Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

290 results about "Data decryption" patented technology

Decryption is the process of transforming data that has been rendered unreadable through encryption back to its unencrypted form. In decryption, the system extracts and converts the garbled data and transforms it to texts and images that are easily understandable not only by the reader but also by the system.

Systems and Methods for Password Management

Systems and methods are disclosed herein for a user to use a mobile device with a camera and a terminal device with a camera to manage and use passwords via QR (Quick Response) codes. The terminal device may generate and display a QR code for a user account or data. The user running a password manager app on the mobile device may scan the QR code of the user account or the QR code of the data to generate, store, and retrieve a password, and to display a QR code for the password. The terminal device may scan the QR code of the password to receive and use the password in sign-up, sign-in, data encryption, and data decryption procedures.
Owner:ZHOU HONGBO

Multi-party data cooperative exchange method, system, device, medium and product

The invention provides a multi-party data collaborative exchange method, system and device, a medium and a product, and belongs to the technical field of data information processing, and the method comprises the steps: in a data exchange process, after identity authentication of participants of data exchange is passed in a trusted space, carrying out the dynamic verification of the access authority of the participants based on the real-time attributes of the participants; under the condition that the dynamic verification is passed, executing data exchange in the trusted space to obtain a data exchange result; sending the data exchange result to a data decryption party corresponding to the data user, so that the data decryption party decrypts the data exchange result; wherein the real-time attributes of the participants comprise real-time environment attributes, behavior attributes of the participants and static attributes of the participants. When the access permission is verified, transition from role-based access control to behavior-based access control is realized on the basis of dynamic combination of multi-dimensional attributes, and dynamic control on the access permission is realized on the aspect of finer granularity.
Owner:INSPUR TIANYUAN COMM INFORMATION SYST CO LTD

Hospital data integration and intelligent management system based on multi-source data

The invention discloses a hospital data integration and intelligent management system based on multi-source data, and particularly relates to the field of medical data management. Comprising a multi-source heterogeneous data acquisition layer, a self-adaptive data fusion engine, a privacy enhanced distributed storage layer, a multi-modal intelligent analysis center, a clinical decision enhancement module, a self-adaptive resource scheduling module and a full-process auditing and tracing module. Through cooperation of multi-modal model fusion, the clinical decision support accuracy is improved, the self-adaptive learning capability is achieved, the risk of data decryption leakage is avoided, 100% coverage of audit tracing and full-process operation of block chain evidence storage recording can be completed, the abnormal access detection rate is greatly improved, resource scheduling optimization is carried out, the equipment vacancy rate is reduced, and the method is suitable for large-scale popularization and application. A particle swarm optimization algorithm is combined with a digital twinborn technology, resource allocation is dynamically adjusted, scheduling is optimized through a genetic algorithm, invalid overtime is reduced, and the satisfaction degree of medical staff is improved.
Owner:SHENZHEN NEW POINT MEDICAL INFORMATION SYST CO LTD

Encryption communication system and method based on cognitive multi-carrier spread spectrum

The invention discloses an encrypted communication system and method based on cognitive multi-carrier spread spectrum, and belongs to the field of covert communication. The encryption communication system comprises a transmitting device and a receiving device. The transmitting device comprises a data encryption module, a constellation encryption modulation module, a multi-carrier spread spectrum module, a frequency hopping module and a cognitive power distribution module. The receiving device comprises a band-pass filtering module, a de-hopping frequency module, a de-spreading module, a constellation decryption demodulation module, a data decryption module and a coherent combination module. The data encryption module is divided into an interleaving coding unit and a double-rule reversible cellular automaton encryption unit. The cognitive power distribution module continuously scans a wireless electromagnetic environment and carries out real-time spectrum analysis to give power spectrum density results sensed under all frequency hopping frequency sets. According to the invention, continuous detection and dynamic response to the spatial frequency spectrum state can be realized, and the communication concealment, the anti-interference performance and the resource utilization efficiency in a complex electromagnetic environment are remarkably improved by utilizing the frequency spectrum hole.
Owner:BEIJING INFORMATION SCI & TECH UNIV

Multi-level privacy protection data sharing method and system based on block chain

The invention discloses a multi-level privacy protection data sharing method and system based on a block chain. The method comprises the following steps: S1, collecting and uploading original data; generating an encryption key by adopting a dynamic DNA coding sequence and combining an AES key expansion method, encrypting the collected data by utilizing the generated encryption key to obtain an encrypted file, and storing the encrypted file in a local storage library; s2, uploading the encrypted file in the step S1 to a distributed hash table of an IPFS distributed storage system through an SHA-256 hash function, and verifying and confirming a block by adopting a dynamic hybrid consensus mechanism; s3, accessing the block chain by the user through the smart contract, and executing space-time double-attenuation permission control; and S4, after the permission verification is passed, a decryption key is provided for the user, and the user performs data decryption by using an AES decryption algorithm and DNA reverse coding. According to the method, more accurate authority management can be provided, the security and compliance of data access are improved, and the method is suitable for management of large-scale data.
Owner:CHANGZHOU WEISHI INTELLIGENT IOT INNOVATION CENT CO LTD

Communication terminal information acquisition method and system

The invention relates to the technical field of communication security, and particularly discloses a communication terminal information acquisition method and system. The method comprises the following steps: acquiring an original data stream of a communication terminal, and generating a task queue through data source marking, dynamic load balancing and protocol packaging; performing desensitization, metadata annotation and lightweight encryption on the task data to form an encrypted data block; secure transmission is realized through transmission channel selection and quality monitoring; decrypting the received data to generate a time sequence database record; generating a rule update package based on invalid data detection and machine learning analysis; and finally, outputting a standardized data set through filtering and verification. According to the invention, efficient acquisition, secure transmission and intelligent processing of mass communication data are realized, and the real-time performance and accuracy of data processing and the load balancing capability of the system are effectively improved.
Owner:GLADIOLUS TECH (CHONGQING) CO LTD

Vehicle information safety protection system based on combination of national secret algorithm and PUF (Physical Unclonable Function)

The invention discloses a vehicle information safety protection system based on combination of a national cryptographic algorithm and a PUF (Physical Unclonable Function), which belongs to the field of vehicle information safety and encrypted communication, and comprises a response generation module used for generating a PUF response in a safety chip of a vehicle; the key derivation module is used for generating an encrypted master key through a key derivation function based on the PUF response, the vehicle owner identity and the random number nonce; the encryption and signature module is used for generating a ciphertext and carrying out digital signature on the ciphertext; the state monitoring module is used for monitoring the running state of the vehicle hardware; the key management module is used for triggering a failure operation of the encrypted master key when the state monitoring module detects that the hardware state is abnormal; and the decryption verification module is used for regenerating the PUF response and verifying the consistency of the generated key so as to execute data decryption. According to the method, hardware-level encryption protection of the vehicle data is realized through combination of the PUF and the national cryptographic algorithm, so that the safety of the vehicle owner data is protected in the whole life cycle of the vehicle.
Owner:HUBEI UNIV

Smart campus network security protection system

The invention relates to the technical field of electric digital data processing, and discloses an intelligent campus network security protection system. A network data acquisition module of the system continuously monitors data transmission flow of a smart campus network environment to obtain an original data packet; the chaotic encryption engine encrypts an original data packet by using a key stream based on dynamic chaotic mapping, wherein the key stream is generated by multi-chaotic system switching and a random parameter distribution mechanism; the security protocol processing module converts the encrypted data packet into a format conforming to a network security protocol standard and transmits the encrypted data packet; the data decryption unit decrypts the received encrypted data packet; the security threat analysis module identifies and estimates potential network attack behaviors according to the decrypted plaintext data; and the protection strategy controller generates and executes a network security protection instruction according to the threat analysis result. The system can effectively protect the network security of the smart campus, resist various network attacks, and ensure the security of data transmission and storage.
Owner:NORTHWEST A & F UNIV

Balloon-based hovering wireless telecommunication and internet data decryption system

This invention introduces a suspended telecommunications system utilizing gas-lift hydrogen-filled balloons for global internet access and secure encrypted communication analysis. Utilizing this gas-lift technology, it deploys an airborne antenna platform stabilized by lightweight carbon fiber structures and secured by ground-based cables. The system integrates various antennas, including parabolic and Starlink dishes, dynamically adjusting for optimal signal reception from terrestrial and satellite sources. a high-frequency amplifier-dissipator and an AI-enhanced ground processing center facilitate the interception and decryption of encrypted communications, filtering potential security threats. The platform features motorized rotating plates, efficient power management, and GSM / Wi-Fi modules for enhanced connectivity. Constructed with composite materials for durability and minimal weight, it includes built-in lighting for visibility and emergency signaling. The system presents an innovative, cost-effective, and scalable solution for global telecommunication coverage and secure communication monitoring, addressing national and social security concerns while ensuring reliable access to digital information worldwide.
Owner:FIROOZI VESAL

Data controlled sharing method and system based on attribute-based encryption

The invention discloses a data controlled sharing method and system based on attribute-based encryption, and the system is characterized in that a key generation center generates a system public key PK, a main private key MK and a user private key SK, a server gateway configures an access strategy, carries out the encryption processing of a data plaintext and the access strategy, generates a ciphertext, and uploads the ciphertext to a storage device for storage. Wherein the access strategy is converted into a mode that an LSSS matrix is embedded into a ciphertext; the one or more data controlled sharing gateways verify whether the attribute set of the data decryption party meets the access strategy according to the ciphertext and the user private key; if yes, the data plaintext is recovered and obtained by calculating the reconstruction coefficient of the LSSS matrix. According to the invention, the algorithm is simplified, and the system operation efficiency and stability are improved; the system does not need to adopt block chain storage, so that the system architecture design is simplified, the deployment is convenient, the cost is low, and the data security is high.
Owner:BEIJING ZHONG XING TONG CHUANG TECH CO LTD

Industrial data desensitization method, system and equipment and medium

ActiveCN121859362AImprove safety and controllabilityEffectively deal with the lack of time adaptabilityDigital data protectionRelational modelBusiness enterprise
The invention relates to a desensitization method, system, equipment and medium for industrial data, and the method comprises the steps: building and dynamically maintaining an industrial field standard data variable rule table, and defining a desensitization strategy and a sensitivity level matched with specific industrial variables such as temperature, rotating speed and the like in physical meanings, time scenes and node levels of the specific industrial variables; the method comprises the following steps: adding a multi-dimensional identifier to original industrial data, establishing a six-dimensional binding relation model of data variable type-time dimension-node hierarchy-cluster role-sensitive level-rule entry, driving the data to execute a time-coordinated stepped desensitization process in four node hierarchies of a workshop, an enterprise, a park and a cluster, according to the method, refined access control and data decryption fusing time, space and role dimensions are realized according to the model and a full-link tracing log, and the problems that rules and industrial scenes are disjointed, dynamic time adjustment is lacked, cross-node collaboration is insufficient and authority control coarse granularity is caused in the prior art are effectively solved.
Owner:江西冠英智能科技股份有限公司 +1

In-memory encryption method based on cross-point array ferroelectric capacitor array

The invention discloses an in-memory encryption method based on a cross-point array ferroelectric capacitor array, and belongs to the field of data security and computing security. According to the invention, a cross-point array ferroelectric capacitor FeCAP array is respectively adopted as a key array and a complementary key array, and array-level XOR operation is executed between a plaintext and a key by the generated operation through a diagonal data coding mode and a coupling signal subtraction circuit, so that high-parallel XOR encryption in a memory is realized. And data decryption can be symmetrically realized by applying the ciphertext to the input and using the same key array and the complementary key array. In combination with the artificial intelligence calculation accelerator based on the cross point array ferroelectric capacitor array, high-density, high-energy-efficiency and data security enhanced in-memory calculation application can be realized.
Owner:PEKING UNIV

Providing data to be protected in a secured execution environment of a data processing system

Various embodiments include methods for providing data to be protected in a secure execution environment. An example includes: executing an enclave code in the environment; generating a key pair using the code with a public key and a private key; sending the public key to an insecure execution environment outside the secure execution environment; sending the public key and sending first encrypted data to an obfuscated program code, wherein the obfuscated program code is part of the insecure execution environment; verifying the public key by means of the obfuscated program code and, depending on results of the verification, converting the first encrypted data into second encrypted data, wherein the second encrypted data are encrypted with the public key; sending the second encrypted data to the enclave in the secure execution environment; and decrypting the second encrypted data into the data to be protected.
Owner:SIEMENS AG

Recovery using an encrypted fallback key in metadata

A computer-implemented method (CIM), according to one approach, includes generating a primary cryptographic recovery key, and generating an alternate cryptographic recovery key, where the alternate cryptographic recovery key is generated and stored in a cryptographic Hardware Security Module (HSM). The method further includes storing an encrypted fallback key in metadata associated with a data set, where the encrypted fallback key is an operational key encrypted by the primary cryptographic recovery key, and storing a Recovery Key Verification Pattern (RKVP) in the metadata, where the RKVP is associated with the primary cryptographic recovery key and is stored for the primary cryptographic recovery key. In response to a determination that the operational key is unavailable, the encrypted fallback key is retrieved to perform a data decryption operation.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION +1

Large-scale AI model-as-a-service-oriented security reasoning and protecting system and method

The invention provides a large-scale AI model-as-a-service-oriented security reasoning and protection method. The method comprises the following steps that S101, a user initiates an encryption request; s102, the server side carries out verification; s103, decrypting the input data; s104, AI model reasoning is carried out; s105, performing output encryption; and S106, the client decrypts and verifies. The security of the sensitive content can be protected.
Owner:CHONGQING HUATANG ADVERTISING CO LTD

Coprocessing system for encrypting and quickly decrypting data of solid state disk

The invention relates to the technical field of data encryption and decryption, in particular to a solid state disk data encryption and rapid decryption co-processing system which comprises a key management module, a task scheduling distribution module, a cache optimization module, an identity verification module and a controller monitoring module. According to the method, the unique random seed is generated by combining the user identity characteristic parameters and the SSD controller state, the key attribute is dynamically adjusted by periodically disturbing the data, the key complexity and safety are improved, cross matching is carried out according to the concurrent task priority and the data safety level in the task scheduling link, and the complexity and safety of the key are improved. The method comprises the following steps: distributing special channels and buffer resources, ensuring that a key task has a higher execution priority, performing cache optimization, dynamically dividing a multi-level cache region, realizing priority scheduling and processing of a high-frequency data block according to the access frequency of the data block, fusing authentication parameters and equipment and environment information in an identity authentication link, realizing multi-identity verification, and realizing high-efficiency and high-efficiency scheduling of the high-frequency data block according to the access frequency of the high-frequency data block. And the data decryption authority is strictly controlled.
Owner:SHENZHEN YUYU TECHNOLOGY CO LTD

Data security protection method for digital twin system of logistics transfer field

The invention discloses a logistics transit field digital twin system data security protection method, which comprises the following steps: S1, sorting heterogeneous sensitive data in a logistics transit field digital twin to construct a data set, and preprocessing to obtain an original data set # imgabs0 #; s2, performing end-to-end data encryption on the original data set # imgabs1 #, and performing digital signature and key protection; and S3, constructing information exchange and storage between digital twin bodies in the block chain logistics transfer field, and carrying out zero-trust access and data decryption. According to the method, information exchange and storage between digital twin in a block chain logistics transfer field can be effectively realized, and encryption protection is carried out on data.
Owner:THE CHINESE UNIV OF HONG KONG (SHENZHEN)

Trusted data encapsulation, decryption and transmission method and system based on attribute password

The invention relates to a trusted data encapsulation, decryption and transmission method and system based on an attribute password, and belongs to the technical field of information security. The trusted data encapsulation method comprises the following steps: randomly selecting an element R on an elliptic curve according to attribute password security parameters; generating a data encryption key based on the R, and encrypting the to-be-encrypted data to obtain ciphertext data; carrying out attribute encryption on the R based on an access control strategy and a system public key to generate a ciphertext strategy; and generating trusted data. The trusted data decryption method comprises the following steps: analyzing trusted data to obtain an access control strategy, a ciphertext strategy and ciphertext data; decrypting the ciphertext policy based on the access control policy and the attribute private key of the data user to obtain an element R '; a data encryption key is obtained based on the element R ', and ciphertext data is decrypted to obtain a data plaintext. Trusted data transmission comprises packaging and decryption, and the packaging system is used for generating and distributing trusted data. Efficient and safe sharing of data in the field of digital processing is achieved.
Owner:BEIJING ZHONGHONG LIDA TECH DEV CO LTD +1

Distributed test data generation and sharing system based on privacy computing

The invention relates to a distributed test data generation and sharing system based on privacy computing, and belongs to the technical field of big data, the system comprises a data generation module used for fragmenting acquired user data to a plurality of computing nodes for k-anonymization processing to obtain local data blocks output by each computing node; the privacy calculation module is used for extracting statistical characteristics of the local data blocks and generating an encrypted data packet based on the statistical characteristics; the data storage module is used for carrying out fragmentation storage on the encrypted data packet based on the data type of the encrypted data packet; the data sharing module is used for constructing an access strategy tree based on the encrypted data element information of the encrypted data packet; the access strategy tree is used for generating a decryption key containing the timestamp and the operation authority for the authorized user. According to the system provided by the invention, only the compliance access operation is allowed to trigger the data decryption process, data sharing is realized under the condition of ensuring that the user data is safe and not leaked, and the risk of data leakage in the data test is reduced.
Owner:WUHAN BIG PULP IND DEV CO LTD

High-performance multi-keyword sorting query privacy computing system for secret state big data

The invention discloses a high-performance multi-keyword sorting query privacy computing system oriented to secret state big data. Comprising four participants including a trusted authority, a data owner, a query user and a cloud server, and seven functional modules including a system initialization module, a key generation module, a data encryption module, a query token generation module, a security query module, a data decryption module and a key tracking module. On the basis of deeply researching and analyzing existing searchable encryption, access control based on attribute-based encryption and high-performance index technology research results, the invention provides a high-performance multi-keyword sorting query privacy calculation scheme and an application system oriented to secret state big data. The invention provides a high-performance safe multi-keyword sorting query scheme for realizing access control for the first time, and has the capabilities of high-performance multi-keyword sorting query, fine-grained ciphertext access control, malicious user tracking and dynamic data updating at the same time on the premise of protecting data privacy.
Owner:EAST CHINA NORMAL UNIV +2

A data processing method, apparatus and device

The application provides a data processing method, device and equipment, wherein the data processing method comprises the following steps: sending a decryption request to at least two data decryption nodes respectively; the decryption request carries a data access address; receiving a decryption result and first verification parameter information for the decryption result fed back by each data decryption node; obtaining decrypted data according to each decryption result and the first verification parameter information; wherein the decryption result comprises part of the decrypted content of the ciphertext data corresponding to the decryption request. This scheme can support the implementation of data decryption by using multiple data decryption nodes, and then the complete decrypted data is obtained according to the decryption results (part of the decrypted data) obtained by each data decryption node, thereby realizing distributed delegated decryption, avoiding the problem of low security caused by single-point storage of asymmetric keys, and the problem of management difficulty caused by symmetric keys.
Owner:CHINA MOBILE COMM LTD RES INST +1

Inter-system data transmission method and device, electronic equipment and computer readable medium

The embodiment of the invention discloses an inter-system data transmission method and device, electronic equipment and a computer readable medium. A specific embodiment of the method comprises the following steps: performing data encryption processing on a local object evaluation information set to obtain an object evaluation encryption information set; performing system identity recognition on the object evaluation information transmission system set to obtain an identity recognition information set; determining a data transmission path set; performing transmission path performance identification on the data transmission path set to obtain a path performance information set; determining a target data transmission path set; performing path dynamic adjustment on the target data transmission path set to obtain an adjusted data transmission path set; carrying out information hybrid transmission on the object evaluation encryption information set, and carrying out transmission congestion control processing on the transmission process; and performing data decryption and storage on the object evaluation transmission encryption information set. According to the embodiment, the interaction performance of data transmission between systems can be improved, the data transmission efficiency is improved, and waste of transmission time and transmission resources is reduced.
Owner:PARK DO CREDIT CO LTD

Data offline transmission method for ship construction management

The invention belongs to the technical field of ship construction management, and particularly discloses a data off-line transmission method for ship construction management, which comprises the following steps: S1, data preprocessing: formatting and encrypting ship construction management data to be transmitted to improve the safety and compatibility of the data; s2, offline storage: writing the preprocessed data into a specific offline storage medium; s3, data transmission: connecting the storage medium with the target equipment through a physical contact or short-distance wireless communication technology to realize offline transmission of data; s4, data receiving and processing: the target device receives the data in the storage medium, performs data decryption and format conversion processing, and performs data integrity verification; a flexible data transmission scheme is provided by combining various offline storage media; a data encryption and integrity verification mechanism is introduced, so that the security of data transmission is ensured; the technology of NFC, Bluetooth and the like is utilized, the offline transmission process is simplified, and the transmission efficiency is improved.
Owner:ZHONGCHUAN NO 9 DESIGN & RES INST

Media data decryption method and device, computer device, and storage medium

ActiveUS12730906B2Control systemMediaFLO
A media data decryption method includes: obtaining a media data encryption package, wherein the media data encryption package is obtained by performing pixel rearrangement encryption on original media data based on position index data, and the position index data correspond to one or more structural parameters of a display screen; decrypting the media data encryption package to obtain the position rearrangement index data and media data to be decrypted; configuring a programmable logic circuit of a control system of the display screen in a media data play terminal based on the position rearrangement index data; and decrypting the media data to be decrypted based on the configured programmable logic circuit to obtain decrypted media data.
Owner:UNILUMIN GRP

Communication method, system and device

The embodiment of the invention provides a communication method, system and device, relates to the field of communication, and is beneficial to improving the security of data processing of longitudinal federated learning. The method comprises the following steps: a first network element determines a first key; the first secret key can be used for all or data encryption in a first longitudinal federated learning group, or can be used for data encryption of network elements participating in a first longitudinal federated learning task in the first longitudinal federated learning group; the first network element receives a first request message from the second network element; the first request message can be used for requesting the first secret key, and / or the first request message can be used for requesting to perform data decryption on the first encrypted data by using a decryption secret key corresponding to the first secret key. Besides, after receiving the first request message, the first network element can verify the second network element to determine whether to send the first secret key to the second network element or not, and / or decrypted data obtained by performing data decryption on the first encrypted data by using a decryption secret key corresponding to the first secret key.
Owner:HUAWEI TECH CO LTD

File processing method and device, electronic equipment and storage medium

Embodiments of the present application disclose a file processing method and device, electronic equipment and a storage medium. The method comprises: when a file access request is received, obtaining a hand vein feature corresponding to a target subject; if the hand vein feature is consistent with a stored vein feature associated with a target vehicle, calling a to-be-matched icon password corresponding to the stored vein feature; if a to-be-verified icon password corresponding to a trigger operation is consistent with the to-be-matched icon password, determining that decryption of a target file corresponding to the file access request is successful, and displaying the target file. The present application solves the problem in the prior art that data is encrypted and decrypted based on a single finger vein feature, and the data is easily leaked due to a low encryption coefficient, thereby improving the difficulty coefficient of data decryption and achieving the effect of ensuring data security.
Owner:CHINA FAW CO LTD

Enterprise financial data security management system and method

The invention discloses an enterprise financial data security management system and method, and relates to the technical field of financial data management, and the method comprises the steps: collecting enterprise financial data needing to be shared, marking the business type, sensitivity level and data mode corresponding to the enterprise financial data, and generating financial sharing and marking data; selecting a proper preset document template based on the data modality, and generating document template sample data; according to the method, the enterprise financial data are subjected to hierarchical encryption, the data subjected to hierarchical encryption are replaced by the placeholders, common documents in various formats are generated, and shared users log in the specified cloud through identity verification; after the shared document is uploaded, the cloud end can decrypt the enterprise financial data which conforms to the identity authority according to the authority of the verified identity and then fill the enterprise financial data into the position of the corresponding placeholder, so that the shared user can obtain the encrypted data which conforms to the authority, and the risk of leakage of the encrypted data is reduced at the same time.
Owner:YONGLANG GRP

Password-based train control system data secure transmission method and system

The invention discloses a password-based train control system data secure transmission method and a password-based train control system data secure transmission system. The system is used for data transmission between a train control data owner and a train control data user, and comprises an identity authentication module deployed on a key management center, a data encryption module and a data uploading module which are deployed on the train control data owner, and a data storage module and a ciphertext search module which are deployed on a train control center, the trap door generation module and the data decryption module are deployed on a train control data user. According to the method, a password-based key derivation mechanism is adopted, and bilinear mapping and a hash function are combined, so that the complexity of key management in the train control system and the user operation burden are remarkably reduced, meanwhile, the confidentiality and integrity of train control data transmission are guaranteed, the bottleneck that efficient query cannot be performed after encryption in a traditional encryption method is solved, and the encryption efficiency is improved. And the comprehensive performance of the train control system in the aspects of data security and real-time performance is improved.
Owner:NANKAI UNIV

Data encryption transmission method and system based on RDMA

The invention relates to a data encryption transmission method and system based on RDMA (Remote Direct Memory Access), and the method comprises the steps: in a user mode driver or a kernel mode driver, when an application calls a create qp function, defaulting to distribute a memory buffer with a fixed size, and registering the memory buffer into an mr to obtain a memory mr specially used for encryption mode transmission; when a user application program calls a modify qp function to switch the QP state to RTS, the distributed memory cache is initialized, an encrypted character is generated and filled in the memory mr, and the encrypted character is packaged into a network frame through RDMA hardware and then sent to a receiving end; the sending end analyzes the encrypted character and modifies the operation mode of the RDMA hardware DMA access memory corresponding to the configuration; and the receiving end analyzes the encrypted characters, modifies and configures the opposite operation mode into a register of a DMA access memory of RDMA hardware, and performs corresponding data increase and decrease operation through the configured DMA operation mode to complete decryption and recovery of the data. According to the invention, the security problem of data transmission can be solved.
Owner:YIHUA TECHNOLOGY (BEIJING) CO LTD

Distributed detection-based responsibility-traceable data retrieval system

The invention discloses a responsibility-traceable data retrieval system based on distributed detection, which comprises a system administrator KMC node, an Internet of Things terminal equipment IoT node, a cloud server CS node, a distributed verification server VS node and a user U node, the data processing process comprises a system initialization stage, a key generation and distribution stage, a data collection and encryption stage, a user query stage, a query detection and responsibility investigation stage, a search matching stage, a data decryption stage and a user updating stage. According to the method, a system administrator allocates identities and accessible data sets to users so as to dynamically control user permissions and responsibility investigation; during responsibility investigation, query information and user identity of a user are verified by using a distributed credible verification server and a blacklist technology, so that a search request is shunted, and message processing of a cloud server and a system administrator is greatly simplified; meanwhile, the integrity of the data, stored in the cloud server, of the Internet of Things equipment can be verified after a user inquires the data.
Owner:CHENGDU UNIVERSITY OF TECHNOLOGY