Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

18 results about "Cloud computing security" patented technology

Cloud computing security or, more simply, cloud security refers to a broad set of policies, technologies, applications, and controls utilized to protect virtualized IP, data, applications, services, and the associated infrastructure of cloud computing. It is a sub-domain of computer security, network security, and, more broadly, information security.

A method and system for verifying the trusted state of a virtual machine based on TIPU

PendingCN122365514AMemory addressTerm memory
This invention relates to the intersection of cloud computing security, trusted computing, and hardware acceleration technologies, and discloses a virtual machine trusted state verification method and system based on TIPU. The method includes: configuring a measurement task on the host side of the TIPU, the measurement task containing the memory address information of the target virtual machine and its corresponding expected hash value; the TIPU directly reading the memory data of the target virtual machine via DMA based on the memory address information to generate an actual hash value; the TIPU comparing the actual hash value with the expected hash value to determine whether the target virtual machine is in a trusted state; when the virtual machine is determined to be in an untrusted state, the TIPU calls a built-in root of trust to sign the verification result and generate a remote proof report. This invention obtains the mapping table from the client's physical address to the host's physical address through the virtualization platform interface via a host agent and pre-configures it to the TIPU. The TIPU only accesses the target virtual machine's memory, achieving virtual machine context awareness and effectively avoiding cross-virtual machine information leakage.
Owner:TIANFU JIANGXI LAB

Cloud host security reinforcement method and device, storage medium and electronic equipment

The present disclosure provides a cloud host security reinforcement method and device, a storage medium and an electronic device; and relates to the technical field of cloud computing security. The method comprises the following steps: obtaining application information of a cloud host resource, and publishing a to-be-reinforced cloud host according to the application information; scanning the to-be-reinforced cloud host to obtain a security scanning report of the to-be-reinforced cloud host; reinforcing the to-be-reinforced cloud host according to the application information and the security scanning report to obtain a security reinforcement result; verifying the security reinforcement result and outputting corresponding reinforced cloud host resources. In the process of starting the cloud host, the cloud host is scanned, reinforced, verified and delivered, so that the allocation and security reinforcement of the cloud host are integrated, the security of the cloud host is improved, and the security reinforcement efficiency of the cloud host is improved.
Owner:CHINA TELECOM CORP LTD

Cloud environment intelligent identity authentication cross-domain interfacing method and system

This invention relates to the fields of cloud computing and identity authentication security technology, and discloses a method and system for cross-domain intelligent identity authentication in a cloud environment. The method includes: collecting and preprocessing heterogeneous identity data from multiple cloud platforms to obtain a standardized identity dataset; constructing a unified identity semantic model based on the standardized identity dataset and generating feature embedding vectors; performing identity mapping transformation on the feature embedding vectors using a deep neural network to obtain mapped identity feature vectors; performing multi-factor adaptive trust assessment by combining the mapped identity feature vectors with real-time behavioral data to obtain dynamic trust assessment results; generating an adaptive security token based on the dynamic trust assessment results; and converting the adaptive security token into the protocol format required by the target system. This invention can solve the problems of heterogeneity and dynamic trust assessment in cross-domain identity authentication in a cloud environment, providing an effective solution for cloud computing security.
Owner:ZHEJIANG HULUWA NETWORK GRP CO LTD

Container data safe use method and system based on decentralized identity

The invention discloses a container data safe use method and system based on a decentralized identity, and relates to the technical field of cloud computing security, and the method comprises the steps: generating a decentralized identity bound with a container life cycle; initiating a data use request based on the decentralized identity; identity verification is executed, and data resources are distributed based on dynamic authorization and encryption of a runtime context; and decrypting and using the data resources in the protected memory of the container. According to the method, the decentralized identity is generated on the basis of the identifier during dynamic operation of the container, and an access control mechanism in the memory is combined, so that the technical defects that the identity is unhooked from the life cycle and the plaintext is exposed in the memory during operation of the data in an existing container data security scheme are overcome.
Owner:PANOVASIC TECHNOLOGY CO LTD

Device and method for realizing bare metal console with endogenous safety capability

PendingCN121567370ASecuring communicationBare metalPolicy decision
The invention relates to the technical field of cloud computing security, in particular to a bare metal console implementation device and method with endogenous security capability, and the device comprises a user side agent module which is used for receiving a bare metal VNC console access request initiated by a user and distributing the request to three heterogeneous service agent nodes; operating systems and CPU (Central Processing Unit) frameworks of the three service agent nodes are different from one another, and service agent components corresponding to different bare metal VNC console access modes are respectively deployed on the nodes; the feedback control module is used for collecting running state data of the service agent node, generating judgment parameters and sending the judgment parameters to the strategy judgment module, and is used for executing release or link reset operation according to a judgment result of the strategy judgment module; and the strategy judgment module is used for carrying out consistency judgment on output results of the three service agent nodes based on the judgment parameters and feeding back a judgment result to the feedback control module. According to the invention, high security and high availability of bare metal VNC console access are realized.
Owner:SONGSHAN LAB

An outsourcing decryption method for protecting revocable user attributes based on cloud environment data

The application discloses an outsourcing decryption method for revoking user attributes based on cloud environment data protection and belongs to the technical field of cloud computing security. The application comprises an initialization algorithm, an encryption algorithm, a key generation algorithm, an outsourcing decryption algorithm and an attribute revocation algorithm. The method of the application is based on a cloud environment, public parameters are composed of a fixed number of group elements, there is no limitation on an attribute set used for encryption, user revocation can be performed at each attribute level instead of at a system level, and more fine-grained user access control is realized. Moreover, user information is not leaked in judgment of whether a user is revoked and outsourcing decryption. The scheme is proved to be safe under the complexity assumption of a composite order group. Through comparative analysis on the performance of similar schemes, the result shows that the scheme is more efficient and more flexible in the scene of user management in a cloud environment.
Owner:GANNAN NORMAL UNIV

A trajectory data-based outsourcing cloud environment privacy protection infection mode mining method

The application belongs to the field of cloud computing security, and discloses a trajectory data-based outsourcing cloud environment privacy protection infection mode mining method, which is divided into two stages: the first stage: trajectory data preprocessing, encryption and outsourcing, first, the data owner pre-processes the trajectory data set to be uploaded, generates a corresponding encoding matrix for the trajectory data of each object, then generates a secure index matrix for the encoding matrix through a strong anti-collision one-way hash function, and finally uploads the encrypted trajectory data and the generated secure index matrix to a cloud server, and shares the key with authorized users; the second stage: a privacy protection infection mode mining method, first, the authorized user sends the infected object number to the cloud server, the cloud server performs infection mode mining after receiving the infected object number, and returns the mining result to the authorized user. The application can ensure high accuracy of the mining result, improve the mining efficiency, and is easy to implement.
Owner:NANJING UNIV OF POSTS & TELECOMM

AI based Cloud Computer security Detection device

ActiveGB6525662SAlgorithmCloud computing security
Owner:DEVA RAJU GANTAKORA

Network security service function chain arrangement method and device of data processing unit, computer equipment, storage medium and program product

The invention relates to the technical field of cloud computing security services, and provides a network security service function chain arrangement method and device of a data processing unit, computer equipment, a storage medium and a program product. The method comprises the steps of obtaining a security service request of a to-be-deployed network security service function chain of a target service flow according to a network security demand of a type to which the target service flow belongs and a security service function of a data processing unit; obtaining a function chain deployment optimization objective function according to the multi-class resource load degree for arranging a to-be-deployed network security service function chain in the security service request at the deployment completion moment and the average utilization rate of acceleration subunits in the data processing unit at the deployment completion moment; and under the constraint of the multi-constraint condition, according to the to-be-deployed network security service function chain, obtaining a network security service function chain target arrangement scheme which enables the function chain deployment optimization target function to reach a preset optimization condition. By adopting the method, waste of resources and power consumption can be reduced.
Owner:SOUTHERN POWER GRID DIGITAL GRID RESEARCH INSTITUTE CO LTD

A Reinforcement Learning-Based Adaptive Policy Generation Method and System for Heterogeneous Resource Scheduling

This invention relates to a method and system for generating adaptive strategies for heterogeneous resource scheduling based on reinforcement learning, belonging to the field of cloud computing security. The system comprises a container module, a CVSS database exploitation module, a state mapping module, and a defense environment. The method includes: acquiring all container instances in the current cloud environment and storing them in a container pool; recording the heterogeneous attributes and replica count of each type of container instance; calculating the vulnerability exploitation difficulty and multi-dimensional heterogeneity indicators of the current container pool; and using a reinforcement learning model to determine the defense strategy, inputting the current container pool state into the model, deciding on the defense strategy, and calculating the reward value by weighted summation of the vulnerability exploitation difficulty and heterogeneity indicators of the container pool. This invention comprehensively considers the multi-dimensional heterogeneous attributes and real-time state information of containers, adaptively selecting the optimal defense strategy to reduce defense costs and improve the system's real-time response capability and defense effectiveness.
Owner:韩道岐

Cloud management platform authentication encryption method based on national secret

The invention discloses a cloud management platform authentication and encryption method based on national secret, particularly relates to the field of cloud computing security authentication, and is used for solving the problems of service interruption and compliance auditing caused by midway drift of authentication and encryption attributes in a link in a multi-cloud multi-tenant environment. Generating a negotiation fingerprint signature and a session policy identifier through the portal agent, and binding a session; the gateway writes a metadata head and sets read-only attribute transfer elements; performing signature verification matching by the micro-service entrance to generate session verification token cache verification; the strategy engine calculates a stability coefficient according to the session strategy identifier to execute a release rerouting or rejection decision; the platform summarizes verification results to update compatibility capability and synchronize with routing strategy issuing; the security semantic consistency of the whole link is ensured, the platform compatibility and the emergency response efficiency are improved, and the method is suitable for a state-password compatible cloud management scene.
Owner:BEIJING BOANTE INFORMATION TECH DEV CO

Cross-architecture unified deployment method for network security drilling scene

The invention provides a cross-architecture unified deployment method for a network security drill scene, belongs to the technical field of cloud computing security, and can at least partially solve the problems of low deployment efficiency, error proneness and complex maintenance caused by manual adaptation of different architectures when a drill scene is deployed in a hybrid architecture resource pool. The method comprises the following steps: acquiring a deployment template containing a mirror image logic identifier; determining a processor architecture type of a target computing node deployed by the virtual machine; based on the mirror image logic identifier and the processor architecture type, querying a mirror image warehouse to obtain a target mirror image identifier matched with the mirror image warehouse; and using the obtained target mirror image identifier to replace the mirror image logic identifier in the deployment template to generate an executable deployment list. According to the method, the mirror image logic identifier and the dynamic mapping mechanism are introduced, so that'one-time writing and cross-framework automatic deployment 'of the drill scene is realized, the user operation is simplified, and the deployment failure risk caused by framework mismatching is eliminated.
Owner:HUANENG POWER INT INC +1

A cross-modal retrieval method supporting authorized access

The application relates to a cross-modal retrieval method supporting authorized access, and relates to the field of cloud computing security. A vector inner product encryption scheme FBIPE realizes the privacy of data and query requests, and an authorized key tree guarantees low-interactive authorized access. First, text / images in a database / query request are converted into text / image vectors by using a cross-modal hashing technology, and all the vectors are encrypted by using the FBIPE. Then, an independent key is generated for each vector in the database by using the authorized key tree, and the corresponding text / image vector ciphertext is re-encrypted by using the key. Finally, in the cross-modal retrieval process, authorized access is completed because the authorized key corresponding to unauthorized access data cannot be restored. The whole authorized cross-modal retrieval method is based on lightweight cryptography primitives, and the designed authorized key tree can realize low-interactive authorization, and the overall operation efficiency is high.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Multi-keyword query method based on vector inner product encryption

The invention provides a multi-keyword query method based on vector inner product encryption, and relates to the field of cloud computing security. The core idea of the invention is to ensure that each query user has a unique key through a re-encryption technology, and at the same time, the addition secret is shared and fused into a double-cloud framework. On the basis of the EIPE, each query user can encrypt a query keyword vector by using an independent key, meanwhile, the file keyword vector can be safely stored through secret sharing, and finally, multi-keyword query is realized through safe inner product calculation. According to the method, the privacy of the file keyword and the query keyword can be guaranteed, meanwhile, it can be guaranteed that each query user has different secret keys, and the method is more suitable for the real environment; according to the method, it is ensured that each query user has different secret keys through a re-encryption thought, and meanwhile, query keyword vector privacy is ensured based on addition secret sharing; the method is based on the lightweight encrypted primitive, and the query efficiency can be effectively improved.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

A multi-keyword query method based on vector inner product encryption

The application provides a multi-keyword query method based on vector inner product encryption, and relates to the field of cloud computing security.The core idea of the application is to ensure that each query user has a unique key through re-encryption technology, and to integrate additive secret sharing into a double cloud framework.Based on EIPE, each query user can encrypt the query keyword vector with an independent key, and the file keyword vector can be securely stored through secret sharing.Finally, multi-keyword query is realized through secure inner product calculation.This method can guarantee the privacy of file keywords and query keywords, and ensure that each query user has a different key, making it more suitable for real-world environments.The method ensures that each query user has a different key through re-encryption, and ensures the privacy of the query keyword vector based on additive secret sharing.The method is based on lightweight encryption primitives, which can effectively improve query efficiency.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA