabled, the processing speed of the lower-level machine slows down. If there is an abnormal program at this time, the processing speed of the abnormal program will also slow down synchronously. The disabled program in the abnormal program cannot be executed in time, which makes it easier for the abnormal program to be exposed.

[0039] In this embodiment, the host computer and the slave computer can communicate wirelessly.

[0040] In one optional implementation, the data security module includes: a hard disk monitoring submodule and a memory monitoring submodule electrically connected to the processor module; the memory monitoring submodule is configured to monitor the remaining capacity of the memory during the storage of random data in the memory; when the remaining capacity of the memory is exhausted, the processor module of the lower-level machine sends a stop signal to the upper-level machine, and the upper-level machine stops sending random data to the lower-level machine; the hard disk monitoring submodule is configured to monitor whether the data in the hard disk changes after the upper-level machine stops sending random data.

[0041] In this embodiment, during the process of the host computer sending random data to the slave computer, the memory monitoring submodule continuously monitors the remaining capacity of the slave computer's memory until the memory is full. Then, the slave computer sends a stop signal to the host computer, and the host computer stops sending random data.

[0042] In this embodiment, if there is already an abnormal program in the memory of the lower-level machine, the upper-level machine will no longer send random data after the memory is filled with random data. At this time, the abnormal program in the memory will cause a small change in the amount of data on the hard disk.

[0043] In this embodiment, if an abnormal program is entering the lower-level machine and the memory is already full, the abnormal program will enter the hard disk, causing a significant change in the amount of data on the hard disk.

[0044] In one optional implementation, the processor module is configured such that after the host computer stops sending random data, if the hard disk monitoring submodule determines that there is a data change on the hard disk, the processor module determines that there is an abnormal program; otherwise, it determines that there is no abnormal program. Furthermore, when the data change exceeds a preset threshold range, the processor module determines that the abnormal program is on the hard disk, and when the data change is within the preset threshold range, it determines that the abnormal program is in memory.

[0045] In this embodiment, when the processor module of the lower-level machine determines that there is an abnormal program, it can issue an alarm to remind the user that the environment is abnormal.

[0046] In this embodiment, after the host computer and the slave computer establish communication, the host computer begins to perform security verification on the slave computer. After the slave computer security verification is successful, the user can log in and sign in through the slave computer. The login method can include, but is not limited to, CA certificate, face recognition, SMS verification code, dynamic Q&A, etc. The host computer can record the sign-in time, IP address, device information, and upload it to the blockchain.

[0047] In this embodiment, communication between the host computer and the slave computer can be established 30 minutes before the bidding starts, so that each user can sign in and log in.

[0048] In this embodiment, the user has uploaded the encrypted bid documents to the server. If multiple bid documents fail to decrypt before the bid opening, it is determined that there may be a problem with the program on the server, and the bid opening time is delayed.

[0049] In this embodiment, the host computer can contact the corresponding user via SMS, telephone, or other means when decryption fails.

[0050] In this embodiment, after all bid documents are successfully decrypted, the host computer can automatically extract bidding information such as the name of the winning bidder, the price, the construction period, and the quality standards from each bid document, and display it through web pages and other means for all users (bidders) to view.

[0051] In this embodiment, the combination of the host computer and the slave computer enables the entire bidding process to be completed without manual operation. The host computer can communicate with the monitoring terminal of the supervisory personnel, who can remotely monitor the entire bidding process through the monitoring terminal. Once the supervisory personnel find any abnormality, they can remotely stop the bidding. The monitoring terminal records the entire operation log, supporting audit traceability.

[0052] In this embodiment, all operations require electronic signature confirmation, complying with the Electronic Signature Law. The National Time Service Center's trusted timestamp is used to prove the accuracy of the bid opening time. Key data (bid document hash, decryption authorization record, and bid opening information) are stored on the blockchain for evidence, and the bid opening record is automatically generated and stamped with an electronic seal.

[0053] At least one other disclosed embodiment also provides a method of operating the above-described remote unattended bidding system, including: After the host computer and the slave computer establish communication, the slave computer disables the CPU cache and monitors the memory and hard disk through the data security module. Then, it uses the processor module to determine if there are any abnormal programs. When no abnormal programs are found, the slave computer sends a security signal to the host computer and sends key data to the host computer. The host computer decrypts the encrypted tender document based on the key data.

[0054] In summary, this remote unattended bidding system, after establishing communication between the host computer and the slave computer, allows the slave computer to disable the CPU cache and monitor the memory and hard drive through a data security module. The processor module then checks for any abnormal programs. If no abnormal programs are detected, the slave computer sends a security signal and key data to the host computer. The host computer then decrypts the encrypted bid document using the key data. This system effectively disables the CPU cache, preventing data from entering the CPU cache during data transmission and thus avoiding data leakage.

[0055] Based on the above-described preferred embodiments of the present invention, and through the foregoing description, those skilled in the art can make various changes and modifications without departing from the inventive concept. The technical scope of this invention is not limited to the contents of the specification, but must be determined according to the scope of the claims.

Claims

1. A remote unattended bidding system, characterized in that, include: The host computer stores the encrypted tender documents; The lower-level machine includes a data security module electrically connected to the processor module, the data security module being configured to monitor the memory and hard disk in the lower-level machine; After the host computer establishes communication with the slave computer, the slave computer is configured to disable the CPU cache and monitor the memory and hard disk through the data security module. Then, the processor module determines whether there are any abnormal programs. When it is determined that there are no abnormal programs, the slave computer sends a security signal to the host computer and sends key data to the host computer. The host computer decrypts the encrypted tender document according to the key data.

2. The remote unattended bidding system as described in claim 1, characterized in that, After determining that there are no abnormal programs, the processor module performs verification login between the host computer and the slave computer. After the CA certificate and / or face recognition and / or SMS verification code and / or dynamic question and answer are verified, the login is successful, and identity authentication and remote check-in are completed.

3. The remote unattended bidding system as described in claim 2, characterized in that, After identity authentication and remote check-in, the lower-level machine sends key data to the upper-level machine, i.e. The lower-level machine randomly splits the key data into several sub-data packets, then adds random data to each sub-data packet to make each sub-data packet the same size, and sends the sub-data packet size to the upper-level machine. The upper-level machine generates a virtual upper-level machine with the same size as the storage space of the lower-level machine. The storage space of the virtual upper-level machine is filled with padding data. The virtual upper-level machine deletes padding data of the corresponding size in its storage space according to the data packet size to form a space with the same size as a sub-data packet. Then the lower-level machine sends a sub-data packet to the virtual upper-level machine for storage until all sub-data packets have been sent to the virtual upper-level machine. The host computer is configured to delete random data from the sub-data packets after receiving all sub-data packets sent by the slave computer, in order to obtain key data, and then decrypt the encrypted tender document based on the key data.

4. The remote unattended bidding system as described in claim 3, characterized in that, The host computer stores backup key data corresponding to the encrypted tender document. When the key data cannot decrypt the encrypted tender document, the backup key data is used to decrypt the encrypted tender document. If the backup key data still cannot decrypt the tender document, the host computer sends a decryption failure message to the slave computer. The host computer is configured to determine that it is abnormal if the number of encrypted tender documents that fail to decrypt exceeds a preset number.

5. The remote unattended bidding system as described in claim 4, characterized in that, The host computer is configured to decrypt all encrypted bid documents, extract the bidding information from the bid documents, display the bidding information of each bid document, and complete the bid opening. The bidding information includes: bidder's name, price, construction period, and quality standards.

6. The remote unattended bidding system as described in claim 5, characterized in that, The host computer communicates with the monitoring terminal to monitor the bidding process.

7. The remote unattended bidding system as described in claim 1, characterized in that, After establishing communication with the host computer, the processor module disables the CPU cache in the lower-level machine and directly stores the random data sent by the host computer in memory.

8. The remote unattended bidding system as described in claim 7, characterized in that, The data security module includes: a hard disk monitoring submodule and a memory monitoring submodule that are electrically connected to the processor module; The memory monitoring submodule is configured to monitor the remaining capacity of memory during the process of storing random data in memory; When the remaining memory capacity is exhausted, the lower-level processor module sends a stop signal to the upper-level computer, and the upper-level computer stops sending data to the lower-level computer. The hard disk monitoring submodule is configured to monitor whether the data in the hard disk changes after the host computer stops sending random data.

9. The remote unattended bidding system as described in claim 8, characterized in that, The processor module is configured such that after the host computer stops sending random data, if the hard disk monitoring submodule determines that there is a data change on the hard disk, the processor module determines that there is an abnormal program; otherwise, it determines that there is no abnormal program. Furthermore, when the data change exceeds a preset threshold range, the processor module determines that the abnormal program is on the hard disk; when the data change is within the preset threshold range, it determines that the abnormal program is in memory.

10. A method for operating the remote unattended bidding system as described in claim 1, characterized in that, include: After the host computer and the slave computer establish communication, the slave computer disables the CPU cache and monitors the memory and hard disk through the data security module. Then, it uses the processor module to determine if there are any abnormal programs. When no abnormal programs are found, the slave computer sends a security signal to the host computer and sends key data to the host computer. The host computer decrypts the encrypted tender document based on the key data.