Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

306 results about "Hardware security module" patented technology

A hardware security module (HSM) is a physical computing device that safeguards and manages digital keys for strong authentication and provides cryptoprocessing. These modules traditionally come in the form of a plug-in card or an external device that attaches directly to a computer or network server. A hardware security module contains one or more secure cryptoprocessor chips.

Vehicle regulation MCU chip safe starting method and system based on national secret algorithm

The invention relates to the technical field of vehicle regulation level MCU chip safety, and discloses a vehicle regulation MCU chip safety starting method and system based on a national secret algorithm, and the method comprises the following steps: taking a built-in BootROM of a chip as a root of trust, initializing a hardware safety module HSM, and loading a bootloader; the invention further discloses a vehicle regulation MCU chip safe starting system based on the national secret algorithm. The vehicle regulation MCU chip safe starting system comprises a safe starting management module, a secret key management and storage module, a firmware integrity verification module, a trusted execution environment module and an anomaly detection and defense module. According to the invention, through supporting cross-platform adaptation of ARMTrustZone and RISC-VPMP architectures, firmware version rollback protection and starting process isolation are introduced, and integrity measurement is carried out during operation, so that comprehensive safety protection of the vehicle-mounted MCU system in starting, updating and operation processes is realized.
Owner:李响

Financial data encryption transmission and storage method based on cloud computing

The invention relates to the technical field of cloud computing financial security, and provides a financial data encryption transmission and storage method. The method is characterized by comprising the following steps of: executing sensitivity-driven data grading fragmentation on a user terminal; dynamic elliptic curve encryption is carried out on transmission data through a two-channel encryption engine, and fully homomorphic encryption is carried out on storage data; dynamically distributing the fragments to heterogeneous cloud nodes by the multi-cloud routing based on reinforcement learning; a distributed key management matrix is constructed, key fragments are dispersed and stored in a block chain and a hardware security module, and reconstruction is activated through biological characteristics. The method has the advantages that full-link ciphertext operation is realized, and the plaintext exposure risk is eliminated; ciphertext state financial calculation is supported; single point failure is resisted; the APT attack is defended dynamically; and the quantum security evolution capability is realized. The method is suitable for mobile banks, cross-border payment and other scenes.
Owner:BEIJING CREDIT MANAGEMENT CO LTD

Health data encryption storage method and device, equipment and storage medium

The invention relates to a health data encryption storage method and device, equipment and a storage medium, and the method comprises the steps: obtaining to-be-processed health data, carrying out the sensitivity analysis and grade division of the health data, and obtaining health data sub-blocks; performing encryption preprocessing on the health data sub-blocks, and performing group data protection according to a preset differential privacy algorithm to obtain encrypted data blocks; generating an initial master key through a hardware security module, and performing derived hierarchical encryption on the encrypted data block to obtain a data encryption key; performing fragmentation processing and regular distributed storage on the data encryption key to obtain a dynamic security key; and performing metadata separation storage on the encrypted data according to the dynamic security key, and performing data permission determination according to a preset role-based access control mechanism to obtain an encrypted isolation database. According to the invention, efficient security protection can be maintained under different application scenes and access permissions, and the risk of data leakage is reduced.
Owner:SHENZHEN MATERNITY & CHILD HEALTHCARE HOSPITAL +1

Food production traceability management system based on block chain

The invention discloses a food production traceability management system based on a block chain, which belongs to the field of food management systems, and is characterized in that a unique identifier ID of an inheritor is generated based on an SHA-256 Hash algorithm, a Merkle tree root Hash value of food production data is dynamically associated, a non-tampering digital identity file is constructed, a data island of traditional decentralized management is broken through, and the traceability of food production is improved. According to the technical scheme, full-chain credible association between the non-abandoned technology and the production process is ensured, validity of an electronic signature is automatically verified by means of an intelligent contract, data tampering or identity failure risks are recognized in real time by comparing a public key decryption result with a signature hash value, JSON format alarms are pushed by means of Apache Kafka message middleware, cross-department collaborative response is achieved, and the security and reliability of the electronic signature are improved. The risk prevention and control efficiency is remarkably improved, encryption signature is performed in combination with an ECDSA key pair of a hardware security module, strong binding of an inheritor identifier, a production batch and equipment is ensured, identity fraudulent use or qualification counterfeiting is prevented, and traceability of the whole life cycle of non-abandoned skill inheritance is achieved.
Owner:BEIJING KAIWU DIGITAL TECH CO LTD

Systems and methods for threshold cryptography for cloud-based software-implemented hardware security modules

Disclosed herein are systems and methods for threshold cryptography for cloud-based software-implemented hardware security modules. In an embodiment, an encryption system collects at least a decryption-threshold number of private-key shares from a secure store, where the private-key shares correspond to a public key generated in a first secure enclave as part of a secret key set, which also includes a first plural quantity of the private-key shares. The encryption system obtains an ephemeral-hardware-security-module-(eHSM)-encryption key by decrypting the collected private-key shares. The encryption system initializes, in a second secure enclave, a second instance of a first eHSM. The initialized second instance of the first eHSM is encrypted with the obtained eHSM-encryption key.
Owner:ASSA ABLOY AB

Remote attestation method for trusted data space

The invention discloses a remote proving method for a trusted data space, which relates to the technical field of computer and data security, and comprises the following steps: initializing a trusted environment and generating a dynamic identity key for a heterogeneous terminal containing a CPU (Central Processing Unit), a GPU (Graphic Processing Unit) and an FPGA (Field Programmable Gate Array) based on a hardware security module and a physical unclonable function, and generating a challenge value by a verifier by using a quantum random number; the method comprises the following steps of: firstly, transmitting to a proving party through quantum encryption and a neuromorphic photonic network, constructing proving by the proving party by adopting a tensor decomposition zero-knowledge proving protocol, finishing multi-stage verification on a verification party in combination with a space-time cause and effect graph and quantum signature aggregation, and finally realizing dynamic trust evaluation and adaptive strategy adjustment through a quantum Bayesian network, reinforcement learning and biological feedback. According to the method, the remote attestation performance of the trusted data space is improved, dynamic trust evaluation is realized by means of the quantum Bayesian network and biological feedback, attacks are effectively resisted, real-time requirements are met, trust is accurately evaluated, and the development of the trusted data space is promoted.
Owner:JIANGSU IDEABANK MICROELECTRONICS TECH

Method and apparatus for distributing encrypted device unique credentials

A system and method for providing credentials device unique credentials to a chip is disclosed. In one embodiment, the method comprises receiving the credentials in credential provisioning server (CPS), the credentials having information encrypted according to a secure server key (SSK) securely stored in a hardware security module (HSM) communicatively coupled to the CPS, the hardware security module also securely storing a master key; receiving a credential request in the CPS, the credential request comprising a chip identifier that identifies the chip; securely decrypting the encrypted information in the HSM according to the SSK; securely computing a chip-unique key in the HSM, according to the chip identifier and the master key; re-encrypting the decrypted information according to the computed chip-unique key; and providing the credentials having the re-encrypted information to the device.
Owner:ARRIS ENTERPRISES LLC

Embedded security management method based on digital RMB industrial control equipment

The invention relates to an embedded safety management method based on digital RMB industrial control equipment, and belongs to the technical field of industrial control system safety. The method comprises the following steps: during first deployment, carrying out information binding on an asymmetric key pair of the industrial control equipment and an equipment identity identifier to generate an equipment digital certificate; the digital signature is verified step by step from a private key of the asymmetric key pair during power-on starting through a safe starting process; when communication is established, performing digital signature on a communication key by calling a signature function of the hardware security module based on a challenge-response mechanism; when a digital RMB transaction is carried out, the trusted execution environment and the digital RMB hardware wallet module carry out secure interaction, and a transaction instruction is analyzed; during the operation period of the equipment, key data streams are continuously collected and analyzed by deploying an exception monitoring module. Reading, querying and related business transactions of the digital RMB on the industrial control equipment are achieved, and it is ensured that the identity is not forged and the instruction is not tampered.
Owner:SHANGHAI FEICHEN ELECTRONIC TECH CO LTD

Tamper-resistant end-to-end service data evidence storage method and system

The invention discloses a tamper-resistant end-to-end service data storage method and system, and relates to the technical field of service data storage methods, and the method comprises the steps: initializing a hardware security module and a monotone increasing clock in terminal equipment, building a unique identity identifier of the equipment, and preparing a log environment for recording service data; the method comprises the following steps: collecting current business data and associated meta-information thereof, and constructing input content of current data processing in combination with an equipment identity, a clock value, a data structure template and an abstract value generated by previous business data; hash operation is carried out on the input content to generate an abstract of the business data, the abstract is signed by using a hardware security module to form an equipment side digital signature, and the abstract, the signature and meta-information are written into a log only increasing but not changing and an offline queue; and after the terminal recovers the network connection, generating a unique idempotent key based on the abstract of the service data or the combination of the equipment identity and the clock, and submitting an evidence storage request containing the abstract and the signature to the server.
Owner:北京跃创三品文化科技有限公司

Multi-dimensional credit asset traceability system and method

The invention discloses a multi-dimensional credit asset traceability system and method. The system comprises a data acquisition and encryption module (10) which is used for performing encryption and digital signature on credit asset data based on a trusted execution environment (TEE) and a hardware security module (HSM) at a data generation end; the parallel Hash processing module (20) is used for performing parallel Hash operation on the encrypted data and generating leaf node Hash values based on GPU acceleration and a multi-thread technology; the nested hash and zero-knowledge proof module (30) constructs leaf node hash values into a compression type Merkle tree and generates a zero-knowledge proof (ZKP), so that a third party can verify the authenticity and consistency of data without accessing full data; the on-chain evidence storage module (40) is used for recording root Hash (RootHash) and zero knowledge proof of the compression type Merkle tree to the block chain; the dynamic authorization and secure multi-party computing module (50) performs access clipping on the credit asset data based on the access intention and realizes verification of the minimum data dimension through secure multi-party computing (SMPC). Through combination of technical means such as trusted hardware acquisition, parallel hash calculation and privacy protection verification, rapid verification is realized on the premise of not exposing original data, and verification performance, data security and privacy protection capability are remarkably improved.
Owner:北京娱广科技有限公司

Cloud storage data encryption and authority management platform

The invention relates to the technical field of computer communication and data security, in particular to a cloud storage data encryption and authority management platform which comprises a user side, a transmission channel module, a distributed processing module, a cloud server and a key management module. A user side divides a file to generate sub-file units and encrypts the sub-file units, and a secret key is stored in a hardware security module; the transmission channel module transmits the sub-file units to the distributed storage nodes; the distributed processing module generates extended data and a storage position key; the cloud server manages and ranks the keys; and the key management module generates a combined key and distributes the combined key according to authority. Through the block chain technology and the semantic hiding rule, the original content is disguised in a fragmented manner, and the detection risk is reduced; and a multi-stage key separation and dynamic combination mechanism is adopted, so that full-disk data exposure caused by leakage of a single key is avoided, and the data security is improved.
Owner:SHANGHAI XINGYI ANYI TECHNOLOGY CO LTD

Power grid industrial control system security protection method and device based on block chain

The invention discloses a power grid industrial control system security protection scheme based on a block chain, and belongs to the field of power grid automation security. Aiming at the problems of high centralized authentication risk, weak physical layer protection and the like of a traditional industrial control system, a trusted execution environment and intelligent contract response system is constructed through fusion of a block chain distributed account book and a hardware security module (HSM). According to the scheme, equipment physical identity binding and vibration monitoring are achieved through an HSM, the consensus efficiency is optimized through an improved PBFT algorithm, instruction legality, parameter compliance and execution logic rationality are dynamically verified in combination with an intelligent contract, a security baseline is generated in real time, and the instruction stream deviation degree is monitored. The method can dynamically balance the security and real-time performance of the instruction, reduce manual intervention, improve the abnormal response efficiency to a second level, is suitable for industrial control systems such as SCADA (Supervisory Control And Data Acquisition) and the like, remarkably improves the protection capability in scenes such as DDoS attack resistance and physical tampering detection, and provides an extensible intelligent protection normal form for power grid security.
Owner:GUANGZHOU POWER SUPPLY BUREAU GUANGDONG POWER GRID CO LTD

System, method, device and equipment for safe communication between charging pile and BMS and storage medium

The invention relates to the field of electric vehicle charging control, and particularly provides a system, method, device and equipment for safe communication between a charging pile and a BMS and a storage medium, the system comprises a bidirectional authentication module, a communication encryption module, a verification module and an optimization module; the bidirectional authentication module is used for constructing a bidirectional authentication protocol between the charging pile and a battery management system (BMS) based on the hardware security module and authenticating the identity; the communication encryption module is used for customizing an integrated transport layer security protocol line through an open source tool and encrypting security communication data; the verification module is used for designing a three-level verification mechanism, blocking a malicious firmware injection path and verifying a secure communication process; and the optimization module is used for optimizing the key process by adopting a redundant backup scheme deployed in a containerization manner. Through the system, the effect of a safe communication process between the charging pile and the BMS can be realized.
Owner:CHINA FAW CO LTD

Energy storage battery cabin control method based on high-safety performance multi-source data acquisition and transmission

The invention provides an energy storage battery cabin control method based on high-safety-performance multi-source data acquisition and transmission, and relates to the technical field of energy storage battery management and control. Original multi-source data in an energy storage battery cabin and in an environment where the energy storage battery cabin is located are acquired; preprocessing the original multi-source data through a cabin-mounted edge controller to obtain a calibrated multi-source data set so as to fuse and generate a transmission feature vector corresponding to the calibrated multi-source data; constructing a multi-objective optimization model according to the short-term load, the renewable output and the transmission feature vector; a management strategy corresponding to the transmission feature vector is solved based on a multi-objective optimization model, and a regulation and control instruction corresponding to the management strategy is encrypted and signed through a cabin-mounted hardware security module, so that the regulation and control instruction is issued to a dispatching center and allocated to a cabin-mounted edge controller; according to the energy storage battery compartment control method and the energy storage battery compartment control system, the response speed of the energy storage battery compartment can be improved, and the fault-tolerant capability of the energy storage battery compartment can be improved.
Owner:HUBEI ELECTRIC POWER EQUIP

Data encryption method suitable for open source gap terminal equipment

The invention discloses a data encryption method applicable to open source gap terminal equipment, which comprises the following steps of: firstly, establishing communication connection based on a gap distributed soft bus technology, and generating a trust relationship through identity identification authentication; during data transmission, a national cryptographic algorithm, a symmetric or asymmetric encryption algorithm, a hybrid encryption algorithm and the like are dynamically selected according to data types, importance, transmission scenes and equipment performance. After being encrypted, the data are transmitted to the target device through the soft bus, and the target device decrypts and verifies the data. And the terminal equipment is integrated with the hardware security module to realize hardware encryption and key storage. Security module adaptation development is carried out based on an HDF library, and one-time development and multi-terminal operation are achieved. In the encryption process, a fragmentation encryption strategy can be adopted, multiple devices can perform collaborative encryption and decryption, and the encryption efficiency is improved by defining the task priority and sequence and utilizing a distributed task scheduling mechanism and reasonably allocating resources.
Owner:BEIJING SPACEFLIGHT TUOPUGAO SCI & TECH CO LTD

Key management system and method, medium and product

The invention discloses a key management system and method, a medium and a product, an offline key generation part and a key storage part are deployed, the offline key generation part stores a first initial key, and the key storage part stores a second initial key paired with the first initial key. According to the method and the device, an offline key generation part is used for generating an encrypted key based on a first initial key in an offline mode, a key storage part is used for decrypting the encrypted key by using a second initial key, and the decrypted key is written into a preset secure storage area. Generation, distribution and storage of the secret key are realized, so that the system cost is effectively reduced.
Owner:SHENZHEN XIHUA TECHNOLOGY CO LTD +2

Hardware security module and controller

The present invention provides an HSM and a controller. The HSM includes an HSM bus matrix and, connected to the HSM bus matrix, a plurality of HSM master modules, an HSM external bus port, an HSM SRAM and a plurality of HSM slave modules. The HSM master modules include an HSM CPU core and an HSM DMA. The HSM slave modules include at least one encryption / decryption engine module. The HSM of the present invention complies with the Evita standard, and through storing sensitive information in the HSM SRAM or the like, provides secure execution and storage. Not only data isolation between the HSM and an external host, and hence protection of sensitive information, can be provided, the use of the HSM DMA allows the HSM CPU core to be offloaded from heavy data movement, thereby enhancing operating efficiency of the HSM CPU core.
Owner:GIGADEVICE SEMICON (BEIJING) INC

KMS dedicated HSM design (direct access)

A method of providing access to a hardware security module (HSM) partition may include receiving request for access to the HSM partition from a client device. The request may include a leaf certificate signed with a public key associated with a user and a secret key associated with the client device. The method may include verifying the request using the leaf certificate and a trust anchor certificate signed with a public key associated with the client device. The method may include a first connection between the HSM partition and the client device. The method may include verifying the request using the leaf certificate and an authentication certificate stored on the HSM partition. The method may include establishing a second connection between the client device and the HSM partition such that the computing system is isolated from the second connection.
Owner:ORACLE INT CORP

Control device and key information concealment method

To provide a control device and a key information concealment method that effectively conceal key information when the key information is stored in a hardware security module provided in an in-vehicle computer system.SOLUTION: A control device 10 includes a control unit 22, a memory unit 16, and a hardware security module 18, and the method of concealing key information by the control unit includes an activation process S1 for activating the hardware security module, a write process S2 for writing key information 32B corresponding to key information 32A stored in the memory unit before the activation process to the hardware security module after the activation process, and a deletion process S3 for deleting the key information stored in the memory unit after the write process.SELECTED DRAWING: Figure 3
Owner:ASTEMO LTD

Link encryption and key diversification on a hardware security module

A Hardware Security Module (HSM) (900), and method thereof, suitable for use in securely servicing cryptographic requests from multiple tenant applications to preserve end-to-end privacy is provided. A Link Encryption and Key Diversification interoperability (43) between two processors provides cryptographic and logical isolation between multiple tenant applications on the HSM (900) that use and share more than one PCIe Physical Function (30) over more than one Virtual Function (VF) (21) to one or more Crypto Units (CU) (61) for satisfying a request (46) of an HSM cryptographic services. An Output Feedback (OFB) block with CRC support is further provided with encryption and decryption. The HSM as configured is more resistant to side channel attacks.
Owner:THALES DIS CPL USA INC

Cryptographic integrity verification and adaptive artificial intelligence document extractor system for workflow automation in various domains

A system and method for secure and efficient automated workflows includes two complementary components. A digest embedding system verifies the integrity of workflow event sequences using a rolling SHA-256 digest salted with microsecond-precision timestamps. A template-caching extractor adaptively processes heterogeneous electronic documents. The digest system enables decentralized verification without querying centralized audit logs. The extractor uses a layout hash derived from document structure to route documents through either a low-latency, rule-based extraction path or a fallback artificial intelligence model path. New templates are generated for previously unseen layouts exceeding a confidence threshold. The disclosed methods improve latency, resource utilization, energy utilization and scalability in sectors including finance, healthcare, and logistics, offering advantages over existing prior art in terms of integration, specific mechanisms for timestamp salting, hardware security module utilization for workflow events, layout-based template caching, and adaptive learning.
Owner:LEGACI LABS INC

Client information confidentiality management method and system based on encryption algorithm

The invention relates to the field of information confidentiality management, in particular to a client information confidentiality management method and system based on an encryption algorithm. The whole-process closed-loop management from key distribution to data encryption and decryption and then to service analysis and optimization is realized. Firstly, high-strength key protection and hardware acceleration provided by a hardware security module are utilized, key management and core encryption and decryption operation of sensitive data are executed in a secure environment as much as possible, and the risks of key leakage and data tampering are reduced from the source. And secondly, the system ensures the responsibility division and information transmission orderliness of each module in the processing flow through clear data stream butt joint. Through the architecture, large-scale and diversified data can be encrypted firstly after entering the system, then differential analysis is realized according to different sensitive levels, and finally a comprehensive result is obtained through linkage optimization.
Owner:SHENZHEN QIANHAI MINGYUE XINSI SOFTWARE CO LTD

Card password generation method and device, card password jet printing method and device, card password verification method and device, terminal and storage medium

The invention discloses a card password generation, jet printing and verification method and device, a terminal and a storage medium, and the method comprises the steps: reading an enterprise code and a seed code corresponding to the enterprise code from a hardware security module, and enabling each enterprise to have a unique enterprise code; based on a hardware security module, generating a card number according to the enterprise code, the seed code and a preset card number generation algorithm, and generating a card password corresponding to the card number in combination with the card number and a preset card password generation algorithm; spraying and printing the generated card password on a card password area on the coupon corresponding to the card number through spraying and printing equipment; carrying out OCR (Optical Character Recognition) on the coupon to obtain a card password recognition result, and comparing the card password recognition result with the card password; and if the comparison result is consistent, covering the card password area and deleting the card password. According to the method, dynamic generation and verification of the card number and the card password are realized based on the hardware security module, and the card password is not stored after being generated, so that the effects of improving the card password security and the product quality and avoiding information leakage are achieved.
Owner:SUZHOU JINHETONG SOFTWARE

Compliance firewall for inline validation of tokens in communication, storage, and financial transactions

The invention provides a compliance firewall that transforms legal and regulatory obligations into protocol-level enforcement. Communication traffic, identifiers, or financial transactions cannot be forwarded unless inseparably bound to a Compliance Jurisdiction Token (CJT), or alternatively a General Authorization Token (GAT), validated inline within a trusted execution environment or hardware security module. Each token carries session identifiers, consent artifacts, jurisdiction codes, adequacy references, and expiry metadata, and is dual-signed using both classical and post- quantum cryptographic algorithms. Replay attempts, jurisdictional leakage, and unauthorized substitution are technically blocked by validation logic that operates simultaneously at application, network, and hardware layers. All allow and deny events are hash-chained into immutable ledgers, furnishing regulators with verifiable audit proofs without exposing raw personal identifiers. The cumulative effect is that compliance frameworks such as GDPR, DPDPA, PSD2, and AML are converted from policy guidance into mandatory, cryptographically enforceable guarantees.
Owner:DAS SANGAM

Personalization of a secure element

A method for personalizing an integrated secure element, which is permanently installed in a mobile end device. The method involves the agreement of a shared secret between the secure element and an HSM, encrypting an operating system, and possibly personalization data and / or one or several profiles, in the HSM based on the shared secret and transferring the encrypted operating system to the secure element, and re-encrypting the operating system in the secure element for storage in the NVM memory of the mobile end device.
Owner:GIESECKE DEVRIENT MOBILE SECURITY GERMANY GMBH

Implementation method of transparent encrypted virtual file system based on hardware key

The invention provides a transparent encryption virtual file system implementation method based on a hardware key, and aims to solve the problems of poor user experience, complex key management, insufficient security and the like of an existing file system encryption scheme. Hardware-level key isolation is realized to ensure that the key never leaves the USB KEY; transparent user experience is provided, and after a hardware key is inserted and a password is input, an encrypted file can be operated like accessing a common file; file-level fine-grained access control is supported, real-time encryption is performed during writing, and real-time decryption is performed during reading; and when the USB KEY is pulled out, the virtual file system cannot be accessed immediately, only the encrypted ciphertext is stored in the physical storage, and meanwhile, the stability of the system is ensured based on the mature FUSE technology, so that the defects in the prior art are effectively solved.
Owner:QINGDAO WEIWEIYAN DATA INFORMATION TECHNOLOGY CO LTD

Cryptographic integrity verification and adaptive artificial intelligence document extractor system for workflow automation in various domains

A system and method for secure and efficient automated workflows includes two complementary components. A digest embedding system verifies the integrity of workflow event sequences using a rolling SHA-256 digest salted with microsecond-precision timestamps. A template-caching extractor adaptively processes heterogeneous electronic documents. The digest system enables decentralized verification without querying centralized audit logs. The extractor uses a layout hash derived from document structure to route documents through either a low-latency, rule-based extraction path or a fallback artificial intelligence model path. New templates are generated for previously unseen layouts exceeding a confidence threshold. The disclosed methods improve latency, resource utilization, energy utilization and scalability in sectors including finance, healthcare, and logistics, offering advantages over existing prior art in terms of integration, specific mechanisms for timestamp salting, hardware security module utilization for workflow events, layout-based template caching, and adaptive learning.
Owner:LEGACI LABS INC

AI model edge device binding protection method based on hardware security module

The invention relates to a security protection method for binding an AI model and an edge device based on a hardware security module, and belongs to the technical field of information security. The method comprises the steps of generating a unique secret key pair of equipment, safely storing a private key, integrating a hardware safety module, recording a public key and an equipment ID, obtaining the public key of target equipment, encrypting an AI model, generating an encryption model file, loading an encryption model, verifying the safety of a decryption process, the integrity of the model and the matching of the equipment ID, and the like. Unique binding of the AI model and the edge device is achieved through the hardware security module, unauthorized access and use are prevented, meanwhile, the security of model parameter transmission and storage is improved, and the requirements of edge computing scenes for efficient and secure AI model deployment are met.
Owner:YUNNAN TRAFFIC PLANNING DESIGN RESEARCH INSTITUTE CO LTD

Supermarket cash register data real-time processing and privacy protection method based on edge computing

The invention discloses a supermarket cash register data real-time processing and privacy protection method based on edge computing. According to the invention, through edge node localization training and a gradient parameter sharing mechanism, the data transmission pressure of a central node is obviously reduced, the convergence speed of a global model is effectively improved through a dynamic weighted aggregation algorithm, the iteration period of a transaction risk control model is greatly shortened, and the response delay of a system to abnormal transactions is controlled at an extremely low level; a high-concurrency transaction scene can be efficiently processed, the real-time detection capability and the system stability are enhanced, a differential encryption strategy is implemented for data with different sensitivities by a hierarchical privacy protection architecture, the unpredictability of a core data key is ensured by quantum random number encryption, a dynamic differential privacy algorithm automatically adapts to data distribution characteristics when noise is added, and the real-time detection capability and the system stability are improved. A hardware security module is combined with a threshold secret sharing mechanism, and a multi-layer protection system is constructed from a physical layer to a protocol layer, so that the risk of data leakage is effectively reduced, and meanwhile, the compliance requirements of related laws and regulations are met.
Owner:GUANGZHOU CHAOYING SOFTWARE ON CO LTD

Decoding algorithm program authorization and binding method on embedded chip

The invention relates to a decoding algorithm program authorization and binding method on an embedded chip, which comprises the following steps that: an authorization server generates an asymmetric key based on a chip UID (User Identifier), performs static encryption on an algorithm code by utilizing symmetric encryption and then splits the key into fragments, the fragments are respectively stored in a chip security area and a server side, and signatures are added to the fragments to verify the integrity. And when the chip is activated for the first time, the server verifies the legality of the UID and issues fragments through the secure channel, and after recombination, the symmetric key is decrypted to recover an algorithm plaintext code. During operation, a dynamic offset is generated through multiple rounds of Hash iteration of a chip UID, a control flow jump address is redirected in real time, and in combination with polymorphic transformation and invalid instruction filling obfuscation logic, a code execution path is uniquely bound with hardware, and fragmentation recombination verification is strongly coupled with dynamic offset calculation logic. According to the method, through cooperation of an encryption strategy, a hardware security module and a dynamic obfuscation technology, the comprehensive protection capability of reverse engineering resistance, physical attack resistance and code duplication resistance is remarkably enhanced.
Owner:NEWLAND YOUMAIJIE (GUANGDONG PROVINCE) TECHNOLOGY CO LTD