Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

2923 results about "Encryption" patented technology

In cryptography, encryption is the process of encoding a message or information in such a way that only authorized parties can access it and those who are not authorized cannot. Encryption does not itself prevent interference, but denies the intelligible content to a would-be interceptor. In an encryption scheme, the intended information or message, referred to as plaintext, is encrypted using an encryption algorithm – a cipher – generating ciphertext that can be read only if decrypted. For technical reasons, an encryption scheme usually uses a pseudo-random encryption key generated by an algorithm. It is in principle possible to decrypt the message without possessing the key, but, for a well-designed encryption scheme, considerable computational resources and skills are required. An authorized recipient can easily decrypt the message with the key provided by the originator to recipients but not to unauthorized users.

Network security situation awareness and analysis platform based on AI

The invention discloses a network security situation awareness and analysis platform based on AI, and relates to the technical field of network security situation awareness and analysis, and the platform comprises a multi-source data collection module which integrates flow, logs, assets and threat intelligence data, and carries out encryption transmission and standardization; the data preprocessing module purifies and optimizes data, and guarantees data quality and sensitive information security; the AI situation awareness analysis module extracts features through a deep learning model, dynamically evaluates the situation and identifies threats; the threat early warning and decision-making module triggers graded early warning and generates a targeted emergency response scheme; the visual display and interaction module displays information in multiple dimensions and supports query and report generation; and the data storage and tracing module adopts a mixed storage architecture, so that the data security and traceability are ensured. The platform integrates multi-source data and realizes situation accurate perception and intelligent decision by means of an AI technology; the early warning is accurate, the visual interaction is convenient, and the intelligent and efficient level of network security protection is comprehensively improved.
Owner:HUNAN CONGMAO TECH CO LTD

Virtual power plant terminal access control system based on dynamic authority

The embodiment of the invention provides a virtual power plant terminal access control system based on dynamic permission, and the system comprises an identity authentication module which is configured to collect hardware invariant features and firmware signature information of terminal equipment and generate an encryption certificate; the trust evaluation module is in communication connection with the identity authentication module and is configured to continuously monitor communication behavior characteristics and service instruction characteristics of the terminal and output a dynamic trust score; the dynamic authority management module is in data connection with the trust evaluation module and is configured to adjust the access authority level in real time according to the mapping relation of the dynamic trust score in a preset authority level interval; the strategy engine module is configured to generate an access control instruction when abnormal behavior characteristics are detected; and the behavior monitoring module interacts with the strategy engine module and the dynamic authority management module and is configured to execute blocking operation and feed back an execution result to the log auditing module. And the hardware invariant features and the dynamic behavior features are subjected to fusion evaluation, so that the terminal credibility quantification precision is improved.
Owner:HUANENG SHANXI ENERGY SALES CO LTD +1

Network space security intelligent monitoring and analysis system

The invention discloses a network space security intelligent monitoring and analysis system, and relates to the technical field of network security monitoring and analysis, and the system comprises a multi-source data collection module which collects multi-dimensional data in a full-link manner, and the collection frequency is dynamically adjusted along with a network load; the data preprocessing module cleans the fused data and generates a standardized analysis data set; the AI intelligent risk identification module identifies various safety risks in real time through a mixed deep learning model; the real-time response processing module starts differential processing according to a three-level mechanism; the threat traceability analysis module traces an attack link and generates a report; the security situation visualization module displays the security state in multiple dimensions; the data encryption storage module encrypts and protects data and performs double backup; and the system self-optimization module dynamically optimizes the strategy through incremental learning. The method is accurate in risk identification, timely in response processing, reliable in traceability and evidence storage, and efficient in cross-domain cooperation; terminal protection and third-party access control are enhanced, and network space security and stable service operation are comprehensively guaranteed.
Owner:HUNAN CONGMAO TECH CO LTD

Dynamic data storage method, system and equipment based on risk level and medium

The invention discloses a dynamic data storage method, system and equipment based on risk levels and a medium, and belongs to the field of electric power systems.The method comprises the steps that feature extraction is conducted on to-be-stored data to obtain an initial feature set, semantic analysis and context association analysis are conducted on the to-be-stored data to obtain a risk feature set, and the risk feature set is stored; combining to obtain a target feature; performing risk assessment according to the target feature to obtain a risk level, and determining an encryption level according to the risk level and a preset encryption mapping table; according to the method and the device, the to-be-stored data is automatically routed to the target storage node matched with the encryption grade, and the corresponding encryption storage operation is executed on the target storage node to complete dynamic data storage, so that the optimal balance of safety and efficiency in data storage can be realized by implementing the method and the device.
Owner:GUANGZHOU POWER SUPPLY BUREAU GUANGDONG POWER GRID CO LTD

Transform encrypted traffic classification method based on pre-training and structure optimization fine tuning

The invention discloses an encrypted traffic classification method based on Transform, and belongs to the technical field of network security and encrypted traffic analysis. In order to solve the problems that load content in a novel encryption protocol (such as TLS 1.3 and VPN) is encrypted, structural disturbance is complex, category distribution is unbalanced and the like, the invention provides a dual-phase Transform framework (DPFT) with pre-training and structure optimization fine tuning. According to the framework, two self-supervision tasks of masked burst prediction (MBP) and burst structure discrimination (BSDT) are introduced in a pre-training stage, and deep data packet representation is learned from unlabeled traffic, so that the deep data packet representation is learned from the unlabeled traffic; in the fine tuning stage, dynamic weighting of word embedding and position embedding, multi-head attention pooling and Focus Loss are adopted, so that the modeling capability of the model on an encrypted traffic complex structure is enhanced, and the recognition sensitivity on minority class samples is improved. Experimental results show that the method disclosed by the invention is obviously superior to the existing method on various encrypted traffic data sets (including TLS 1.3, VPN, malicious traffic and the like), and achieves leading performance on classification accuracy and macro average F1 index.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Adaptive multi-level digital watermarking method based on coding process optimization

The invention discloses a self-adaptive multi-level digital watermarking method based on coding process optimization. The method comprises the following steps: firstly, performing deep preprocessing on an input video stream through a pre-trained multi-modal deep learning model, extracting space complexity, time dynamics and content significance features, and generating a uniform feature vector; and constructing a dynamic decision model based on the feature vectors, adaptively determining the watermark intensity, the embedding position and the type, and realizing accurate matching of watermark parameters and video content characteristics. A multi-level watermark hierarchical embedding mechanism is adopted, a robust invisible watermark, a fragile invisible watermark and a dynamic visible watermark are embedded into a video, and the security is enhanced by combining chaotic encryption or Hash chain encryption. During copyright verification, watermark information of each layer is recovered through an adaptive extraction algorithm, and data verification and infringement traceability are completed in combination with a block chain evidence storage system. According to the method, a full-process copyright protection system of embedding, coding, extraction and verification is constructed.
Owner:HANGZHOU BAOMIHUA TECH CO LTD

Verification system for proving authenticity and ownership of digital assets

Methods and systems described herein may implement blockchain asset authentication. A verification system may generate an encryption key associated with a digital asset, wherein the digital asset is associated with a first entity. The verification system may sign the digital asset using the encryption key. The verification system may generate a first key and a second key based on the encryption key, wherein the first key and the second key are part of a set of multi-party secret keys. The verification system may send the first key to the first entity and store the second key on the verification system. The verification system may receive a request to authenticate the digital asset. The verification system may in response to the request to authenticate, generate the encryption key based on the first key and the second key. The verification system may authenticate the digital asset based on the recreated first secret.
Owner:PAYPAL INC

MySQL database incremental encryption backup method and device based on MySQLdump

PendingCN121681228AError detection/correctionThird partyDatabase backup
The invention relates to the technical field of database backup, and particularly provides a MySQL database incremental encryption backup method and device based on MySQLdump, and the device comprises a total backup module, an incremental backup module, an encryption module and a backup management module; the full backup module adopts a MySQL official tool mysqldump to realize complete backup of the database; the incremental backup module is realized on the basis of a MySQL binary log binlog, and data changes are captured by analyzing event records in the binlog; the encryption module is constructed based on an OpenSSL library and provides enterprise-level data protection capability; and the backup management module realizes backup full-life-cycle management. Compared with the prior art, the method has the advantages that the problem of high consumption of traditional total backup resources and the safety problem can be solved, and meanwhile, the complexity and extra cost of a third-party backup tool are avoided.
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

Electric power multi-protocol data conversion method and system based on object model dynamic mapping

The invention discloses an electric power multi-protocol data conversion method and system based on object model dynamic mapping, and the method comprises the steps: receiving an original protocol message, recognizing a protocol type, extracting a logic name as a unique identifier of equipment, extracting an object identifier as a measurement point identifier, and extracting an electric energy array as a measurement point value; according to the protocol type and the equipment unique identifier, matching a corresponding object model template from a unified object model library; mapping the equipment unique identifier, the measuring point identifier, the measuring point numerical value and the acquisition timestamp obtained by analysis to corresponding fields in a template; and generating an object model data object conforming to a standard format, packaging the object into a message, executing an encryption authentication mechanism of a network layer and a transmission layer through the power Internet of Things security access gateway, and sending the message to an Internet of Things management platform. According to the invention, standardized, automatic and secure access of different protocol terminals is realized through protocol analysis and the unified object model library.
Owner:STATE GRID INFO TELECOM GREAT POWER SCI & TECH

Clinical test data security sharing method and device based on block chain

The invention provides a clinical test data security sharing method and device based on a block chain. The method is applied to the technical field of data processing, and comprises the following steps: extracting feature dimensions corresponding to various types of data, and calculating corresponding data sensitivity coefficients; determining a data sensitivity level of the corresponding data category; extracting corresponding associated metadata; selecting a corresponding encryption algorithm to encrypt the data, and generating corresponding encrypted data and a data abstract; uploading the associated metadata, the encrypted data and the data abstract to a block chain node, constructing a clinical test data sharing account book, and recording a timestamp and a node signature of data operation; extracting identity authentication information and historical access records of visitors, and calculating access credibility; judging whether the visitor is allowed to acquire the decryption key or not; after the visitor obtains the encrypted data, the integrity in the data transmission process is verified based on the non-tampering property of the block chain. Therefore, the security of clinical test data sharing based on the block chain is improved.
Owner:HENAN HUAPU PHARM TECH CO LTD

A composite robot multi-modal data encryption transmission method, system and terminal

The application relates to a composite robot multi-modal data encryption transmission method and system and a terminal, and relates to data transmission, which comprises the following steps: collecting information of a composite robot; classifying and encrypting the collected information through a preset encryption algorithm to obtain encrypted information; acquiring data calling information of the composite robot; determining whether the data calling information is consistent with preset reference calling information; if the data calling information is not consistent with the reference calling information, continuously acquiring the data calling information; if the data calling information is consistent with the reference calling information, encrypting the data calling information through the preset encryption algorithm to obtain encrypted calling information; and decrypting the encrypted information according to the encrypted calling information to obtain target collected information and outputting the target collected information to a preset calling platform. The application has the effect of improving the security of composite robot data transmission.
Owner:重庆优好人形机器人有限公司 +1

Edge data security protection system and method based on security chip

The invention relates to the technical field of data security of the Internet of Things, in particular to an edge data security protection system and method based on a security chip, and the system comprises edge equipment which is deployed at the edge of a network and is used for detecting or collecting original data; the security chip is embedded in or externally connected to the edge equipment, and an encryption engine and a security storage area are integrated in the security chip; the encryption engine is integrated with an encryption algorithm, and a secret key is stored in the secure storage area; the security agent software runs on a control system of the edge equipment and is in communication connection with the security chip, and the security agent software is configured with a security policy; wherein the security agent software is configured to receive original data, call an encryption engine of the security chip according to a security policy to encrypt the original data, generate protected data, and send the protected data to a cloud or a data center; or the original data is monitored, and safety measures are taken for the original data with risks.
Owner:BEIJING ANCHEN INFORMATION TECHNOLOGY CO LTD

Large language model-agnostic data anonymization

Systems and methods for large language model (LLM)-agnostic data anonymization. Data anonymization includes data obfuscation (and data deobfuscation) to protect confidential information a user is going to send to an LLM service or application programming interface (API). Encryption can be used for data obfuscation and particularly, for securing data from unauthorized access. Likewise, decryption can be used for data de-obfuscation.
Owner:ARACOR INC

Data zero-copy processing method and system based on eBPF zero-trust gateway

The invention discloses a data zero-copy processing method and system based on an eBPF zero-trust gateway, and belongs to the technical field of computer network security. According to the method, an XDP program is loaded on a network card driving layer, and an AFXDP technology is combined to construct a kernel mode and user mode shared memory pool UMEM; when an original message arrives, an eBPF unit mounted by an XDP program intercepts the message in real time, a tunnel packaging space is reserved in situ in an original memory, and if the head space is insufficient, a new memory page is logically mapped from a UMEM standby buffer pool to achieve extension. Identity fingerprints are generated by extracting message feature vectors, load in-situ encryption is completed in cooperation with a kernel kTLS module, and data are prevented from being returned to a user mode for processing. According to the method, multiple copying and context switching of a kernel-user mode of a traditional SSL VPN are eliminated, the throughput is improved by 2-3 times, the delay is reduced to the microsecond level, the CPU utilization rate is reduced by 40% or above, application layer DDoS attacks are effectively defended, and the method is suitable for 5G edge computing and cloud native zero-trust gateway scenes.
Owner:JIANGSU ENLINK NETWORK TECH CO LTD

Medical conjunct data security access control system based on quantum encryption

The invention relates to the field of medical information security, and discloses a medical conjunct data security access control system based on quantum encryption, and the system comprises a data fragmentation module which processes original electronic medical record data according to a patient identifier and a module type to obtain a plurality of scattered data units; the labeling encryption module is accessed to the quantum key distribution network to obtain a dynamically updated encryption key, and performs homomorphic encryption operation on the dispersed data units; the distributed storage module is used for generating a storage topology constraint condition containing a logic adjacency degree and a synchronous delay tolerance threshold value according to a causal sequence and a relative time interval carried in the annotation encryption fragments, and distributing the annotation encryption fragments to different medical institution servers for storage; and the access verification module is used for verifying the access authority and marking the integrity of the encrypted fragment when receiving an access request. The problems that at present, the data semantic relation is split, the storage and access efficiency is low, and the ciphertext utilization capacity is insufficient are solved.
Owner:ANHUI PROVINCIAL HOSPITAL +1

Data security evidence storage method and system for smart city construction

The invention relates to the technical field of equipment management, and discloses a data security evidence storage method and system for smart city construction. The method comprises the following steps: acquiring operation state data of target equipment and performing encryption preprocessing to construct a security data set, further identifying data exception and determining a potential emergency list with relevance; equipment is intelligently grouped according to event priorities, a resource allocation scheme is generated and dynamically adjusted, and when the scheme does not meet the evidence storage requirement, standby resources are automatically obtained, and configuration is expanded; calculating and verifying a data storage path with the shortest delay by using a path selection model fusing bandwidth and priority constraints on the basis of an expansion scheme; and finally, carrying out full-link log recording on the evidence storage process along the path, implementing integrity verification based on a cryptographic hash chain, and carrying out closed-loop evaluation on a resource adjustment effect based on a verification result to generate a confirmation result. According to the invention, the timeliness and reliability of equipment data evidence storage in a complex environment of a smart city are improved.
Owner:BEIJING MUNICIPAL ENG RES INST

Data line system and data line for intelligently switching data transmission and charging

The invention relates to the technical field of data lines, and particularly discloses a data line system and a data line for intelligently switching data transmission and charging, and the system comprises a dual-core synchronization management module which is used for enabling dual cores to enter an initial detection state through encryption synchronization signaling when equipment is connected; the asynchronous signal processing module is used for generating state judgment parameters through multi-scale sliding window processing and time-frequency domain feature fusion; the consensus decision arbitration module outputs a backtracking trigger signal through dynamic projection transformation and self-adaptive threshold comparison; the state backtracking recovery module is used for generating a retry instruction with a random delay period based on the historical backtracking success rate and the signal quality evaluation; the safety mode control module is used for identifying dominant features by analyzing historical failure records and switching to a safety operation mode; through distributed dual-core cooperative processing and an intelligent fault recovery mechanism, the technical problems of confusion of protocol stacks and deadlock of a state machine in a complex electromagnetic environment are solved, and the anti-interference capability and reliability of the system are improved.
Owner:JINING AVOVE ELECTRONICS TECH CO LTD

Encrypted traffic detection method based on space-time fusion and small sample self-supervised learning

The invention discloses an encrypted traffic detection method based on space-time fusion and small sample self-supervised learning, and the method comprises the steps: 1, multi-dimensional encrypted traffic feature extraction: extracting discriminative time sequence features and spatial header byte features from original encrypted traffic data; step 2, constructing and training a space-time fusion detection model, constructing an efficient space-time fusion detection model, and performing deep fusion and classification on the time sequence features and the space head byte features extracted in the step 1; and step 3, realizing a small sample self-supervised learning mechanism. According to the method, a space-time fusion detection model specially designed for encrypted traffic is constructed, and parallel processing and deep fusion are carried out on a time sequence and a space head byte feature. The fusion of the time-space dual features enables the model to understand the time sequence features and the structural features at the same time, significantly improves the detection precision and robustness, and can effectively cope with various encryption protocols and traffic confusion technologies.
Owner:AIRLAND INTERNET TECH CO LTD +1

End-cloud collaborative privacy protection data processing method and device, equipment and medium

The invention relates to the technical field of artificial intelligence, can be applied to business scenes of financial science and technology, medical health and the like, and discloses an end-cloud collaborative privacy protection data processing method, device, equipment and medium. Performing privacy disturbance and encryption processing on the model update information and sending the model update information to a service node, aggregating the protected model update information from a plurality of terminal nodes by the service node to form global model update, and issuing the global model update to the terminal nodes to update and optimize a local model, and meanwhile, the service node generates control parameters according to the updating effect of the global model and issues the control parameters to the terminal node so as to dynamically adjust the privacy budget and the data uploading frequency. According to the method, privacy processing is completed at the end side and aggregation and dynamic control are executed at the cloud end, so that cooperative training under the condition of no data leakage is realized, the communication burden is reduced, the model updating efficiency is improved, and privacy protection and model performance are considered.
Owner:PING AN TECH (SHENZHEN) CO LTD

Data security storage method adaptive to network security prevention and control

The invention belongs to the technical field of network security management and control, and particularly relates to a data security storage method adaptive to network security prevention and control, which comprises the steps of data acquisition, multi-dimensional feature extraction, optimal prevention and control strategy generation, hierarchical encryption storage, abnormal behavior traceability and dynamic isolation response. According to the system, illegal data injection risks are blocked from an entrance through a source data authentication acquisition module, multi-dimensional effective features of data are extracted through a multi-dimensional feature purification module, the multi-dimensional effective features and real-time network threat situations are fused through a prevention and control strategy adaptation module, and an optimal prevention and control strategy is screened by quantifying the adaptation degree; the hierarchical encryption storage module reasonably distributes storage hierarchies and executes differential encryption and hierarchical backup, the abnormal behavior traceability module accurately identifies abnormal behaviors, and the dynamic isolation response module executes hierarchical isolation and triggers emergency response and strategy optimization, so that full-life-cycle safety management and control of data from collection, storage to access is realized, and the safety of data storage is improved. And the prevention and control accuracy and the system operation efficiency are both considered.
Owner:HENAN SHENGSHI TECH CO LTD

Method, device and system for safely processing astronomical sensitive data based on privacy calculation and storage medium

The invention relates to the technical field of computers, discloses an astronomical sensitive data security processing method, device and system based on privacy calculation, and a storage medium, and aims to solve the problems that in astronomical data cross-mechanism joint analysis, original data is easy to leak, the cooperation efficiency is low, and a traditional desensitization or encryption method is difficult to consider security and availability at the same time. The method specifically comprises the following steps: each participant deploys a private computing agent node locally, and original data is not out of a domain; the task coordination center issues an analysis task; the proxy node extracts and preprocesses local data, and loads a corresponding secure multi-party computing protocol template; according to the method, share segmentation is carried out on multi-modal data such as images, spectrums and star catalogues by adopting addition homomorphic secret sharing, and distribution is carried out through a national secret SM4 encryption channel; and multiple parties cooperatively execute task-oriented security calculation in an encrypted state, and the result is aggregated and returned with the minimum information amount. The method has the effect of realizing high-precision safe collaborative analysis which is available and invisible.
Owner:HENAN ACADEMY OF SCIENCES GRAVITY WAVE ASTRONOMY RESEARCH INSTITUTE +1

Dynamic data security requirements in a network

Systems, methods and / or computer program products for dynamically adjusting levels of data security, encryption enforcement, confidentiality, network policies and other parameters within a network and at processing nodes thereof, implementing heightened levels of security and encryption as needed, based on the type of datasets being processed. Enforcement and removal of data security, encryption requirements, confidentiality, network policies and other parameters at the nodes of the network is performed using headers and footers added to the source dataset. Headers prescribe the heightened level of security or encryption being enforced at each node of the network along the source dataset's flow trajectory, while footers follow the completed processing of the source dataset and indicates to the nodes along the data flow trajectory the conditions for removing the heightened level of security, encryption, confidentiality, network policies and other parameters prescribed by the headers.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Remote monitoring method and system for explosion-proof distribution box

The invention discloses a remote monitoring method and system for an explosion-proof distribution box, and the method comprises the steps: synchronously collecting an electrical operation parameter, an explosion-proof structure state parameter and an environment related parameter, carrying out the wavelet threshold noise reduction processing and coupling correction, improving the data precision, encrypting, adding a check code, and transmitting to a remote monitoring center through dual-mode transmission. And the remote monitoring center verifies the data integrity and decrypts the data, carries out graded early warning based on a preset threshold system and a parameter change rate, and sends a corresponding intervention instruction for abnormity of an early warning grade and above. All-dimensional monitoring is achieved, safety and accuracy of data transmission are guaranteed, risks are pre-judged in advance, remote risk control is achieved, the operation safety and operation and maintenance efficiency of the anti-explosion distribution box are improved, and the system is suitable for flammable and explosive dangerous places.
Owner:SHENHAI EXPLOSION-PROOF TECH CO LTD

HTTPS protocol flow detection method, program product, electronic equipment and storage medium

The invention provides an HTTPS protocol flow detection method, a program product, an electronic device and a storage medium, and is applied to the technical field of network security, the HTTPS protocol flow detection method is applied to a security gateway which does not decrypt the HTTPS protocol flow, and the method comprises the following steps: obtaining a session record corresponding to the HTTPS protocol flow, the session record comprises time sequence feature metadata, packet length feature metadata and TLS handshake metadata; feature extraction is carried out on the session record to obtain corresponding multi-dimensional behavior features, and the multi-dimensional behavior features comprise a traffic statistical feature, a TLS fingerprint feature and a time sequence behavior feature; and performing anomaly detection on the multi-dimensional behavior features to obtain a corresponding detection result. According to the scheme, an SSL decryption function does not need to be started, the problem that traditional feature code detection fails in an encryption scene is solved, and meanwhile, the performance loss and privacy disclosure risks caused by decryption are avoided.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

Dynamic coding and decoding negotiation method based on link state quality

The invention provides a dynamic coding and decoding negotiation method based on link state quality. The dynamic coding and decoding negotiation method comprises the following steps: grouping reference station RTCM data and determining the priority of the RTCM data according to the message ID of the RTCM data; based on the determined first strategy selection mode, the RTCM data is subjected to check code generation, character coding and encryption in sequence, and the strategy selection mode of the base station is synchronized to a strategy selection module of the moving station; after the moving station receives the data, decryption, character decoding and verification are sequentially carried out on the encrypted data based on the information synchronized by the strategy selection module; meanwhile, the moving station counts the packet loss rate and the verification failure rate of the RTCM data in real time; and adjusting the strategy selection mode of the next group of data according to the quality of the current link, the system load and the priority of the RTCM data until all grouped data are sent. According to the invention, a real-time closed loop is provided, and the link quality is evaluated more comprehensively.
Owner:ZHENGZHOU XINDA ADVANCED TECH RES INST

Digital signature generation and authentication system and method

The invention discloses a digital signature generation and authentication system and method. The system comprises a first terminal and a second terminal, the first terminal comprises a first acquisition module for generating a first graphical interface, responding to a signature executed by a user on the first graphical interface, and acquiring first vector coordinate data signed on the first graphical interface; the second acquisition module is used for sampling facial features of the user; the data processing module is used for extracting a first secret key parameter from the first vector coordinate data, taking the facial feature as a second secret key parameter, and encrypting the first vector coordinate data through the first secret key parameter and the second secret key parameter to obtain secret key data; the storage module is used for storing key data; the communication module is used for transmitting the key data to a second terminal; the second terminal comprises a third acquisition module for verifying the facial features of the user; and the generation module verifies the facial features, decrypts the key data by using the second key parameter, and requests the first terminal to generate a digital copy to the second graphical interface.
Owner:HUNAN VOCATIONAL COLLEGE OF SCI & TECH

Switch configuration method and system based on AI adaptive congestion control

The invention relates to the technical field of computer network communication and intelligent control, and discloses a switch configuration method and system based on AI adaptive congestion control, and the method comprises the steps: collecting the multi-dimensional feature data of a network in real time through a data plane programmable pipeline of a switch, and transmitting the multi-dimensional feature data to an AI intelligent decision engine through an encryption channel; based on the multi-dimensional feature data, executing congestion prediction, strategy generation and interpretability analysis through an AI intelligent decision engine to obtain a congestion control regulation and control strategy; converting the congestion control regulation and control strategy into an executable switch configuration command, and issuing the executable switch configuration command to switch hardware to dynamically adjust congestion control parameters of the switch; and acquiring the network performance index after configuration execution, calculating the profit value of the congestion control strategy, and updating the model weight of the AI intelligent decision engine based on the profit value. According to the invention, the adaptability of the network to dynamic loads and complex scenes is effectively improved, delay and packet loss are reduced, and the operation and maintenance complexity is reduced.
Owner:SHANDONG CHAOYUE DATA CONTROL ELECTRONICS CO LTD

System and method for tokenization of sensitive data across computing environments

A system for protecting sensitive data through vaulted and vaultless tokenization across a distributed computing environment is provided. The system includes a processor and memory containing multiple integrated modules to secure data transmission and storage. A tokenization application programming interface (API) receives sensitive data from the distributed computing environment through a network. An encryption module applies format-preserving cryptographic transformation to the sensitive data, creating encrypted data while preserving original data format and length characteristics. A tokenization engine receives the encrypted data and generates format-preserving tokens that include structural characteristics based on the sensitive data. A management module processes encrypted data and format-preserving tokens to generate cryptographic responses. An enforcement module applies authorization rules for access control based on user roles and data classification levels. The tokenization API provides the format-preserving tokens and the cryptographic responses back to the distributed computing environments according to established user roles and data classification.
Owner:DIGITRANS LLC

Micro-service processing system

The micro-service processing system provided by the embodiment of the invention comprises an event identification module which is used for defining a business domain event type and registering an event attribute structure; the event bus module constructs a distributed communication network containing a dual-channel message queue, and the event bus module implements partition routing according to event types; the event processing module is composed of an event producer and a consumer which are executed asynchronously, the event producer packages service actions into a standardized event data packet, and the consumer processes subscription events through a thread pool; the event storage module adopts a hierarchical log database for persistence of an event sequence and supports reestablishment of a service state according to a timestamp; and the security control module is used for implementing service authentication and event content encryption on a transmission layer. Through event bus dual-channel design, sender box transaction binding and hierarchical storage optimization, millisecond-level event processing delay is realized while the reliability of distributed transactions is ensured, and second-level state recovery can be realized based on a complete event log when a service fault occurs.
Owner:HUANENG ZHAOCAI DIGITAL TECHNOLOGY CO LTD +1

Vision health data management and privacy protection method based on block chain

The invention provides an eyesight health data management and privacy protection method based on a block chain, and the method comprises the steps: verifying the role identity of a requester through an intelligent contract if a query request is detected in an encrypted archive structure, judging whether the role identity accords with a preset hierarchical authorization rule or not, and obtaining an authorization verification result; after the filtered data response is obtained, generating a hash value of query operation by adopting an encryption algorithm, and determining a unique identifier of the access so as to facilitate subsequent tracking; broadcasting the generated hash value and access details to all nodes of the block chain network through a consensus algorithm, judging whether the network is consistent or not, and obtaining a confirmed log recording block; historical access behaviors are retrieved from the confirmed log record blocks, if an abnormal access mode is found, an alarm mechanism is triggered, and a complete traceable audit path is obtained to maintain data privacy.
Owner:ZHENGZHOU RAILWAY VOCATIONAL & TECH COLLEGE