Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

12 results about "Insider attack" patented technology

An insider attack is a malicious attack perpetrated on a network or computer system by a person with authorized system access.

Protection method and system for preventing file leakage in cloud space

The invention discloses a protection method and system for preventing file leakage in a cloud space, and the method comprises the steps: encrypting a file stored in the cloud space by a user in the cloud space, and enabling the user to remotely log in and access the cloud space to carry out the cloud file operation of the file. The access trace of the user for accessing the cloud space last time needs to be provided for decrypting the file. A user private key is protected by a symmetric key associated with a user name, a user password HASH and an access trace, a file encryption key is decrypted by using the user private key obtained by decryption, all files stored in a cloud space by a user are encrypted and stored, and the key is subjected to multiple protection, so that all files are encrypted and stored by an internal attacker, a manager or an external attacker. Even if the user name and the password and even all private information of the user stored in the system are obtained, the file stored in the cloud space by the user cannot be decrypted.
Owner:STATE GRID LIAONING SHENYANG ELECTRIC POWER SUPPLY COMPANY +2

A Post-Quantum Secure Linkable Ring Signature Method and System Resistant to Internal Attacks

This invention discloses a post-quantum secure linkable ring signature method and system resistant to internal attacks, comprising: a first service device generating public parameters; each user device generating its own public-private key pair using the public parameters and sending its public key to the first service device for registration; the first service device verifying all received identity information and forming a public key ring from the public keys of all verified user devices and making it public; when any user device needs to send a message to a second service device, it generates a ring signature containing a linkable tag based on its own private key, the message, and the public key ring, and sends the ring signature and the message to the second service device; the second service device performing security verification on each ring signature and, after successful verification, verifying whether different ring signatures belong to the same user device based on the linkable tag. This invention can protect user privacy in anonymous scenarios, enable multiple signatures from the same user, and resist attacks from within.
Owner:XIAN UNIV OF POSTS & TELECOMM

API security monitoring and risk analysis system

The invention relates to the technical field of API security monitoring, and discloses an API security monitoring and risk analysis system, which comprises an intelligent sampling module used for intelligently sampling interface calling flow in an enterprise API gateway system to obtain a standardized API calling data set; the feature extraction module is used for performing multi-dimensional security feature extraction to obtain an API calling security feature set; the real-time processing module is used for performing real-time processing to obtain a potential attack type judgment result; the mode matching module is used for carrying out behavior sequence analysis and mode matching to obtain an API attack behavior characteristic spectrum and a real-time threat level; according to the method and the system, the session token leakage attack and the privilege internal attack are effectively prevented, and the security of API calling is improved.
Owner:深圳华科讯通科技有限公司

A distributed data storage security protection system

This invention relates to the field of data storage protection technology and discloses a distributed data storage security protection system. The invention includes a data sharding and commitment unit, a high-fidelity deception shard generation unit, an obfuscated storage control unit, an immune verification and reading unit, and a distributed commitment and graph management unit. By dividing logical data objects into real data shards and constructing a Merkle tree to generate the Merkle tree root, high-fidelity deception shards are generated by extracting the structural features of the real shards. Real and deception shards are obfuscated and stored on multiple nodes. During reading, the shards and proof paths returned by multiple nodes are cross-validated based on the Merkle tree root to identify compromised nodes and trigger an immune response, including node marking, alarm broadcasting, and data self-healing. This invention can effectively respond to internal attacks and highly covert deception attacks, improving the security and reliability of the distributed storage system.
Owner:HEBEI MINGWEI DIGITAL TECHNOLOGY CO LTD

A physical layer identity authentication method and device of a network time synchronization system

The application provides a physical layer identity authentication method and device of a network time synchronization system, and belongs to the technical field of network security, and specifically comprises the following steps: encoding and modulating a sending end original time synchronization message, and inserting an identity authentication pilot sequence; performing pre-distortion of the message signal related to the sending end identity; performing step-by-step equalization of the message signal by each device based on a pre-measured and stored frequency domain channel matrix of a physical channel; a security demodulator extracts a current sub-block identity authentication pilot sequence, estimates, interpolates and stores the pre-distorted sequence, and then performs frequency domain equalization, demodulation and decoding on the current sub-block data sub-carrier by using the pre-distorted sequence to recover the original time synchronization message and a message security indication vector; identity authentication is judged based on the error code rate of the message security indication vector, and the original time synchronization message is sent to a receiving end or discarded according to the judgment. The scheme of the application effectively overcomes external and internal attackers, and realizes time source identity authentication.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

A trust management method for a fog node in edge computing

ActiveCN116244700BPathPingData set
This invention belongs to the interdisciplinary fields of edge computing, privacy and security, and machine learning. It discloses a trust management method for fog nodes in edge computing. First, it calculates the fog node's trust value based on subjective trust value, indirect trust value, and capability trust value. The Bellman equation is used to solve for the shortest trust path, resulting in an initial dataset containing the three trust attributes of the fog node. This initial dataset is divided into a training set and a test set. The dataset is preprocessed by blurring the distribution range of the trust values. The trust attribute with the largest information gain in the training set is calculated as the splitting attribute. The training set is then divided into several subsets. The partitioning terminates if all fog nodes in a subset belong to the same category or if all candidate attributes of a fog node have been used. After generating a decision tree, a loss function is used to prune the decision tree. This invention demonstrates reliability and effectiveness in detecting malicious nodes and internal attacks.
Owner:NANJING UNIV OF POSTS & TELECOMM

A database insider attack detection method, system, device and medium based on ensemble learning

A database insider attack detection method, system, device and medium based on ensemble learning, the method comprises the following steps: obtaining logs and human resource forms in a database, and preprocessing the obtained data; dividing a training set and a validation set; splitting and recombining to construct a training set and a validation set of query syntax data set, query result data set and insider information data set; training respective sub-models using the training set, optimizing the sub-models through the validation set, and obtaining optimal sub-models; fusing the three sub-models to form a trained integrated model, calculating an alarm threshold, and confirming data stealing behavior; obtaining newly generated logs and human resource forms from the database, preprocessing the new data; reconstructing a new data set; inputting the new data set into the optimal sub-model and the integrated model to determine data stealing behavior; the present application reduces the false detection rate and the missed detection rate, improves the detection accuracy, and effectively improves the comprehensive performance of the model.
Owner:XIDIAN UNIV

Practical quantum privacy comparison protocol method based on Bell state and rotation operation

The invention discloses a Bell state and rotation operation-based practical quantum privacy comparison protocol method, which comprises the following steps that: a semi-honest third party prepares S and records the state of the S, and first particles and second particles in all Bell states are respectively utilized to form S1 and S2; first eavesdropping detection is carried out, if the first eavesdropping detection passes, the first participant and the second participant respectively obtain S1 and S2, and the next step is continued, otherwise, communication is stopped; the first participant and the second participant act rotation operations Ry (piX) and Ry (piY) on the S1 and the S2 respectively to obtain SA and SB and send the SA and the SB to the semi-honest third party; the semi-honest third party sequentially executes Bell-based measurement on the SA and the SB to obtain a measurement result, if the measurement result is consistent with the quantum sequence S, the semi-honest third party declares that the privacy information of the first participant and the privacy information of the second participant are the same, otherwise, the privacy information of the first participant and the privacy information of the second participant are different. According to the method, possible information leakage is effectively prevented, the capability of resisting external and internal attacks of the method provided by the invention is remarkably enhanced, and the technical threshold and the cost of implementation are greatly reduced.
Owner:JINJIANG COLLEGE OF SICHUAN UNIV

A reverse firewall method for identity ring signature

The present invention discloses a reverse firewall method suitable for identification ring signatures, which belongs to the field of information security technology. The present invention defends against backdoor attacks by deploying a reverse firewall on the private key generation center PKG and the signer in the identification ring signature protocol. Regardless of whether an internal attacker subverts any participant in the signature method, the method of the present invention can ensure that the anonymity of the signing participant will not be destroyed and the private information will not be leaked to the internal attacker, thereby achieving the privacy leakage prevention of the overall ring signature method. Compared with the ordinary ring signature method, the method of the present invention can ensure that even if the signer and PKG of the ring signature use a subverted algorithm, that is, an algorithm tampered with by an internal attacker, the present invention can also ensure that the anonymity of the signer of the ring signature will not be destroyed and the privacy will not be leaked to the attacker.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Multi-dimensional privacy-preserving data aggregation method for industrial IoT based on homomorphic proxy re-encryption

The present invention discloses a multi-dimensional privacy-preserving data aggregation method for the industrial Internet of Things based on homomorphic proxy re-encryption. In the data reporting stage, smart sensors perform data reporting; the aggregation gateway performs proxy re-encryption and data aggregation; and in the data decryption stage, the power control center decrypts the data. The present invention proposes a reliable and flexible data aggregation framework based on super-increasing sequences, homomorphic encryption, and proxy re-encryption. The proposed framework supports multi-dimensional data aggregation and dynamic management of smart sensors, aggregation gateways, and power control centers. The present invention supports a privacy-preserving data aggregation scheme based on a modified Paillier cipher algorithm with proxy re-encryption, which solves the problem of internal attacks. The present invention ensures privacy, integrity, authenticity, resistance to external attacks, and fault tolerance, and provides more functions while maintaining similar overhead.
Owner:ANHUI UNIV

Distributed data storage security protection system

The invention relates to the technical field of data storage protection, and discloses a distributed data storage security protection system. The system comprises a data fragmentation and commitment unit, a high-fidelity deception fragmentation generation unit, a confusion storage control unit, an immune verification reading unit and a distributed commitment and atlas management unit. A logic data object is divided into real data fragments, a Merkel tree is constructed to generate a Merkel tree root, real fragment structure features are extracted to generate high-fidelity deception fragments, and the real fragments and the deception fragments are confused and stored in a plurality of nodes; during reading, performing cross validation on fragments returned by multiple nodes and a proof path based on a Merkel tree root, judging a lost node and triggering immune response, including node marking, alarm broadcasting and data self-healing; according to the method, internal attacks and high-concealment spoofing attacks can be effectively handled, and the safety and reliability of the distributed storage system are improved.
Owner:HEBEI MINGWEI DIGITAL TECHNOLOGY CO LTD

Trust Management Method and System for Smart Water Conservancy Integrated Machine Based on Two-Layer Blockchain

This invention discloses a trust management method and system for a smart water conservancy integrated machine based on a two-layer blockchain. The method includes: when the smart water conservancy integrated machine and the edge computing unit start up, initiating identity registration with a trusted institution and transmitting the device identifier to obtain a security certificate; after acquiring water conservancy monitoring and environmental climate data, calculating a local trust value for the message and reporting it to the edge computing unit, calculating a global trust value for the message and synchronizing it to other units, and finally broadcasting the final trust value of the message from the smart water conservancy integrated machine; encapsulating the data and the final trust value of the message into a block, and publishing it to the global and local blockchains using a lightweight consensus mechanism; if the node's trust value is lower than a threshold, the trusted institution will mark the node as a malicious node and revoke its security certificate. This invention solves the problem of inaccurate trust value calculation in existing technologies when using trust management to defend against internal attacks.
Owner:JIANGXI DIGITAL NETWORK INFORMATION SECURITY TECH CO LTD