Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

514 results about "Information leakage" patented technology

Information leakage happens whenever a system that is designed to be closed to an eavesdropper reveals some information to unauthorized parties nonetheless. For example, when designing an encrypted instant messaging network, a network engineer without the capacity to crack encryption codes could see when messages are transmitted, even if he could not read them. During the Second World War, the Japanese for a while were using secret codes such as PURPLE; even before such codes were cracked, some basic information could be extracted about the content of the messages by looking at which relay stations sent a message onward. As another example of information leakage, GPU drivers do not erase their memories and thus, in shared/local/global memories, data values persist after deallocation. These data can be retrieved by a malicious agent.

Water conservancy design file retrieval system and method based on local lightweight large model

The invention discloses a water conservancy design archive retrieval system and method based on a local lightweight large model, and the method comprises the steps: S1, constructing a Python automatic preprocessing assembly line, extracting texts for PDF and Word multi-format archives, correcting metadata, and outputting standardized data; s2, constructing a full-text retrieval and semantic retrieval dual-mode cross-document retrieval service by relying on a Weavi ate local vector database and a lightweight text embedding model; s3, analyzing a user query intention through a local large model, synchronously triggering metadata accurate retrieval and content semantic retrieval, and generating a structured result; and S4, integrating the core module into a local area network Web platform, adopting Docker containerization deployment, and combining an RBAC permission model and JWT authentication to guarantee security. The system comprises a preprocessing module, a cross-document retrieval module, an intelligent agent module and a background management module, and collaboration is achieved through a standardized API. According to the method, the problem of archive fragmentation is solved, multi-mode retrieval breaks through keyword limitation, an intelligent agent reduces manual intervention, a localized architecture prevents secret-related leakage, background management adapts to an existing I T environment, and full-process intelligent archive service is provided for water conservancy design.
Owner:ZHONGSHAN WATER CONSERVANCY PROJECT SURVEY & CONSULT CO LTD

Tunnel fire inversion method based on multi-modal fusion and physical constraint

The invention provides a tunnel fire behavior inversion method based on multi-modal fusion and physical constraint, and aims to solve the problem that the position and power of a fire source are difficult to invert accurately in real time in traditional fire behavior monitoring. According to the method, data, temperature distribution images and physical parameters of distributed temperature sensors in a tunnel are collected, and a spatial-temporal feature fusion network is constructed; designing an information leakage prevention training mechanism, and adopting a modal random discarding and sensor shielding technology to avoid overfitting of the model to a specific input mode; a physical constraint loss function is introduced, and the temperature gradient, the maximum temperature rise and the longitudinal attenuation law are combined to ensure the physical rationality of an inversion result; a coarse-fine two-stage position prediction framework is adopted, and meter-scale precision positioning of the position of a fire source is achieved. According to the invention, the power and position of the fire source can be inversed accurately in real time, and reliable technical support is provided for intelligent monitoring and emergency rescue of tunnel fire.
Owner:CHINA UNIV OF MINING & TECH

Bidding document total-factor blind-state desensitization method fused with multi-modal artificial intelligence

The invention relates to a bidding document total-factor blind-state desensitization method fusing multi-modal artificial intelligence, and the method comprises the following steps: S1, obtaining an original bidding document package, carrying out the data preprocessing, and obtaining a standardized document set; s2, according to the standardized document set, performing multi-modal content identification and alignment to obtain a multi-modal content library; s3, constructing a sensitive information classification system based on domain expert knowledge and a historical case library; s4, constructing a dynamic rule base according to the sensitive information classification system; s5, according to the multi-modal content library and the dynamic rule library, in combination with deep learning, multi-modal sensitive information intelligent detection is carried out, and a sensitive area set is confirmed; and S6, based on the dynamic rule base, performing intelligent desensitization on the sensitive area set to obtain a desensitized document. According to the method, the risk of sensitive information leakage is effectively reduced while the bidding file expression effect is improved.
Owner:STATE GRID INFO TELECOM GREAT POWER SCI & TECH

Multi-source heterogeneous big data management method and device

The invention relates to the technical field of intelligent agriculture, in particular to a multi-source heterogeneous big data governance method and device.The multi-source heterogeneous big data governance method comprises the following steps that S1, multi-source heterogeneous data collection and semantic alignment are conducted, hidden semantic conflicts are eliminated; s2, performing dynamic data source adaptation and quality monitoring; s3, performing cross-domain permission penetration control; s4, building an industrial model driven by federal learning; and S5, double-chain block chain evidence storage and traceability are carried out. The method is used for disambiguating dialect term conflict, federated learning cross-domain privacy modeling and double-chain block chain evidence storage traceability through a dynamic semantic alignment neural network, and systematically solves the problems of dialect semantic segmentation, data islands and sensitive information leakage caused by small scattered distribution of peasant households in the field of traditional Chinese medicinal material planting. And a trust closed loop of government-enterprise-peasant household three-party cooperative treatment is constructed.
Owner:GUANGXI ZHUANG AUTONOMOUS REGION ACAD OF AGRI SCI +1

Non-intrusive load decomposition method and system based on xLSTM-Transform model

The invention discloses a non-intrusive load decomposition method and system based on an xLSTM-Transform model, and is applied to the technical field of non-intrusive load decomposition. XLSTM is constructed by combining sLSTM (scalar LSTM) and mLSTM (matrix LSTM), so that the processing capability of the model on time sequence data is enhanced; a causal convolution module is added behind an input layer, a sliding window in a fixed direction of the causal convolution module can more accurately extract a local load mode of an electric appliance while ensuring causality, and future information leakage is avoided; a self-attention mechanism in a Transform architecture is introduced to establish an xLSTM-Transform combination model, historical data is adopted to train the model, and finally, the model is used to perform electric appliance load decomposition. According to the method, a multi-scale electrical load mode can be effectively processed, and the problem of long-term dependence faced by a traditional time sequence model is solved.
Owner:JILIN INST OF CHEM TECH

Information security management system based on network operation and maintenance

The invention belongs to the technical field of network information security, and discloses an information security management system based on network operation and maintenance. The method comprises the following steps: periodically acquiring multi-dimensional traffic data of a network node through a traffic acquisition module, and constructing and labeling a network security situation map by means of an asset labeling module; the authority distribution module automatically adjusts the authority of the abnormal access node by analyzing the node access behavior; the threat detection module analyzes the flow in real time, drives the self-adaptive isolation module to quickly isolate threat nodes according to the generated temporary strategy, and updates the joint defense model for cooperative defense; the attack evolution prediction module performs attack path prediction by extracting attack features and optimizes an isolation strategy accordingly; and information leakage is effectively prevented.
Owner:GUANGZHOU PENGLONGJISUANJI TECH CO LTD

Lithium battery SOH and RUL prediction system and method based on multi-scale feature federation

The invention discloses a lithium battery SOH and RUL prediction system and method based on multi-scale feature federation, and relates to the technical field of battery detection, the system comprises a data acquisition and feature extraction module, an encryption and uploading module, a model construction module, a recursion updating module and a work order generation module; through the multi-scale feature fusion formula, the time sequence features and the statistical features of the lithium battery are organically combined, the fusion feature vector is generated, degradation information of the lithium battery under different time scales and operation conditions is comprehensively captured, the health state of the lithium battery and the accuracy of prediction of the remaining service life of the lithium battery are improved, and the prediction accuracy of the remaining service life of the lithium battery is improved. And meanwhile, through dynamic Top-K sparse compression, 8-bit linear quantization and AES-256-GCM encryption technologies and in combination with a differential privacy protection mechanism, the data transmission quantity is reduced, the data security is enhanced, sensitive information leakage is prevented, and a reliable guarantee is provided for remote monitoring and predictive maintenance of the lithium battery.
Owner:SHAANXI WINDRIDERPOWER CO LTD +2

Video conference multi-modal data alignment method and device based on causal mask, equipment and medium

The invention discloses a video conference multi-modal data alignment method and device based on a causal mask, equipment and a medium, and relates to the technical field of computers, and the method comprises the steps: carrying out the feature extraction and fusion of an original audio, an original video stream and an original document in an online video conference, time sequence division is carried out based on the obtained multi-modal fusion features to obtain a triple time sequence window; determining an initial weight value corresponding to the triple time sequence window, and performing normalization adjustment on the initial weight value by using a preset constraint condition to obtain an adjusted weight; indexing a preset time sequence offset matrix by using a speaking identifier of a speaking party, correcting an original time sequence of the triple time sequence window based on an indexing result, and determining a target attention result corresponding to the triple time sequence window by using a preset causal mask mechanism, and performing multi-level alignment fusion on the multi-modal fusion features based on the target attention result to obtain a multi-modal alignment result. The precision of the multi-mode alignment technology is improved, and future information leakage is avoided.
Owner:SHANDONG INSPUR SCI RES INST CO LTD

Archive resource intelligent retrieval and hierarchical authorization utilization system and method

The invention discloses an intelligent retrieval and hierarchical authorization utilization system and method for archive resources, and belongs to the field of intelligent retrieval. Natural language query of a user is received, the language type of the user is recognized, a semantic vector is generated in combination with a multi-language natural language processing model, and then the semantic vector is matched with each archive semantic representation in an archive database; for the situation related to cross-language matching, a cross-language similarity offset rate and a language context consistency score are further calculated, the semantic generalization ability is divided into a high level, a middle level and a low level according to a preset weight model, and for the middle level situation, a misjudgment risk assessment mechanism is introduced to judge whether additional authorization is needed or not; and when the file is low in level and the languages are inconsistent, the user is directly prohibited from accessing the high-security-level file, so that the information leakage risk caused by semantic generalization is effectively prevented, and the high-sensitivity file is safely and accurately controlled in a multi-language environment.
Owner:FOSHAN POWER SUPPLY BUREAU GUANGDONG POWER GRID +1

Supervisable data security sharing method and device based on three-chain architecture

The invention relates to the technical field of data sharing, and discloses a supervisible data security sharing method and equipment based on a three-chain architecture, and the method comprises the steps that a user submits a data sharing strategy to a strategy contract, the contract generates a strategy verification key and returns the strategy verification key, and the user creates a temporary symmetric key and a data identifier; packaging into a security token and encrypting by using a supervision chain public key to finish strategy registration and key initialization; and the user transmits the encrypted security token to the storage chain through the relay chain, the relay chain verifies the identity of the user and then forwards the token, and the storage chain verifies that the contract decrypts the token by using the private key of the supervision chain. Through a three-chain architecture, zero-knowledge proof and an anti-quantum evidence storage mechanism, data operation compliance can be verified through a non-tampering operation evidence storage chain, the risk of sensitive information leakage caused by opening of supervision authority is reduced, the defect that encrypted data is difficult to audit is overcome, a cross-chain security token fusing mechanism is utilized to resist communication threats, and the safety of the system is improved. And privacy protection and supervision compliance are dynamically balanced.
Owner:ZHEJIANG HEALTH CLOUD CO LTD

Rail transit quantum communication system data transmission method, device, system and medium

The embodiment of the invention provides a rail transit quantum communication system data transmission method, device and system and a medium, and relates to the technical field of data transmission. The method comprises the following steps: performing quantum key distribution through a first channel; and transmitting the train data encrypted by the quantum key through a second channel. A quantum communication dual-channel isolation architecture is adopted, namely, a first channel is specially used for quantum key distribution, a second channel is specially used for transmitting encrypted data, a key distribution characteristic of information theory security is realized by utilizing a quantum key distribution technology based on a quantum mechanics principle, key distribution and a data transmission channel are physically isolated, and the security of the key distribution is improved. The risk of secret key and data mixed leakage is avoided, so that traditional eavesdropping and quantum computing attacks are effectively resisted, the safety and integrity of train data in the transmission process are guaranteed, quantum-level safety guarantee is provided for train-ground communication, safety accidents and economic losses caused by information leakage are avoided, and the safety and reliability of train-ground communication are improved. And meanwhile, low time delay and high efficiency of the communication system are ensured.
Owner:CRRC TANGSHAN CO LTD

Risk management and control method for cross-domain interaction of power data

The invention discloses a risk management and control method for cross-domain interaction of power data. The method comprises the following steps: deploying a pre-trained sensitive information identification model at a data exit gateway to identify a sensitive information type and a risk level; dynamically matching a desensitization strategy according to the risk level, and executing hierarchical desensitization operation; performing attribute-based encryption operation on a core field of the desensitized data, wherein an access attribute of a receiver is defined by a logic combination of a role attribute and a domain attribute; data are transmitted through a cross-domain secure channel based on a block chain, and decryption can be performed only when and only when a private key binding attribute set of a receiving party meets a logic combination access strategy predefined by a sender. According to the method disclosed by the invention, the risk of sensitive information leakage in cross-domain interaction of the power data is solved, hierarchical protection, dynamic access control and transmission integrity verification of the sensitive data are realized, and the security of data sharing of the power system is remarkably improved.
Owner:NANYANG POWER SUPPLY COMPANY OF STATE GRID HENAN ELECTRIC POWER

Vehicle OTA upgrading method and upgrading system based on quantum encryption

The invention provides a vehicle OTA upgrade method and upgrade system based on quantum encryption, relates to the technical field of vehicle OTA upgrade, and is applied to a server, and the server and a vehicle establish a quantum channel and a classical channel through an optical fiber interface integrated on a charging pile. The method comprises the following steps: in response to a received quantum state light pulse which is sent by a vehicle through a quantum channel and is coded with a random first basis vector, measuring the light pulse; comparing a second basis vector for measurement with the first basis vector in a classic channel, screening a matching result to obtain a first key, and determining the quantum bit error rate of the first key; if the quantum bit error rate is smaller than the bit error rate threshold, compressing the first key to obtain a second key; and encrypting an OTA upgrade package obtained from the main engine plant cloud platform based on the second key, sending the OTA upgrade package to the vehicle through the optical fiber interface, and decrypting the vehicle to complete upgrade. According to the method, the information leakage risk is effectively eliminated by utilizing quantum characteristics and combining quantum bit error rate judgment, compression processing and the like, so that the security of OTA upgrading is improved.
Owner:ZHEJIANG ZEEKR INTELLIGENT TECH CO LTD +1

Information leakage suppression device

To provide an information leakage prevention device capable of making information in a hard disk unusable and preventing information leakage from the hard disk. [Solution] The information leakage prevention device 1 comprises a holder 14, a base body, and a holder arranged so as to contact the top surface of a hard disk, the holder having a first explosive loading section formed so as to penetrate from the bottom to the top inside the holder, a cover section, and an ignition device 22 having a heating section, a first type explosive layer 84 arranged within the first explosive loading section, in which the average particle size of metal powder particles is a first average particle size, and a second type explosive layer 86 arranged in contact with the first type explosive layer within the first explosive loading section, in which the average particle size of metal powder particles 82 is a second average particle size larger than the first average particle size, the first type explosive layer 84 being arranged closer to the hard disk than the second type explosive layer 86, and the first type explosive layer being arranged so as to contact the heating section of the ignition device.
Owner:COGNITIVE RES LABS INC

Prevention of information leakage through signature

Techniques for preventing leakage of sensitive information through a signature are disclosed. Data is received, and the data is transmitted to a signature and encryption (SE) service, along with an encryption key. Signed and encrypted data is received from the SE service, where the signed and encrypted data is (i) encrypted using the encryption key and (ii) signed by the SE service. A verification is performed to verify that that sensitive information (such as the encryption key) is not leaked through a side channel of a signature of the signed and encrypted data, such as by (i) determining a length of the side channel of the signature, and (ii) verifying that the length of the side channel of the signature does not exceed a threshold length. Responsive to verifying that the sensitive information is not leaked through the side channel of the signature, the signed and encrypted data is transmitted.
Owner:ORACLE INT CORP

Network security supervision system and method based on network technology

The invention relates to the technical field of network security, and discloses a network security supervision system and method based on a network technology, and the system comprises the following modules: a data collection module which is used for obtaining browsing information data of a collection target, and the browsing information data comprises an access time period, an information browsing duration, page stay data, and an access IP address; the data analysis module is used for analyzing and calculating an abnormal behavior value of the collection target according to the browsing information data of the collection target, and comparing the obtained abnormal behavior value with a safety threshold value; and the risk assessment module is used for calculating and acquiring a leakage risk value of the acquisition target and comparing the leakage risk value with a risk threshold value. A data acquisition module is constructed to comprehensively obtain access information, a behavior abnormal value and a leakage risk value are calculated respectively, a safety threshold and a risk threshold are combined to be compared with the obtained behavior abnormal value and the leakage risk value, obvious browsing abnormity is rapidly recognized, and potential information leakage risks can also be recognized.
Owner:SHANDONG XINJIEMAI INFORMATION TECH CO LTD

Self-adaptive authority control method and device, equipment and storage medium

The embodiment of the invention provides an adaptive permission control method and device, equipment and a storage medium, and relates to the technical field of information security. The method comprises the steps of generating an object permission vector and an object query vector corresponding to a query request, obtaining a dynamic attribute of a target object according to a current query rule, determining an authentication mode according to a rule attribute dependency relationship corresponding to the current query rule, obtaining a candidate data set corresponding to the dynamic attribute in a vector database, and sending the candidate data set to the target object. Calculating a comprehensive score corresponding to the joint vector according to the object query vector, the object permission vector, the data feature vector and the data permission vector, and determining target data corresponding to the query request from the initial data based on the comprehensive score. The query request of the target object is responded in real time in a mode of obtaining the dynamic attribute, so that the requirements of real-time access control and flexibility are met. The comprehensive score is used as fine-grained permission evaluation information, dynamic permission fuzzy processing is realized, the information leakage risk is reduced, and the security is improved.
Owner:PENG CHENG LAB

Card password generation method and device, card password jet printing method and device, card password verification method and device, terminal and storage medium

The invention discloses a card password generation, jet printing and verification method and device, a terminal and a storage medium, and the method comprises the steps: reading an enterprise code and a seed code corresponding to the enterprise code from a hardware security module, and enabling each enterprise to have a unique enterprise code; based on a hardware security module, generating a card number according to the enterprise code, the seed code and a preset card number generation algorithm, and generating a card password corresponding to the card number in combination with the card number and a preset card password generation algorithm; spraying and printing the generated card password on a card password area on the coupon corresponding to the card number through spraying and printing equipment; carrying out OCR (Optical Character Recognition) on the coupon to obtain a card password recognition result, and comparing the card password recognition result with the card password; and if the comparison result is consistent, covering the card password area and deleting the card password. According to the method, dynamic generation and verification of the card number and the card password are realized based on the hardware security module, and the card password is not stored after being generated, so that the effects of improving the card password security and the product quality and avoiding information leakage are achieved.
Owner:SUZHOU JINHETONG SOFTWARE

Prevention of information leakage through signature

Techniques for preventing leakage of sensitive information through a signature are disclosed. Data is received, and the data is transmitted to a signature and encryption (SE) service, along with an encryption key. Signed and encrypted data is received from the SE service, where the signed and encrypted data is (i) encrypted using the encryption key and (ii) signed by the SE service. A verification is performed to verify that that sensitive information (such as the encryption key) is not leaked through a side channel of a signature of the signed and encrypted data, such as by (i) determining a length of the side channel of the signature, and (ii) verifying that the length of the side channel of the signature does not exceed a threshold length. Responsive to verifying that the sensitive information is not leaked through the side channel of the signature, the signed and encrypted data is transmitted.
Owner:ORACLE INT CORP

Method for realizing multi-modal large-model fine-grained privacy grading protection in edge-cloud collaborative inference system

The invention relates to a method for realizing multi-modal large-model fine-grained privacy grading protection in an edge-cloud collaborative inference system, belongs to the technical field of large-model data security and privacy protection, and aims to solve the problems that privacy grading is rough, inference intermediate features are easy to leak and precision is damaged by protection measures in the prior art. According to the method, multi-modal data such as images and texts are received by edge computing nodes, deep semantic analysis and fine-grained segmentation are performed by using a local pre-trained multi-modal large model, and privacy scores are calculated to divide high and low privacy levels; uploading low-privacy data to a cloud computing center, and locally processing high-privacy data; and selectively shielding a middle layer feature map F generated by the edge based on the correlation degree and the contribution degree, then completing local reasoning, and uploading a result to be fused with the cloud. According to the method, precise fine-grained protection is achieved, the sensitive information leakage risk is remarkably reduced, and meanwhile the model reasoning precision and the system real-time performance are kept to the maximum degree.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Business information desensitization method and system based on spreadsheet file

The invention discloses a commercial information desensitization method and system based on spreadsheet files. The system is implemented by a spreadsheet file containing a runnable macro code (VBA). A user inputs business information needing to be desensitized into a pre-named worksheet of a spreadsheet file with a preset system code, and the system identifies and classifies sensitive information in the worksheet and provides a classification result composition for the user to review and edit. And the user completes the editing and reviewing result, namely, the content comparison table before and after desensitization is reserved for future reference. The table is also used for desensitization reference of the whole content of the file. A user operates the system through a button / icon of a VBA form control or a button / icon of a VBA ActiveX control and the content input into a pre-named worksheet (WorkSheets) in a spreadsheet file, and the system is operated by the user through the button / icon of the VBA form control or the button / icon of the VBA ActiveX control and the content input into the pre-named worksheet in the spreadsheet file. According to the invention, low-cost and high-security business information desensitization is realized, and the risk of information leakage in a network transmission process is avoided.
Owner:李尚儒

Browser plug-in single sign-on method, device and equipment based on cross-domain communication and medium

The invention belongs to the technical field of computers, and particularly relates to a browser plug-in single sign-on method and device based on cross-domain communication, equipment and a medium, and the method comprises the following steps: obtaining a login TokenB of a parent page through cross-domain communication between the parent page and a child page; analyzing the obtained TokenB into a TokenA suitable for the embedded website of the inline framework through a preset conversion interface; dynamically splicing the converted TokenA into a source access URL (Uniform Resource Locator) of an inline framework to realize automatic login; the step of splicing the TokenA into the source access URL of the inline framework specifically comprises the following steps: constructing an inline framework access URL containing TokenA parameters; and refreshing the inline framework and loading the URL with the TokenA to complete authentication. The problem of sharing authentication information among webpages under different domain names is solved. Through cross-domain communication and Token conversion, secure transmission and use of authentication information are ensured, and the risk of information leakage is reduced.
Owner:山东浪潮智慧医疗科技有限公司

Distributed privacy protection formation control method and system based on state decomposition

The invention belongs to the technical field of distributed cluster cooperative control, and particularly discloses a distributed privacy protection formation control method and system based on state decomposition, a multi-unmanned-vehicle system is divided into an information layer and a physical layer, the information layer is responsible for operating a dynamic average consistency algorithm, calculating the target position of each unmanned vehicle, and calculating the target position of each unmanned vehicle; according to the formation geometric center estimation, the physical layer utilizes the target position calculated by the information layer to further calculate the following required running speed of the unmanned vehicle according to the actual position. Comprising the following steps: performing decomposition configuration on the initial state of the unmanned vehicle; auxiliary cooperative variables are designed to perform distributed iterative calculation, so that the anti-interference capability of the system in a complex communication environment is remarkably improved; and converting a cooperative calculation result into a linear speed control instruction and an angular speed control instruction to realize accurate formation control of the multi-unmanned vehicle system. According to the method, the problem that state information leakage and noise robustness are difficult to consider in traditional cooperative control in cooperation of multiple unmanned vehicle systems is solved.
Owner:NORTHWESTERN POLYTECHNICAL UNIV

Screen information leakage prevention method and system based on UWB positioning

The invention discloses a method and system for preventing screen information leakage based on UWB positioning, relates to the field of smart screens, and aims to capture facial features, eyeball movement and other information of an observer carrying shooting equipment in front of a screen in real time by combining a UWB positioning technology and a high-speed camera, and identify whether the observer is a legal user or not through a deep learning algorithm. For an unauthorized observer, the system can generate false information which is similar to the screen content but has no practical significance in real time to replace the display content of the sensitive area. According to the dynamic replacement technology, illegal observers cannot obtain effective information without affecting legal user experience, further, an attention tracking algorithm is introduced, the sight focus of the observers is predicted, only areas which are possibly concerned are protected, and therefore the calculation load is reduced.
Owner:BEIJING TIANHE DIYUAN SAFETY TECH SERVICE CO LTD +1

Hadoop tenant-level encryption isolation implementation method and device

The invention discloses a Hadoop tenant-level encryption isolation implementation method, and aims to solve the problems of single key leakage risk, namespace planarization, encryption area unauthorized binding, no tenant dimension auditing and the like existing in an existing Ranger-KMS scheme. The method comprises the following steps: creating an independent master key for each tenant to realize physical isolation; the key alias, the encryption area paths and the strategy resources are forced to carry tenant prefixes, and the consistency is verified; a tenant context is transmitted through a thread local variable; when an encryption area is created, tenant attributes are persisted, and operation consistency is verified; and the key plaintext is only stored in the KMS memory and is safely reset after being used. According to the method, full-dimension isolation of keys, data, strategies and auditing is realized, single-tenant key leakage does not influence the cluster, unauthorized access and information leakage are completely eradicated, compliance auditing requirements are met, single-cluster multi-tenant safe coexistence is supported, and hardware cost is reduced.
Owner:CHINA ELECTRONICS CLOUD DIGITAL INTELLIGENCE TECH CO LTD

Screen information leakage prevention method and system

The invention provides a screen information anti-leakage method and system, and relates to the field of information security, and the method comprises the steps: calculating and generating a target moire fringe pattern which can strongly interfere with secret photographing equipment based on preset secret photographing equipment parameters and the energy distribution of original information in a transform domain; the Hash value of the original information content and the dynamic safety parameters are subjected to logical operation and then input into a hyperchaotic system, a chaotic phase mask bound with the content and time is generated, amplitude-frequency information and a mask of moire fringes are combined, a preset imaging light path model is subjected to reverse optimization calculation, and a stable and effective anti-divulging disturbance pattern within a preset range is obtained. And carrying out pixel-level superposition on the anti-leakage disturbance pattern and the original information through a multi-scale fusion algorithm, generating a display frame, outputting the display frame to a screen, and updating the disturbance pattern along with the frame or the period to resist the attack of multi-frame average interference elimination.
Owner:BEIJING TIANHE DIYUAN SAFETY TECH SERVICE CO LTD +1

Prevention of information leakage through signature

Techniques for preventing leakage of sensitive information through a signature are disclosed. Data is received, and the data is transmitted to a signature and encryption (SE) service, along with an encryption key. Signed and encrypted data is received from the SE service, where the signed and encrypted data is (i) encrypted using the encryption key and (ii) signed by the SE service. A verification is performed to verify that that sensitive information (such as the encryption key) is not leaked through a side channel of a signature of the signed and encrypted data, such as by (i) determining a length of the side channel of the signature, and (ii) verifying that the length of the side channel of the signature does not exceed a threshold length. Responsive to verifying that the sensitive information is not leaked through the side channel of the signature, the signed and encrypted data is transmitted.
Owner:ORACLE INT CORP

Security cooperative computing gateway and privacy protection method for industrial sensitive data flow

The invention provides a security cooperative computing gateway and privacy protection method for industrial sensitive data streams, and the method comprises the steps: carrying out the protocol de-framing and point semantic mapping of the industrial data streams through a gateway, generating a minimum semantic data stream, and binding privacy protection constraints; calculating a semantic key admission mark according to a collaborative task demand, and solidifying the processing logic into an executable object; executing security cooperative computing according to the executable object, and packaging the result stream and the constraint view into a privacy protection result packet; when a use request is received, a restricted use gating flag is calculated based on the use, the operation type and the period of validity, and restricted decapsulation or compliance degradation delivery is performed. According to the method, fine-grained permission control and dynamic privacy protection of industrial sensitive data in the cooperative computing process are realized, the data are ensured to be invisible or limited to be visible, sensitive information leakage is effectively prevented, and the industrial data circulation security is improved.
Owner:GUANGZHOU SIYUN DATA TECH CO LTD

On-chain multi-path sealed submission and threshold timing revealing method and system

The invention provides an on-chain multipath sealed submission and threshold timing revealing method and system. Comprising the following steps: encrypting operation content into a ciphertext during submission, and exposing a small amount of necessary header information in a network; and meanwhile, a decryption key is divided into a plurality of small parts, a unified revealing time window is appointed, and unlocking can be performed as long as enough shares are collected. In order to avoid single-point failure or manual selection, the sealed packets are simultaneously sent through a plurality of mutually independent channels. After a window is reached, the system carries out rapid batch verification on a plurality of sequential certificates generated based on a verifiable delay function VDF, and when a threshold is reached, one-time deblocking is carried out, and then the sequential certificates are delivered to an existing execution entry for processing; and if the time is out, the threshold is not reached or the channel is abnormal, the preset rollback strategy is automatically retransmitted or switched. According to the scheme, the existing on-chain process does not need to be changed, information leakage in the propagation stage can be remarkably reduced, false start and selective rejection are inhibited, the fairness of price discovery is improved, and stable processing time delay is kept through parameter coordination.
Owner:ZHEJIANG UNIV

Communication systems and methods

Various techniques are provided to implement information leakage mitigation associated with data communications. In one example, a method includes receiving a bitstream including a plurality of bits. The method further includes, for each bit of the plurality of bits, transitioning between two states of a plurality of states in response to the bit; inverting a differential pair of data signals associated with the bit in response to the transitioning to obtain differentially transitioned data signals; maintaining a third data signal associated with the bit in response to the transitioning; and transmitting each data signal of the differentially transitioned data signals and the third data signal over a respective wire. Related systems and devices are provided.
Owner:LATTICE SEMICON CORP