Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

687 results about "Encryption" patented technology

In cryptography, encryption is the process of encoding a message or information in such a way that only authorized parties can access it and those who are not authorized cannot. Encryption does not itself prevent interference, but denies the intelligible content to a would-be interceptor. In an encryption scheme, the intended information or message, referred to as plaintext, is encrypted using an encryption algorithm – a cipher – generating ciphertext that can be read only if decrypted. For technical reasons, an encryption scheme usually uses a pseudo-random encryption key generated by an algorithm. It is in principle possible to decrypt the message without possessing the key, but, for a well-designed encryption scheme, considerable computational resources and skills are required. An authorized recipient can easily decrypt the message with the key provided by the originator to recipients but not to unauthorized users.

Telecommunication system and method of operating the telecommunications system

PendingCN122319638ATicketTelecommunications
A method (200) for operating a telecommunications system (100), the system comprising: a client device (110); a set of servers (130) for providing services to the client device; and an authentication server (120) for generating authentication tickets for the set of servers to provide services to the client device; the method comprising the steps of: generating at the authentication server: a set of encrypted service levels (220), the set comprising at least two different service levels, each level: including performance requirements; and encrypted with a corresponding encryption key from a set of encryption keys; and an authentication ticket for the client device and services, the ticket comprising the set of encrypted service levels; transmitting the authentication ticket to the set of servers (230); and performing a process comprising the following steps Process: Transmits an encryption key from a set of encryption keys that has not yet been transmitted to the server set (240); The server set processes the authentication ticket using the transmitted encryption key to retrieve the performance requirements within the corresponding service level (250); The server set determines whether to provide service at least according to the retrieved performance requirements (250); and after determination, identifies whether to provide service at least according to the retrieved performance requirements (260): rejected by the server set (260-1), in response to which the process is iterated again (240); or accepted by at least one server (260-2), in response to which one of the servers is selected to provide service at least according to the retrieved performance requirements (280).
Owner:BRITISH TELECOM PLC

A highly integrated edge computing security gateway with end-to-end encryption suitable for industrial environments

This invention discloses a highly integrated edge computing security gateway with end-to-end encryption suitable for industrial environments. It comprises a routing module with firewall functionality, a switching module, a storage module, an edge computing module, a high-performance security encryption / decryption module, a low-performance security encryption / decryption module, and an industrial field interface module. All modules are connected via an internal high-speed data bus. The routing module coordinates the operation of all modules within the security gateway. This invention can be applied to numerous fields with network security connectivity requirements, such as factories, construction sites, and transportation networks, significantly expanding the application scenarios of related equipment.
Owner:CHINA TRANSPORT INFORMATION TECH GRP CO LTD

Distribution and update of keys

Cluster storage systems (100) and methods provide secure generation, distribution, and update of encryption keys (132, 142) during initial cluster formation and cluster membership changes without using readable persistent media. A cryptographic co­processor (130) stores a key encryption key (132) in write-only memory and uses the unreadable key (132) for encryption and decryp­tion of a data encryption key (142). Methods to securely distribute the initial or updated the key (132) to be stored in the coprocessor (130) and securely update the key (132) when cluster membership changes are provided.
Owner:NVIDIA CORP

Intelligent dynamic mesh adaptation method and device for additive manufacturing droplet pool simulation

PendingCN122347092ASimulationConcentration gradient
The application discloses an intelligent dynamic grid self-adapting method and equipment for droplet pool simulation of additive manufacturing, and the method comprises the following steps: establishing a simulation model of additive manufacturing by using a pool simulation tool; extracting the simulation real-time gas phase fraction gradient, solid phase fraction gradient, solute concentration gradient and pool temperature gradient of each grid at each time step of simulation as the perceived physical parameters; adaptively calculating the encryption urgency index of each grid according to the perceived physical parameters; obtaining the historical encryption urgency index of each grid, calculating the second-order difference value, and predicting the change trend of the encryption urgency index of each grid at the future time; determining the encryption threshold and the coarsening threshold according to the encryption urgency index of all grids at the current time step, and combining the change trend of the encryption urgency index, the size relationship between the encryption urgency index and the threshold to determine whether the grid needs to be encrypted or coarsened; and iterating until the simulation is completed. The application has high precision, low cost and high automation degree.
Owner:NANJING NORMAL UNIVERSITY

Firmware updating method, electronic device, server and system

This disclosure relates to a firmware update method, an electronic device, a server, and a system. The method includes: obtaining from a user device an encrypted firmware update package sent by a server to the user device in response to a firmware update request from the electronic device, and a firmware decryption key enDecKey encrypted by the server using a key encryption key KEK, wherein the key encryption key KEK is a temporary key derived based on a predetermined key derivation function; decrypting the received encrypted firmware decryption key enDecKey using the key encryption key KEK to obtain a firmware decryption key decKey; and decrypting the encrypted firmware update package using the firmware decryption key decKey to obtain a firmware update package for updating the firmware in the electronic device.
Owner:TP-LINK INT SHENZHEN CO LTD

Method and system for securely selecting applications

PCT designated stageWO2026130660A1Multiple keys/algorithms usageDigital data protectionEngineeringMessage authentication code
The disclosure relates to a method and system for securely selecting applications using application identifiers. The method for securely selecting applications using Application Identifiers (AIDs), wherein application-specific static keys are utilized to encrypt AIDs, ensuring privacy and preventing inference about the selected application. The method includes generating a random number to embed in the encryption for uniqueness and replay attack prevention, authenticating the selection command with a Message Authentication Code (MAC) for integrity, and transmitting the encrypted selection command to a recipient device for further processing.
Owner:ASSA ABLOY AB

Chip self-heating-based encryption control information nonlinear mapping method

The application discloses a kind of encryption control information nonlinear mapping methods based on chip self-heating, it is related to chip circuit's encryption information nonlinear mapping technical field, comprising: chip is divided into several physical area blocks according to two-dimensional matrix form, each physical area block is correspondingly provided with a hotspot unit and a network node, each physical area block corresponds different data representation;Each network node is numbered in disorder;Each array of heat intensity control information obtained according to encryption control information is transmitted to each corresponding network node;For a certain network node, the heat intensity control information received is transmitted to the corresponding hotspot unit, and the hotspot unit generates heat;According to the thermal imaging of chip and the data representation corresponding to each physical area block of chip, the nonlinear mapping result of encryption control information is obtained.The application improves the effectiveness of information mapping, better protects the transmission process of control information, and improves the security of information mapping.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Cross-industry data assetization governance and circulation system

The application discloses a cross-industry data assetization management and circulation system, which comprises five core modules. A data block encryption module receives cross-industry biological data flow, performs sequence block and nested encryption, and generates an encrypted data flow; a blockchain section storage module generates a hash storage certificate for the data block and writes the hash storage certificate into a blockchain; a federal contribution attenuation evaluation module receives a federal learning gradient update signal, performs time attenuation and marginal benefit adjustment to generate a contribution evaluation signal; a cross-modal knowledge graph alignment desensitization module realizes cross-modal entity semantic alignment, calls a configurable desensitization rule chain to generate a desensitized data flow; and a data circulation gateway module integrates three types of signals to generate a data asset circulation control signal. The application solves the collaborative management problems of safe storage, privacy protection, contribution quantification and compliance desensitization in the circulation of cross-industry biological data.
Owner:HANGZHOU YIKANGXIN TECH CO LTD

A data synchronization method and system based on front-end orchestration management

PendingCN122093407ASolving Conflict PuzzlesPrecision FusionElectric digital data processingSecuring communicationData synchronizationMessage queue
This invention discloses a data synchronization method and system based on front-end orchestration management, belonging to the field of data synchronization. The method includes the following steps: selecting the data table and field information to be monitored through the front-end interface, generating configuration information, and orchestrating the synchronization process logic according to business needs; storing the configuration information in real time to the configuration center to generate real-time monitoring rules; capturing changed data of the data table and field information, encapsulating it into standard data units and sending it to a message queue; preprocessing the standard data units in the message queue; the synchronization adaptation module matching the corresponding driver type according to the synchronization process logic to generate a synchronization instruction set, and executing data synchronization operations based on the preprocessing results; performing full-link monitoring of the synchronization process, and performing task lifecycle management based on the lifecycle rules configured on the front end. This invention improves synchronization efficiency through dynamic threshold verification, multi-source field fusion weighting, and dynamic encryption strategies, and the full-link monitoring further enhances front-end manageability.
Owner:SICHUAN ZHONGDIAN AOSTAR INFORMATION TECHNOLOGIES CO LTD

Low cost and low latency logical unit erase

A memory control unit of a memory device includes at least one hardware processor; and memory storing instructions that cause the at least one hardware processor to perform operations comprising: generating a scrambler seed and a logical block address (LBA) for a block of write data received by the memory control unit from a host device; generating a flash translation layer (FTL) to map the LBA to a physical address (PA); scrambling the block of data using the scrambler seed; encrypting the scrambler seed, the LBA, and the PA in the FTL using an encryption key; initiating writing a scrambled block of data and encrypted LBA and scrambler seed to a memory array; and decrypting the FTL using an incorrect encryption key in response to an erase command received by the memory control unit from the host device.
Owner:LODESTAR LICENSING GROUP LLC

Network anomaly monitoring method, device and program product based on traffic fingerprint learning

The present disclosure belongs to the technical field of network security, and particularly relates to a network anomaly monitoring method, device and program product based on traffic fingerprint learning, which comprises the following steps: extracting metadata irrelevant to encryption of a target network; the metadata comprises five-tuple, timestamp, length and protocol flag information of a data packet; the metadata is aggregated with a source IP address as a primary key to define a network entity; session feature extraction is performed on a session of the target network entity and other network entities; the extracted session features comprise timing features, operation sequence features and scale distribution features; the operation sequence features comprise Shannon entropy of a continuous request and response type pair; an action fingerprint of the target network entity is constructed according to the session features; and whether the target network and the target network entity are abnormal is judged according to a deviation degree of a current action fingerprint of the target network entity and a fingerprint baseline. The present disclosure can realize accurate identification of network anomalies.
Owner:WUHAN COLLEGE

Wireless communication system for establishing wi-fi connectivity between different hosts

PendingCN122137913ACathode-ray tube indicatorsDevices with bluetooth interfacesCommunications systemIp address
A wireless communication system including an adapter is provided. The adapter is configured to connect with a host through a universal serial bus interface and connect with a handset through a Bluetooth interface to form a Bluetooth connection. After the adapter connects with the host through the universal serial bus interface and connects with the handset through the Bluetooth interface, the adapter is configured to provide a first IP address of the host to the handset to establish a Wi-Fi connection between the host and the handset. The Bluetooth connection is further configured to transmit an encryption key between the host and the handset. The Wi-Fi connection is not configured to transmit the encryption key.
Owner:PIXART IMAGING INC

Encryption and decryption system and method

ActiveCN116896603BComputer hardwareInformation recovery
The present disclosure provides an encryption and decryption system and method. The encryption and decryption system includes a transmitting device and a receiving device. The transmitting device is configured to store a plurality of original images. The receiving device is connected to the transmitting device and configured to store a corresponding table. The transmitting device generates an encrypted string, selects a representative transformed image from the plurality of transformed images according to the encrypted string, transmits the representative transformed image to the receiving device, and does not transmit the encrypted string to the receiving device. The receiving device identifies a first original image number and a second original image number from the representative transformed image, and looks up the corresponding table according to the first original image number and the second original image number to generate the encrypted string. Thus, various network attacks can be prevented, resource and time consumption can be greatly reduced, the problem of excessive distortion or low capacity of embedded data can be solved, and the information recovery capability can be greatly improved.
Owner:HON HAI PRECISION INDUSTRY CO LTD

Secure Storage and Management of Sensitive Information

PendingUS20260213922A1Internet privacyEngineering
Systems, apparatuses, and methods are described for securely storing and managing sensitive information. A gateway may manage the encryption and storage of the sensitive information. A mobile device may be authenticated by the gateway using a local connection between the gateway and the mobile device. The mobile device may access, encrypt and / or decrypt the sensitive information based on being authenticated by the gateway. As an added layer of security, the gateway may re-encrypt the sensitive information when the mobile device is disconnected from the gateway and / or based on a period of time associated with the storing of the sensitive information. The mobile device may receive the re-encrypted information after reconnecting and / or being reauthenticated with the gateway.
Owner:COMCAST CABLE COMM LLC

A battlefield information processing method based on multi-modal data fusion

The application discloses a battlefield information processing method based on multi-modal data fusion, comprising the following steps: acquiring multi-modal original data of battlefield information, standardizing different original data to obtain a structured data set; performing time and space alignment on the structured data set to obtain a space-time reference data set; performing feature completion on the space-time reference data set to obtain a complete analysis data set; performing hierarchical encryption on the complete analysis data set to obtain an encrypted transmission data set; performing distributed storage on the encrypted transmission data set to obtain a secure storage data set; performing isolation processing on the secure storage data set to obtain an intermediate result data set; performing real-time detection and protection on the intermediate result data set to obtain a final protection data set; and performing processing detection and credibility judgment on the final protection data set to obtain a final credible information analysis result.
Owner:BEIJING FANGYUAN QIZHENG TECHNOLOGY CO LTD

Controller authentication-based encrypted tunnel establishment method and device, and electronic device

ActiveCN121508952BAttackEngineering
The application discloses a kind of based on controller authentication's encryption tunnel establishment method and device, electronic equipment, it is related to network security technical field or other related fields, the method includes: after encryption tunnel establishment flow is started, by client device to server device sends security negotiation request, and by server device returns security negotiation response;After receiving security negotiation response, by client device to server device sends identity authentication request, simultaneously to controller sends chain building permission request;By controller, chain building permission response is generated based on chain building permission request, and is synchronized to server device;By server device, chain building permission response and identity authentication request are verified, in the case where verification succeeds, the communication encryption tunnel between server device and client device is established based on identity authentication request.The application solves the technical problem that encryption tunnel establishment flow in the related art relies on static authorization detection, cannot cover real-time dynamic attack, leading to insufficient security.
Owner:CHINA TOWER CO LTD

A network security device N+1 cluster hot backup system and method based on chain physical cascade

The application discloses a network security device N+1 cluster hot backup system and method based on a chain type physical cascade, which comprises N main devices and at least one public backup machine, and each device is connected into a daisy chain topology through a special cascade interface. Each device is internally integrated with an encryption module and a physical switching matrix composed of multiple mechanical latching type optical switches. The system defines three modes of service processing, fault source bypass and transparent relay: when a device suddenly fails or is powered off, the optical switch automatically maintains the redirected optical path by relying on the mechanical latching characteristics, and physically bypasses the local port traffic to the cascade channel; after detecting the cascade signal, the downstream normal node directly establishes a straight-through transparent optical path by using the internal optical switch matrix, so that the fault traffic is relayed at the physical layer. The application realizes "physical layer complete unloading" of fault traffic, realizes zero computing power consumption for intermediate nodes, has a forwarding delay of less than 1 mu s, effectively eliminates the performance avalanche problem of a high computing power cluster, and has high availability of power failure self-healing.
Owner:BEIJING GUOLING TECH CO LTD

Method, device, equipment, storage medium and program product for file transmission

ActiveCN119814766BData transportEngineering
The application discloses a file transmission method, device, equipment, storage medium and program product, and is applied to an authentication server. The specific technical scheme comprises the following steps: receiving an identity authentication request sent by a terminal, wherein the identity authentication request carries user identity information and a to-be-transmitted file; querying authentication information corresponding to the user identity information in a database; calculating a check parameter corresponding to the user identity information based on the authentication information and a preset authentication algorithm; authenticating the terminal based on the check parameter; and transmitting the to-be-transmitted file in the case that the terminal is authenticated successfully. In this way, the data encryption speed can be improved, and thus the data transmission efficiency is improved.
Owner:CHINA MOBILE INTERNET CO LTD +1

Workflow permission control method and system based on quantum encryption mechanism

ActiveCN121150950BConfidentialityEngineering
The application discloses a kind of workflow authority control method and system based on quantum encryption mechanism.Method includes: in response to the application submitted, obtain first quantum flow key and first quantum group key;According to the first quantum flow key, the business data of application is encrypted;According to the first quantum group key, the authority data of application is encrypted;In response to the approval request of application, according to the first quantum group key, the authority data is decrypted, and the approval authority of the approval request object is determined;According to the approval authority, the business data is decrypted with the first quantum flow key.In this way, when approving, first decrypt the authority data through the first quantum group key to verify the authority, then decrypt the business data as needed with the first quantum flow key, build pre-authorization protection, which can effectively intercept unauthorized access to information by non-approval person, to some extent solve the problem of non-approval person impersonating approval person to leak information, and protect the confidentiality of application information.
Owner:中电信量子信息科技集团有限公司

Image encryption region determination method and device, electronic equipment and storage medium

The application provides a method and device for determining an image encryption region, electronic equipment and a storage medium, and relates to the field of data security. The method comprises the following steps: obtaining a first preprocessed image; obtaining the size of the first preprocessed image and the length of text corresponding to target embedded information; converting the format of the first preprocessed image into a preset format to obtain a target preprocessed image; determining the target number of channels corresponding to the length of text and the size of the first preprocessed image according to the correspondence between the length of text, the size of the first preprocessed image and the number of channels; and performing identification processing on the target preprocessed image based on the target number of channels to obtain two-dimensional matrix data matching the target number of channels, wherein the two-dimensional matrix data is the information of a secure region. The secure region information obtained is determined as a region in the first processed image, which can improve the security of image encryption.
Owner:CHINA MOBILE INFORMATION TECHNOLOGY CO LTD +1

Inter-format encryption of data independent of an encryption and a decryption key

The present disclosure relates to encryption techniques, leveraging inter-format conversions for encrypting input data. These techniques enable keyless encryption and decryption, independent of traditional encryption or decryption keys. The input data that corresponds to any digital format (such as audio, text, or image) undergoes one or more inter-format conversions during both encryption and decryption processes. The first inter-format conversion involves applying one or more transformations to the input data, generating encrypted data in a first digital format. A second inter-format conversion may then be applied to the encrypted data through modeling or other transformations, resulting in a secondary encrypted representation in a second digital format. During decryption, inverse encryption logic is used to reverse the process, applied either to the encrypted data or the secondary encrypted representation. This enables restoration of the original input data, providing a secure and keyless method of encryption and decryption across different digital formats.
Owner:CERNER INNOVATION INC

A secure system for identity fragment cross dynamic verification

PendingCN122457265APasswordSoftware engineering
The application discloses a kind of security systems of identity fragment cross dynamic verification, it is related to network security verification technical field.System includes verification request module, fragment extraction module, dynamic combination module, session security module, verification feedback module, salted hash preprocessing module, equipment environment detection module and dynamic rule synchronization algorithm module.By extracting mobile phone number and identity card fragment and carrying out irreversible de-identification processing, cross combination is generated according to dynamic rule Verification password, combined with unique session identifier and end-side encryption realizes one-time security verification.The application does not store complete identity information, can dynamically switch verification rule, has the advantages such as anti-fraud, anti-cracking, data compliance, full-scene application, etc., and is suitable for financial transfer, e-commerce, government affairs, online car-hailing, points mall and other high-security demand scenes.
Owner:赵锋利

An authentication method for encrypted radiometric measurements

PendingCN122085398Aprevent leakageGuaranteed Recognition ReliabilityNuclear energy generationGeometric image transformationAbsolute differencePrivacy protection
This invention relates to the field of radiation measurement technology, specifically to an authentication method for encrypted radiation measurement. It addresses the problem that existing technologies lack mechanisms to effectively shield and minimize the disclosure of sensitive information while maintaining identification efficiency, making them unsuitable for application scenarios where privacy protection demands are increasingly prominent. The method includes obtaining irradiation image data of a reference item and a test item, scaling their sizes to N×N, and denoting them as D₁ and D₂ respectively; introducing a key matrix λ; obtaining encryption matrices α₁ and α₂ through matrix multiplication of λ with D₁ and D₂ respectively; obtaining an absolute difference matrix β; obtaining a hash matrix σ; when β(i,j)>μ(i,j), setting σ(i,j) to 1, indicating that at this position, the difference between the reference item and the test item has exceeded the maximum difference, and the difference index increases by 1; when β(i,j)≤μ(i,j), setting σ(i,j) to 0, indicating that there is no difference between the two items at this position; scrambling and reducing the dimension of the hash matrix σ to obtain a hash sequence denoted as F, and using the elements of the hash sequence and H as the final difference index to accurately determine the identity or legitimacy of the test item.
Owner:JIANGSU INST OF METROLOGY

system

We provide the system. [Solution] A means that enables multiple information processing modules to cooperate with each other on a distributed communication structure, A means for securely sharing data between these information processing modules using encryption technology, Each information processing module has a means to individually perform a specific analysis task, A means of integrating environmental data in real time and providing decision support information, A means of displaying results on the user's terminal and dynamically updating the information, A system that includes this.
Owner:SOFTBANK GROUP CORP

Multimodal dynamic haptic encryption method, haptic encryption skin, system and applications

ActiveCN116049852BGranular layerBi modal
The application provides a multi-modal dynamic tactile encryption method, a tactile encryption skin, a system and an application, which comprises the following steps: a dynamic tactile force acts on a tactile encryption epidermis, image data of an initial state of the tactile encryption epidermis and an image data generated in a dynamic tactile action process are collected through a tactile encryption subcutaneous tissue; based on the image data, a position cell tensor, a velocity tensor and a depth tensor generated before and after the encryption epidermis granular layer is subjected to a tactile stimulation are obtained; based on the position cell tensor, the velocity tensor and the depth tensor, a double-modal dynamic tactile feature or a multi-modal dynamic tactile feature based on a dynamic force-velocity-depth coupling is constructed; and the double-modal dynamic tactile feature or the multi-modal dynamic tactile feature is subjected to multi-level standard encryption based on a self-defined initial key to obtain a final dynamic multi-modal tactile process encryption result. The application has high specificity, which includes spatial and temporal features; the encryption process is dynamic, contains the whole process of biological tactile action, and has high reliability.
Owner:SHANGHAI JIAOTONG UNIV

A vehicle electronic control unit information security debugging port encryption method and device

The present disclosure provides a vehicle electronic control unit information security debugging port encryption method and device, which identifies the byte sequence of the data in the electronic control unit debugging protection configuration area, and adaptively processes the debugging encryption configuration data and unlocking data based on the identification result, thereby improving the accuracy and consistency of the debugging port encryption configuration under different controller platforms, reducing the risk of manual configuration, improving the reliability and compatibility of the debugging interface authorization unlocking, and thus achieving the safety protection effect of the vehicle electronic control unit debugging interface.
Owner:CHINA FAW CO LTD

IoT lock circuit based on national cryptographic chips

This application relates to an IoT lock circuit based on a national cryptographic chip, comprising: a core board, a W5500 network communication module, a USB interface, a security encryption chip U7, a door status module, and a motor drive circuit; one end of the USB interface is electrically connected to the core board, and the other end of the USB interface is suitable for connecting a USB electronic key; the security encryption chip U7 is bidirectionally electrically connected to the core board; the W5500 network communication module is bidirectionally electrically connected to the core board, and the core board is suitable for communicating with the IoT lock central platform through the W5500 network communication module; the output end of the door switch module is electrically connected to the input end of the core board; the input end of the motor driver is electrically connected to the output end of the core board, and the output end of the motor drive circuit is suitable for being electrically connected to the power supply of the door lock motor; the circuit is suitable for unlocking the door lock by driving the motor drive circuit to work when a USB electronic key is inserted into the USB interface and the security encryption chip U7 verifies the data of the USB electronic key.
Owner:BEIJING EASY NUCLEAR TECH CO LTD

Quantum echo encryption and retrospective decryption mitigation

ActiveUS12675573B2Quantum entanglementEngineering
Methods, systems, and apparatus may encrypt data using an encryption key and securely store the encrypted data on a quantum medium so that the data is not accessed without authorization. The encrypted data may be stored on a quantum medium in the form of quantum bits that are encoded as quantum-entangled particles having correlated quantum states. An authorized user at a second quantum computer may access the stored data and decrypt the data with a copy of the encryption key that may be obtained from the first quantum computer via quantum tunneling. An intrusion attempt by an unauthorized party to access the quantum encrypted data via the quantum medium may cause one or more echoes to be generated and passed into the quantum medium. The echoes may disturb the quantum-entangled particles and make the quantum encrypted data unintelligible to the unauthorized party so that the encrypted data cannot be accessed.
Owner:BANK OF AMERICA CORP

A method, system, device, medium, and product for intelligent layered packaging of containers.

This invention discloses a method, system, device, medium, and product for intelligent layered packaging of container applications, relating to the field of computer application technology. The method includes: reading the Docker Compose configuration and Dockerfile and parsing the instructions; automatically splitting the image into a base layer, core dependency layer, business code layer, and configuration layer based on a preset strategy and layering priority rules; generating a current file fingerprint for the file content of each layer, comparing the current file fingerprint with a historically built layered fingerprint database, performing incremental builds only on layers with changed content, and directly reusing unchanged layers; loading packaging parameters according to environment tags, and using asymmetric encryption and digital signatures for the core dependency layer and business code layer; integrating the image layers to generate a complete image and updating the configuration file. This invention solves the problems of low efficiency and incompatibility with security hardening in traditional full builds, achieving consistent, rapid image building and secure, controllable distribution.
Owner:SOUTHWEST CHINA RES INST OF ELECTRONICS EQUIP