Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

1314 results about "Communications security" patented technology

Communications security is the discipline of preventing unauthorized interceptors from accessing telecommunications in an intelligible form, while still delivering content to the intended recipients. In the North Atlantic Treaty Organization culture, including United States Department of Defense culture, it is often referred to by the abbreviation COMSEC. The field includes cryptographic security, transmission security, emissions security and physical security of COMSEC equipment and associated keying material.

Bidirectional authentication security mobile communication method and system based on public key digital fingerprint

The invention discloses a bidirectional authentication secure mobile communication method and system based on a public key digital fingerprint, and belongs to the technical field of communication security. The method specifically comprises the following steps: S1, digital certificate application and issuing: a mobile terminal and a service server respectively use an encryption algorithm to generate an asymmetric key pair which comprises a public key and a private key, an entity submits a CSR file which comprises a public key, entity identity information and an extension field to a CA, and the CA strictly audits the entity identity and issues a digital certificate; and performing digital signature on the public key and the entity information by using a CA private key after the auditing is passed. Two-way identity authentication is achieved, communication safety is improved, a traditional scheme only supports one-way authentication of a client to a server and is prone to phishing attack and identity false use, digital certificates are exchanged before communication between a mobile terminal and a service server, the legality of the certificates is verified through a public key of a CA root certificate, and the authenticity of the identities of the two parties is ensured. A bidirectional authentication mechanism effectively prevents man-in-the-middle attack and identity counterfeiting problems, and the security risk is greatly reduced.
Owner:HAINAN SOFTWARE VOCATIONAL & TECH COLLEGE

Quantum key distribution secure communication system based on quantum mechanics principle

The invention relates to the technical field of quantum communication security, and discloses a quantum key distribution secure communication system based on a quantum mechanics principle. The system comprises a quantum state preparation unit which controls a quantum emission device to output a quantum state sequence containing a preset polarization angle and a phase modulation photon group; a quantum channel feature extraction unit captures channel environment interference parameters and constructs a photon polarization distribution matrix; a quantum communication security evaluation unit receives the matrix, and calculates a channel security coefficient threshold through a quantum bit error rate analyzer; the quantum key dynamic optimization unit generates an optimized key segmentation strategy in combination with a security coefficient threshold and a historical key negotiation record; the quantum key rotation control unit switches quantum state modulation parameters according to a segmentation strategy and a time window; and the quantum node synchronization management unit monitors node clock offset and injects a calibration signal to realize key distribution time slot alignment. The system can dynamically cope with environmental interference, and improves the security and adaptability of quantum key distribution.
Owner:PANZHIHUA UNIV

SSL VPN security gateway communication method fused with post quantum cryptography

The invention discloses an SSL VPN security gateway communication method fused with a post quantum cryptography technology. Comprising the following steps: S1, a client and a server respectively configure a serial hybrid signature digital certificate containing an SM2 algorithm and a serial hybrid encryption digital certificate containing a PQC algorithm, and a corresponding PQC encryption key pair private key, a PQC signature key pair private key, an SM2 encryption key pair private key and an SM2 signature key pair private key; s2, newly adding a hybrid algorithm password suite using an SM2 algorithm and a PQC algorithm in a password suite list of the client, and forcibly jacking the priority of the hybrid algorithm password suite; and S3, a message structure in a handshake protocol is transformed to use a series hybrid encrypted digital certificate to realize that PQC algorithm processing is added on the basis of an original national cryptographic algorithm to realize quantum key negotiation resistance. According to the method, the PQC algorithm is added on the basis of the original national secret algorithm, and the handshake protocol is transformed, so that anti-quantum-attack key agreement and identity authentication can be realized, the communication security is remarkably improved, and meanwhile, the interoperability with the standard SSL VPN is kept.
Owner:HEBEI PRIME NUMBER INFORMATION SECURITY CO LTD +1

Method and system for decomposing door lock communication group

The invention discloses a door lock communication group decomposition method and system, and the method comprises the steps: encrypting and issuing a sub-feature vector to a local storage of a corresponding member door lock through a secure channel according to the sub-feature vector generated by a main control door lock and a binding relation between the sub-feature vector and the member door lock; generating a multicast message containing a target subgroup feature vector and a digital signature according to a splitting request sent by a main control door lock; according to the result of querying the local ARP table and the subgroup registry by the multicast router, determining the subgroup to which the door lock connected with each interface belongs, and registering the corresponding sub-feature vector for the corresponding interface in the multicast forwarding table; and according to a detection message sent by each sub-group master control door lock and a confirmation message of a member door lock, the multicast router identifies and removes sub-feature vector registration of an interface which is not associated with an effective door lock, and communication group decomposition is completed. By utilizing the embodiment of the invention, safe, reliable and interface-level refined door lock group decomposition can be realized, and the splitting efficiency and the communication safety are improved.
Owner:DESSMANN CHINA MACHINERY & ELECTRONICS

Communication encryption method and device, equipment, storage medium and computer program product

The invention relates to the technical field of communication security, in particular to a communication encryption method and device, equipment, a storage medium and a computer program product. The method comprises the following steps: dynamically generating a main session key between two communication parties based on a preset key negotiation protocol; dynamically generating sub-keys according to a preset time interval based on the main session key and the key sequence; performing encryption processing on each data block in the communication data stream based on the sub-key and the encryption strategy; generating a message authentication code for each encrypted data block; adding timestamp information based on the message authentication code, and introducing a random offset into the timestamp information; and the encrypted data blocks, the message authentication code and the timestamp information are packaged into the target data message, so that the transmission security of the communication data is improved.
Owner:SHENZHEN DINSTAR TECH

Data security risk early warning method and system based on big data analysis

The invention provides a data security risk early warning method and system based on big data analysis, and the method comprises the steps: firstly constructing a data security risk feature map, collecting a heterogeneous data set in a mobile communication network in real time through a multi-source data access interface, generating a multi-source heterogeneous data fusion stream through distributed cleaning and standardization processing, and carrying out the data security risk early warning. Then inputting the data security risk feature into a preset distributed risk feature learning network, performing feature mapping and association enhancement processing based on a data security risk feature map to obtain a real-time risk feature vector, performing big data association analysis on the real-time risk feature vector, mining a risk feature conduction dependency relationship, generating a risk propagation path weight set, and performing big data association analysis on the real-time risk feature vector; and finally, determining a risk diffusion level and a key influence node, generating a security risk early warning instruction containing a risk diffusion path identifier, and pushing the security risk early warning instruction to a mobile communication security management platform, thereby realizing accurate early warning and quick response of the data security risk, and ensuring safe and stable operation of a mobile communication network.
Owner:CHINA MOBILE COMM GRP TIBET CO LTD

Method for applying anti-quantum certificate to TLS1.2 handshake process

The invention discloses a method for applying an anti-quantum certificate to a TLS1.2 handshake process, which realizes the application of an MLDSA anti-quantum signature algorithm and an MLKEM anti-quantum key encapsulation mechanism in the handshake process by expanding a cipher suite and a signature algorithm field of a TLS1.2 protocol. The method specifically comprises the following steps: defining a cipher suite supporting MLKEM and an MLDSA signature algorithm enumeration value; the client declares algorithm support in ClientHello, and the server responds and returns a certificate chain containing the double-antibody quantum certificate; after the client verifies the certificate, the pre-master key is encapsulated by using MLKEM, and the server de-encapsulates the derived session key; and the two parties send Finished messages to each other to complete handshake. According to the scheme, on the premise that a TLS1.2 basic framework is not changed, the communication security is enhanced through double-resistance quantum algorithm integration, international and national cryptographic algorithms are supported, quantum computing attacks can be resisted, meanwhile, adaptation of the international and national cryptographic algorithms is supported, compatibility with an existing system is ensured, the security risk of a traditional cryptographic algorithm in a quantum environment is solved, and the security risk of the traditional cryptographic algorithm in the quantum environment is reduced. And a standardized solution is provided for anti-quantum upgrade of the TLS1.2 protocol.
Owner:BEIJING SKYFAITH TECH CO LTD

System and method for operating system distribution and version identification using communications security fingerprints

A system and method for inferring an operating system version for a device based on communications security data. A method includes identifying a plurality of sequences in communications security data sent by the device; determining an operating system type of an operating system used by the device based on the identified plurality of sequences; applying a version-identifying model to the identified plurality of sequences, wherein the version-identifying model is a machine learning model trained to output a version identifier, wherein the applied version-identifying model is associated with the determined operating system type; and determining the operating system version of the device based on the output of the version-identifying model.
Owner:ARMIS SECURITY LTD

Track design method and system in unmanned aerial vehicle hidden and inductive integrated network

The invention provides a trajectory design method and system in an unmanned aerial vehicle hidden and sensing integrated network, and the method comprises the steps: firstly deducing a multi-listener cooperative receiving signal expression and a probability density function in the sensing integrated network with multiple cooperative listeners; then deriving a minimum detection error rate expression of multi-listener collaborative detection and an optimal power division ratio expression meeting covert communication constraints based on a maximum likelihood principle; and establishing an unmanned aerial vehicle track and scheduling optimization problem of anti-cooperative detection in the unmanned aerial vehicle hidden and inductive integrated network according to the deduced formula. And finally, iteratively solving the problem based on convex approximation and an ellipsoid method to obtain an optimal unmanned aerial vehicle trajectory and scheduling. According to the method provided by the invention, the covert communication requirement in the unmanned aerial vehicle communication perception integrated network can be well met, and the communication safety in the future unmanned aerial vehicle Internet of Things is improved.
Owner:WUHAN UNIV

Network security control system and method for multi-level protection of communication of Internet of Things equipment

The invention relates to the technical field of equipment communication security, in particular to a network security control system and method for multilevel protection of Internet of Things equipment communication, comprising a protocol security adaptation layer, a heterogeneous equipment authentication module, a behavior baseline modeling unit and an adaptive defense decision engine, the security conversion of a plurality of Internet of Things communication protocols is supported; the heterogeneous equipment authentication module adopts a differential authentication strategy, and dynamically adjusts authentication strength for different equipment types; the behavior baseline modeling unit generates an equipment communication mode fingerprint database through time sequence analysis; and the adaptive defense decision engine associates the security event with the network topology in real time to generate a dynamic isolation and flow control strategy. Therefore, the problems that in the prior art, protocol compatibility is poor, an authentication mechanism is rigid, behavior analysis is static, threat response is lagged, resource scheduling is unbalanced, and auditing tracing is not credible are solved.
Owner:SHANXI ELECTRIC POWER CO POWER COMM CENT

Internet of Things secure access method based on cloud edge collaboration

The invention discloses an Internet of Things secure access method based on cloud edge collaboration, which comprises the following steps: firstly, an Internet of Things device and an edge server respectively register in a CSC (Content Service Controller), and obtain an intelligent card or related data to complete information updating and storage; the equipment is inserted into an intelligent card to log in, and data are sent to the edge server after identity password verification; the edge server verifies the timestamp and then forwards the data to the CSC; the CSC verifies the timestamp and the identity, generates a session key parameter and sends the session key parameter to the edge server; the edge server verifies the identity of the CSC and then generates session key encrypted data to be transmitted back, and after the verification of the device is passed, secure communication is established. According to the method, mutual verification and encryption protection are adopted in identity verification; a timestamp, a random value and strict verification are used for message transmission to prevent replay and man-in-the-middle attack; secret key management guarantees safety through dynamic change of secret values, attacks such as physical capture are resisted in combination with PUF, and communication safety is comprehensively guaranteed.
Owner:SICHUAN BAICHENG INFORMATION TECHNOLOGY CO LTD

Key sharing and detection scheme based on intelligent electric meter

The invention discloses a key sharing and security detection scheme based on an intelligent electric meter, and aims to solve the problems that an untrusted electric meter in an intelligent power grid is difficult to identify effectively, the detection scale is uncontrollable and the communication security is insufficient. According to the scheme, the elliptic curve cryptography, the threshold secret sharing mechanism and the physical unclonable function are combined, and hardware-level binding of the unique identity of the equipment and the secret key is achieved in the registration stage. Through a threshold password mechanism, a plurality of intelligent electric meters cooperatively participate in key reconstruction and encryption communication, and the intelligent electric meters can still work normally when part of the electric meters fail or are broken through. The center node can actively identify a fault or a malicious ammeter and dynamically adjust a communication strategy according to the integrity and correctness of the feedback information. Meanwhile, the scheme supports dynamic identity updating and integrity verification, and effectively resists modeling attacks, Sybil attacks, replay attacks and DoS / DDoS attacks. According to the invention, secure identity authentication, reliable key distribution and efficient anomaly detection are realized, and the security of smart grid terminal communication is improved.
Owner:CHUXIONG POWER SUPPLY BUREAU OF YUNNAN POWER GRID CO LTD

Power grid data secure transmission system and method based on quantum cryptography, and medium

The invention relates to the technical field of electric power communication security, in particular to a power grid data secure transmission system and method based on quantum cryptography and a medium, comprising: a power grid data access module extracts identities of a power grid data request end and a target response end; the quantum key distribution module obtains an original shared key pre-stored by the two communication parties, and generates a quantum key according to the one-time session password and the original shared key; the communication security management module analyzes the shared key information from the quantum key received by the target response end to obtain analyzed shared key information, and performs communication security verification on the original shared key and the analyzed shared key information; and the power grid security communication module encrypts the to-be-transmitted power grid data when the communication security verification result is that the verification is passed, and transmits the power grid encrypted data to the target response end. Through cooperation mechanisms such as quantum key dynamic distribution and security verification, security protection of power grid data transmission is realized, and power grid data communication security is improved.
Owner:GUANGZHOU POWER SUPPLY BUREAU GUANGDONG POWER GRID CO LTD

Internet of Things authentication method and electronic equipment

The embodiment of the invention provides an Internet of Things authentication method and electronic equipment, and relates to the technical field of communication security, and the Internet of Things authentication method comprises the steps: obtaining a dynamic key element of terminal equipment; generating a dynamic key of the terminal equipment according to the dynamic key element, the static identity public key of the terminal equipment and the identity identification information; the static identity public key is obtained through calculation based on hardware fingerprint information and identity identification information of the terminal equipment and pre-configured bilinear pair parameters; sending an authentication request to an access point accessed by the terminal equipment; the authentication request carries identity identification information and a dynamic key; and the access point is used for acquiring the static identity public key from the block chain system according to the identity information, and authenticating the dynamic key based on the static identity public key. According to the method and the device, the security of the dynamic key can be ensured from multiple aspects, the authentication process can be accurately and efficiently completed without pre-storing a public key certificate, and the communication security between the terminal equipment and the access point is improved.
Owner:NINGBO TELIAN INFORMATION TECH CO LTD

All-in-one machine encryption communication transmission method and system based on dynamic strategy

The invention relates to the technical field of communication transmission, and particularly discloses an all-in-one machine encryption communication transmission method and system based on a dynamic strategy, and the method comprises the steps: collecting hardware state parameters, network environment parameters and communication content characteristics of an all-in-one machine and a target communication opposite end in real time; calculating a risk index of the current communication process based on the network environment parameters of the all-in-one machine and the target communication opposite terminal; matching an encryption algorithm sequence, a key updating frequency and a transmission protocol according to hardware state parameters, risk indexes and communication content characteristics of the all-in-one machine and a target communication opposite end, performing segmented encryption and multi-channel parallel transmission on communication data of the all-in-one machine, and performing security key distribution in combination with a distributed key management mechanism to obtain a security key; performing encrypted communication security verification based on the security key to obtain communication verification data; the security of the communication process of the all-in-one machine is improved, and the risks of data leakage and man-in-the-middle attack are prevented.
Owner:JINJI FUTURE (SHENZHEN) TECHNOLOGY CO LTD

Unloading method in ultra-dense millimeter wave MEC network

The invention relates to the technical field of wireless communication, and discloses an unloading method in an ultra-dense millimeter wave MEC network. Aiming at the problems of insufficient terminal capability, high energy consumption of an ultra-dense base station, millimeter wave coverage limitation, communication security risk and the like under the condition of sharp increase of a calculation-intensive task, the method comprises the following steps: firstly, obtaining network basic information, constructing a network architecture containing communication, calculation unloading and a security model, and establishing a multi-constraint optimization problem; based on the optimization problem, initializing a multi-strategy black-wing plinuary optimization algorithm population through logic mapping and elite selection; updating individual positions through global and local search in algorithm iteration, and screening historical optimal individuals; and finally, configuring and unloading resources according to the configuration. According to the method, the NOMA technology, a multi-step unloading framework and a hybrid communication mode are combined, the optimization efficiency is improved through a multi-strategy black-wing optimization algorithm, the local energy consumption is reduced, the communication rate is improved, the safety is guaranteed, the optimal scheme meeting time delay and safety constraints is rapidly converged, and the user experience is improved.
Owner:EAST CHINA JIAOTONG UNIVERSITY

Multi-user near-field secure communication method based on stacked intelligent metasurfaces

The invention provides a multi-user near-field secure communication method based on stacked intelligent metasurfaces, and relates to the technical field of wireless communication. The method comprises the following steps: obtaining an equivalent beamforming matrix and a first-layer channel transmission matrix of an SIM according to parameters of the SIM in a base station; according to the transmission distance between the SIM and the user and the transmission distance between the SIM and the eavesdropper and the parameters of the SIM, modeling a near-field channel to obtain a near-field channel model; obtaining a data transmission rate in combination with a beamforming vector of the base station, and further determining the security and the rate; and by taking maximization of the safety and the rate as a target, constructing an optimization model and decomposing the optimization model into two sub-problems to carry out alternate iterative optimization so as to obtain an optimized equivalent beam forming matrix and an optimized beam forming vector. An SIM is introduced, the freedom degree of beam regulation and control is increased, optimization is carried out on the basis of a near-field channel model by taking maximization of safety and rate as targets, legal users and eavesdroppers are effectively distinguished, signal energy is accurately guided to the legal users, and the communication safety is improved.
Owner:ANHUI UNIV

Method and device for safely accessing industrial control equipment to public test platform

The invention discloses a method and device for safely accessing industrial control equipment to a public test platform, and the method comprises the steps: carrying out the initialization of the public test platform, including the generation of a public and private key pair, the configuration of a digital certificate, the configuration of a Bloom filter, the selection of a hash function set matched with the Bloom filter, and the construction of a controlled resource identifier set; the public test platform receives registration information of the industrial control equipment, grants a corresponding authority to the industrial control equipment according to the registration information, generates a minimum authorized resource set corresponding to the authority, writes the minimum authorized resource set into the Bloom filter, and stores identity information of the industrial control equipment; the public testing platform performs bidirectional authentication of the public testing platform and the industrial control equipment based on an authentication request initiated by the industrial control equipment, and dynamically updates authentication information held by the public testing platform and the industrial control equipment respectively; and after the bidirectional authentication is completed, the public test platform performs access admission judgment on a resource access request initiated by the industrial control equipment by using a bloom filter based on the controlled resource identifier set and corresponding authority granted to the industrial control equipment. The invention aims to solve the problems that the current industrial control equipment in a large-scale access scene is weak in authentication anti-attack capability, a secret key is easy to leak and counterfeit, physical attack protection is insufficient, communication lacks forward and backward security, and a resource authorization mechanism does not have a fine granularity and minimum authorization principle.
Owner:XI AN JIAOTONG UNIV

Information communication method based on communication security protection

The invention belongs to the field of communication transmission, relates to a data analysis technology, is used for solving the problems that time delay exists in channel state feedback and static weight cannot adapt to burst interference in the prior art, and particularly relates to an information communication method based on communication security protection, which comprises a link switching analysis sub-method and a feedback analysis sub-method. The link switching analysis sub-method comprises the following steps: acquiring channel parameters of a communication link and performing entropy conversion; carrying out weight distribution according to the entropy value of the channel parameter to obtain a weight coefficient of the sampling parameter in the acquisition period; analyzing the priority of the communication link; according to the method, the essential characteristics of the channel parameters can be dynamically captured, the timeliness and accuracy of the link switching decision are improved, the abnormal switching operation is effectively identified by a closed-loop feedback mechanism, the communication resource waste caused by invalid switching is reduced, and the method can maintain stable information transmission quality in a complex electromagnetic interference environment, so that the user experience is improved. And the communication interruption risk caused by channel abrupt change is avoided.
Owner:BEIJING MAGIC HUACHUANG INFORMATION TECH CO LTD

Non-contact power supply three-level control system based on series redundancy

The invention discloses a non-contact power supply three-stage control system based on series redundancy, and belongs to the field of non-contact power supply control. Comprising a power correction module, a voltage conversion module, a full-bridge inversion module, a cooperative control module, an analysis adjustment module, a monitoring switching module, a simulation maintenance module, a communication security module, a remote interaction module, an energy efficiency optimization module and a diagnosis recording module. High conversion efficiency can be dynamically kept under different loads and working conditions, energy loss is reduced, electric energy quality is remarkably improved, damage and misoperation under abnormal working conditions are prevented, high-reliability continuous power supply is achieved, PID parameters can be dynamically adjusted or direct control quantity can be generated, the system adapts to complex and changeable operating environments, and failure rate and shutdown loss are reduced.
Owner:JIANGSU DAODA INTELLIGENT TECH CO LTD

Network security communication method and system applied to unmanned equipment formation, and medium

The invention relates to the technical field of wireless communication, in particular to a network security communication method and system applied to an unmanned equipment formation and a medium. The method comprises the following steps: firstly, according to a wind speed, a wind direction and a difference condition between an actual spatial position and a set spatial position of unmanned equipment, obtaining a self-noise representation degree at a to-be-analyzed moment; according to the noise interference degree, the initial smoothing coefficient of the to-be-analyzed moment is adjusted, and the adjusted smoothing coefficient of the unmanned equipment at the to-be-analyzed moment is obtained; filtering the actual spatial position by using the adjusted smoothing coefficient at each sampling moment to obtain filtered actual spatial position data; and performing communication transmission based on the filtered actual spatial position data. According to the method, the smoothing coefficient of each sampling moment is reasonably set, and exponential smoothing filtering is performed on the actual spatial position data of the unmanned equipment, so that the filtering effect is improved, the filtering data accuracy in wireless communication is improved, and the wireless communication safety is guaranteed.
Owner:NORTHWESTERN POLYTECHNICAL UNIV

Intelligent agent high-speed bus implementation method and system based on FPGA and dynamic smoothing technology

ActiveCN121585742ASecuring communicationCommunications securityLightweight protocol
The invention relates to the technical field of data communication, and discloses an intelligent agent high-speed bus implementation method and system based on an FPGA and a dynamic smoothing technology. The method comprises the following steps: constructing a single handshake message through a lightweight protocol, adjusting network indexes by adopting an exponential smoothing method, constructing a pipeline processing unit in an FPGA card by utilizing a VHDL, realizing key updating and encryption processing, constructing a three-layer adaptive structure connection subsystem, and optimizing algorithm parameters and resource allocation according to a running state. And a high-performance bus communication system is formed. On the premise of ensuring the communication security and reliability, the network transmission delay is remarkably reduced, and the data throughput is improved, so that the communication system can meet the requirements of emergency linkage and large data volume transmission in a scene (such as a rail transit station-level system) with a high real-time requirement.
Owner:SHANGHAI HOLLEYSOFT SYST

Method and device for dynamic secure communication between micro-services based on chaos cryptography

The invention provides an inter-micro-service dynamic secure communication method and device based on chaos cryptography. The method comprises the steps that a service provider instance registers a public key and chaos initial parameters to a service registration center; before calling, the service consumer instance acquires a public key and a chaos initial parameter of a target service provider instance from a service registration center; the service consumer instance performs key negotiation with the acquired public key by using a private key of the service consumer instance to determine a shared key; performing key derivation on the shared key and the chaotic initial parameter to generate an initial key; respectively using the initial keys to initialize the chaotic system so as to generate synchronous encryption key streams; and the two communication parties perform real-time stream encryption and decryption on the communication data between the micro-services by using the encryption key stream. The unpredictability of a chaotic system and modern cryptography can be combined, and a micro-service design mode is deeply integrated, so that a lightweight and high-security communication security mechanism which does not need to share a key in advance and can be adaptive to dynamic change of service is realized.
Owner:浪潮智能终端有限公司

Multi-device automatic configuration encryption method and system based on Bluetooth

The invention relates to the technical field of key generation and distribution, in particular to a multi-device automatic configuration encryption method and system based on Bluetooth. The method comprises the following steps: firstly, acquiring instruction information and attributes, RSSI values and historical pairing information of to-be-distributed network equipment, and providing a data basis for configuration; core equipment is screened through instruction and attribute matching and attribute similarity analysis, and equipment strongly related to user requirements is accurately positioned; historical pairing and RSSI value quantization equipment distance weights are fused, association conditions are analyzed, and a network structure is visually presented; analyzing the path length of the core equipment based on a graph structure, dividing closely associated target equipment groups, and determining the influence range of the core equipment; finally, the differentiated dynamic key is dynamically generated in combination with the equipment attribute, the distance weight and the instruction information in the group, the scheme effectively adapts to the dynamic change scene of the equipment through association analysis and dynamic adaptation, and the communication security and specificity are improved.
Owner:NINGBO XIAOJIANG ELECTRONICS TECH

Multi-band mobile phone signal detection and alarm method and system

The invention provides a multi-band mobile phone signal detection and alarm method and system, and relates to the technical field of communication safety monitoring, and the method comprises the steps: collecting and preprocessing an electromagnetic signal of a target area, obtaining a signal frequency spectrum through fast Fourier transform, extracting mobile phone signal characteristic frequency band information, and carrying out the detection and alarm. The communication state is judged according to the uplink and downlink frequency band signal strength ratio, the position of a mobile phone signal source is calculated based on a signal strength difference positioning algorithm, the moving track is recorded, the use scene is judged according to the track data and the communication state time sequence relation, the threat level is evaluated, and alarm information is sent. According to the invention, real-time monitoring and accurate positioning of mobile phone use behaviors in the target area can be realized, and the safety management and control efficiency is improved.
Owner:BEIJING UNISECURITY CO LTD

Anti-quantum tunnel communication security enhancement method and system based on software definition

The invention belongs to the technical field of network communication security, and relates to an anti-quantum tunnel communication security enhancement method and system based on software definition, and the system comprises a message processing module, a remote management module, a password module and an access control module. By introducing an anti-quantum cryptography algorithm and modular design, an anti-quantum tunnel architecture realized by pure software is provided, quantum secure communication is realized without depending on hardware, non-intrusive deployment is supported, and compatibility with various service scenes is realized. According to the invention, by introducing an anti-quantum cryptography algorithm and modular design, an anti-quantum tunnel architecture realized by pure software is provided, quantum secure communication can be realized without depending on hardware, non-intrusive deployment is supported, and compatibility with various service scenes is realized.
Owner:STATE GRID JIANGXI ELECTRIC POWER CO LTD RES INST

Anti-quantum key management method for vehicle-mounted domain centralized electronic and electrical architecture

The invention discloses an anti-quantum key management method for a vehicle-mounted domain centralized electronic and electrical architecture. Firstly, the invention provides a self-adaptive security policy generation method based on an analytic hierarchy process. Key factors influencing vehicle-mounted service safety are sorted through a system, a three-layer AHP hierarchical structure model with the purpose of selecting an optimal encryption mechanism is constructed, and therefore vehicle-mounted service safety modeling is achieved. According to the method, the most suitable security policy can be automatically matched according to the characteristics of different services, the self-adaptive security policy generation of the service granularity is realized, and the optimization of the system resource use efficiency is realized while the communication security is ensured. Secondly, the invention provides a fine-grained anti-quantum key management scheme based on the Chinese remainder theorem, and the fine-grained anti-quantum key management scheme is specially designed for adapting to a one-to-many communication scene widely existing in a vehicle-mounted network. The method supports efficient distribution and dynamic updating of group keys of service granularity, and has good quantum attack resistance.
Owner:XIDIAN UNIV +2

Discrete variable quantum key distribution data coordination method

The invention belongs to the technical field of quantum communication, and particularly relates to a discrete variable quantum key distribution data coordination method and system based on a code rate adaptive multi-system LDPC code. Aiming at the defect of performance bottleneck of an existing discrete variable quantum key distribution system adopting a binary low-density parity check code in a long-distance and high-noise environment, the invention provides a discrete variable quantum key distribution data coordination method. The method comprises the following steps: preparing and transmitting a quantum state; screening data; error rate estimation and eavesdropping detection; data coordination based on symbol-level code rate adaptation and / or bit-level code rate adaptation; and confidentiality enhancement. According to the method disclosed by the invention, the construction and storage pressure of the system on error correction codes with different code rates is obviously reduced, the robustness of the system under a complex channel condition is enhanced, and efficient and unconditionally safe key distribution is ensured; the eavesdropping attack can be effectively resisted, and the communication security is ensured.
Owner:ELECTRIC POWER RES INST OF STATE GRID ZHEJIANG ELECTRIC POWER COMAPNY +3

Privacy number-based traceable secure communication method, device and equipment

The invention relates to a traceable security communication method, device and equipment based on a privacy number, and belongs to the technical field of communication processing, and the method realizes credible storage of communication data by obtaining a communication record and generating a distributed unique identifier, adopting an SM2 algorithm for signature and writing evidence data into a block chain. Meanwhile, the preset master key is subjected to fragmentation processing, a plurality of sub-key fragments are generated, the storage position is determined, and the session key is generated by adopting an SM4 algorithm to perform end-to-end encryption on the communication content, so that the communication security is guaranteed. Besides, a zero-knowledge proof protocol is introduced for identity verification, dynamic risk assessment and an authority fusing mechanism are combined, high-risk communication is effectively prevented, multiple cryptography technologies and safety mechanisms are comprehensively applied, and safety, credibility and auditing performance of the communication process are comprehensively improved.
Owner:HANGZHOU RONGXUAN INFORMATION TECH CO LTD

Unmanned aerial vehicle navigation signal collaborative blocking system based on quantum key distribution

The invention provides an unmanned aerial vehicle navigation signal cooperative blocking system based on quantum key distribution, relates to the technical field of communication security, and realizes high-precision threat identification through quantum key distribution and a multi-layer convolutional neural network so as to significantly reduce the risk of misjudgment. The characteristic comparison accuracy is ensured in combination with a standardized encryption parameter and an incremental updating mechanism, and error interference caused by signal confusion is avoided; meanwhile, the intelligent probability model evaluates flight data in real time, and only when the risk exceeds a threshold value, directional interference or signal adjustment is triggered, so that the safety of the legal unmanned aerial vehicle is guaranteed; the supervision module ensures that the authority is controllable through biometric authentication and operation logs, and the security efficiency and the flight safety are both considered.
Owner:JIANGSU HAICHUANG INTEGRATED SYST CO LTD