Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

1830 results about "High security" patented technology

Secure communication method for edge node and terminal equipment based on dynamic key negotiation

The invention relates to a secure communication method for an edge node and terminal equipment based on dynamic key negotiation. The method comprises the following steps: the terminal equipment sends an initial signal when initiating a communication request; the edge node generates a scenarized first key negotiation parameter and feeds back the scenarized first key negotiation parameter after passing dual identity and state verification; after the terminal device decrypts the parameter, a dynamic entropy value is collected by combining a network adaptive sensor, and a second key negotiation parameter associated with the first parameter feature is generated; the two parties calculate session keys based on an ECDH algorithm, and the consistency of the keys is ensured through dynamic entropy verification and Hash comparison; and after the key negotiation succeeds, entering a hierarchical encrypted data transmission stage, and dynamically updating a session key based on a multi-dimensional trigger mechanism. According to the method, through hardware credibility verification, a scenarized key strategy, dynamic entropy enhancement and national secret algorithm adaptation, dynamic management of keys and adaptive matching of terminal resources are achieved, attacks such as equipment counterfeiting and parameter tampering are effectively resisted, and the high-security and compliance requirements in the fields of industrial control and the like are met.
Owner:BEIJING HUAKUN ZHENYU INTELLIGENT TECH CO LTD

APP data trusted storage and sharing method based on block chain

The invention relates to the field of block chain technology and application security, and discloses a block chain-based APP data trusted storage and sharing method, which comprises the following steps of: maintaining a verifiable state container comprising state data and an access policy dual-Merkel tree under a chain, and recording a root hash of the verifiable state container in the block chain; for different updates, generating corresponding evidences: generating single-step evidences containing Merkel evidences for single-step updates; and generating the composite proof containing the zero-knowledge proof for the complex process. And the intelligent contract can update the root hash in an atomized manner only through verification and certification. During data sharing, data and dual Merkel proof are provided for a consumer to verify data authenticity and access legality. According to the method, complex calculation is arranged under a chain, low cost and constant overhead of on-chain verification are achieved, and meanwhile high-safety data credible storage and refined authority control capacity are provided through a dual-tree dual-certificate mechanism.
Owner:CHENGDU YIDOU TECHNOLOGY CO LTD

Power real-time data dynamic encryption transmission method and system based on national secret algorithm

The invention discloses an electric power real-time data dynamic encryption transmission method and system based on a national secret algorithm. According to the method, the real-time updating of the session key is realized by fusing the SM3 Hash algorithm and the multi-dimensional dynamic factor, and the anti-attack capability of data transmission of the power system is improved. A timestamp and data counter double-trigger mechanism is introduced in the key generation process, so that the key is automatically alternated under a fixed time interval or a data volume threshold value, a key exposure window is shortened, and the security risk caused by using the same key for a long time is reduced. Key synchronization is carried out in combination with an SM2 bidirectional authentication channel, the confidentiality of key distribution is ensured, access of unauthorized equipment is avoided through an identity authentication mechanism, full-closed-loop security protection from key generation to transmission is formed, the high-security requirement of the power industry for key data transmission is met, and the security of key data transmission is improved. Through deep combination of a cryptographic algorithm system and a dynamic adaptation mechanism, the high efficiency and compliance of power real-time data transmission are considered while the security is ensured.
Owner:GUIZHOU WUJIANG HYDROPOWER DEV

Transformer substation fire risk dynamic assessment method and electronic equipment

The invention discloses a transformer substation fire risk dynamic assessment method, which comprises the following steps: constructing a transformer substation digital twin model according to the live information of a transformer substation; constructing a transformer substation fire risk deduction model according to a fire propagation mechanism and the live information; and generating substation fire risk assessment information according to fire deduction information output by the substation fire risk deduction model. By adopting the transformer substation fire risk dynamic assessment method, the current data of the transformer substation can be collected and analyzed in real time to dynamically assess and predict the fire risk, the fire risk management and prevention and control level of the transformer substation is remarkably improved, and the operation requirements of the transformer substation for high reliability and high safety are met.
Owner:GUIYANG BUREAU OF CHINA SOUTHERN POWER GRID CO LTD EHV TRANSMISSION CO

Multi-band multi-channel unmanned aerial vehicle RID signal analysis system

The invention relates to the technical field of unmanned aerial vehicle supervision, and discloses a multi-band multi-channel unmanned aerial vehicle RID signal analysis system. According to the system, RID signals of 2.4 GHz, 5.2 GHz and 5.8 GHz frequency bands are collected in parallel through a multi-frequency-band antenna group and a multi-channel radio frequency receiving module, and real-time analysis and algorithm scheduling of the RID signals are achieved through an FPGA + ARM heterogeneous processing unit. Four modules of multi-sensor space-time alignment and cross validation, lightweight national secret encryption and data integrity verification, self-adaptive scheduling based on reinforcement learning and unmanned aerial vehicle behavior digital twinning and intrusion early warning are integrated in algorithm, and a closed-loop processing flow from RID signal receiving, data calibration and secure transmission to intelligent research and judgment is formed. The method effectively solves the problems of incomplete RID signal coverage, low data reliability, weak safety protection, insufficient early warning capability and the like in the prior art, has the advantages of high analysis precision, good safety, high resource utilization rate, accurate early warning and the like, and is suitable for low-altitude supervision scenes such as urban security and protection, border management and control and the like.
Owner:CHENGDU KONGYU TECH CO LTD

An underwater data center

The application discloses an underwater data center, which comprises a pressure cabin, an outer frame, a lifting structure, a pipeline structure, a server cabinet inside the pressure shell, an inspection lifting structure, a fixing and moving mechanism, and an internal state monitoring system; the pressure cabin is a closed structure formed by the pressure shell, and at least one pressure cabin entrance structure is arranged on the surface of the pressure cabin; the lifting structure comprises a hydraulic jacking oil cylinder and a lifting guide column; the server cabinet is arranged in an array in the pressure shell, and is fixed and moved by the fixing and moving mechanism at the upper end and the lower end for control. The application can realize efficient water-out and water-in actions by using the lifting mechanism; the application is suitable for high-stable underwater cooling of a large-volume high-density data center system; the pressure cabin entrance is provided, so that the inspection personnel can enter the pressure cabin for inspection without water-out, and the working efficiency and use efficiency are high; and the state monitoring system ensures high safety of the internal environment and timeliness of risk discovery.
Owner:翟恒亮

Distributed quantum security encryption method, system and device

The invention provides a distributed quantum security encryption method, system and device. The method comprises the following steps: monitoring the quality of a quantum key distribution link in real time, and dynamically selecting a quantum key, a post-quantum session key or a fusion key of the quantum key and the post-quantum session key as a working key; and when the node cannot be directly reached, the trusted relay node generates an end-to-end key seed by using a quantum key and a post-quantum cryptography shared key which are respectively established with the two ends, the end-to-end key seed is encrypted and distributed by a public key and then a session key is independently derived by the two communication parties, and the relay node cannot decrypt. The system adopts a distributed Mesh network architecture supporting a terminal / relay dual mode. The device integrates a quantum random number generator, a post quantum cryptography coprocessor and a mixed key engine. The method integrates the advantages of quantum physical security and post quantum cryptography, has high security and availability, and is suitable for constructing a key infrastructure security communication network resisting quantum computing attack.
Owner:INFORMATION & COMMNUNICATION BRANCH STATE GRID JIANGXI ELECTRIC POWER CO

Intranet and extranet synchronous transmission method and system based on TCP protocol

According to the internal network and external network synchronous transmission method and system based on the TCP provided by the invention, file type detection and file title detection are realized at a server side, compliance screening is carried out on file contents before a transmission link, and sensitive files are prevented from entering a transmission link; after the detection is passed, segmented transmission is carried out by adopting a preset fragmentation rule, and breakpoint resume is executed by utilizing a fragmentation index when the transmission is interrupted, so that the stability and the efficiency of large file transmission are remarkably improved; furthermore, the server pushes the downloading notice to the extranet client through the TCP after receiving the auditing result of the intranet client with the auditing authority, so that the file is ensured to be subjected to the auditing link before being transmitted to the extranet, and the unification of high safety, controllability and high efficiency is realized.
Owner:GUANGZHOU BAOLUN ELECTRONICS CO LTD

Implementation method of electronic signature of customs business scene and seal management system

The invention relates to the technical field of information security, discloses a realization method of an electronic signature of a customs business scene and a seal management system, and aims to solve the problems of trust centralization, easy data tampering, difficult traceability, poor business adaptation and insufficient interoperability of an existing electronic signature. According to the method and the system, a distributed account book technology is introduced, decentralized creation and registration, signature generation and verification, life cycle management and on-chain recording of auditing and tracing of the electronic seal are realized, a dynamic and configurable business scene strategy engine is constructed, a customs business process is flexibly adapted, and high safety, high efficiency and high adaptability are ensured. According to the method, a decentralized trust basis is established, the tamper-proofing capability and efficiency are improved, full-chain auditing traceability and cross-mechanism interoperation are realized, and data security is guaranteed.
Owner:ORIENT KOUAN TECH CO LTD

Two-dimensional code full-life-cycle tracking management system based on dynamic encryption

The invention discloses a two-dimensional code full-life-cycle tracking management system based on dynamic encryption, relates to the technical field of two-dimensional code tracking management, and is characterized in that a target object life cycle state sequence diagram is constructed, and a two-dimensional code coding index is dynamically generated based on a current state, an equipment environment and a time factor; and dynamic generation and secure binding of two-dimensional code content are realized in combination with a multi-factor asymmetric encryption mode. Meanwhile, through path consistency verification and state chain continuity judgment, validity verification is carried out on a two-dimensional code access behavior, and the validity of the two-dimensional code is judged in combination with an environment deviation detection mechanism; compared with the prior art, the method can effectively prevent the two-dimensional code from being counterfeited, replayed and visited unauthorized, improves the uniqueness, verifiability and safety of the two-dimensional code in the whole life cycle, and is suitable for high-safety product tracking, anti-counterfeiting authentication, multi-stage identity recognition and other scenes.
Owner:SHANGHAI MAILIAN INFORMATION TECHNOLOGY CO LTD

Low-altitude economic flight data management method based on block chain technology

The invention discloses a low-altitude economic flight data management method based on a block chain technology, and relates to the technical field of low-altitude traffic management, and the method comprises the steps: verifying an encrypted positioning proof, generating a verification state set, decrypting flight coordinates according to the verification state set, and generating a credible coordinate data stream; performing sensitive airspace intrusion detection according to the credible coordinate data stream and the high-security protection node, performing collision risk analysis by the traffic management node to obtain an encrypted aggregated threat vector, and identifying a threat level according to the encrypted aggregated threat vector; and dynamically adjusting the working parameters of the airborne equipment according to the threat level, generating an airborne equipment regulation and control instruction set, scanning the signal-to-noise ratio and the threat intensity in real time, dynamically allocating a communication frequency band, and generating a new positioning strategy parameter. According to the method, the real-time signal-to-noise ratio and the threat intensity scanning result are combined, communication frequency band dynamic allocation and encryption strategy dynamic optimization are driven, the airspace situation awareness capacity is formed, the resource utilization rate is increased, and the anti-interference capacity is enhanced.
Owner:NANTONG INST OF TECH

Sweep point imaging encryption transmission method based on GaN heterojunction device

The invention discloses a scanning point imaging encryption transmission method based on a GaN heterojunction device, and belongs to the technical field of semiconductor photoelectronics. According to the method, the same device is switched between a high-speed'detection mode 'and a'synaptic mode' with a memory effect, encryption is realized by utilizing response difference of the device in two working modes, and an encryption key of the device is an analog and time-varying bias protocol instead of a simple digital sequence. The characteristics of the physical unclonable function endow the physical unclonable function with extremely high encryption strength, so that the physical unclonable function is difficult to crack by a conventional algorithm and has higher security.
Owner:JIANGNAN UNIV

Collaborative secret state task matching method based on edge calculation in mobile crowdsourcing

The invention discloses a collaborative secret state task matching method based on edge calculation in mobile crowdsourcing. The method comprises the steps of system initialization and key generation, requester-cloud platform registration authentication, worker-edge server registration authentication, login authentication and attribute submission, requester task issuing, cloud platform task delegation, secret state matching, worker task content decryption, worker answer submission, answer forwarding and decryption. According to the invention, cooperative authentication of workers and requesters and precise task matching based on attributes are realized under an edge-cloud architecture. A fuzzy extractor and an authentication encryption method with associated data are introduced, so that low-cost user local authentication and registration and authentication of a joining system are realized, the security is improved, and the calculation cost is reduced. Through function hidden inner product encryption and a Paillier cryptographic algorithm, task-worker matching and task answer submission are realized in a ciphertext state, and the requirements of a mobile crowdsourcing application scene with high safety, high privacy and dispersed cost are met.
Owner:SHAANXI NORMAL UNIV

Pipeline welding parameter optimization method and system for construction of natural gas conveying system

The invention belongs to the technical field of welding process optimization, provides a pipeline welding parameter optimization method and system for natural gas conveying system construction, and is used for solving the technical problems of high hydrogen-induced cracking risk, parameter dependence on artificial experience and optimization process isolation lag in shallow hydrogen natural gas conveying pipeline welding. According to the method, a visual image of a molten pool, a joint thermal field, electric arc electrical parameters and environmental data are synchronously collected through a multi-source sensor, a hydrogen diffusion-thermal coupling model is constructed to calculate hydrogen concentration and stress, after reference parameters of a knowledge base are called, current, voltage and speed adjustment amounts are generated through a GBDT algorithm, and then real-time correction is conducted through a closed-loop module. According to the method, hydrogen-induced cracking can be quantitatively prevented and controlled, the weld joint failure probability in the shallow hydrogen environment is reduced, the process robustness and quality consistency are improved, the safe service life of the pipeline is effectively prolonged, and the high-safety energy conveying requirement is met.
Owner:BEIJING BODA SHUNYUAN NATURAL GAS CO LTD

Lightweight low-delay quantum key distribution method and system adaptive to electric power scene

The invention discloses a lightweight low-delay quantum key distribution method and system adaptive to an electric power scene, and belongs to the technical field of quantum communication and electric power communication crossing. The method comprises the steps cooperatively executed by a sending end and a receiving end: the sending end determines a basis vector based on a pre-associated quantum fingerprint sequence and a timestamp, sends a key through polarization-phase two-dimensional coding, generates a selection mark and executes privacy amplification; and a receiving end synchronizes a timestamp to determine a basis vector, compares the basis vector with the quantum fingerprint to complete authentication, decodes through an integrated module, performs collaborative error correction and executes privacy amplification. The system comprises functional modules of a sending end and a receiving end, is integrated on a miniaturized board card, and supports common-fiber transmission and protocol conversion. According to the method, the problems of high time delay, high deployment cost and poor adaptability of the traditional QKD are solved, the end-to-end time delay is reduced to 14 microseconds, the deployment cost is reduced by more than 60%, the requirements of high safety, low time delay and lightweight deployment of a power system are met, and the method is suitable for key services such as power dispatching and relay protection.
Owner:CHINA ELECTRIC POWER RESEARCH INSTITUTE CO LTD

Weak-current intelligent building control management system

The invention discloses a weak current intelligent building control management system, which comprises a plurality of groups of different types of sensors, a data collection module, a data storage module, a data comparison and elimination module, an emergency management module and a control center. A plurality of groups of different types of sensors are distributed in each key area of a building, all-directional environment monitoring is ensured, preprocessing steps such as Kalman filtering and mean value filling are introduced to improve data quality, data storage adopts a block chain technology based on Hyperledger Fabric, data cannot be tampered and high security is realized, and the method is suitable for large-scale popularization and application. And the data comparison and elimination module verifies the sensor data in multiple dimensions by using transverse comparison, longitudinal comparison, logic verification and redundancy cross validation, so that the accuracy and consistency are improved, and the fault-tolerant and anti-interference capabilities of the system are enhanced.
Owner:HANGZHOU JINCHENG QINGYUN TECHNOLOGY CO LTD

Intelligent cabin mechanical arm system

The invention relates to the technical field of automobile electronics and intelligent control, and discloses an intelligent cabin mechanical arm system which comprises a folding mechanical arm body, a tail end sensing interaction module, a driver state monitoring subsystem and a central control unit which are installed in a cabin. The central control unit controls the storage or working mode of the mechanical arm according to the comprehensive fatigue index of the driver; in the working mode, visual gazing information is used as a gating signal to activate electroencephalogram analysis, the operation intention is confirmed in combination with the visual prior probability and electroencephalogram signals, and the mechanical arm impedance parameters are adjusted in real time based on the fatigue state. According to the method, through Bayesian fusion of vision and electroencephalogram signals, the problem that single-mode control is unstable is solved; by means of variable impedance control and collision detection of the momentum observer, active safety protection based on the physiological state of the driver is achieved, and non-sensitive and high-safety intelligent auxiliary experience is provided in a limited cabin space.
Owner:BEIJING YINGZHI TECH CO LTD

Encryption access control method and platform for industrial security data

The invention provides an encryption access control method and platform for industrial security data, and relates to the technical field of data encryption access, and the method comprises the steps: carrying out the attribute classification and code identification of an industrial system data set; performing security level division on the industrial system data set according to the data security quantitative index system; performing matching analysis on the multi-level industrial security data set based on the data encryption algorithm list; encrypting and storing the industrial system data set based on the industrial data identification code set by adopting a multi-stage data encryption algorithm to generate an industrial encrypted data warehouse; and establishing a fine-grained access mechanism and a decryption interaction mechanism according to the user role library, and performing access authority distribution and encryption access control on the industrial encrypted data warehouse based on the fine-grained access mechanism and the decryption interaction mechanism. According to the invention, the technical problem that the comprehensive requirements of high safety, high precision and high flexibility in a modern industrial system are difficult to meet in the prior art can be solved.
Owner:BEIJING RONGSHUAN TECH CO LTD

Security data isolation and information exchange method and system based on lightweight protocol

The invention relates to a security data isolation and information exchange method and system based on a lightweight protocol, belongs to the technical field of industrial automation control system security, and solves the technical problems of low transmission efficiency, high analysis overhead, high security risk and high resource consumption of an existing method. Comprising the following steps: collecting and preprocessing original plaintext data at an industrial control network side; an external unit identifier, a timestamp and a pre-shared key on the industrial control network side are used as encryption factors, lightweight stream cipher encryption and packaging are carried out on the preprocessed data, and a lightweight protocol data packet is generated; through a special physical isolation device, the light-weight protocol data packet subjected to deep detection is unidirectionally isolated and ferried from an industrial control network side to an internal network side; performing post-processing on the received lightweight protocol data packet at the intranet side to restore original data; and delivering the restored original plaintext data to an intranet service application. And safe and efficient information data exchange is realized.
Owner:BEIJING JINGHANG COMPUTING & COMM RES INST

High-performance polypropylene material for food packaging and preparation method thereof

ActiveCN121021983AElastomerMontmorillonite
The invention discloses a high-performance polypropylene material for food packaging and a preparation method thereof, and the high-performance polypropylene material comprises the following raw materials by weight: 80-90 parts of polypropylene, 10-15 parts of POE, 5-8 parts of modified montmorillonite, 4-7 parts of a compatilizer, and 0.3-0.5 part of an auxiliary agent. According to the high-performance polypropylene material for food packaging, the montmorillonite subjected to multi-step modification is introduced into a polypropylene matrix, and meanwhile, the POE elastomer and the compatilizer are added, so that the prepared composite material keeps excellent mechanical toughness and processability, and meanwhile, the barrier property of the composite material to gases such as oxygen and water vapor is remarkably improved; the heat resistance and the ultraviolet aging resistance of the material are also remarkably improved, toxic and harmful solvents or auxiliaries are not introduced into the material, the preparation process is stable and controllable, and the strict requirements for long shelf life, high safety and cost control in the field of high-performance food packaging can be met.
Owner:JIEYANG SHUNLIYE PLASTIC TECHNOLOGY CO LTD

Method and system for generating random number by using mobile phone holding micro-vibration and touch pressure

The invention relates to the technical field of information security and random number generation, and particularly discloses a method and a system for generating a random number by utilizing mobile phone holding micro-vibration and touch pressure, and the random number is generated by collecting physical behavior characteristics when a user holds a mobile terminal within preset time and combining sensor signal processing and a randomness extraction algorithm. The random number generation does not need external hardware support, the randomness is higher, the operation is simple and convenient, and the problems of insufficient randomness and complex operation caused by dependence on an external noise source or specific input in the prior art are solved. According to the method, the dependence on the external environment or additional hardware is avoided, the security, unpredictability and practicability of random number generation are remarkably improved through a multi-level security protection mechanism, reliable technical support is provided for the field of modern information security, and the method has the advantages of being easy to implement, low in cost and high in security and has wide application prospects. The method is suitable for popularization and application in multiple fields of mobile payment, Internet of Things, games and the like.
Owner:HENAN INFORMATIZATION GRP CO LTD

High-safety energy storage system and fault detection method thereof

The invention relates to the technical field of power distribution system protection, in particular to a high-safety energy storage system and a fault detection method thereof, the system comprises a measurement and control center, an insulation monitoring device, a bidirectional DC-DC converter and an integrated DC power distribution unit, the insulation monitoring device is connected with a DC power distribution bus, and the ground insulation state of the bus is monitored in real time; the input end of the bidirectional DC-DC converter is connected with the storage battery pack, and the output end is connected with the DC power distribution bus through the integrated DC power distribution unit to construct an electric energy distribution path. The integrated direct current power distribution unit comprises a circuit breaker, two voltage detection modules and two current detection modules, the first voltage detection module is connected with the direct current power distribution bus and the measurement and control center, the second voltage detection module is connected with the circuit breaker and the measurement and control center, and the circuit breaker is connected with the direct current power distribution bus. And the two current detection modules are connected in series between the output end of the bidirectional DC-DC converter and the circuit breaker to form a current detection loop. According to the invention, through multi-level real-time monitoring and centralized control, the safety and fault response capability of the system are significantly improved.
Owner:YUNCHENG POWER SUPPLY COMPANY OF STATE GRID SHANXI ELECTRIC POWER

Encrypted wireless communication terminal equipment special for electric power

The invention discloses encrypted wireless communication terminal equipment special for electric power, which belongs to the technical field of electric power equipment communication and comprises a security encryption module, a wireless communication module and a wireless communication module, the multimode communication module is used for uploading the encrypted data to a master station through a cellular wireless communication link or a power line carrier communication link; the protocol adaptation module is used for packaging the original data of the equipment into a data frame conforming to a master station protocol; the edge intelligent processing module is used for performing variable quantity compression and dead zone filtering on the acquired field equipment data; the remote operation and maintenance management module is used for realizing equipment parameter configuration, firmware upgrading, state monitoring and warning management; and the core control processing module is used for executing task scheduling, resource allocation and security policy control. By adopting the equipment, the data is effectively prevented from being stolen, tampered or forged in the transmission process of the wireless public network or the power carrier link, and the high-security requirement of the power industry on network communication is met.
Owner:TIANJIN HAIHE ELECTRIC CO LTD

Verifiable on-chain data query method based on challenge authentication mechanism

The invention relates to a challenge authentication mechanism-based verifiable on-chain data query method, and belongs to the technical field of block chains. According to the method, the maintenance task of the authentication data structure ADS is entrusted to a limited number of service providers from a full node, and the correctness of the maintenance task is ensured by the full node through verification instead of reconstructing the ADS. A mechanism based on challenge authentication is designed, and a service provider extracts on-chain data, constructs an ADS and provides a query service; before a user queries, a challenge node constructs a challenge token containing a known result query expression and sends the challenge token to a service provider, and after the service provider issues a query result and a proof, the result correctness and the proof validity are verified in a full-node manner, so that an attack initiated by a wrong ADS can be detected at an extremely high probability. According to the method, the ADS maintenance overhead is greatly reduced while the correctness of the ADS is ensured, the validity of verifiable query is ensured, and the method has very strong robustness and very high security for adaptive attacks, so that the diversity of query services is effectively expanded.
Owner:BEIJING INST OF TECH

Method for establishing reinforcement learning network security attack and defense double-agent control strategy model

The invention discloses a method for establishing a reinforcement learning network security attack and defense double-agent control strategy model, which is suitable for high-security network environments such as an electric power monitoring system and the like. The model realizes a dynamic attack and defense decision through a double-agent collaborative architecture: an attack end agent adopts a three-level CNN to mine network topology spatial-temporal characteristics, and extracts association information of five-dimensional dynamic matrixes such as node states, region levels and defense slots; the defense end intelligent agent combines a KL divergence adaptive penalty mechanism to optimize a PPO algorithm, and dynamically adjusts the exploration intensity by monitoring strategy distribution offset in real time. And introducing a CLIP truncation function to constrain the strategy update amplitude, and realizing priority protection and resource elastic scheduling of the core control area in combination with an attack and defense reward function. The model supports hundred-level node scale deduction, effectively solves the problems of response lag, unknown node sensing delay and slow large-scale network convergence of a traditional static rule, and meets the real-time attack and defense requirements of a power system under the principles of'security partitioning, network specialization, transverse isolation and longitudinal authentication '.
Owner:ELECTRIC POWER RES INST CHINA SOUTHERN POWER GRID CO LTD +1

Shared charging equipment instruction control system and method based on multi-modal signal fusion

The invention discloses a shared charging equipment instruction control system and method based on multi-mode signal fusion, particularly relates to the field of shared charging control, solves the protocol out-of-step overshoot risk, takes a handshake millisecond window as a switching-in port, and synchronously checks a digital message and a physical transient state through surge energy and thermal inertia double indexes. Locking an instruction missing risk before a driving link; the residual error-message joint judgment captures hidden abnormity in real time at a power issuing node, a rollback channel is rapidly pulled back to a safe power grade, and brand-channel mapping logic is triggered to re-plan output resources; a threshold bin dynamically tightens a threshold according to a target-actual measurement power difference, so that prediction and actual measurement are gradually fitted, and new prior is written back to a forward inference link; high-voltage overshoot and power failure of the whole row are avoided, a billing curve is completely matched with a charging curve, high turnover of a port can be kept in a passenger flow peak, the safety is integrally improved, the service life of hardware is prolonged, and the user experience is improved.
Owner:SHENZHEN YUANHONG CHAOCHANG EQUIPMENT CO LTD

Enterprise intranet information security solution supporting multiple encryption protection

The invention discloses an enterprise intranet information security solution supporting multiple encryption protection, which belongs to the field of computer network information security, and comprises a user terminal, a movable encryption gateway, a cloud authentication management platform, an operator network infrastructure and an enterprise intranet, the user performs biological characteristic and dynamic token double-factor authentication through the gateway; after the authentication is passed, the gateway sends encrypted authentication data to a cloud authentication management platform; after the platform verification is passed, calling an operator platform interface, and dynamically calculating the fine-grained network access authority of the user; an operator platform establishes an isolation security data tunnel from a mobile network to an enterprise intranet according to the security data tunnel, encryption transmission and access control based on dynamic authority are implemented for gateway data streams, multiple authentication, cloud authentication and an operator special line tunnel are integrated, and high-security and high-reliability enterprise intranet access flexibly supporting mobile office is achieved.
Owner:SHENZHEN XINXUE TECHNOLOGY CO LTD

Ground password selective encryption method for keeping RTPS protocol compatibility

The invention relates to the technical field of network security, in particular to a national secret selective encryption method capable of keeping RTPS protocol compatibility, which comprises the following steps of: analyzing an RTPS communication structure and field information, calculating a sensitive identification code judgment field, obtaining a length and position number, combining a link rate with a CPU utilization rate to calculate a threshold value, establishing a segmented secret key and performing SM2 authentication; field binding key SM4 encryption and Hash verification, ciphertext reordering, timestamp and random number matching super-threshold reconstruction key, decryption verification splicing optimization data packet. According to the method, sensitive fields are dynamically judged by analyzing a communication structure, segmentation threshold guarantee efficiency is calculated in combination with equipment performance, safety credentials are enhanced through elliptic curve authentication, segmentation key mapping is combined with encryption and verification multi-protection, anti-attack force is improved through ciphertext sorting, keys are refreshed through a timestamp and a random number mechanism, and high safety of the whole transmission process is ensured.
Owner:FUJIAN JINJIANG THERMAL POWER CO LTD

ARM processor-oriented microkernel operating system confidential computing environment construction method

The invention relates to an operating system environment construction technology, and discloses an ARM (Advanced RISC Machines) processor-oriented micro-kernel operating system confidential computing environment construction method, which is characterized in that a hierarchical system architecture is constructed, a virtual machine monitor and a confidential domain management monitor are decoupled at an ARM exception level EL2, and the virtual machine monitor and the confidential domain management monitor run in mutually isolated address spaces. The RMM is used as an independent module for dynamic loading, a management mechanism of a confidential computing domain is specially used, and the Hypervisor is only responsible for strategy scheduling, so that the defect that the Hypervisor is bloated in function in a traditional scheme is overcome. According to the method, the RMM is loaded through the security startup process during startup, the confidential virtual machine is dynamically created during running, mirror image security verification, memory encryption and other mechanisms are integrated, and finally the security domain is destroyed after the application is finished. The method has the advantages that a flexible and safe confidential computing environment conforming to the minimum privilege principle is provided for the microkernel system, and the method is particularly suitable for embedded scenes with high safety requirements such as the Internet of Things and industrial control.
Owner:CHENGDU TIANRUAN TECHNOLOGY CO LTD

Block chain-based big data secure storage sharing method and system

The invention discloses a block chain-based big data secure storage sharing method and system. The method comprises the following steps: firstly, preprocessing original big data, including data cleaning, desensitization and blocking operation; then the preprocessed data is encrypted, and the safety of the data in the storage and transmission process is ensured; generating a data fingerprint from the encrypted data, and storing the data fingerprint on the block chain to realize non-tampering and traceability of the data; the encrypted data is stored in a distributed storage system, so that the reliability and the expandability of data storage are improved; sharing and access control of data are realized through an intelligent contract, and only an authorized user can obtain a data key, decrypt and use the data; and finally, realizing full-life-cycle traceability of the data by using the block chain. The method has the advantages of high security, high traceability, high reliability and the like, and is suitable for security storage and sharing scenes of big data.
Owner:SHANGHAI QUZHI NETWORK TECH CO LTD