Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

246 results about "End-to-end encryption" patented technology

End-to-end encryption (E2EE) is a system of communication where only the communicating users can read the messages. In principle, it prevents potential eavesdroppers – including telecom providers, Internet providers, and even the provider of the communication service – from being able to access the cryptographic keys needed to decrypt the conversation.

Cloud-edge collaborative intelligent storage node dynamic deployment method and system

The invention discloses a cloud-edge collaborative intelligent storage node dynamic deployment method and system. The method comprises the following steps: monitoring performance indexes such as edge node data traffic and storage resource state in real time; a deep learning algorithm combining time sequence analysis and an LSTM neural network is adopted to analyze traffic information, and a data access demand is predicted; edge nodes and cloud storage resource configuration are dynamically adjusted based on a prediction result, and an intelligent scheduling algorithm, a data cold and hot separation strategy and a self-adaptive fragmentation technology are introduced to allocate resources; the storage node layout is optimized in real time, and an optimal data distribution path is selected through a reinforcement learning strategy; data security and access control are realized by adopting end-to-end encryption, multi-level access control and block chain technologies. The system comprises a monitoring acquisition module, a prediction analysis module, a resource scheduling module, a path optimization module and a security control module. According to the method, the utilization efficiency of storage resources is improved, data delay is reduced, system stability and data security are enhanced, and the method is suitable for a cloud edge collaborative storage scene.
Owner:NANJING NANDA SIWEI TECHNOLOGY DEVELOPMENT CO LTD

Traditional Chinese medicinal material processing and production monitoring management system

The invention belongs to the field of production monitoring management, and provides a traditional Chinese medicinal material processing production monitoring management system, which comprises a data acquisition module used for acquiring environment parameter data at each flow node of traditional Chinese medicinal material processing production; the encryption and signature module is used for performing end-to-end encryption on the acquired data and the image data; the edge calculation module is used for receiving the encrypted data from the data acquisition module; the block chain storage module is used for uploading the data verification record of each process node to a block chain main chain through a smart contract; the out-of-chain storage module is used for storing the encrypted data and generating a unique distributed storage address; the intelligent contract module is used for checking at each process node; the anomaly detection and alarm module is used for triggering an anomaly alarm when the verification of the smart contract fails; and the tracing module is used for tracing the processing links of each batch of traditional Chinese medicinal materials based on the whole process record stored by the block chain.
Owner:YUNNAN DAODI MEDICINAL MATERIALS CITY CO LTD

Apparatus and method for secure communication and integration with secure and non-secure root ports

Secure communication provided with secure and non-secure root ports. One embodiment comprises: a plurality of cores; a memory controller to couple to a memory; an interconnect fabric coupled to the plurality of cores and the memory controller; and a root complex to support end-to-end encrypted channels between devices, the root complex comprising: a root port to receive non-posted requests from a requestor device, the root port to associate a first tag value with a non-posted request to indicate whether the non-posted request is received over an end-to-end encrypted channel; and a bridge device to transmit the non-posted request with the first tag value and to subsequently receive a completion message including the first tag value, wherein the root port is to determine whether the completion message is to be encrypted in accordance with the end-to-end encrypted channel based on the first tag value.
Owner:INTEL CORP

Distributed computing power dynamic scheduling method, equipment and medium

The invention discloses a distributed computing power dynamic scheduling method and device and a medium, and the method comprises the steps: packaging heterogeneous computing power resources of a home terminal and an edge cloud node through a lightweight containerization technology, and collecting the hardware resource state data of the home terminal and the load data of the edge cloud node in real time; generating a dynamic scheduling strategy according to the task calculation type and the real-time network state of the to-be-calculated task, and splitting the to-be-calculated task into a plurality of sub-tasks according to the dynamic scheduling strategy; distributing the sub-tasks to home terminals or edge cloud nodes according with a dynamic scheduling strategy, and aggregating calculation results of the sub-tasks; and performing end-to-end encryption and fragmentation verification on the cross-domain transmitted data stream, and dynamically adjusting the task allocation permission of the home terminal based on the equipment security score.
Owner:INSPUR YUNZHOU (SHANDONG) IND INTERNET CO LTD

Remote data rapid transmission system and method based on Internet

The invention discloses a remote data rapid transmission system and method based on the Internet, a client initiates a session establishment request containing a session type identifier and a transmission protocol identifier to a server, receives a session response message after transmitting an initial data packet, obtains a temporary session key through verification of a key distribution center, and transmits the session response message to the server; an authorization identifier and a protocol verification symbol are generated through hierarchical decryption, a security enhancement data packet is constructed and sent, an end-to-end encryption transmission channel is further established, and meanwhile, a session maintenance mechanism is provided. And the server verifies a session type identifier and a transmission protocol identifier of the client, generates a session response message containing a dynamic confusion strategy and a trap identifier, submits the session response message to a key distribution center for signature, returns the session response message to the client, activates a secure transmission service instance after verifying a security enhancement data packet, and implements a series of security control strategies. According to the invention, the problems of low transmission efficiency and poor security of the existing remote data transmission system are effectively solved, and efficient and secure data transmission is realized.
Owner:GUANGZHOU KAIYAS TECHNOLOGY CO LTD

Safety transmission system based on multimedia short message

The invention discloses a secure transmission system based on a multimedia short message, and relates to the technical field of communication and network security, and the system comprises a protocol stack security reinforcement module which carries out the hierarchical reconstruction of an MMS protocol stack, comprises a preprocessing layer, is used for intercepting and filtering illegal characters, and verifies the legality of a message structure through a finite-state machine; the analysis layer is used for pre-judging memory requirements based on message types and lengths by adopting a dynamic memory allocation strategy; the execution layer is integrated with a null pointer checking mechanism, and the validity of a pointer is forcibly verified before a protocol stack calls a function; the encryption and signature module is used for carrying out end-to-end encryption on a message body and metadata by adopting a hybrid encryption algorithm and carrying out message integrity verification through a lightweight hash tree; and the vulnerability real-time monitoring module is embedded into an abnormal behavior detection model based on machine learning and is used for dynamically identifying memory occupation abnormity and illegal instruction calling high-risk operation when the protocol stack runs.
Owner:BEIJING XUNYIN TECH CO LTD

QR-Code-Based Authentication for Closed Mesh Networks

A method for secure onboarding to a closed mesh network in which a camera-equipped device scans a QR code embedded in a durable physical carrier (e.g., adhesive bandages, photographs, ID cards) to extract an access credential, configuration profile, or secure URL that automatically configures the device for network access, authenticates the device to the mesh without manual credential entry or transmission of plaintext credentials over insecure channels, and establishes end-to-end encrypted communications between network nodes; the method supports cryptographically random, single-use or time-limited credentials with periodic refresh to prevent replay, encoding of VPN / WireGuard or proprietary configuration profiles, substantially real-time onboarding (e.g., under five seconds), optional multi-factor verification (biometric or PIN), immediate initiation of secure messaging, voice / video or data sessions upon onboarding, audit logging for compliance and revocation based on detected unauthorized activity, and covert or overt embedding of QR codes in environment-resistant carriers for emergency, disaster response, first responder, or covert deployment, with the QR code rendered unreadable or deactivated after successful onboarding to prevent credential reuse.
Owner:DURYA SARA +2

Data encryption transmission method and device in hybrid cloud environment, equipment and storage medium

The invention relates to the field of data encryption, in particular to a data encryption transmission method and device in a hybrid cloud environment, equipment and a storage medium. The method comprises the following steps: acquiring data to be transmitted; performing key field deep semantic analysis on the to-be-transmitted data, and performing dynamic layered encryption to obtain a plurality of layered encrypted transmission data packets; available transmission path detection is carried out on the hybrid cloud environment, dynamic end-to-end encryption is carried out, and a plurality of end-to-end encryption transmission links are constructed; performing distributed encryption transmission and dynamic transmission path decision on the plurality of layered encryption transmission data packets based on the plurality of end-to-end encryption transmission links, and constructing a dynamic transmission path adjustment strategy; detecting all user access behaviors in the hybrid cloud environment; and carrying out user cloud service provider classification on all the user access behaviors, carrying out personalized behavior modeling, and constructing a behavior portrait of each user. According to the invention, efficient and safe data encryption transmission for the hybrid cloud environment is realized.
Owner:SHENZHEN TRUSTED CLOUD TECH CO LTD

Star flash chip isolation and end-to-end encryption Internet of Things management system

The invention discloses an Internet of Things management system for star flash chip isolation and end-to-end encryption, and relates to the technical field of data security. An isolation communication link is established based on a physical frequency hopping channel through a star flash chip, and bottom layer identity confirmation is performed based on equipment hardware fingerprints; generating a session dynamic identity tag through the current timestamp, the equipment hardware fingerprint and the star flash channel signal feature; executing multiple rounds of challenge and response recursive interaction according to the dynamic identity tag to form an authentication closed loop; detecting abnormal response and calculating risk intensity in the authentication process so as to feed back a threat level signal; the authentication and encryption algorithm is dynamically adjusted based on the real-time state of the smart home equipment; predicting a user behavior and generating a session cache in advance; and finally, on the basis of the weight of the task and the pressure of the bandwidth, allocating the resources of the channel to which the current channel establishment unit is switched.
Owner:FUJIAN MAIWEI INFORMATION ENG CO LTD

Systems and methods for blockchain-enabled end-to-end encryption

A system is provided to leverage blockchain for a Multi-Signed Certificate-To-Identity (MSC-To-IT) system using a distributed approach to allow end users to have greater control over their digital identities and cryptographic keys. The system can manage cryptographic keys in a distributed network. The system can include a plurality of nodes configured to participate in a blockchain network. The system can include a key generation module, operable on at least one of the nodes, to distribute generation of cryptographic keys using a threshold scheme, where the cryptographic keys can include a public key and a private key share for each participating node.
Owner:EL MAJDOUBI DRISS

Cloud platform scheduling method and system based on multi-source Internet of Things perception

The invention discloses a cloud platform scheduling method and system based on multi-source Internet of Things perception, and relates to the technical field of cloud platform scheduling, and the method comprises the steps: constructing a dynamic adjustable sensor topology network, optimizing a node communication path, and employing an AES symmetric encryption protocol real-time dynamic key distribution and topology synchronization updating mechanism; fusing the core indexes in real time, establishing a multi-dimensional coupling model, and generating a dynamic priority matrix; based on the dynamic priority matrix, quantitatively analyzing the coupling relationship of the core indexes; based on historical data and real-time monitoring information, carrying out security-aware dynamic partition management on the encrypted computing resources, and dynamically allocating the encrypted computing resources; a closed-loop security control framework from the edge to the cloud is constructed, data flow security is guaranteed through end-to-end encryption transmission, cross-task interference is prevented by calculating security partitions of encryption calculation resources, fusion of multi-modal data is completed, and a real-time feedback adjustment closed-loop control mechanism is formed.
Owner:JIEYANG HUAXUN NETWORK SERVICE CO LTD

Dynamic verification method for informatization system based on zero-trust architecture

The invention discloses an informatization system dynamic verification method based on a zero-trust architecture, and the method comprises the steps: collecting and standardizing user operation requests of all business systems, and achieving unified resource and organization identification; a distributed encryption operation log link is constructed through an end-to-end encryption protocol, and safe synchronization and tampering prevention of an operation behavior abstract are guaranteed; extracting a multi-dimensional right decision variable, inputting the multi-dimensional right decision variable into an adaptive artificial intelligence decision model, dynamically generating a reversible permission factor set, and supporting fine-grained and rollback permission authorization and real-time automatic revocation; the log chain is encrypted and recorded in the whole process, intelligent abnormity monitoring and end-to-end traceability are combined, the consistency and compliance auditing of the global permission state are supported, and the security, traceability and intelligent self-adaptive treatment capacity of sensitive operation in the multi-organization cooperation environment are effectively improved.
Owner:GUANGDONG YUEMI TECH SERVICE CO LTD

End-to-end encryption with per-hop path-selection based on unique edge identities for sd-wan and multi-hop networks

A system and associated methods provide solutions for end-to-end privacy and per-hop routing and policy decision in multi-hop and Software-Defined Wide Area Networks (SD-WANs) by leveraging unique SDWAN edge identities of edge devices. The system enables end-to-end encryption between traffic source and destination sites using IPsec ESP tunnel mode, with System IPs as the outer IP addresses. The system further enables per-hop integrity protection using IPsec AH transport mode, with WAN IPs as the outer IP addresses. By having some information encrypted between a source device and a destination device and other information encapsulated between hops (e.g., between source device and an intermediate device), the system enables route and policy lookup based on destination site System-IP, along with integrity protection based on SLA-class in packet metadata for independent path selection at intermediate hops.
Owner:CISCO TECHNOLOGY INC

Data exchange method and device for trusted data space and medium

The invention discloses a data exchange method and device for a trusted data space and a medium. The method comprises the following steps: establishing a verifiable registry and a distributed digital steward of a trusted data space; registering a data space main body ID for each main body of the trusted data space, and signing and issuing an identity certificate for each main body based on the data space main body ID; according to the identity credentials and the private keys of all the main bodies, identity mutual recognition among all the main bodies is achieved, and an incidence relation is established; writing metadata required by the data provider or the data developer to publish data into a verifiable registry, and establishing a data space data ID of the metadata based on the data space main body ID of the data publisher and the metadata; connection is established among distributed digital housekeepers, an end-to-end encryption connection pipeline is formed, and encryption data exchange is completed based on a connection channel.
Owner:AISINO CORPORATION

Intelligent community management service system

The application discloses a smart community management service system, and particularly relates to the field of service management, comprising a perception layer module, a communication layer module, a data processing layer module and an application layer module; the application realizes global intelligent management through the collaborative architecture of the perception layer module, the communication layer module, the data processing layer module and the application layer module; the perception layer is deployed with multi-source heterogeneous sensors, and data preprocessing is conducted in combination with edge computing; the communication layer adopts multi-protocol fusion transmission, supports 5G+NB-IoT dual-channel redundancy and end-to-end encryption; the data processing layer is based on a cloud-edge collaborative architecture, uses Kalman filtering denoising, D-S evidence theory fusion conflict information, LSTM-Attention prediction device failure, and constructs a digital twin simulation optimization energy consumption; the application layer provides a three-dimensional visual management and control platform, integrates security linkage, air conditioner group control strategy driven by reinforcement learning and convenient service scheduling, and supports cross-platform access and RBAC permission management.
Owner:宋新伟

Methods, systems and computer program products for secure encryption of data for transmission via an untrusted intermediary

The invention is directed toward systems, methods and computer program products that enable end to end user authentication along with encryption to mitigate the risks posed by untrusted or unsecure intermediary entities. The invention (i) enables full end to end encryption of sensitive data that has been input by a user on a terminal device at one end, and the intended or authorized recipient at the other end, (ii) ensures that data entered by the user on the terminal device is not readable by any intermediary entity including a partner application or other software application implemented within the terminal device, and (iii) eliminates the risk of successful local attacks on the terminal device to unauthorizedly access user data, or to unauthorizedly obtain access to encryption / decryption keys that can be used to unauthorizedly access encrypted user data.
Owner:EPIFI TECH PTE LTD

Distributed photovoltaic data acquisition method and device based on adaptive encryption communication and multi-link redundancy

The invention provides a distributed photovoltaic data acquisition method and device based on adaptive encryption communication and multi-link redundancy, and the method comprises the steps: collecting real-time power generation data, equipment state data and environment parameters of a photovoltaic system through a multi-source sensor, and forming original data; an MQTT over TLS adaptive encryption communication protocol is adopted to perform end-to-end encryption on original data, and dynamic key management is combined to ensure transmission security; based on a dynamic link selection algorithm, encrypted data is transmitted to a power master station through 4G and LoRaWAN double-link redundancy, so that the transmission reliability is improved; and the master station side decrypts the data and then integrates the data to a database to support power grid dispatching and predictive analysis. According to the invention, the problems of safety and reliability in distributed photovoltaic data acquisition are solved, and the method is suitable for a smart power grid monitoring scene with high reliability and high real-time performance requirements.
Owner:HUBEI CENT CHINA TECH DEV OF ELECTRIC POWER

Privacy number-based traceable secure communication method, device and equipment

The invention relates to a traceable security communication method, device and equipment based on a privacy number, and belongs to the technical field of communication processing, and the method realizes credible storage of communication data by obtaining a communication record and generating a distributed unique identifier, adopting an SM2 algorithm for signature and writing evidence data into a block chain. Meanwhile, the preset master key is subjected to fragmentation processing, a plurality of sub-key fragments are generated, the storage position is determined, and the session key is generated by adopting an SM4 algorithm to perform end-to-end encryption on the communication content, so that the communication security is guaranteed. Besides, a zero-knowledge proof protocol is introduced for identity verification, dynamic risk assessment and an authority fusing mechanism are combined, high-risk communication is effectively prevented, multiple cryptography technologies and safety mechanisms are comprehensively applied, and safety, credibility and auditing performance of the communication process are comprehensively improved.
Owner:HANGZHOU RONGXUAN INFORMATION TECH CO LTD

Smart home equipment control method and system based on QUIC point-to-point communication

The invention relates to a smart home equipment control method and system based on QUIC point-to-point communication, and belongs to the technical field of smart home control, and the control method comprises the steps: receiving a natural language instruction of a user terminal, and carrying out the analysis to obtain a target equipment identifier and an operation intention description text; retrieving a pre-constructed equipment registry according to the target equipment identifier, and obtaining a corresponding cue word template and a QUIC connection address; calling an artificial intelligence model deployed locally, and outputting a structured equipment control instruction in combination with the operation intention description text and the cue word template; performing signature encryption on the structured equipment control instruction, establishing a QUIC end-to-end encryption transmission channel between the user terminal and the target equipment, and transmitting the QUIC end-to-end encryption transmission channel to the target equipment; receiving operation response data fed back by the target equipment after the target equipment verifies and executes the structured equipment control instruction; the device registry is dynamically optimized based on the operational response data. According to the invention, the risk of cloud service privacy leakage can be reduced, and the data security of the smart home system is improved.
Owner:BEIJING LIUJINSUIYUE TECH CO LTD

Forward and backward secure audio and video communication system and communication method based on dynamic key updating

The invention discloses a forward and backward secure audio and video communication system and method based on dynamic key updating. The system comprises a client and a server. The client is responsible for interacting with a user, completing end-to-end encryption and key dynamic updating functions of data communication, and providing protection for audio and video communication data; the server side is responsible for user identity authentication, certificate issuing management, friend group chat relationship maintenance and audio and video streaming media data forwarding; the method comprises the following steps: a user registers an account, establishes a video room and invites the user to initiate an audio and video call, and the room user quits at any time and initiates key update actively in the whole call process; according to the method, the data security of audio and video communication of a user is ensured through end-to-end encryption, and meanwhile, a key version management mechanism is adopted, so that when the user joins in or leaves a conference, a video initiator (Host) can issue a new key version and automatically switch to a new key after a certain time, and the synchronization and security of key updating are ensured; the method supports forward security and backward security, even if a certain key version is leaked, an attacker still cannot decrypt historical or future communication content, and the method has a wide market application prospect.
Owner:XIDIAN UNIV

Audio and video transmission method and device based on multi-modal AI enhancement and dynamic end-to-end encryption, equipment and storage medium

The invention discloses an audio and video transmission method and device based on multi-mode AI enhancement and dynamic end-to-end encryption, equipment and a storage medium, and relates to the technical field of digital audio and video processing and secure transmission, and the method comprises the steps: obtaining an original audio and video stream, and separating the original audio and video stream into audio data, video data and subtitle text data; performing multi-mode AI enhancement processing on the audio data, the video data and the subtitle text data to obtain enhanced audio and video data; generating an encryption decision instruction based on the real-time network state, and performing encryption processing on the enhanced audio and video data according to the encryption decision instruction to generate encrypted data with a tamper-proof watermark; and when the encrypted data passes integrity verification and copyright legality judgment, the encrypted data is transmitted through a secure transmission channel, and collaborative optimization of security and efficiency is realized through a core technology chain of multi-modal separation enhancement, dynamic encryption decision, hardware-level watermark binding and credible verification transmission.
Owner:SHENZHEN JIUZHOU ELECTRIC

Systems, methods and devices for device fingerprinting and automatic deployment of software in a computing network using a peer-to-peer approach

Disclosed herein are embodiments of methods, devices and systems for device fingerprinting and automatic and dynamic software deployment to one or more endpoints on a computer network. The device fingerprinting systems and devices herein are configured to operate with limited data without sitting between network devices and the internet, without monitoring all network traffic, and without limited or no active scanning. The embodiments herein may passively collect information as distributed peers and may perform very limited active scans. In some embodiments, the information is used as an input to a custom hierarchical learning model to fingerprint devices on a network by identifying attributes of the devices such as the operating system family, operating system version, and device role. In some embodiments, a dynamic deployer selection process may be utilized to simply and efficiently deploy software. Some embodiments herein involve end-to-end encryption of credentials in a deployment process.
Owner:SENTINEL LABS ISRAEL

Hardware-level identity authentication and end-to-end encryption near-field data interaction method and system for electric red-in secure connection terminal

The invention relates to the technical field of near-field communication security, in particular to a hardware-level identity authentication and end-to-end encryption near-field data interaction method and system for an electric red-connected terminal, and the method comprises the steps: a first electric red-connected terminal and a second electric red-connected terminal initiate pairing based on a Bluetooth secure connection pairing protocol, and negotiate to generate a long-term key through an ECDH algorithm; performing bidirectional identity verification by adopting an application layer authentication protocol; activating AES-CCM encryption by using a session key derived from a long-term key; bluetooth signal strength and a connection state are monitored in real time, and a negotiation key is automatically paired again when abnormity occurs; generating an interaction log, digitally signing the log by using a locally stored private key, and securely storing the signed log in a local secure storage area of the terminal; the digital signature of the latest log is verified, and if interaction abnormity is found, the local security module of the terminal recovers the local data to the pre-interaction state according to the last credible log record. The problem that traditional Bluetooth communication is prone to eavesdropping and tampering can be solved.
Owner:ELECTRIC POWER RES INST OF GUANGXI POWER GRID CO LTD

Multi-link data return system and method based on low-altitude aircraft and medium

The invention discloses a multi-link data return system and method based on a low-altitude aircraft and a medium, and the system comprises an airborne multi-link communication gateway which is used for connecting a plurality of communication links at the same time, and dynamically selecting the communication link with the optimal current performance based on link quality parameters for data return; the protocol conversion module is used for receiving the TCP data stream from the aircraft intranet equipment and converting the TCP data stream into a QUIC data stream in a QUIC protocol; the data encryption module is used for performing end-to-end encryption processing on the QUIC data stream to generate an encrypted QUIC data packet; and the data transmission module is used for receiving the encrypted QUIC data packet, keeping QUIC connection when an IP address changes through a Consection ID mechanism of a QUIC protocol, and sending the encrypted QUIC data packet to a ground receiving end through the selected optimal communication link. According to the invention, seamless switching among multiple links and efficient and safe data transmission are realized.
Owner:JITAI AVIATION TECH (SUZHOU) CO LTD

End-to-end encrypted communication-based permission allocation method and system

The invention relates to the field of dynamic permission allocation, and discloses a permission allocation method and system based on end-to-end encrypted communication, and the method comprises the steps: mapping a user attribute set into a multi-dimensional vector, and generating a multi-dimensional vector set reflecting the dynamic characteristics of a user; extracting a user vector and an access strategy vector from the multi-dimensional vector set, and calculating a matching degree score of the user vector and the access strategy vector; if the matching degree score is higher than a first threshold value, extracting a corresponding permission identification code and a permission valid period from a permission database, and generating a preliminary permission allocation scheme containing permission hierarchical division and permission association roles; and allocating a scheme according to the preliminary authority. The method has the advantages that authority distribution is dynamically adjusted according to user behaviors and contexts which change in real time.
Owner:HANGZHOU RONGXUAN INFORMATION TECH CO LTD

End-to-end encryption with password access

Presented herein are techniques to implement end-to-end encryption. A method includes, encrypting content C with an encryption key EK to obtain encrypted content C′, generating a key encrypting key KEK based on a password, encrypting the encryption key EK with the key encrypting key KEK to obtain an encrypted encryption key EK′, storing the encrypted content C′ and the encrypted encryption key EK′ such that the encrypted content C′ and the encrypted encryption key EK′ are accessible to a content consumer via a link, sending the link and the password to the content consumer, and in response to a request, received via the link, for the encrypted content C′ and the encrypted encryption key EK′, sending the encrypted content C′ and the encrypted encryption key EK′ to the consumer based on the content consumer being on an access control list.
Owner:CISCO TECHNOLOGY INC

Systems and methods for end-to end-encryption with encrypted multi-maps

According to some aspects, provided are systems and methods that implement end-to-end encryption, and provide implementation configured to secure information during execution of queries on an encrypted data source. Various embodiments include multiple encrypted multi-map data structures and associated encryption schemes configured to securely read, write, and delete information while supporting any one or more of the following features: snapshot security, multiple client support, efficient execution under concurrent operation, and resilience to client failures. In various embodiments, addressable multi-map data structures enable concurrent access, and allow correct operation under polynomial time constraints.
Owner:MONGODB INC

End-to-end encrypted data key distribution method, electronic device and program product

The invention provides an end-to-end encrypted data key distribution method, electronic equipment and a program product, and the method comprises the steps: randomly generating a session key if an effective data key does not exist in a memory; encrypting the first data by using the public key to obtain a session key ciphertext; the first data comprises a session key; generating a first type of request information and sending the first type of request information to a server, wherein the first type of request information comprises a session key ciphertext; the server receives the first type of request information, obtains a session key ciphertext, decrypts the session key ciphertext by using a private key to obtain a session key, generates a data key through a pseudo-random function according to a current first timestamp, a client identity identifier and a master key, and sends the data key to the server; encrypting the data key and the first timestamp by using the session key to obtain a data key ciphertext, and sending a first type of response information including the data key ciphertext to the client; the client analyzes a data key ciphertext according to the first type of response information; and decrypting the data key ciphertext by using the session key to obtain the data key and the first timestamp, and storing the data key and the first timestamp in a memory. According to the invention, the security of end-to-end communication is greatly improved, and the calculation and storage burden of the server is reduced.
Owner:KE COM (BEIJING) TECHNOLOGY CO LTD

Energy storage terminal remote security upgrading method and system based on end-to-end encryption

The invention relates to the technical field of terminal upgrading, and provides an energy storage terminal remote security upgrading method and system based on end-to-end encryption. The method comprises the following steps: acquiring a first upgrading task packet sent by a trusted user in an encrypted manner; performing polymorphic malicious implantation detection fusion to generate a detection result; tracing the tampering feature based on the source data, and generating a tracing result; purifying the task package in combination with the detection and tracing results to generate a second upgrading task package; performing block encryption on the second task packet, predicting a transmission risk, and constructing a risk chain; implementing block security upgrading according to the risk chain to generate a fourth task package; and the upgrade management server issues the fourth task package to the energy storage terminal. The technical problem that malicious implantation and tampering behaviors are difficult to find and clear in time in the remote upgrading process of an existing energy storage terminal, and consequently data leakage and system intrusion risks exist in terminal upgrading is solved, and the technical effect of improving the safety and reliability of remote upgrading of the energy storage terminal is achieved.
Owner:NANTONG GOTION NEW ENERGY TECHNOLOGY CO LTD