Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

639 results about "Confidentiality" patented technology

Confidentiality involves a set of rules or a promise usually executed through confidentiality agreements that limits access or places restrictions on certain types of information.

System and method for secure ai-based financial technology governance and risk management

The present invention discloses a system and method for secure artificial intelligence-based financial technology governance and risk management, designed to provide real-time, autonomous, and verifiable compliance assurance within digital financial ecosystems. The invention integrates a secure artificial intelligence processing unit, a governance control processor, a cryptographically anchored storage unit, a federated learning coordination processor, and a quantum-resistant communication interface enclosed within a tamper-proof hardware structure. The system performs encrypted machine learning computations on financial transaction data using homomorphic encryption and trusted execution environments to preserve confidentiality during analysis. It computes a governance risk index based on probabilistic inference and anomaly detection to identify regulatory deviations, applies adaptive compliance reasoning across multi-jurisdictional frameworks, and automatically enforces governance actions through secure decision logic.
Owner:MAHESHKAR JAYKUMAR AMBADAS

Safe communication method and system for V2G charging pile and energy storage system, and storage medium

The invention provides a safe communication method and system for a V2G charging pile and an energy storage system and a storage medium. The system comprises an energy management system EMS, a charging pile EVSE, a vehicle battery management system BMS and an energy storage battery management system BMS. A session key is established through certificate bidirectional authentication and ECDH negotiation, encryption and anti-replay are realized based on AES / SM4-GCM and additional authentication data, and digital signature verification and REST / TLS transmission are performed on a cross-domain instruction; and when the cloud is unreachable, the EVSE locally executes cooperative control and virtual droop voltage stabilization, or the EMS adopts model prediction control to issue an optimal charging and discharging track. According to the protocol, the confidentiality, integrity and availability of V2G communication and control and the stability of the micro-grid are improved.
Owner:SHENZHEN JIMU ENERGY CO LTD

Power real-time data dynamic encryption transmission method and system based on national secret algorithm

The invention discloses an electric power real-time data dynamic encryption transmission method and system based on a national secret algorithm. According to the method, the real-time updating of the session key is realized by fusing the SM3 Hash algorithm and the multi-dimensional dynamic factor, and the anti-attack capability of data transmission of the power system is improved. A timestamp and data counter double-trigger mechanism is introduced in the key generation process, so that the key is automatically alternated under a fixed time interval or a data volume threshold value, a key exposure window is shortened, and the security risk caused by using the same key for a long time is reduced. Key synchronization is carried out in combination with an SM2 bidirectional authentication channel, the confidentiality of key distribution is ensured, access of unauthorized equipment is avoided through an identity authentication mechanism, full-closed-loop security protection from key generation to transmission is formed, the high-security requirement of the power industry for key data transmission is met, and the security of key data transmission is improved. Through deep combination of a cryptographic algorithm system and a dynamic adaptation mechanism, the high efficiency and compliance of power real-time data transmission are considered while the security is ensured.
Owner:GUIZHOU WUJIANG HYDROPOWER DEV

Universal Identity Verification for Video Conferencing

Systems, methods, and apparatuses are described for verifying a user identity in a video conference. A computing device may receive user data and a plurality of security parameters associated with accessing a video conference based on a confidentiality level of the video conference. The computing device may generate a security code that is encoded with user data. The computing device might cause the security code to be displayed on the mobile device for a predetermined time period. The computing device may receive an indication that the first device scanned the security code by using a camera. To verify the identity of a user, the computing device may decode the security code, compare the decoded user data of the decoded security code and expected user data associated with the video conference. The computing device may determine the authenticity of a user video and allow access to the video conference.
Owner:CAPITAL ONE SERVICES LLC

Power production management system security situation awareness method based on national secret algorithm

The invention discloses an electric power production management system security situation awareness method based on a cryptographic algorithm. According to the invention, by deeply fusing SM2, SM3, SM4 and other national cryptographic algorithms and power system characteristics, a full-link autonomous and controllable security protection system is constructed. In a data acquisition stage, SM4 encryption transmission and SM3 hash evidence storage are adopted to ensure confidentiality and integrity of data from a source to processing, and eavesdropping and tampering risks in a transmission process are effectively resisted; in a core situation assessment link, point multiplication operation of SM2 elliptic curve cryptography is innovatively introduced into a node aggregation process of a graph neural network, and graph structure mapping of physical topology of a power system is combined, so that the model can accurately capture implicit association and cascade influence between equipment, and the situation assessment accuracy is improved. At the same time, the recognition capability of the hidden attack mode is enhanced by using the nonlinear transformation of SM4, and the perception depth and anti-attack toughness of the system to the complex threats in the power production scene are improved from the bottom layer of the algorithm.
Owner:GUIZHOU WUJIANG HYDROPOWER DEV

Secure key injection method and system

The invention discloses a secure key injection method and system, which are applied to electronic equipment with a rich execution environment and a secure virtual machine environment, and the method comprises the following steps: receiving a key injection request in the rich execution environment, and loading and starting the secure virtual machine environment; forwarding the key injection request to a secure virtual machine environment; generating a key pair in the secure virtual machine environment, and sending a public key certificate and an identity certificate of the key pair to a key management background through a rich execution environment; the key management background returns response data after verification is passed, and the response data is forwarded to the secure virtual machine environment through the rich execution environment; verifying the response data in the secure virtual machine environment; and after the verification is passed, storing the to-be-injected key material in the response data in the secure virtual machine environment. According to the invention, end-to-end security protection of the key material is realized through dual-environment cooperation, and the anti-attack capability and the data confidentiality of the injection process are effectively improved.
Owner:FUJIAN WISBO DIGITAL TECHNOLOGY CO LTD

Dynamic data security requirements in a network

Systems, methods and / or computer program products for dynamically adjusting levels of data security, encryption enforcement, confidentiality, network policies and other parameters within a network and at processing nodes thereof, implementing heightened levels of security and encryption as needed, based on the type of datasets being processed. Enforcement and removal of data security, encryption requirements, confidentiality, network policies and other parameters at the nodes of the network is performed using headers and footers added to the source dataset. Headers prescribe the heightened level of security or encryption being enforced at each node of the network along the source dataset's flow trajectory, while footers follow the completed processing of the source dataset and indicates to the nodes along the data flow trajectory the conditions for removing the heightened level of security, encryption, confidentiality, network policies and other parameters prescribed by the headers.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

System, method, and apparatus for estimating life-cycle impact while preserving privacy

A system, method, and apparatus for estimating life-cycle impact while preserving data privacy uses federated learning to train machine learning models across multiple local clients without exposing private data. Local clients train local models on private datasets. Privatized update data from these local models may be transmitted to a central server which aggregates this data to enhance a global model. The global model is redistributed to clients, thereby improving its accuracy through successive federated learning rounds, without accessing any raw private data. Local clients can query their local models to obtain impact scores for products or processes based on the aggregated learning. A range of privacy-preserving computation protocols limit exposure of sensitive data. This cooperative framework enables collective model refinement reflective of broad data access without compromising confidentiality. The system provides accurate impact values alongside data security assurances for clients.
Owner:MERCK PATENT GMBH

Multi-party supply chain sensing data encryption metering and traceability method based on space-time coupling watermark embedding

The invention discloses a multi-party supply chain sensing data encryption measurement and traceability method based on space-time coupling watermark embedding, which comprises the following steps of: constructing a double-domain coupling model of a time sequence and a space distribution characteristic, and embedding dynamic watermark information into a sensing data stream to realize data source identity identification and tamper-proof protection. A self-adaptive key generation and credible chain verification mechanism is introduced in an encryption metering stage, so that the data integrity and confidentiality can be guaranteed on the premise of not influencing the real-time transmission performance of the data; in the tracing stage, a data transmission path is reconstructed by using the watermark tracing matrix, and data responsibility definition and anomaly detection among multiple nodes are realized. The method is suitable for high-security data management and credible tracking in a supply chain multi-node collaborative environment.
Owner:SHANXI JINPUDA ELECTRONIC TECHNOLOGY CO LTD

Logistics in-transit data secure transmission system

The invention relates to the technical field of internet-of-things encryption, in particular to a logistics in-transit data secure transmission system, which comprises a trajectory hash presetting module used for extracting longitude and latitude dotting data according to a logistics transportation plan, arranging the longitude and latitude dotting data according to a time sequence to generate a predetermined trajectory coordinate sequence, and transmitting the predetermined trajectory coordinate sequence to a database; and performing iterative hash operation on the predetermined track coordinate sequence in combination with a time slice index, and storing a check value output by the operation as a reference hash check chain. According to the method, the real-time reliability of each network node can be quantified, so that the evaluation result focuses on the recent behavior performance, finally, the low-trust node is moved out of the routing topology according to the dynamic score, and a safe and purified transmission link is actively constructed; according to the whole set of processing flow, security reinforcement is carried out on a path from a key generation source to data transmission, so that the confidentiality of data content is ensured, and the availability and integrity of data transmission are ensured by dynamically cleaning network infrastructures.
Owner:HUBEI UNIV OF AUTOMOTIVE TECH

Urban rail vehicle electronic history data processing method

The present application provides a kind of urban rail vehicle electronic history data processing method, the method establishes vehicle operation configuration in combination with vehicle structure design, and vehicle configuration data structure is structured using database technology;Vehicle history data granularity refined to the smallest maintainable unit is used, the correctness and timeliness of data are guaranteed through data analysis and integration technology based on business process, the whole life cycle stage document of vehicle is stored using data storage technology, and preliminary vehicle knowledge framework is established in combination with full-text search technology, to provide basic data support for later subway vehicle procurement, technical reform, operation.In history data management, block chain technology is added to ensure the confidentiality and integrity of data flow, to prevent sensitive data from being leaked and tampered with during transmission, and to enhance the security and correctness of vehicle history data, to provide reliable data security guarantee for subsequent history sharing.
Owner:BEIJING MASS TRANSIT RAILWAY OPERATION CORPORATION LIMITED

Adaptively Secure Attribute-Based Encryption Using Witness Encryption

The present disclosure provides a method for secure message encryption and decryption using witness encryption. The method includes generating a master public key and a master secret key, generating common reference strings for a non-interactive zero-knowledge (NIZK) proof system and a commitment scheme, creating commitments using random values, and setting the master public and secret keys. A function key is generated by creating a dummy function tag and a NIZK proof. Message encryption involves generating a dummy input tag and creating a witness encryption ciphertext. The encrypted output includes attributes, the dummy input tag, and the witness encryption ciphertext. Decryption is performed using the function key and a witness decryption algorithm. The method enables secure message transmission with confidentiality and integrity throughout the encryption and decryption phases.
Owner:NTT RESEARCH INC

Safe acquisition method and device of BMC information, equipment and medium

The invention relates to the technical field of BMC security, and provides a security acquisition method and device of BMC information, equipment and a medium, and the method comprises the steps: generating a one-time public key and a one-time private key for a single communication session according to a self MAC address and real-time time; performing hash operation on the one-time public key to obtain a one-time public key hash value; sending the one-time public key hash value to a key management server, so that the key management server signs the one-time public key hash value by using a preset private key, and receiving a returned signature result; packaging the one-time public key and the signature result into a request message, and broadcasting the request message to a local area network to enable the BMC to generate and return an encrypted response message after signature verification; and monitoring and receiving an encrypted response message returned by the BMC, decrypting the encrypted response message by using the one-time private key, and extracting and displaying BMC information. According to the technical scheme, confidentiality, safety and integrity of the response information in the transmission process are guaranteed.
Owner:NINGCHANG INFORMATION TECH (HANGZHOU) CO LTD

Customized network interface card oriented to intranet security access and design method thereof

The invention discloses a network interface card with autonomous access authentication, and provides an integrated hardware authentication mechanism. The EAP-TLS client protocol stack is integrated on the bottom layer of the network card, so that the defect that an authentication module depends on a host system, manual intervention and the like in the existing scheme is overcome, TLS handshake and certificate verification are independently completed on the network card side, and authentication interaction is automatically initiated. The network interface card serves as a unique identity certificate of an access network, a client certificate and a corresponding private key are embedded in the network interface card and are stored in a protected nonvolatile area, and data confidentiality is effectively enhanced. The network card is used as an identity certificate and network access equipment at the same time, and the integrated design reduces the dependence on the service capability of management personnel. A traditional physical network card and an automatic authentication protocol are fused, and the method is suitable for application environments with high requirements for access control and authentication safety, such as an enterprise intranet and a government affair private network.
Owner:INFORMATION TECH RES INST OF EXIT & ENTRY MANAGEMENT OF THE NAT IMMIGRATION ADMINISTRATION

Isolation-Based Confidentiality

Systems and techniques for isolation-based confidentiality are described. In one example, a processor is communicatively coupled to memory accessible by multiple applications. The processor requests a private memory region in the memory for data of a first application of the multiple applications. The processor causes the data of the first application to be stored in the private memory region without encryption (e.g., in an unencrypted format). The data in the private memory region is not accessible by the other applications of the processor or other processors. In this way, confidentiality is provided for sensitive data without the overhead required of traditional encryption techniques.
Owner:ADVANCED MICRO DEVICES INC

Remote monitoring and scheduling management and control platform for signal shielding equipment

The invention discloses a remote monitoring and scheduling management and control platform for signal shielding equipment, which comprises a general control center and four linkage sub-modules, wherein the four linkage sub-modules realize data interaction with the general control center through an encryption special communication protocol; the four linkage sub-modules are respectively a secret-involved subject permission shielding linkage module, a multi-scene shielding mode adaptation module, a precise anti-secret-stealing shielding module and a full-link monitoring traceability module; the general control center is internally provided with a multi-dimensional confidential risk decision-making engine, the decision-making engine is integrated with a weighted scoring algorithm, and accurate binding of confidential subject qualification and a shielding strategy is achieved. Based on a double-biological-characteristic cross verification mechanism and carrier circulation management and control logic, personnel confidentiality qualification, carrier confidentiality-related state and shielding permission are deeply associated, confidentiality-related risks caused by access of non-qualified personnel are completely eradicated, meanwhile, shielding strategy automatic switching of the whole carrier access process is achieved, the problem that platform personnel permission is disjointed from a protection strategy is solved, and the safety of the platform is improved. And the basic protection safety of a secret-related area and a carrier is greatly improved.
Owner:BEIJING TIANYUAN JEBSEN ELECTRONIC TECHNOLOGY SERVICES CO LTD

Method and system for mandatory access control during container operation based on path mark

The invention discloses a path mark-based mandatory access control method and system during container operation. The method comprises the following steps of: generating a security mark for a container process and a file; executing dynamic access control, and dynamically starting a security model according to the file marking field; dynamic mark adjustment is implemented, the file access frequency is counted in real time through a kernel layer, and when overrun access is detected, if the process confidentiality level is higher than the lowest level, the confidentiality level is degraded; if the process is the lowest level, the BLP model verification permission of the process is temporarily forbidden; all strategy updating and audit log recording are completed locally, and it is ensured that the operation track is traceable; the system comprises a path marking module, an access control module, a dynamic regulation and control module, a strategy management module and a log auditing module. According to the method, error interception is reduced, millisecond-level real-time blocking of high-frequency abnormal access is realized, and the safety protection capability and the operation and maintenance efficiency of the container platform are remarkably improved.
Owner:NARI INFORMATION & COMM TECH

Data exchange and execution method, system and device for protecting data privacy and medium

The invention relates to the technical field of data security, and relates to a data exchange and execution method, system and device for protecting data privacy and a medium, the method comprises the following steps: acquiring sandbox environment information created by a user side, dynamically creating and configuring an isolation container, loading sample data based on the operation authority of the user side, and storing the sample data in a database; generating a temporary access link with time limit and returning the temporary access link to the user side; writing an algorithm in the sandbox environment for the user side according to the access link to perform static security detection to obtain a detection result, and auditing the detection result and algorithm metadata to obtain a security detection report; auditing the security detection report and the algorithm metadata, setting access authority, encrypting the algorithm, and transmitting the encrypted algorithm to a production environment to execute the algorithm; after the algorithm is executed, the output result is encrypted and stored, and the encrypted result is authorized to be delivered to the corresponding user side, so that the user side decrypts the result through the private key. The algorithm has confidentiality and integrity during cross-environment transmission.
Owner:CHINA ELECTRONICS CLOUD DIGITAL INTELLIGENCE TECH CO LTD

Android SoftPOS trusted application method and application system

The invention discloses an Android SoftPOS (Point Of Sale) trusted application method and an Android SoftPOS trusted application system. The method comprises the following steps: an application end initiates an authentication request to an application proof server, and obtains verification data and a plurality of random numbers; carrying out equipment and application integrity verification, generating an integrity proof and a hardware authentication certificate, and submitting the integrity proof and the hardware authentication certificate to a server; after the server passes the verification, signing and issuing a specific safety communication certificate of the equipment to the application end; and the application end establishes a secure communication channel with the server according to the certificate. Through multi-stage verification and a random number mechanism, it is ensured that only trusted equipment and applications can complete authentication, end-to-end secure communication is achieved by combining dynamic certificate signing and issuing, the confidentiality and integrity of payment data are remarkably improved, and the security risk is reduced.
Owner:SHENZHEN TOPWISE COMM CO LTD

Intelligent household equipment communication method driven by physical unclonable function

The invention relates to the technical field of smart home devices, in particular to a smart home device communication method driven by a physical unclonable function, which is used for establishing a secure session between a resource-limited initiating device and a resource-limited receiving device, and comprises the following steps: A, generating a physical unclonable function key; b, anti-quantum key negotiation; c, combining identity authentication and signature; d, establishing a secure session key; and E, safely transmitting the instruction. According to the method, the non-persistent key is generated and established through the physical unclonable function key, so that the problems of physical attack and key stealing are solved; anti-quantum key negotiation and lattice ciphertext de-encapsulation provide anti-quantum security, and the problem of future calculation threats is solved; identity authentication and signature are combined to realize single handshake, delay and power consumption are reduced, and the requirements of low power consumption and high efficiency are met; drift calibration is implemented, so that the stability of the key of the physical unclonable function is guaranteed, and the reliability is improved; and the confidentiality and the integrity of the instruction are ensured by the final secure transmission of the instruction.
Owner:DONGGUAN LAIMSEN TECH BUILDING MATERIAL CO LTD

Local data security storage method for non-networked vehicles

The invention discloses a local data security storage method for a non-networked vehicle, which comprises the following steps of: setting a vehicle-mounted MP5 (Mobile Pentium 5), and storing local data through the vehicle-mounted MP5; setting a three-level storage architecture for the vehicle-mounted MP5, and storing vehicle static information into a configuration data area; storing the operation parameters into a runtime data area according to a time sequence; storing the fault event into an event data area; implementing a hierarchical encryption strategy on data, performing full disk encryption on storage equipment, performing independent file encryption on sensitive data files, and implementing additional character encryption on key fields; an encryption key is derived based on a vehicle VIN code and a user PIN, a circular buffer management mechanism is established, and a secure data export interface is provided. According to the invention, the confidentiality, integrity and availability of vehicle local data can be improved, and the safety and reliability of vehicle data storage are improved.
Owner:ANHUI JIANGHUAI AUTOMOBILE GRP CORP LTD

Workflow authority control method and system based on quantum encryption mechanism

The invention discloses a workflow permission control method and system based on a quantum encryption mechanism. The method comprises the following steps: in response to a submitted application, obtaining a first quantum process key and a first quantum group key; performing encryption processing on the applied service data according to the first quantum process key; performing encryption processing on the applied permission data according to the first quantum group key; in response to an approval request for the application, decrypting the permission data according to the first quantum group key, and determining an approval permission of an approval request object; and decrypting the service data by using the first quantum process key according to the approval authority. Thus, during examination and approval, the authority data is decrypted through the first quantum group key to verify the authority, then the service data is decrypted by using the first quantum process key as required, and the preposed authority protection is constructed, so that the situation that a non-approver obtains information beyond the authority can be effectively intercepted, and the problem that the non-approver tends to be the approver to divulge is solved to a certain extent; and the confidentiality of the application information is ensured.
Owner:中电信量子信息科技集团有限公司

Method and system for protecting source code privacy in memory error detection

The invention discloses a method and a system for protecting privacy of source codes in memory error detection, belongs to the technical field of computer software security, and particularly relates to a technology for protecting confidentiality of the source codes in a third-party memory error analysis process of software. According to the method, a debugging information minimization processing system DIREDUCER is constructed, a selective deletion and type minimization technology is utilized, on the premise that complete source codes are not exposed, necessary debugging information used for memory error detection is effectively reserved, and dual guarantee of source code privacy and memory error detection effects is achieved. According to the method, the debugging information in the non-stripping binary file is compressed to be within 10% of the original volume, and the recognition capability of an analysis tool on the problems such as memory leak, buffer overflow and overhanging pointers is not remarkably reduced. Experimental results show that the method has good adaptability and expandability in actual deployment, is suitable for various debugging tools and binary analysis frameworks, and has wide application prospects and practical values.
Owner:NANJING UNIV

Multi-medical image encryption method with tampering localization capability

The invention provides a multi-medical image encryption method with tampering localization capability, and aims to solve the problems of security and integrity of digital medical images in transmission and storage, and the core is to provide localized tampering prevention capability. According to the method, firstly, a novel two-dimensional S-type logarithmic chaotic mapping 2D-SLCM is utilized to generate a secret key and a chaotic sequence which are highly related to plaintext content so as to resist differential attacks; then, performing efficient compression on each medical image by adopting a block compressed sensing (BCS) technology to ensure the transmission efficiency; in the encryption stage, data confidentiality is ensured through a multi-layer encryption process including local binary tree traversal scrambling and global random block scrambling; most importantly, an encrypted unique digital watermark is embedded into each image before the images are merged; the dual mechanism not only can detect the tampering behavior, but also can accurately identify which image in the multi-image set is damaged by verifying the watermark extracted from each image, thereby ensuring the reliability of residual data.
Owner:安阳市肿瘤医院

Codebook-based homomorphic encryption for efficient and privacy-preserving data processing

The codebook-based homomorphic compression system is a novel approach that combines data compression and homomorphic encryption to enable efficient and secure computation on compressed data. It involves quantizing the input data, generating an optimized codebook using techniques like Huffman coding or deep learning, and compressing the data by replacing each value with its corresponding codeword. The compressed data is then encrypted using a homomorphic encryption scheme, such as the Paillier cryptosystem, allowing computations to be performed directly on the encrypted compressed data without decryption. Homomorphic properties of the encryption scheme enable operations like addition and multiplication on the ciphertexts, while preserving the confidentiality of the underlying data. The system also incorporates error correction techniques to mitigate the impact of quantization and encryption on the accuracy of the computations. This approach combines the benefits of data compression and homomorphic encryption, enabling efficient storage, transmission, and secure computation on compressed data.
Owner:ATOM BEAM TECHNOLOGIES INC

Secure tunnel access to remote client resources for artificial intelligence agents

Systems are disclosed for enabling secure cloud connections between artificial intelligence (“AI”) agents and client resources. A cloud connector executing at a client establishes an authenticated secure tunnel with a connection manager on a connection server. An AI agent is initiated to access cloud- and client-hosted AI models or data sources. The system uses guardrails to process inputs and outputs over the secure tunnel with the client, detecting prompt injection, confidential information, or personally identifiable information. Redundant secure tunnels and load balancing can be employed to ensure availability. Modified results are transmitted to a user device for display, providing AI agents with controlled access to client resources while enforcing confidentiality, integrity, and policy compliance.
Owner:AIRIA LLC

Method and system for bidirectional authentication and session key negotiation of NFC passive lock

The invention belongs to the technical field of key agreement, and particularly relates to a bidirectional authentication and session key agreement method and system for an NFC passive lock, and the method comprises the following steps: S1, a mobile phone side generates a first temporary private key and a first random number, and carries out the first temporary private key agreement on the basis of an identity label of the NFC passive lock, the first random number, and a first base point G and a second base point P of an elliptic curve; and calculating a first temporary public key by using the first hash function, and sending the first temporary public key and the first random number to the NFC passive lock. According to the invention, on the premise that the hardware storage burden of the NFC passive lock is not increased, safe bidirectional authentication and key negotiation are realized, the capability of resisting physical attacks and network attacks is improved, and the confidentiality and integrity of communication are guaranteed.
Owner:HANGZHOU SCIENER INTELLIGENT CONTROL TECH CO LTD

System and computer-implemented method for preserving model confidentiality during graph optimizations

A system and method are described which provide a unique obfuscation mechanism for conducting performance optimization of deep neural network (DNN) computational graphs. The method obfuscates performance optimization in three steps. First, an obfuscation step where the original computation graph is obfuscated such that an adversary cannot feasibly identify the original model, thus providing confidentiality. Second, the optimization step is carried out flexibly and independently by the optimizer party on the obfuscated computational graph, providing performance speedups. Finally, the de-obfuscation step where the original model is retrieved by the model owner in its optimized form.
Owner:CENTML AI INC

Database autonomous protection method based on dual-system architecture

The invention discloses a database autonomous protection method based on a dual-system architecture, and belongs to the technical field of database information security. The static measurement agent calculates SM3-256 hash values for all key files of a database in a trusted environment, and the SM3-256 hash values serve as static trusted references to be uploaded and safely stored to a trusted analysis center. And the dynamic measurement agent loads an eBPF program to enter a baseline learning mode. The monitoring and intelligent response during operation comprises static monitoring, dynamic monitoring and correlation analysis and response. Through the design of the dual-system architecture, the protection system and the computing system run in parallel, and the continuous protection capability of the database system is realized. Therefore, the database system has deep security protection capability, and confidentiality, integrity and availability of the database system can be effectively guaranteed when the database system is faced with known and unknown threats.
Owner:BEIJING UNIV OF TECH

Time-sensitive network end-to-end secure communication method

The invention relates to a time-sensitive network end-to-end secure communication method, and belongs to the technical field of communication. According to the method, a TSN terminal system of Linux is used for realizing bidirectional identity authentication and key agreement based on an SM2 cryptographic algorithm, and an SM4-CCM algorithm is used for realizing time-sensitive network security communication and data integrity verification; the SM2 national secret algorithm is an asymmetric encryption algorithm, a signature pair is generated based on an elliptic curve discrete logarithm problem, the two parties negotiate a shared key through elliptic curve point operation, a public key of a receiver is used for encryption, and only a private key can be used for decryption; sM4-CCM is a combination of an SM4 block cipher algorithm and a CCM mode, and is used for providing confidentiality, integrity and authenticity of data; according to the CCM mode, through combination of CTR encryption and CBC-MAC authentication, efficient authentication encryption is realized. The method can be used for real-time secure communication in a high-reliability industrial scene.
Owner:CHONGQING UNIV OF POSTS & TELECOMM