Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

10 results about "Ipsec protocol" patented technology

Cross-domain file secure transmission method, system and device and storage medium

The invention provides a cross-domain file secure transmission method, system and device and a storage medium wherein a server establishes an encryption tunnel between a sending end gateway and a receiving end gateway based on an IPSec protocol and deploys a firewall; the sending end gateway packages the original file to obtain an original compressed package, and encrypts the original compressed package by using a target encryption algorithm to obtain a target compressed package; transmitting the target compressed packet to a receiving end gateway by using an SFTP protocol in an encryption tunnel internal server; in the transmission process of the target compressed packet, the server performs real-time security policy control on the SFTP protocol data flow bearing the target compressed packet by using the firewall; after the control is passed, the receiving end gateway receives the target compressed packet; and the receiving end gateway decrypts the target compressed packet to obtain a decrypted compressed packet, and unpacks the decrypted compressed packet to obtain a decrypted file. By adopting the method, the security, integrity and availability of cross-domain file transmission are comprehensively guaranteed.
Owner:EVERSEC BEIJING TECH +1

Dynamic load IPsec optimization module and application method in embedded system

The invention discloses a dynamic load IPsec optimization module and an application method in an embedded system, and relates to the related field of network information security, and the method comprises the steps: obtaining DMA data according to a DMA interface, sending the DMA data to a core processor, and carrying out the data reading and writing; the overtime timer carries out data volume timing on the read and written DMA data, and a timing result is determined; the state register responds to the timing result, state adjustment is carried out to determine a target encryption mode, and the target encryption mode is a first encryption mode or a second encryption mode; the AES encryption engine responds to the target encryption mode, and data IPsec protocol processing based on the target encryption mode is executed. The technical problems of low encryption processing efficiency and unreasonable resource occupation caused by lack of flexibility in performance optimization of an existing IPsec protocol in an embedded system are solved, and the technical effects of realizing encryption processing flexibility, improving encryption processing efficiency and realizing reasonable allocation of system resources are achieved.
Owner:联想长风科技(北京)有限公司

A redcap-based 5g quantum encryption communication method and device

The application forms a 5G RedCap quantum encryption method and device supporting 5G communication, quantum key and IPSec protocol for wireless public network access, aiming at productization, practicality and light weight, based on quantum key services platform, real-time distribution, better randomness and faster update frequency of quantum key, power 5G wireless virtual private network is used to build quantum encryption tunnel, and the security of 5G wireless channel transmission real-time business information and operation state monitoring data is improved. Based on the 5G RedCap quantum CPE terminal, safe, efficient and reliable access of power distribution automation, unmanned aerial vehicle inspection and inspection robot business can be realized, so as to improve the safety access level of power business.
Owner:STATE GRID ANHUI ELECTRIC POWER CO LTD +2

Hardware implementation method and device of ipsec protocol processor based on ascon lightweight encryption algorithm

The application belongs to the technical field of network communication. The application provides a hardware implementation method and device of an IPSec protocol processor based on an ASCON lightweight encryption algorithm. According to the method, the ASCON lightweight encryption algorithm and an optimized security policy matching algorithm are introduced, resource consumption is reduced and delay is lowered while high throughput is ensured, the hardware implementation of the ASCON algorithm is optimized for the application scenario of the IPSec protocol processing, the overall process of the ASCON algorithm is split into two stages of pre-computation and packet encryption, the initialization and associated data encryption intermediate state of each security alliance are pre-computed and stored, repeated computation is avoided, and the throughput is improved by single-cycle parallel execution of multiple rounds of transformation in the hardware implementation of the packet encryption module.
Owner:XIDIAN UNIV

Safety and credible module design and implementation method of video monitoring system

The invention relates to the field of video monitoring systems, and discloses a safe and credible module design and implementation method of a video monitoring system, which comprises the following steps that: a master station end executes classified access management according to the type of video terminal equipment, executes two-way identity authentication based on a hardware chip on safe and credible equipment, and executes white list auditing on other equipment; after the authentication is passed, establishing an encrypted communication channel based on an IPSec protocol and a national cryptographic algorithm; the video terminal performs encrypted transmission and encrypted storage on the data; and the master station end monitors the network state of the terminal in real time, and executes the emergency processing of terminal isolation or network banning when an abnormity is found, and the invention also relates to a multi-device concurrent access processing and network interruption automatic recovery mechanism. Through the integrated security design, the security access of equipment, the encryption protection of the full life cycle of data and the active defense of security threats are realized, and the security, reliability and stability of the system are improved.
Owner:CHINA SOUTHERN POWER GRID INTERNET SERVICE CO LTD

A national secret IPSec secure communication method supporting quantum-resistant cryptography

The present invention relates to the field of information security technology, and more particularly to a national secret IPSec secure communication method supporting quantum-resistant cryptography, comprising: an initiator receiving a hybrid signature dual certificate from a responder for verification, and constructing hybrid key exchange parameters and a hybrid signature; the responder sequentially verifies the initiator's hybrid signature dual certificate, decrypts the hybrid key exchange parameters, verifies the hybrid signature, and performs a quantum-resistant key encapsulation operation to obtain a temporary ciphertext and a quantum-resistant temporary shared key; the responder constructs the hybrid key exchange parameters and a hybrid signature; the initiator decrypts the responder's hybrid key exchange parameters; verifies the responder's hybrid signature; performs a quantum-resistant key decapsulation operation to obtain a quantum-resistant temporary shared key; and the initiator and responder both generate their own hybrid key parameters based on the quantum-resistant temporary shared key. The present invention can enhance the security of the IPSec protocol in the quantum computing era and achieve dual protection during communication.
Owner:SHANDONG DUOFANG SEMICON CO LTD +1

IPSec Protocol State Change Identification Method Based on def-use Data Dependence Graph

ActiveCN116566866BEnergy efficient computingTransmissionData dependency graphAlgorithm
The present invention provides a method for identifying the state change of the IPSec protocol based on the def-use data dependence graph. The method includes: Step 1: Obtain the target binary program implementing the IPSec protocol; Step 2: Rewrite and instrument the target binary program to achieve the identification and positioning of basic blocks; Step 3: Scan the rewritten and instrumented target binary program to obtain all function pointer indirect call instructions, and generate a pointer function dictionary containing the location indexes of all function pointer indirect call instructions; Step 4: Traverse all functions in the target binary program to generate corresponding def-use data dependence graphs for each function; Step 5: Traverse all structure variable assignment instructions in the target binary program, and identify the location of the code where the protocol state change operation is located according to the def-use data dependence graph of the function where each assignment instruction is located and the pointer function dictionary.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

A method for sharing an IPTV real-time picture to a mobile terminal for playing

PendingCN122293899ABreak through space constraintsRealize configuration-freeSTUNIp address
This invention relates to a method for sharing real-time IPTV content to a mobile terminal for playback, belonging to the field of wireless communication and terminals. The method includes: the IPTV device and the mobile terminal sending a STUN request to a public STUN server to bypass NAT and automatically obtain the corresponding public IP address; the IPTV device and the mobile terminal establishing an IPSec encrypted tunnel based on the IPSec protocol; the IPTV device receiving the operator's playback stream, extracting video and audio data, re-encapsulating it into RTP format, encrypting it, and transmitting it to the mobile terminal through the IPSec encrypted tunnel; the mobile terminal decrypting and verifying the integrity of the data packets, extracting the RTP payload, and playing the corresponding video and audio data in real time; the mobile terminal sending control commands to the IPTV device through the IPSec encrypted tunnel; the IPTV device parsing the control commands and calling an API to switch channels, synchronously updating the electronic program guide information to the mobile terminal. This method enables mobile devices to remotely receive and play television channel content from a home IPTV device via the public network, overcoming spatial limitations.
Owner:E-SURFING DIGITAL LIFE TECH CO LTD

Tclas element for filtering ipsec traffic

To carry 5G QoS traffic flows over an IPsec Security Association (SA) within a WLAN network, a STA is configured to encode a frame to include a Traffic Classification (TCLAS) element that includes a frame classifier field. The frame classifier field can include a classifier type subfield and a classifier parameter subfield. To identify and filter 5G QoS traffic flows carried over an IPsec SA, the STA can set the classifier type subfield to a predetermined value (e.g., 11) to indicate that an IPsec SA parameter is included in the classifier parameter subfield, and include a Security Parameter Index (SPI), a destination IP address, and an IPsec protocol within the classifier parameter subfield.
Owner:INTEL CORP