Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

48 results about "Critical infrastructure" patented technology

Critical infrastructure (or critical national infrastructure (CNI) in the UK) is a term used by governments to describe assets that are essential for the functioning of a society and economy – the infrastructure.

Key infrastructure risk identification method and device in flood disaster chain scene

The invention discloses a key infrastructure risk identification method and device in a flood disaster chain scene. The device comprises an acquisition module used for acquiring multi-source data and performing time-space alignment and fusion processing; the extraction module is used for extracting spatio-temporal evolution characteristics of a flood disaster chain based on the multi-source data; the construction module is used for constructing a key infrastructure coefficient according to the prior infrastructure information; the coupling module is used for coupling the spatio-temporal evolution characteristics and the key infrastructure coefficient, and calculating a regional risk index through a dynamic coupling coefficient and a space sensitivity factor; and the early warning module is used for generating a risk space distribution map and triggering dynamic early warning. According to the technical scheme, through multi-source data collection and space-time fusion, the space-time evolution characteristics of the flood disaster chain are extracted, key infrastructure coefficients based on information of buildings, roads, population and the like are constructed, the regional risk index is calculated through dynamic coupling, risk distribution is visually reflected, accurate early warning and emergency response are achieved, and the reliability of the system is improved. The urban disaster prevention and reduction level is effectively improved, and the public safety guarantee efficiency is remarkably enhanced.
Owner:YUNNAN UNIV

Systems and methods for formal verification of computer platforms

Systems and methods for mathematical modeling of the hardware and software stack of commodity computer platforms are provided, enabling provable guarantees on memory, device, and program execution. This approach addresses the technical problem of reliance on system agents that rely on implicit trust in the operating environment, which can be exploited by sophisticated attackers using complex threats such as memory access exploits and code / data integrity exploits. The solution provides a proactive, mathematically-backed security solution that eliminates entire classes of cyberattacks by design, ensuring realizable guarantees on commodity computer platforms running hardware and software stack elements at the lowest operating level. This approach has significant advantages over current reactive cybersecurity methods, including reduced complexity and overhead, and increased confidence in the integrity of the system. The solution's main uses include providing mathematically-backed security and availability guarantees for critical infrastructure, financial institutions, and other organizations vulnerable to cyberattacks.
Owner:UBERSPARK INC

Counter measure strategy construction method and system based on attack intelligence

The invention belongs to the technical field of network security, and discloses a countering measure strategy construction method and system based on attack intelligence. According to the method, firstly, multi-source attack intelligence is fused, and a causal time sequence attack knowledge graph is constructed; then, mapping the atlas on a digital twinborn model based on the IEC 62443 standard, constructing a Bayesian attack graph, and quantifying the risk of each attack path; then, taking the risk, the cost and the operation influence as multiple targets, and adopting an NSGA-II algorithm to generate a Pareto optimal countering strategy set; further, an optimal robust strategy is selected from the strategy set by solving the Stackelberg safety game model; and finally, explaining the decision process by using an interpretable AI technology. According to the method, the problems of passive threat intelligence analysis, static risk assessment, sub-optimal strategy selection and opaque decision-making process in the prior art are solved, and active, quantitative, optimal and credible defense decision-making for the key infrastructure is realized.
Owner:GUANGXI POWER GRID CORP

Encryption-decryption scheme for detecting linear spoofing attack in cyber-physical system

The invention discloses a novel encryption-decryption scheme, and aims to detect and defend linear spoofing attacks on a cyber-physical system (CPS). With the wide application of CPS in key infrastructures such as industrial automation, smart power grids and automobile systems, it is particularly important to ensure the safety and integrity of CPS. Linear spoofing attacks are malicious behaviors, normal operation of the linear spoofing attacks is interfered by controlling input or output of a system, and a traditional security mechanism is often difficult to effectively cope with the type of attacks. According to the invention, an encryption algorithm is designed to protect data transmission of the CPS, and the encryption algorithm is combined to recover original data and identify potential attack signs at the same time. According to the scheme, the combination of the cryptography technology and the signal processing method is utilized, the data stream can be monitored in real time, and the possible linear attack is identified by analyzing the change of the data before and after encryption. In addition, according to the scheme, calculation efficiency and implementation feasibility are considered, and it is ensured that necessary safety guarantee is provided on the premise that system performance is not affected. Experimental results show that the proposed encryption-decryption scheme can effectively detect linear spoofing attacks in the cyber-physical system, and has relatively low false alarm rate and missing report rate. In addition, the scheme shows good adaptability and robustness in practical application, and provides a new thought and technical support for the security protection of the CPS in the future.
Owner:QINGDAO UNIV

System and method for sensor placement, configuration and tracking

A system and method for placing and configuring physical security sensors & barriers, are described. The system generates and analyzes a three-dimensional model of a customer's premises using non-imaging sensors to determine optimal sensor placement. Based on customer requirements, the system distributes sensor models within the premises while accounting for environmental obstructions, coverage gaps, and redundancy minimization. An extended reality (XR) interface allows users to visualize and refine sensor configurations before deployment. The system integrates AI-driven analytics to optimize surveillance coverage, adjust sensor orientations dynamically, and generate detailed reports outlining sensor locations and configurations. The sensor stand transmits real-time data to the system for continuous monitoring, predictive maintenance, and security threat analysis. The system enhances security planning by reducing design time, installation costs, preventing post-deployment modifications, and ensuring comprehensive monitoring coverage across diverse environments, including commercial, industrial, and critical infrastructure sites.
Owner:4LIBERTY INC

APT attack defense method based on edge intelligence

The invention discloses an APT (Advanced Persistent Threat) attack defense method based on edge intelligence, which aims to improve the dynamic perception capability, strategy response capability and resource adaptability of an edge network to APT attacks, and comprises the following steps of: firstly, constructing a topological adjacency matrix of an edge node communication network and defining five states and state conversion processes of a life cycle of edge equipment; the method comprises the following steps: firstly, designing an attack defense model based on optimal control and differential game, then introducing a system evolution model based on hidden confrontation, and accurately simulating dynamic interaction of attack and defense in an actual edge network, secondly, designing an attack defense model based on optimal control and differential game, and finally, adopting a Nash strategy reinforcement learning mechanism based on a multi-agent deep Q network, optimizing an edge game strategy, and finally, obtaining an attack defense result. And the attack detection performance is improved. According to the method disclosed by the invention, the modeling precision and defense effectiveness of the system in a complex APT attack scene are remarkably improved, and the method is suitable for key infrastructure network environments with relatively high requirements on safety, timeliness and expandability, such as industrial Internet and Internet of Things.
Owner:HANGZHOU NORMAL UNIVERSITY

Energy yield management software system for industrial grade solar microgrids and critical infrastructure

In one aspect, a computerized system of an Energy Yield Management Software (EYMS) framework includes an Industrial Grade Solar Microgrids (IGSM) deployment comprising a control unit configured to communicate with a power generating source, collect data from the power generating source, and issue instructions to the power generating resource. The control unit is further configured to communicate with a sensor, an automation module, a local load, an energy storage systems, or a generation resource within a customer IGSM deployment. The EYMS is configured to communicate through a communication network to the IGSM deployment. A Digital Twin configured to actively use real time and historical data to learn how each component in the IGSM performs under a plurality of operational conditions and characteristics, wherein a predictive model is employed by the Digital Twin for a prediction operation, an optimization operation and a prescriptive maintenance operation of the IGSM.
Owner:CHOUDHURY AMIT +1

System and Method for Analyzing Cyber Security Postures and Real-Time Asset Validation for Critical Infrastructure

A system and method for analyzing cybersecurity posture for an OT infrastructure includes categorizing a plurality of devices of one or more plants into levels, based on an exposure of each device to a communication network, identifying CVEs of components of the plurality of devices; assigning a severity value to the one or more CVEs of components and determining a plant cybersecurity posture score for the one or more plants; computing a critical infrastructure cybersecurity posture score for the OT infrastructure; and applying remediation to one or more vulnerable components based on a prioritization sequence.
Owner:ABB (SCHWEIZ) AG

The method of using seismic sensors to monitor the health and safety of infrastructure, facility sites, and humans

This disclosure describes systems, methods and workflows; computer-implemented methods; computer software products; and ML models for real-time monitoring of the infrastructures in modern cities, including bridges, road tunnels, airports, buildings, and wind turbine towers, utilizing seismic data. The monitoring is not restricted solely to the recorded seismic data. This disclosure also emphasizes the importance of monitoring various critical infrastructures using seismic sensors, including security sites and manufacturing facilities, to enhance safety and security, detect infrastructure health, and prevent unauthorized intrusions. Additionally, seismic sensors can be used to monitor indoor human activity. Bridge monitoring involves continuous assessments to ensure structural integrity and longevity, while road tunnel monitoring focuses on optimizing traffic conditions and monitoring structural images. Monitoring at airports improves runway safety and ensures optimal performance of the aviation infrastructure, minimizing potential risks and enhancing overall safety and efficiency in air travel. Deploying seismic sensors to monitor a building's infrastructure enables the detection and location of potential risks to the building structures. Monitoring wind turbine towers is crucial for optimizing green energy production and ensuring the structural health of the turbines. Security and manufacturing sites are monitored to ensure the safety and security of the facilities and prevent unauthorized intrusions. By monitoring and analyzing seismic data of human activities in rooms, one can identify different types of activities and detect instances of walking and falling. By employing seismic sensors and real-time processing of the seismic data, these monitoring systems collectively contribute to the safety, security, resilience and reliability of vital infrastructures in various domains.
Owner:BAFANG SEISMIC INC

Unmanned aerial vehicle real-time countering method for LoRa communication protocol

The invention belongs to the technical field of wireless communication interference in the field of wireless communication security and unmanned aerial vehicle security, and particularly relates to an unmanned aerial vehicle real-time countering method for a LoRa communication protocol, which comprises the following steps: step 1, continuously monitoring electromagnetic signals, and finding a target LoRa signal in the electromagnetic signals; 2, analyzing signal parameters; the method comprises the following steps: analyzing a captured remote controller signal to obtain parameters required for sending an interference signal by a center frequency (Freq), a bandwidth (BW), a preamble length (preamble Length) and a spreading factor (SF); step 3, sending an interference signal; and sending an interference signal according to the signal parameters analyzed in the step 2, wherein the interference signal is used for interfering communication between the remote controller and the unmanned aerial vehicle. The method comprises a detection part and an interference part, and is used for protecting key infrastructures, important activities and sensitive areas from threats possibly brought by an unmanned aerial vehicle of a LoRa communication protocol.
Owner:BEIJING INST OF TECH

A Heuristic Dynamic Path Optimization Method for Physical Protection Systems in 3D Scenes

This invention provides a heuristic dynamic path optimization method for physical protection systems in a three-dimensional scene, comprising the following steps: Through three-dimensional path direction planning, beacon point setting, and detection point distribution estimation based on a geometric model, a perspective representation of virtual interwoven profiles between different floors in a virtual three-dimensional space is established based on the structural and connection characteristics of upper and lower floors of a building in three-dimensional space. The three-dimensional path planning direction is determined through adjacent grid cell mapping of each level profile, and agent recognition is achieved using ray detection functionality in Unity. Based on beacon points and detection probability estimation based on a geometric distribution model, a three-dimensional heuristic reverse path planning algorithm is constructed to achieve dynamic path planning and navigation for adversaries or agents. Based on the EASI model theory, the system interception probability is dynamically searched and calculated along the path planning direction to effectively identify the weakest path in the system, which is used for the optimization and improvement of critical infrastructure entity security protection design.
Owner:SOUTH CHINA UNIV OF TECH

System and method for sensor placement, configuration and tracking

A system and method for placing and configuring physical security sensors & barriers, are described. The system generates and analyzes a three-dimensional model of a customer's premises using non-imaging sensors to determine optimal sensor placement. Based on customer requirements, the system distributes sensor models within the premises while accounting for environmental obstructions, coverage gaps, and redundancy minimization. An extended reality (XR) interface allows users to visualize and refine sensor configurations before deployment. The system integrates AI-driven analytics to optimize surveillance coverage, adjust sensor orientations dynamically, and generate detailed reports outlining sensor locations and configurations. The sensor stand transmits real-time data to the system for continuous monitoring, predictive maintenance, and security threat analysis. The system enhances security planning by reducing design time, installation costs, preventing post-deployment modifications, and ensuring comprehensive monitoring coverage across diverse environments, including commercial, industrial, and critical infrastructure sites.
Owner:4LIBERTY INC

A GNSS timing data prediction method and related equipment

This invention relates to the field of navigation and timing technology, specifically to a GNSS timing data prediction method and related equipment. The method involves acquiring Roland timing data when GNSS timing data is invalid and preprocessing it. The preprocessed data is then input into a trained single-hidden-layer extreme learning machine model. This model calculates the hidden-layer output matrix by randomly initializing the input layer weight matrix and bias vector, and solves for the output weights using regularized least squares. The model outputs a normalized GNSS timing data prediction value, which is then denormalized to obtain the final GNSS timing prediction result. This method combines the high stability of the Roland system with the efficient computational power of the extreme learning machine to achieve accurate GNSS timing data prediction. It is suitable for enhancing the resilience of positioning, navigation, and timing systems in critical infrastructure scenarios, ensuring the continuous operation of the system even when GNSS signals are interfered with or fail.
Owner:NAT TIME SERVICE CENT CHINESE ACAD OF SCI

Ai-enabled device ownership identification for securing nationwide critical infrastructure systems

Various techniques for providing artificial intelligence-enabled (AI-enabled) device ownership identification for securing nationwide critical infrastructure systems are disclosed. In some embodiments, a system / process / computer program product for providing artificial intelligence-enabled (AI-enabled) device ownership identification for securing nationwide critical infrastructure systems includes discovering vulnerable devices across a plurality of networks; automatically identifying device owners using a large-language model (LLM); and automatically enriching the discovered vulnerable devices with sector, location, and point of contact (POC) information.
Owner:PALO ALTO NETWORKS INC

Systems and methods for formal verification of computer platforms

Systems and methods for mathematical modeling of the hardware and software stack of commodity computer platforms are provided, enabling provable guarantees on memory, device, and program execution. This approach addresses the technical problem of reliance on system agents that rely on implicit trust in the operating environment, which can be exploited by sophisticated attackers using complex threats such as memory access exploits and code / data integrity exploits. The solution provides a proactive, mathematically-backed security solution that eliminates entire classes of cyberattacks by design, ensuring realizable guarantees on commodity computer platforms running hardware and software stack elements at the lowest operating level. This approach has significant advantages over current reactive cybersecurity methods, including reduced complexity and overhead, and increased confidence in the integrity of the system. The solution's main uses include providing mathematically-backed security and availability guarantees for critical infrastructure, financial institutions, and other organizations vulnerable to cyberattacks.
Owner:UBERSPARK INC

Key infrastructure network attack tracing method based on dynamic risk assessment

The invention discloses a key infrastructure network attack tracing method based on dynamic risk assessment, and particularly relates to the technical field of network and information security, session watermarks are generated through an entrance side, source aperture records are unified, a session chain is formed through cross-domain splicing, and a command sequence and assets are aligned; auditing records and measurement are extracted on the equipment side according to the command track, fluctuation irrelevant to the command is eliminated through adjacent comparison, and stable equipment response is obtained; a window alignment robust index and a command effect sensitive index are put forward, a discrimination rule is synthesized to generate a stripping sequence basis, commands are imported piece by piece in an isolation replay environment, a minimum command subset is selected in combination with a unified trade-off factor, and causal matching is verified through dynamic sorting of stripping strength coefficients. A matching result is backfilled to generate a responsibility-accounting label, settlement is performed to a dynamic risk vector, a disposal priority is formed, and the whole process can be audited and rechecked; the method solves the problems of evidence splitting, cause and effect unconfirmation and unstable responsibility of key infrastructures in a multi-hop environment.
Owner:WUHAN ANYU INFORMATION SECURITY TECH CO LTD

Urban key infrastructure toughness evaluation method under typhoon disaster and related device

The invention belongs to the technical field of natural disaster risk and infrastructure toughness evaluation, and discloses an urban key infrastructure toughness evaluation method under typhoon disasters and a related device, and the method comprises the steps: obtaining typhoon disaster data, analyzing main risk factors, and obtaining a risk factor set and a cascade disaster set; analyzing risk factors in a risk factor set contained in the typhoon disaster needing to be analyzed, and obtaining a risk factor coupling type and frequency; acquiring the coupling degree of different risk factors by using the N-K model and the frequency of the risk factor coupling type, and further determining the risk factor which is most easily coupled with other risk factors; decoupling each cascade disaster in the cascade disaster set by using the interpretation structure model to obtain an evolution path of the cascade disaster and further obtain a key node; and determining the failure probability of the key nodes in the selected region by using the interpretation structure model, and evaluating the failure probability by using a sorting centroid method. According to the invention, key infrastructure failure early warning can be realized.
Owner:XI'AN UNIVERSITY OF ARCHITECTURE AND TECHNOLOGY

Power-Aware: DFOS Deployment A Hybrid Heuristic and Integer Linear Programming Strategy

A novel, two-stage Distributed Fiber Optic Sensor (DFOS) placement strategy and method that ensures resilient monitoring of critical infrastructure during electrical power supply failures. This strategy and method combines a heuristic algorithm, PURE (Power Source-aware Route Exploration), with Integer Linear Programming (ILP) optimization. The PURE algorithm explores potential DFOS routes while explicitly considering the dependency of DFOS devices on the electrical power distribution network, ensuring routes electrically powered by the same electrical power feeder are disjoint. Subsequently, the ILP selects the optimal set of DFOS placements to minimize the total number of deployed sensors while meeting critical infrastructure monitoring requirements, such as redundant monitoring for high-importance links. The method enhances the observability of critical links, achieving 100% monitoring coverage for important links during simulated power outages affecting an electric feeder.
Owner:NEC LABORATORIES AMERICA INC

Power grid network security anti-fact defense method based on multi-agent cooperation

The invention discloses a network security anti-fact defense method based on multi-agent collaboration, which comprises the following steps: deploying local defense agents with autonomous decision-making capability in different areas of a network, and setting a core defense agent oriented to global collaboration to carry out unified coordination and control on a multi-point linkage security policy; therefore, cross-region and cross-security domain cooperative defense is realized. The method is suitable for a power secondary system, an industrial control system, an industrial internet and other key infrastructure networks, and can also be popularized and applied to a cloud computing data center, a government affair private network and other network environments with complex topology and strict service continuity requirements. And the technical problems that an existing static boundary isolation and access control method lacks dynamic description capability on the influence of the service running state, the attack evolution process and cross-site linkage, and a timely, fine and interpretable defense decision is difficult to realize when the attack is quickly diffused or the service topology is frequently changed can be solved.
Owner:BENGBU POWER SUPPLY COMPANY STATE GRID ANHUI ELECTRIC POWER

Architecting resilience for enterprise ai: preventing data reconstruction, exfiltration, and unauthorized consequence in compromised ai environments

PCT designated stageWO2026176422A2Occurrence dataInterface (computing)
A computer-implemented security architecture prevents compromise of an artificial-intelligence workload, agent, model-orchestration platform, or application server from automatically becoming an enterprise-wide data breach, unrestricted semantic reconstruction, strategic-intelligence extraction, unauthorized cross-domain correlation, or unauthorized externally effective operation. Enterprise information is partitioned among independently controlled identity, content, relationship- mapping, and optional cryptographic-material domains such that protected components remain Technically Non-Joinable outside an authorized reconstruction session. A non-bearer Reconstruction Authorization Object (RAO) binds permitted fields, permitted association scope, authorized purpose, execution context, attested workload identity, tenant, session, policy epoch, jurisdiction, recipient, destination, disclosure conditions, and output scope to protected authorization state. Approved components are released as session-bound components and reconstructed only within a Protected Reconstruction Domain to create an ephemeral minimum-necessary representation without persistently reconstructing a complete semantically usable enterprise record outside the protected processing span. Where an artificial-intelligence server, autonomous agent, retrieval pipeline, model-orchestration framework, tool-use environment, vector-store interface, or application server is compromised, an attacker may attempt to reconstruct customer data, financial records, research assets, source code, intellectual property, product-development information, communications, operational intelligence, or strategic enterprise relationships. However, compromise of computation does not itself provide reconstruction authority, semantic association authority, or Release Authority. Generated Candidate Acts and Candidate Outputs remain sealed, capability-restricted, confined to protected state, or otherwise Non-Releasable while current execution-context correspondence, provenance continuity, permitted association scope, revocation state, policy epoch, destination, recipient, disclosure budget, inference-channel budget, and jurisdiction conditions are independently verified. A Protected Output Validation Receipt is committed before an output-specific Output Release Capability is generated, such that only a designated Output Release Boundary can render, transmit, invoke, store, commit, execute, or otherwise effectuate the verified result. The disclosed architecture establishes Execution–Consequence Decoupling, Mandatory Mediation, Technical Non-Joinability, and Technical Non-Completability, enabling enterprise artificial intelligence to compute without independently acquiring authority to disclose protected enterprise relationships or produce unauthorized external consequences. The architecture is applicable to enterprise AI, agentic AI, multi-agent systems, model-serving infrastructure, retrieval-augmented generation, vector databases, cloud computing, confidential computing, cybersecurity, telecommunications, financial services, healthcare, government systems, industrial automation, critical infrastructure, robotics, autonomous systems, and cyber-physical environments.
Owner:DAS SANGAM

Cross-domain collaborative emergency response and attack mitigation methods for critical infrastructure

This application relates to the field of cybersecurity technology and discloses a cross-domain collaborative emergency response and attack suppression method for critical infrastructure. The method includes: collecting and correlating security data from at least two independent security domains; performing identification and correlation analysis using a graph neural network model to generate a fused security posture describing a cross-domain attack chain; based on this fused security posture, generating an optimal collaborative response strategy with specific defensive actions and execution sequences through a preset attack-defense game model; parsing the strategy into layered security instructions to drive security execution devices within the target security domain to perform configuration operations; and coordinating security execution devices from multiple security domains to jointly address the cross-domain attack chain based on the configuration operations. This invention enables overall perception, intelligent collaborative decision-making, and integrated linkage suppression of high-level, cross-domain network attack chains, effectively improving the overall defense capabilities of critical infrastructure.
Owner:GUANGZHOU ELECTRIC POWER COMM NETWORK LTD

Reliable time synchronization device and method

PendingCN122293445ATime managementEngineering
This invention discloses a trusted time synchronization device and method, relating to the field of trusted time synchronization technology, including a trusted time management platform and a trusted time synchronization client. The trusted time management platform is used to complete platform identity authentication, service activation, time synchronization message and service management, real-time control of the time synchronization client, and time synchronization billing and evidence storage management. The trusted time synchronization client, based on dedicated hardware and a trusted execution environment, completes certificate application, login management, status reporting, time synchronization and metering management to achieve trusted time synchronization and accurate metering. This invention constructs a new trusted time synchronization system that is highly secure, verifiable, traceable, and operable, meeting the high reliability and commercial operation requirements of critical infrastructure for time benchmarks in the digital economy era.
Owner:SICHUAN TAIFU GROUND BEIDOU TECH CO LTD

Critical infrastructure blueprint selection for optimized response to state changing conditions

Critical infrastructure (CI) blueprint selection for optimized response to state changing conditions includes defining a hierarchy of interdependent CI elements of a community in a digital twin and receiving characterization data for different nodes of the digital twin. A fingerprint is generated for the hierarchy based upon the characterization and a blueprint which corresponds to the fingerprint retrieved from a data store, the blueprint defining a set of parameters to be applied to different computing elements of different nodes in the hierarchy determined to minimize a cascading effect of a state changing condition in one of the nodes. Finally, the set of parameters of the retrieved blueprint is applied to corresponding computing elements of the digital twin and a state changing condition is simulated in the digital twin in a selected node so as to compute the cascading effect of the state changing condition to other nodes dependent upon the selected node.
Owner:INLECOM GRP BV

Risk quantitative evaluation method for gateway-based system

The invention discloses a risk quantitative evaluation method for a gateway-based system, and the method comprises the following steps: S101, selecting a risk scene suitable for an evaluated gateway-based system from a pre-constructed risk scene library of the gateway-based system; s102, calculating and evaluating the information security risk of each risk scene selected in the step S101; and S103, summarizing the information security risks of all the risk scenes calculated in the step S102, and analyzing the overall information security risk condition of the assessed gateway-based system. According to the method, the attacker and the attacked person in the information security risk are comprehensively analyzed, and the isolated vulnerability is integrated into the attack process; meanwhile, when risk factors are evaluated, single-point values are changed into a distribution curve, through a simulation mode, the information security event occurrence probability quantification result and risk value quantification are subjected to dimension raising from the single-point values to the distribution curve, and the characteristics of dynamic nature and uncertainty of information security risks are highlighted.
Owner:THE FIRST RES INST OF MIN OF PUBLIC SECURITY

Power-aware DFOS deployment a hybrid heuristic and integer linear programming strategy

A novel, two-stage Distributed Fiber Optic Sensor (DFOS) placement strategy and method that ensures resilient monitoring of critical infrastructure during electrical power supply failures. This strategy and method combines a heuristic algorithm, PURE (Power Source-aware Route Exploration), with Integer Linear Programming (ILP) optimization. The PURE algorithm explores potential DFOS routes while explicitly considering the dependency of DFOS devices on the electrical power distribution network, ensuring routes electrically powered by the same electrical power feeder are disjoint. Subsequently, the ILP selects the optimal set of DFOS placements to minimize the total number of deployed sensors while meeting critical infrastructure monitoring requirements, such as redundant monitoring for high-importance links. The method enhances the observability of critical links, achieving 100% monitoring coverage for important links during simulated power outages affecting an electric feeder.
Owner:NEC LABORATORIES AMERICA INC

Autonomous agentic ai defense framework for critical infrastructure

The present invention relates to an autonomous agentic artificial intelligence based defense system for protecting critical infrastructure from cyber threats through continuous, validated, and adaptive security operations. The system employs distributed processing units configured to analyze operational telemetry, network communication data, and control signals in real time to identify deviations from established infrastructure behavior. Artificial intelligence based characterization logic is applied to correlate detected deviations with stored threat profiles and infrastructure parameters, followed by multi-stage validation to confirm threat authenticity and severity. Adaptive learning mechanisms dynamically update characterization thresholds and validation parameters based on historical incidents and evolving attack patterns, enabling continuous improvement without manual reconfiguration.
Owner:BHAND NILESH DNYANESHWAR

Micro-service-based low-code development framework and method

The invention provides a low-code development framework and method based on micro-service, relates to the technical field of computers, and solves the technical problems that in the prior art, diversified software development requirements of enterprises are difficult to meet, and resource conflicts, deployment coupling and service avalanche are likely to occur in the software development process. The framework specifically comprises service support design, micro-service design, storage design and deployment design. The service support design is used for providing key infrastructure and public service for the micro-service system; the micro-service design is used for constructing a series of small micro-services capable of independently bearing a service function based on a service field and a responsibility boundary; the storage design is used for selecting an adaptive storage scheme according to data characteristics and business requirements; the deployment design is used for supporting deployment and operation of the micro-service application under different operating systems. The method is used for secondary development of software products and customized software.
Owner:ANHUI SUN CREATE ELECTRONICS

Wide-beam anti-drone equipment

1. Name of the product in this design: Wide-beam anti-drone equipment. 2. Application of this design: It is used in temporary major security tasks, border areas, critical infrastructure and other occasions where drone control is required, and can effectively deal with various types of drones. 3. The key design feature of this product is its shape. 4. The image or photograph that best illustrates the design's key points: a 3D model.
Owner:ANHUI CIVIL-MILITARY INTEGRATION INFORMATION TECH CO LTD

Intelligent lock anti-theft and early warning method based on quantum security enabling and multi-mode sensing, intelligent lock, electronic equipment and medium

The invention belongs to the technical field of locks, and discloses an intelligent lock anti-theft and early-warning method based on quantum security enabling and multi-mode sensing, an intelligent lock, electronic equipment and a medium, the method comprises the following steps: providing multi-level authentication for a work order authorization instruction and user identity data by adopting a quantum key distribution technology; environment data of the intelligent lock are collected in real time through the multi-mode sensing technology, abnormal behaviors are recognized in combination with an artificial intelligence algorithm, risk assessment is automatically triggered, and an emergency processing work order is generated; the block chain technology is used for storing work order authorization and operation records, and the access authority of the intelligent lock is dynamically adjusted through edge calculation. According to the invention, the communication security is guaranteed in combination with quantum encryption, the abnormal behavior recognition capability is enhanced by using a multi-mode sensor, and risk prediction and adaptive protection are realized through an intelligent algorithm, so that the security protection level of key infrastructures and household access control is comprehensively improved, and core support is provided for energy digitization and smart city construction.
Owner:TIANJIN YINGDAXIN HYDROGEN ENERGY TECHNOLOGY CO LTD

An artificial intelligence secure running system and method based on a hardware one-way data channel and a network-free kernel

This invention discloses an artificial intelligence (AI) secure operation system and method based on a hardware unidirectional data channel and a network-free kernel. The system includes a data access unit, an isolated AI computing unit, a hardware unidirectional data channel, and a security management terminal. The hardware unidirectional data channel enables unidirectional data transmission from the data access unit to the isolated AI computing unit at the physical layer. The isolated AI computing unit runs an operating system kernel stripped of general network communication protocol stacks, preventing processes running within it from actively establishing external network connections. By combining a hardware-level unidirectional transmission structure with kernel-level network capability limitations, an AI operating environment with unidirectional data input is constructed. This invention also supports collaborative computing with remote computing nodes through a controlled encrypted tunnel under the control of the security management terminal, and can be used in high-security AI deployment scenarios such as finance, government affairs, and critical infrastructure.
Owner:吴英杰