Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

699 results about "Communications security" patented technology

Communications security is the discipline of preventing unauthorized interceptors from accessing telecommunications in an intelligible form, while still delivering content to the intended recipients. In the North Atlantic Treaty Organization culture, including United States Department of Defense culture, it is often referred to by the abbreviation COMSEC. The field includes cryptographic security, transmission security, emissions security and physical security of COMSEC equipment and associated keying material.

Multi-user near-field secure communication method based on stacked intelligent metasurfaces

The invention provides a multi-user near-field secure communication method based on stacked intelligent metasurfaces, and relates to the technical field of wireless communication. The method comprises the following steps: obtaining an equivalent beamforming matrix and a first-layer channel transmission matrix of an SIM according to parameters of the SIM in a base station; according to the transmission distance between the SIM and the user and the transmission distance between the SIM and the eavesdropper and the parameters of the SIM, modeling a near-field channel to obtain a near-field channel model; obtaining a data transmission rate in combination with a beamforming vector of the base station, and further determining the security and the rate; and by taking maximization of the safety and the rate as a target, constructing an optimization model and decomposing the optimization model into two sub-problems to carry out alternate iterative optimization so as to obtain an optimized equivalent beam forming matrix and an optimized beam forming vector. An SIM is introduced, the freedom degree of beam regulation and control is increased, optimization is carried out on the basis of a near-field channel model by taking maximization of safety and rate as targets, legal users and eavesdroppers are effectively distinguished, signal energy is accurately guided to the legal users, and the communication safety is improved.
Owner:ANHUI UNIV

Non-contact power supply three-level control system based on series redundancy

The invention discloses a non-contact power supply three-stage control system based on series redundancy, and belongs to the field of non-contact power supply control. Comprising a power correction module, a voltage conversion module, a full-bridge inversion module, a cooperative control module, an analysis adjustment module, a monitoring switching module, a simulation maintenance module, a communication security module, a remote interaction module, an energy efficiency optimization module and a diagnosis recording module. High conversion efficiency can be dynamically kept under different loads and working conditions, energy loss is reduced, electric energy quality is remarkably improved, damage and misoperation under abnormal working conditions are prevented, high-reliability continuous power supply is achieved, PID parameters can be dynamically adjusted or direct control quantity can be generated, the system adapts to complex and changeable operating environments, and failure rate and shutdown loss are reduced.
Owner:JIANGSU DAODA INTELLIGENT TECH CO LTD

Intelligent agent high-speed bus implementation method and system based on FPGA and dynamic smoothing technology

ActiveCN121585742ASecuring communicationCommunications securityLightweight protocol
The invention relates to the technical field of data communication, and discloses an intelligent agent high-speed bus implementation method and system based on an FPGA and a dynamic smoothing technology. The method comprises the following steps: constructing a single handshake message through a lightweight protocol, adjusting network indexes by adopting an exponential smoothing method, constructing a pipeline processing unit in an FPGA card by utilizing a VHDL, realizing key updating and encryption processing, constructing a three-layer adaptive structure connection subsystem, and optimizing algorithm parameters and resource allocation according to a running state. And a high-performance bus communication system is formed. On the premise of ensuring the communication security and reliability, the network transmission delay is remarkably reduced, and the data throughput is improved, so that the communication system can meet the requirements of emergency linkage and large data volume transmission in a scene (such as a rail transit station-level system) with a high real-time requirement.
Owner:SHANGHAI HOLLEYSOFT SYST

Method and device for dynamic secure communication between micro-services based on chaos cryptography

The invention provides an inter-micro-service dynamic secure communication method and device based on chaos cryptography. The method comprises the steps that a service provider instance registers a public key and chaos initial parameters to a service registration center; before calling, the service consumer instance acquires a public key and a chaos initial parameter of a target service provider instance from a service registration center; the service consumer instance performs key negotiation with the acquired public key by using a private key of the service consumer instance to determine a shared key; performing key derivation on the shared key and the chaotic initial parameter to generate an initial key; respectively using the initial keys to initialize the chaotic system so as to generate synchronous encryption key streams; and the two communication parties perform real-time stream encryption and decryption on the communication data between the micro-services by using the encryption key stream. The unpredictability of a chaotic system and modern cryptography can be combined, and a micro-service design mode is deeply integrated, so that a lightweight and high-security communication security mechanism which does not need to share a key in advance and can be adaptive to dynamic change of service is realized.
Owner:浪潮智能终端有限公司

Hardware-level identity authentication and end-to-end encryption near-field data interaction method and system for electric red-in secure connection terminal

The invention relates to the technical field of near-field communication security, in particular to a hardware-level identity authentication and end-to-end encryption near-field data interaction method and system for an electric red-connected terminal, and the method comprises the steps: a first electric red-connected terminal and a second electric red-connected terminal initiate pairing based on a Bluetooth secure connection pairing protocol, and negotiate to generate a long-term key through an ECDH algorithm; performing bidirectional identity verification by adopting an application layer authentication protocol; activating AES-CCM encryption by using a session key derived from a long-term key; bluetooth signal strength and a connection state are monitored in real time, and a negotiation key is automatically paired again when abnormity occurs; generating an interaction log, digitally signing the log by using a locally stored private key, and securely storing the signed log in a local secure storage area of the terminal; the digital signature of the latest log is verified, and if interaction abnormity is found, the local security module of the terminal recovers the local data to the pre-interaction state according to the last credible log record. The problem that traditional Bluetooth communication is prone to eavesdropping and tampering can be solved.
Owner:ELECTRIC POWER RES INST OF GUANGXI POWER GRID CO LTD

Hybrid intrusion detection method and system for Internet of Vehicles intersection communication security

The invention discloses a hybrid intrusion detection method and a hybrid intrusion detection system for vehicle networking intersection communication security, the system adopts a two-stage detection architecture, the first stage is a rule-based rationality check module RPCM, the module uses a predefined rule set to quickly screen received messages, and the second stage is a rule-based rationality check module RPCM; the method comprises the following steps of: performing RPCM inspection on vehicles in an intersection to eliminate obvious malicious or forged messages, sending the messages which successfully pass RPCM inspection into a DADM, dynamically modeling the vehicles in the intersection and the interaction relationship thereof into a graph structure by the DADM, and identifying more hidden and collaborative attacks by learning a complex space-time interaction mode of a vehicle group under a normal condition. And the fusion and decision module makes a final judgment on each message according to a preset fusion strategy. The method aims at operating on the vehicle-mounted unit or the road side unit with low delay, effectively dealing with specific complex V2X security threats of the signalized intersection, and providing a reliable data basis for advanced V2X application.
Owner:SOUTHEAST UNIV

Wireless instruction encryption method and system for mining intrinsic safety type equipment

The invention relates to the field of mine wireless communication security, and discloses a wireless instruction encryption method and system for mining intrinsic safety type equipment. The method comprises the following steps: collecting historical mine environment data and extracting features to obtain characterization environment description; constructing a nonlinear mapping function of the multipath propagation characteristic and the interference degree of the signal; collecting current environment data to calibrate the nonlinear mapping function to obtain a calibrated model; obtaining an encryption strength prediction value based on the current environment data in combination with the calibrated model; if the predicted value is lower than the encryption strength threshold value, key parameters are adjusted to generate optimized encryption configuration; based on the configuration, a support vector machine is adopted to classify the dynamic environment data, an interference area is divided, and an adjustment coefficient of the interference area is determined; and adjusting the encryption parameter in real time according to the coefficient to obtain an encryption strength adjustment scheme matched with the actual demand. According to the method, the problem that the wireless instruction encryption strength is not matched in a complex mine environment is solved, and the wireless instruction transmission safety and adaptability are improved.
Owner:NINGBO LONG WALL FLUID KINETIC SCI TECH

WAPI electric power communication security access method and system based on zero trust, and storage medium

The invention discloses a zero-trust-based WAPI electric power communication security access method and system and a storage medium, and the method comprises the steps: carrying out the identity authentication of a terminal device, the identity authentication comprising certificate authentication and biological feature authentication, and the biological feature authentication comprising fingerprint authentication; if the identity authentication is passed, starting a dynamic access strategy for the network based on the trust level; monitoring an identity authentication process and a dynamic access process in real time, and continuously performing risk assessment to obtain a risk assessment result; and granting dynamic access authority or directly terminating access based on an evaluation result. According to the invention, through dynamic fingerprint authentication and dynamic granting of the access authority, fine-grained access control is carried out on resources while the security is ensured, the reliability and service continuity of the system can be improved, and unauthorized access and potential network attacks can be effectively prevented.
Owner:ELECTRIC POWER RESEARCH INSTITUTE OF STATE GRID SHANDONG ELECTRIC POWER COMPANY +2

WAPI intelligent air switch, end-network-cloud security measurement and control method and system thereof, and medium

The invention discloses a wireless authentication and privacy infrastructure (WAPI) intelligent air switch, an end-network-cloud security measurement and control method and system thereof and a medium, and relates to the field of power internet of things security. A closed-loop system consisting of terminal equipment, a WAPI wireless access network, an authentication server and a cloud management platform is constructed; the authentication server verifies a negotiation session key and establishes an encrypted communication link, the terminal collects electric power parameters, encrypts and uploads the electric power parameters to the cloud, the cloud analyzes the electric power parameters and then issues a control signal, the terminal verifies and analyzes the electric power parameters through a trusted execution environment and drives an execution mechanism to operate, meanwhile, a power consumption mode is dynamically switched, and the cloud stores logs in a hash chain mode. According to the invention, through the technologies of hardware encryption, isolation execution and the like, the communication security and the equipment reliability are improved, and the requirements of high security, low power consumption and traceability of an electric power scene are met.
Owner:QUJING BUREAU OF SUPERVOLTAGE POWER TRANSMISSION CHINA SOUTHERN POWER GRID

5G RedCap application layer security test method, system and device for power business and medium

The invention relates to the technical field of 5G communication security, and discloses a 5G RedCap application layer security test method, system, device and medium for power business, comprising: constructing a power business test scene library, setting a test case for each scene, performing power business communication environment simulation, and in the application layer communication process of a terminal and a master station, establishing a test case for each scene; multiple types of security attacks are dynamically injected to obtain a detection result of the security event; and constructing a multi-dimensional safety evaluation index system, carrying out quantitative scoring and grade evaluation on the application layer safety performance of the 5G RedCap terminal in the power business scene, and generating a test report. According to the method, the test efficiency and consistency are greatly improved, a quantitative security assessment result is provided, the expandability is good, the power business protocol, the business logic and the security risk characteristics are deeply fused, and a business semantic driven security test system is constructed.
Owner:GUIZHOU POWER GRID CO LTD

Multi-unmanned aerial vehicle cooperation-oriented low-altitude Internet of Things security communication method and system

The invention discloses a multi-unmanned aerial vehicle cooperation-oriented low-altitude Internet of Things secure communication method and system, and belongs to the technical field of low-altitude Internet of Things. The method comprises the following steps: constructing a multi-unmanned aerial vehicle collaborative optimization model integrating a no-fly zone, a ground obstacle zone, communication security and energy consumption constraint; aiming at a high-dimensional non-convex characteristic of the model, a solution algorithm based on a multi-agent depth deterministic strategy gradient framework is adopted, and a local observation space containing a self state, environment information and a channel state and an action space containing speed adjustment and power adjustment are designed for each unmanned aerial vehicle agent through a centralized training decentralized execution mechanism; and a multi-target reward function is defined, so that the intelligent agent autonomously learns a cooperative strategy in a complex environment through training, and an optimized unmanned aerial vehicle track and transmitting power control instruction is jointly output. According to the invention, on the premise of strictly ensuring flight safety and physical layer safety, the sum of long-term safety communication rates of the low-altitude Internet of Things is effectively improved, and the method has good dynamic adaptability and expandability.
Owner:JIAXING UNIV

Dynamic interference cooperative communication optimization system and method for hierarchical medical scene

The invention provides a hierarchical medical scene-oriented dynamic interference cooperative communication optimization system and method, and relates to the technical field of medical data communication security. The hierarchical medical scene-oriented dynamic interference cooperative communication optimization method comprises the following steps: S1, based on hierarchical medical scene differences of emergency treatment, ICU and common wards, realizing covert communication by using native physiological data transmission mutual interference signals of multiple devices in a medical monitoring network; s2, different communication security thresholds and data timeliness indexes are set for different levels of scenes; and S3, constructing a dynamic interference coordination framework, and realizing interference intensity adaptation by adjusting the transmission power (Pi) of the medical equipment and the dedicated channel gain (hj, iva). According to the invention, through linkage with the HIS system, differentiated safety thresholds and timeliness indexes are set for emergency treatment, ICU and common wards, and priority requirements of different scenes are accurately met; parameter synchronization can be rapidly completed during cross-scene transfer, and the problem of connection lag of a traditional scheme is solved.
Owner:THE AFFILIATED HOSPITAL OF XUZHOU MEDICAL UNIV

Active STAR-RIS-based integrated sensing and communication secure transmission method

The invention relates to an integrated perception and communication secure transmission method based on an active STAR-RIS. The integrated perception and communication secure transmission method comprises the following steps: establishing an active STAR-RIS assisted communication perception integrated downlink system model; constructing an optimization problem by taking maximization of the total secrecy rate as an optimization purpose; and solving the optimization problem by adopting a two-stage alternative optimization framework. According to the method, the total secrecy rate of legal users can be maximized, and meanwhile, multi-dimensional constraints such as perception and power are met.
Owner:HENAN UNIV OF SCI & TECH

Distributed low-cost hotel view and photo stealing intelligent supervision system

The invention belongs to the technical field of wireless communication safety monitoring and intelligent supervision, and particularly relates to a distributed low-cost hotel view-stealing and photo-stealing intelligent supervision system which comprises a wireless probe and a sky-wing cloud wireless analysis management and control platform. The wireless probe is connected to a hotel room router, collects space electromagnetic signals and terminal and AP wireless data, and pre-processes and reports the space electromagnetic signals and the terminal and AP wireless data; the cloud platform is constructed based on OpenStack, network mapping is updated through an ANO adversarial online automatic learning algorithm, wired / wireless attributes and event characteristics are subjected to correlation analysis by means of a VAE-CWGAN model, risks are identified, and an alarm is issued. The system realizes lightweight deployment, low-cost operation and maintenance, real-time intelligent supervision and room-level accurate positioning, can detect hundreds of wireless security incidents and dozens of cameras, is suitable for the fields of secrecy, national security and public security, and assists in security guarantee of smart civilized cities.
Owner:NO 33 RES INST OF CHINA ELECTRONICS TECHNOOGY GRP

Semantic communication security enhancement system based on SIM (Subscriber Identity Module) card quantum key presetting

The invention relates to the technical field of mobile communication, and particularly provides a semantic communication security enhancement system based on SIM card quantum key presetting, comprising an SIM card security base module configured to generate physical unclonable function characteristics and preset quantum security keys by using SIM card hardware characteristics; the lightweight authentication protocol module is in communication connection with the SIM card security base module and is configured to realize dynamic identity authentication based on physical unclonable function characteristics and a quantum security key; the semantic security enhancement module is configured to perform privacy protection processing on the semantic communication data; the trusted execution environment optimization module is in communication connection with the SIM card safety base module and the lightweight authentication protocol module and is configured to construct a hardware-software collaborative trusted execution environment; the quantum security enhancement module is integrated on the SIM card security base module and is configured to provide quantum attack resistance and dynamic key management; according to the invention, the real-time performance and anti-quantum computing capability of key distribution are significantly improved.
Owner:CHINA MOBILE INTERNET CO LTD +1

Method for evaluating security credibility of digital content

The invention relates to the technical field of communication security, and discloses a digital content security credibility evaluation method, which comprises the following steps of: performing normalization processing on an original verification data set to obtain standardized verification data; constructing a security feature knowledge graph by taking a content entity, a user entity and an environment entity as nodes, taking an association relationship between entities as a relationship edge and taking an entity feature attribute and a behavior attribute as node attributes; performing feature extraction on the security feature knowledge graph to obtain a semantic feature matrix, a behavior feature tensor and a propagation feature vector; performing dynamic credibility analysis on the standardized verification data to obtain a behavior credibility evaluation index; establishing a multi-dimensional assessment framework according to propagation path features and diffusion features in the propagation feature vectors and the risk assessment parameters; analyzing the propagation feature vector and the behavior credibility evaluation index, and outputting a quantitative credibility evaluation result; according to the invention, the accuracy of security credibility evaluation of the digital content can be improved.
Owner:ANHUI UNIV

Access permission adjustment method, equipment and computer program product

The invention discloses an access permission adjustment method and device and a computer program product, and relates to the technical field of safety protection, and the method comprises the steps: collecting access behavior data of a source device to a target device; according to the access behavior data and a target reference value corresponding to the access behavior data, performing exception analysis on the access behavior data, and extracting exception features in the access behavior data; converting the abnormal features into numerical vectors; according to the numerical value vector, adopting an isolated forest to calculate an abnormal score, adopting a first-class support vector machine to generate a boundary distance value, and adopting a local abnormal factor algorithm to calculate a local density ratio; performing weighted fusion on the abnormal score, the boundary distance value and the local density ratio to obtain a risk assessment result of the source equipment; and adjusting the access authority of the source device for the target device according to the risk assessment result. The problem that the communication security is reduced due to misjudgment of the access permission of the source device to the target device is solved, and the communication security between the source device and the target device is improved.
Owner:ZHEJIANG ZHENENG ELECTRIC POWER

Stackelberg game monitoring enhancement method based on model predictive control

The invention provides a model predictive control-based Stackelberg game monitoring enhancement method, which is applied to an unmanned aerial vehicle confrontation communication scene. According to the method, a Stackelberg game model is established, a legal communication party serves as a leader to optimize transmitting power and a signal distribution factor, and an eavesdropping party serves as a follower to jointly optimize interference power and a motion trail. For a non-convex problem of an eavesdropper, alternating optimization is adopted to decompose the non-convex problem into power and trajectory sub-problems for iterative solution, and a model prediction control (MPC) mechanism is introduced to enable the non-convex problem to be subjected to rolling optimization based on future prediction. Layered optimization is adopted by a legal communication party, a distribution factor closed-form solution is solved firstly, and then the power is optimized. Through the gaming and optimization, the system is converged to be balanced, and the long-term secrecy performance and the anti-interference capability are remarkably improved on the premise of ensuring legal communication. According to the method, the shortness of a single-slot game is overcome, and joint optimization of communication security and efficiency under dynamic confrontation is realized.
Owner:NANJING UNIV

Dynamic beam hopping and resource allocation method for NGSO satellite security communication

The invention discloses a dynamic beam hopping and resource allocation method for NGSO satellite security communication, and belongs to the field of sixth-generation mobile communication security communication and wireless resource allocation. According to the method, significant non-uniformity of distribution of ground flow requirements in a time domain and a space domain is considered, and a satellite-ground security communication network dynamic beam hopping and resource allocation problem model is constructed by considering ground user flow requirements and composition elements and channel characteristics of an NGSO multi-beam satellite network. Through joint optimization of satellite hopping beam scheduling, power resource allocation and auxiliary interference unmanned aerial vehicle deployment strategies, service requirements of different users and ground eavesdropping environments are dynamically adapted, and the safety throughput and queue delay fairness of the system are improved. According to the method, mixed integer linear programming modeling is adopted, and a low-complexity approximation algorithm is combined, so that the method not only has optimality guarantee, but also can be deployed and operated in an actual satellite communication system, and thus unification of secure communication and efficient resource scheduling is realized.
Owner:BEIJING INST OF TECH

Physical layer security-oriented motion sensing integrated unmanned aerial vehicle track and wave beam joint optimization method

The invention belongs to the field of communication sensing integration, and particularly relates to a physical layer security-oriented communication sensing integrated unmanned aerial vehicle track and beam joint optimization method. Comprising the following steps: constructing an unmanned aerial vehicle assisted wireless communication system model; with maximization of a secure communication reachable rate as an optimization target, constructing an unmanned aerial vehicle trajectory and beam joint optimization problem according to a transmitting power constraint, a beam matrix constraint, a flight speed constraint, a flight power constraint and a wide beam constraint; decoupling the unmanned aerial vehicle trajectory and wave beam joint optimization problem to obtain a common inductance integrated waveform sub-problem and an unmanned aerial vehicle flight trajectory sub-problem; iterative solution is carried out on the flux-inductance integrated waveform sub-problem and the unmanned aerial vehicle flight path sub-problem to obtain an optimal flux-inductance integrated waveform and an optimal unmanned aerial vehicle flight path; according to the method, communication perception integration is combined with extended Kalman filtering, waveform and unmanned aerial vehicle trajectory for design, so that the quality of wireless communication is ensured while communication security is realized.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Self-adaptive anti-monitoring communication system

The invention discloses a self-adaptive anti-monitoring communication system, and relates to the technical field of communication security. The system comprises a multi-dimensional fusion sensing module, a dynamic adaptation engine, an encryption communication subsystem and a verification feedback module. The innovation points are that the monitoring situation is accurately researched and judged through multi-source information fusion, a communication parameter and an encryption strategy are dynamically matched based on a research and judgment result, a transmission mechanism combining improved adaptive frequency hopping and dynamic network coding is adopted, and meanwhile, a key dynamic updating and identity bidirectional verification system is constructed. The problems that in the prior art, self-adaptive adjustment is poor in pertinence, encryption and transmission efficiency is unbalanced, and anti-monitoring scene adaptation is single are solved, collaborative optimization of monitoring risk perception, dynamic defense and communication quality is achieved, and the safety and reliability of communication in the complex electromagnetic environment are improved.
Owner:田成文 +2

A method and apparatus for integrating third-party algorithm components based on dual-core collaboration

PendingCN122293458AIntegrated, efficient and stablelow costCommunications securityDual core
This invention relates to the field of computer technology, specifically to a method and apparatus for integrating third-party algorithm components based on dual-core collaboration. This application directly integrates third-party algorithm components into the BCM dual-core MCU, eliminating reliance on ZCU and CAN bus communication. This fundamentally eliminates the latency and security overhead caused by cross-ECU transmission and E2E protection, improving signal real-time performance and communication security. By clearly defining the functions and allocating resources of the BCM dual-core, a dedicated storage area is planned for the third-party algorithm components, and a standardized integration environment is built, achieving efficient and stable component integration. Simultaneously, peripheral access strategies are optimized, unnecessary protections and redundant polling are disabled, releasing idle computing power and hardware resources of the BCM and improving utilization. Without increasing the ZCU hardware cost, the chassis braking algorithm is deployed and executed locally, reducing performance losses caused by cross-domain communication and effectively improving the overall system operating efficiency and resource utilization efficiency.
Owner:ZHEJIANG GEELY HLDG GRP CO LTD +1

A method and system for lightweight secure communication between in-vehicle network ECUs

ActiveCN121077828BIncrease communication delayImplement legality verificationKey distribution for secure communicationPublic key for secure communicationPlaintextCommunications security
The present application relates to the technical field of in-vehicle network communication, and discloses a lightweight and secure communication method and system between ECUs in an in-vehicle network. The communication method comprises an ECU identity authentication phase: each ECU interacts with a CAN gateway, and the CAN gateway performs batch identity authentication to verify the legality of all ECUs; a data classification phase: according to the data sensitivity, the data to be transmitted is classified as confidential data or non-confidential data; a data transmission phase: if the data to be transmitted is confidential data, the sender ECU uses a session key and an ASCON encryption algorithm to encrypt and authenticate the plaintext of the confidential data, generates ciphertext and authentication parameters, and sends a data packet containing the ciphertext and authentication parameters to the receiver ECU; if it is non-confidential data, the sender ECU uses a session key and an ASCON encryption algorithm to only sign but not encrypt the plaintext, generates an authentication tag, and sends a data packet containing the plaintext and the authentication tag to the receiver ECU. The present application takes into account the security and computational overhead of in-vehicle ECU communication.
Owner:HEFEI UNIV OF TECH

Communication method and apparatus

Provided in the embodiments of the present application are a communication method and apparatus, which are used for improving the communication security. In the present application, a transmit end can perform security processing on a data unit of a MAC layer. For example, the transmit end calculates verification information of a MAC subunit on the basis of parameters such as a count value corresponding to the MAC subunit, and a receive end verifies the MAC subunit on the basis of the parameters such as the count value corresponding to the MAC subunit. In the present application, a count value at a MAC subunit granularity is maintained in the MAC unit, and a location in the MAC unit that bears the count value is defined, such that the receive end can acquire the count value, thereby implementing integrity verification on the MAC subunit, and thus helping improve the communication security performance. In addition, in the present application, the count value is maintained at the granularity of the MAC subunit, which helps improve the security performance of the MAC layer.
Owner:HUAWEI TECH CO LTD

System and method for cryptologically tethering user devices to one another in adaptable manner for trusted communication across untrusted network

A high assurance system provides for communication between trusted user devices with auxiliary adaptation for augmenting communication security across an untrusted environment. First and second main encrypting devices coupled to respective trusted user devices are cryptologically tethered to one another by a main communication link established across the untrusted environment between trusted user devices in cryptologically protected manner. An auxiliary encrypting device is cryptologically tethered to the first main encrypting device by an auxiliary communication link established across the untrusted environment between a trusted auxiliary device and one trusted user device in cryptologically protected manner. The main and auxiliary encrypting devices define portals traverse trust boundaries between trusted and untrusted environments, each including at least one encryption unit and a communication unit coupled thereto by a connectionless interconnect. The encryption unit encrypts and decrypts message data, while the communication unit transmits and receives encrypted message data through the communication links.
Owner:GOVERNMENT OF THE UNITED STATES AS REPRESENTED BY THE DIRECTOR NAT SECURITY AGENCY

An encryption communication system applied to new energy vehicles and charging piles

This invention relates to the field of new energy vehicle technology and discloses an encrypted communication system for communication between new energy vehicles and charging piles. The system includes: a vehicle gateway, used to generate an initial vehicle-to-charging pile communication key and a message authentication code, and to send the initial vehicle-to-charging pile communication key and the message authentication code to both communicating parties; and, upon receiving a message indicating successful communication between the battery management system and the charging pile, updating the current vehicle-to-charging pile communication key and regenerating the message authentication code to send to both communicating parties; the battery management system and the charging pile, i.e., the two communicating parties, verify each received message authentication code based on the code. If the verification is successful, they initiate the current round of communication using the current vehicle-to-charging pile communication key; after each message transmission, the current vehicle-to-charging pile communication key is updated, and a message indicating successful communication for the current round is sent to the vehicle gateway. This invention updates the key multiple times during vehicle-to-charging pile communication and verifies it in each round of communication, thus improving communication security.
Owner:CHERY NEW ENERGY AUTOMOBILE TECH CO LTD

Internet of vehicles communication security situation assessment and decision optimization method based on reinforcement learning

The invention discloses an Internet of Vehicles information security situation assessment and decision optimization method based on reinforcement learning, which is applied to vehicle-vehicle and vehicle-cloud communication scenes. The method comprises the following steps: step 1, collecting multi-source Internet of Vehicles security data; 2, preprocessing the multi-source data, and extracting a feature vector reflecting the security situation of the Internet of Vehicles; 3, inputting the feature vector into a reinforcement learning model, and outputting a defense action by the model according to the current security situation; 4, executing a defense action and obtaining a reward signal, wherein the reward signal is generated based on the change of the security situation of the Internet of Vehicles; and 5, updating parameters of the reinforcement learning model according to the reward signal, and optimizing the security situation assessment and defense decision of the Internet of Vehicles. The system adopts a multi-agent cooperation mechanism of federal learning, and the defense knowledge is shared between each vehicle node and the road infrastructure, so that the cooperative defense capability is improved. The method has the advantages of adaptability and distributed cooperation, and can effectively deal with diversified security threats in the Internet of Vehicles.
Owner:SOUTHEAST UNIV

Communication method and device for trusted decision

The invention provides a communication method and device for trusted decision, relates to the technical field of communication, and is used for solving the problems that only the security capability of a terminal is considered in a security policy generation process, and the generation mode is single and not flexible enough. The method comprises the following steps: acquiring a decision mode used for indicating whether a first device serves as a decision party of a trusted policy, or the first device determines the decision party based on a competition mode; sending a first message to the second device based on the decision mode for triggering negotiation of a trusted policy, the trusted policy being used for indicating a security technology and / or a security algorithm employed by communication between the first device and the second device; obtaining a credible policy, the credible policy being obtained according to a first input parameter and a second input parameter corresponding to a second device, the first input parameter being obtained according to a credible demand of the first device, and the credible demand of the first device being used for indicating a demand of the first device for the current communication security capability;
Owner:HUAWEI TECH CO LTD

Intelligent tablet anti-intrusion system for field communication

The invention relates to the technical field of intelligent tablet communication protection, in particular to an intelligent tablet anti-intrusion system for field communication, which is characterized in that an intelligent tablet device emits a detection signal in a tunnel environment, receives and acquires a response signal from a legal communication node and then extracts multipath characteristic parameters; calculating the multipath statistical characteristics of the current channel according to the multipath characteristic parameters, and performing compensation according to the real-time moving speed of the intelligent tablet equipment and the inertia measurement data to obtain compensated multipath statistical characteristics; performing matching analysis on the compensated multipath statistical characteristics and a tunnel multipath blind area fingerprint database to obtain matching success information; when the matching success information is monitored, judging that the intelligent tablet device is in a communication blind area and starting hierarchical anti-intrusion response; and when it is monitored that the multipath statistical features are recovered to the non-blind area channel mode and secure connection with the legal communication node is reestablished, the anti-intrusion response is quitted, and the blind area event log is uploaded, so that the problem of communication security and stability in the tunnel environment is effectively solved.
Owner:SICHUAN ZHIYUAN LIXING TECHNOLOGY CO LTD

Communication method and related device

A communication method and a related device are applied to the technical field of communication. In the application, under the scene that the second node is associated with the first node, the third node is introduced to authenticate the identity of the second node. In order to ensure information security, on one hand, the first node and the second node negotiate to determine the first key, and the first key is used for security protection of the session. And on the other hand, the first node and the second node also respectively obtain a second key, the second key is an authentication key determined by the third node and the second node, the third node can issue the authentication key to the first node, and information verification can be performed between the first node and the second node based on the authentication key. In the application, the first node and the second node respectively establish two sets of key systems, and the session key and the authentication key are independent, so that high privacy of the session key of the node is ensured and the communication security performance of the node is improved under the condition of realizing identity authentication of the node.
Owner:HUAWEI TECH CO LTD