Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

455 results about "Key distribution" patented technology

In symmetric key cryptography, both parties must possess a secret key which they must exchange prior to using any encryption. Distribution of secret keys has been problematic until recently, because it involved face-to-face meeting, use of a trusted courier, or sending the key through an existing encryption channel. The first two are often impractical and always unsafe, while the third depends on the security of a previous key exchange.

Extension of network control system into public cloud

Some embodiments provide a method for a first data compute node (DCN) operating in a public datacenter. The method receives an encryption rule from a centralized network controller. The method determines that the network encryption rule requires encryption of packets between second and third DCNs operating in the public datacenter. The method requests a first key from a secure key storage. Upon receipt of the first key, the method uses the first key and additional parameters to generate second and third keys. The method distributes the second key to the second DCN and the third key to the third DCN in the public datacenter.
Owner:VMWARE INC

Power real-time data dynamic encryption transmission method and system based on national secret algorithm

The invention discloses an electric power real-time data dynamic encryption transmission method and system based on a national secret algorithm. According to the method, the real-time updating of the session key is realized by fusing the SM3 Hash algorithm and the multi-dimensional dynamic factor, and the anti-attack capability of data transmission of the power system is improved. A timestamp and data counter double-trigger mechanism is introduced in the key generation process, so that the key is automatically alternated under a fixed time interval or a data volume threshold value, a key exposure window is shortened, and the security risk caused by using the same key for a long time is reduced. Key synchronization is carried out in combination with an SM2 bidirectional authentication channel, the confidentiality of key distribution is ensured, access of unauthorized equipment is avoided through an identity authentication mechanism, full-closed-loop security protection from key generation to transmission is formed, the high-security requirement of the power industry for key data transmission is met, and the security of key data transmission is improved. Through deep combination of a cryptographic algorithm system and a dynamic adaptation mechanism, the high efficiency and compliance of power real-time data transmission are considered while the security is ensured.
Owner:GUIZHOU WUJIANG HYDROPOWER DEV

Distributed quantum security encryption method, system and device

The invention provides a distributed quantum security encryption method, system and device. The method comprises the following steps: monitoring the quality of a quantum key distribution link in real time, and dynamically selecting a quantum key, a post-quantum session key or a fusion key of the quantum key and the post-quantum session key as a working key; and when the node cannot be directly reached, the trusted relay node generates an end-to-end key seed by using a quantum key and a post-quantum cryptography shared key which are respectively established with the two ends, the end-to-end key seed is encrypted and distributed by a public key and then a session key is independently derived by the two communication parties, and the relay node cannot decrypt. The system adopts a distributed Mesh network architecture supporting a terminal / relay dual mode. The device integrates a quantum random number generator, a post quantum cryptography coprocessor and a mixed key engine. The method integrates the advantages of quantum physical security and post quantum cryptography, has high security and availability, and is suitable for constructing a key infrastructure security communication network resisting quantum computing attack.
Owner:INFORMATION & COMMNUNICATION BRANCH STATE GRID JIANGXI ELECTRIC POWER CO

Block chain cross-domain service method and system based on sharing verification and smart contract

The invention discloses a block chain cross-domain service method and system based on sharing verification and a smart contract, and the method comprises the steps: building a cross-domain sharing channel between a first business domain of a first block chain and a second business domain of a second block chain through a main node on a relay chain; performing hash operation on the original data to obtain a data fingerprint, packaging the data fingerprint, the data metadata and the digital signature of the data holding node into a first message, and submitting the first message to a relay chain through a sharing channel; after receiving the first message, performing consensus verification on the data fingerprint based on a threshold signature mechanism, and writing a verification result into a shared state table; querying the verification state of the data fingerprint from the sharing state table through the data use node in the second service domain, and requesting to download the encrypted data from the intelligent contract of the relay chain; executing permission judgment, and triggering a key distribution contract to transmit a decryption key to a data use node; and downloading the encrypted data, and writing the cross-domain data sharing transaction record into a block chain account book of the second business domain.
Owner:CHINESE PEOPLES LIBERATION ARMY INFORMATION SUPPORT CORPS ENGINEERING UNIVERSITY

Method and system for verifying a cryptographic key forwarding path in a quantum key distribution network

The invention provides a method for verifying a key forwarding path of at least one cryptographic key in a quantum key distribution, QKD, network, and a system for the verification of the key forwarding path of at least one cryptographic key, the method comprising at least steps of:selecting (using either a centralized or a decentralized method) a number of QKD nodes of the QKD network, which define a key forwarding path of the at least one cryptographic key;transmitting to each of the selected QKD nodes data indicating at least partial information about the key forwarding path of the at least one cryptographic key;generating, by each selected QKD node, a digital signature, wherein the digital signature contains at least the data indicating at least partial information about the key forwarding path of the at least one cryptographic key;transmitting, by each selected QKD node (N1-N9), the digital signature generated at that selected QKD node (N1-N9); andverifying the key forwarding path of the at least one cryptographic key through a verification of the transmitted digital signatures.
Owner:ADVA NETWORK SECURITY GMBH

Clinical nursing patient information monitoring and recording method and system

According to the clinical nursing patient information monitoring and inputting method and system, the data accuracy, the data inputting efficiency and the privacy protection safety are improved; the method comprises the following steps: firstly, collecting and preprocessing vital sign data of a patient in real time through various physiological sensors; then, acquiring a nursing record image, acquiring nursing record data through an OCR model, acquiring nursing information voice, transwriting the nursing record data and the nursing information voice into nursing information data through a medical scene voice transwriting model, and performing unified standardization processing on the three groups of data to generate patient information data; and finally, when patient information data is input, symmetric encryption is carried out by adopting a national cryptographic SM4 algorithm, encrypted data is obtained, a dynamic encryption key is generated through an ECDH key distribution technology, and the dynamic encryption key can be called to carry out decryption operation after authentication of a dual protection mechanism of Hash value pre-verification and identity authentication is passed.
Owner:DUHUI HEALTH (CHENGDU) MEDICAL TECH CO LTD

Identity authentication method and system based on national secret algorithm

The invention discloses an identity authentication method and system based on a national secret algorithm, and the method comprises the steps: building a hierarchical key management system based on a national secret IBE framework, generating a system master key pair through employing an SM2 algorithm, and achieving a decentralized key distribution mechanism; constructing a domain perception differential privacy protection module, defining a privacy budget allocation strategy according to the security level, and adding calibrated Laplace noise to the user identity feature vector; designing a distributed batch matrix multiplication protocol, and decomposing the distributed batch matrix multiplication protocol to a plurality of computing nodes for parallel processing through a secret sharing technology; a zero-knowledge proof verification mechanism is implemented, and identity verification is completed through a commitment scheme based on an SM3 hash algorithm; deploying a self-adaptive key updating strategy, and analyzing threat level change through a threat situation evaluation function; and establishing a secure communication channel based on SM4 symmetric encryption, and performing encryption processing by using the temporary session key. The security and expandability of the system are improved, the privacy of the user is effectively protected, and the system adapts to a dynamically changing network threat environment.
Owner:GUIZHOU BLUESKY INNOVATIVE SCI & TECH CO LTD

Quantum sensing intelligent key distribution method for intelligent quantum communication network

The invention relates to a quantum sensing intelligent key distribution method for an intelligent quantum communication network, and the method comprises the steps: inputting original observation data of a quantum channel to a computer system, and extracting a quantum feature vector of each step; stacking into a two-dimensional matrix, and obtaining space-time representation through a convolutional neural network; obtaining time sequence cleaning features in combination with a bidirectional long-short-term memory network and an attention mechanism; extracting associated quantum channel characteristics and noise statistics, and executing anomaly detection and error correction prediction; a near-end strategy optimization algorithm is used for inputting the two to adjust the transmission distance and protocol parameters; and constructing a saturated noise channel model in combination with the adjustment parameters, and carrying out error correction and privacy amplification to generate a final security key. The method aims to fully combine quantum feature perception, depth sequence modeling and reinforcement learning optimization mechanisms, and realizes robust feature extraction of original observation of a quantum channel by constructing high-dimensional quantum feature mapping and performing standardization, filtering and abnormal value processing.
Owner:GUIZHOU UNIV

Electrical drawing safety collaborative management method, system and equipment based on cloud computing technology and medium

The invention discloses an electrical drawing security collaborative management method, system and device based on a cloud computing technology and a medium. The method comprises the steps that an initial key is generated through a quantum key distribution device, the key is divided into a plurality of sub-blocks, and a dynamic session key is generated; encrypting data blocks divided by the electrical drawing file according to the logic structure through the dynamic session key, and transmitting the encrypted data blocks to a cloud computing platform for storage; generating a temporary key to encrypt the modified content, adding a digital signature and position information, and combining the modified content after the cloud verifies the signature to generate a new electrical drawing; synchronizing the new electrical drawing full-text security operation credential update record to the block chain, and verifying the consistency of the data on the chain and the cloud drawing version; and splitting the dynamic session key into a plurality of fragments and storing the fragments in different cloud nodes. According to the invention, safe transmission, efficient collaborative management and accurate data tracing of the electrical drawings are realized, and the safety, reliability and efficiency of full-life-cycle management of the electrical drawings are remarkably improved.
Owner:GUIZHOU POWER GRID CO LTD

Timing sequence post-synchronization quantum key extraction method based on classical information fusion

A time sequence post-synchronization quantum key extraction penetration test method comprises the following steps: A) under the condition of penetration test, a QKD system operates normally, and a sending end and a receiving end smoothly complete key distribution; b) the man-in-the-middle selects an initial original key exchange period to establish synchronization and correlation so as to realize clock synchronization with a receiver; c) analyzing quantum bit error rate information obtained from a public channel by a man-in-the-middle, deducing a corresponding relation between a receiver detector and each quantum state, and establishing a mapping model of the quantum states and bit values; d) determining a quantum state type responded by the receiver in each response time slot in a subsequent original key exchange period by the middleman in combination with path information obtained by other sub penetration tests; and E) the intermediary obtains a final key which is the same as the two communication parties by implementing an error correction and privacy amplification process, the quantum bit error rate between the intermediary and the sender is maintained at a relatively low level and is lower than a security threshold, and a security alarm is not triggered in a penetration test process.
Owner:NAT UNIV OF DEFENSE TECH

Signal encryption method and device based on quantum key distribution

The invention discloses a signal encryption method and device based on quantum key distribution, and relates to the technical field of satellite navigation, and the method comprises the steps: building a quantum key distribution system based on a plurality of interconnected quantum key servers, and enabling a user communication terminal to be connected with a nearby quantum key server; the communication relay unit performs basis vector comparison on the quantum state data of the satellite and the ground station through a key distribution protocol to generate a quantum key; the key distribution unit dynamically updates the quantum key and distributes the quantum key to the user communication terminal; the user communication terminal encrypts the satellite navigation data by using the quantum key to obtain an encrypted data packet, and sends the encrypted data packet to the receiving end through the communication relay unit; and the receiving end decrypts the encrypted data packet based on the quantum key to obtain the satellite navigation data. According to the method, the generation rate of the quantum key can be improved, the anti-interference performance of the quantum key distribution system in a complex environment is enhanced, and the stability and reliability of the quantum key distribution system are ensured.
Owner:CETC XINGHE BEIDOU TECH (XIAN) CO LTD

Identity privacy protection system and method for safe sharing of power data

PendingCN121561950AData processing applicationsDigital data protectionChosen-plaintext attackAttack
The invention discloses an identity privacy protection system and method oriented to power data security sharing, which combine single-factor combination authentication and identity traceability and utilize the transparency and tamper resistance of a block chain. Comprising an electric power key generation center, an electric power cloud service provider, an electric power data owner, an electric power data user and a block chain, user identity privacy is ensured, safe identity verification is supported, identity traceability is achieved under necessary conditions, and meanwhile safe distribution of keys is achieved. In addition, services and resources are isolated by using groups, so that the flexibility and the expandability of the services and the resources are enhanced. Security analysis and experimental evaluation prove that the method can effectively resist selected plaintext attacks, and meanwhile, high efficiency and practicability are kept.
Owner:STATE GRID HENAN INFORMATION & TELECOMM CO

Federal recommendation privacy protection method and system based on ring signature and selective aggregation

The invention discloses a federal recommendation privacy protection method based on ring signature and selective aggregation, which realizes anonymization privacy protection and selective aggregation in a federal learning process through an innovative double-server architecture and a hierarchical security mechanism. The method comprises the following steps: 1) deploying an aggregation server and a security server in a system initialization stage, and completing parameter initialization and key distribution; 2) the client executes local model training, and anonymization privacy protection uploading is realized by adopting a ring signature technology; 3) the security server performs selective aggregation of credibility verification, and completes grouping and parameter fusion based on user similarity; and 4) ensuring the completeness and source credibility of model updating through a hierarchical security parameter distribution mechanism. While the recommendation precision is ensured, the user identity leakage and privacy tracking are effectively prevented, the comprehensive security guarantee is provided for the federal recommendation system, and the method has the advantages of low calculation overhead and high communication efficiency.
Owner:SOUTHEAST UNIV

Quantum encryption method and system based on lightweight end equipment, and medium

The invention discloses a quantum encryption method and system based on a lightweight end device and a medium, and relates to the technical field of quantum encryption, and the method comprises the steps: obtaining the real-time state of a receiving-transmitting end lightweight device, carrying out the self-adaptive analysis, and determining a key generation strategy; starting a quantum key distribution device to generate an initial key, distributing the initial key through an authentication channel, and performing post-processing; classified storage is carried out through a key management server, key identifiers are generated, and a sender requests a quantum key according to the identifiers before sending data; and encrypting data by using the key and a lightweight symmetric encryption algorithm, generating a ciphertext, and sending the ciphertext to a receiving end for decryption. The technical problems of resource limitation and low key generation and distribution efficiency of lightweight end equipment in quantum key distribution and encryption application are solved, the real-time state of the equipment is matched by dynamically adjusting the key generation rate and length through a self-adaptive key generation strategy, the calculation overhead is reduced, and the key generation efficiency is improved. And the encryption efficiency and the resource adaptability are improved.
Owner:ANHUI XINJIE INTELLIGENT TECH CO LTD

Big data secure storage method and system based on cloud computing

The invention relates to the field of cloud computing big data secure storage, in particular to a cloud computing-based big data secure storage method and system. The method comprises the following steps: performing encryption and fragmentation processing on an original data stream to generate a fragmentation sequence with an index; generating a dynamic key sequence and a verification key group based on the fragment information; constructing a secure transmission channel through a quantum key distribution mechanism in combination with a geographic position weight and a load balancing strategy, and realizing encapsulation and transmission of a secure fragment packet; node state monitoring and redundancy management are implemented, and an update mapping table is generated; and finally, a complete data stream is recovered through fragment positioning retrieval, data recombination and dynamic decryption. According to the invention, the security and reliability of data storage and the overall load balancing capability of the system are improved.
Owner:ANHUI ADDITION SUBTRACTION MULTIPLICATION & DIVISION TECHNOLOGY CO LTD

Dynamic key fragment storage management method and system for multi-cloud architecture

The invention relates to the technical field of key distribution, in particular to a multi-cloud architecture-oriented dynamic key fragmentation storage management method and system, which comprises the following steps of: dividing a manufacturing process of the manufacturing industry into a plurality of time sequence stages corresponding to different data access authority levels and security requirements, and constructing corresponding quantum state evolution operators; driving the key state to evolve among different time sequence stages through a quantum state evolution operator according to the progress of the manufacturing process, and adjusting the access authority of the key; quantum entanglement connection is established between supply chain nodes, the trust degree between the nodes is measured and quantized through the association of the quantum entanglement state, and the distribution weight of the key fragments is adjusted based on the change of the trust degree; collecting constraint parameters of production takt, equipment state, logistics delay and quality index in the manufacturing process, and converting the constraint parameters into quantum state constraint conditions; and when it is detected that the constraint condition changes, recalculating the key fragment distribution scheme based on the quantum state constraint condition and the credibility, and synchronously distributing the key fragment distribution scheme to each supply chain node.
Owner:SUZHOU GUANGCHI INFORMATION TECHNOLOGY CO LTD

Performance improvement method for double-independent quantum key distribution of actual reference system measurement equipment

The invention discloses a method for improving the performance of double-independent quantum key distribution of actual reference system measurement equipment, belongs to the technical field of quantum key distribution (QKD), and aims to improve the performance of the double-independent quantum key distribution when non-ideal factors such as a post-pulse effect of a detector and finite sample statistical fluctuation are considered. The invention relates to a method and a system for improving the performance of a reference system measurement device by introducing an advantage extraction technology into a double independent quantum key distribution (RFI-MDI-QKD) protocol of the reference system measurement device. Simulation results show that when the post-pulse effect and the statistical fluctuation effect are considered, the advantage extraction method can effectively improve the security key rate and the security transmission distance of the RFI-MDI-QKD protocol on the premise of not changing optical hardware. According to the invention, a valuable reference technology can be provided for practical research of the RFI-MDI-QKD system.
Owner:NANJING UNIV OF POSTS & TELECOMM

Secure communication network system and method based on quantum key

The embodiment of the invention provides a secure communication network system and method based on a quantum key, and the system comprises a quantum key distribution module which is used for building and updating a symmetric key between communication nodes through a quantum key distribution protocol; the quantum encryption communication module is used for encrypting and decrypting communication data by using the symmetric key; the quantum algorithm acceleration module is used for deploying a quantum algorithm in machine learning and optimization calculation tasks to realize calculation acceleration; the hybrid computing scheduling module is used for coordinating task allocation and resource scheduling between the classical computing resources and the quantum computing resources; and the block chain verification module is used for recording life cycles of key distribution, communication sessions and calculation tasks and ensuring non-tampering and traceability of the data. A key distribution and encryption communication basis of an information theory security level is constructed, and long-term data confidentiality is provided for a network. And the complex service processing capability and efficiency of the whole network system are obviously improved.
Owner:HUANENG ZHAOCAI DIGITAL TECHNOLOGY CO LTD +1

Adaptive information negotiation method suitable for continuous variable quantum key distribution system

The invention relates to a self-adaptive information negotiation method applicable to a continuous variable quantum key distribution system, which comprises the following steps of: estimating an optimal code rate that an LDPC (Low Density Parity Check) code should reach under a current quantum channel, converting an initial code rate into the optimal code rate by a receiver, and obtaining a low-reliability bit number l which needs to be disclosed in conversion calculation, the method comprises the following steps of: decoding an LLR (Local Library Ratio) by using Bob, sending the LLR to Alice through a classic channel in combination with an encryption technology, sorting absolute values of the LLR by Alice in a decoding iteration process, selecting l bit positions with low reliability, sending the bit positions to Bob, determining a bit value by Bob according to the bit positions with low reliability sent by Alice, and feeding back and sending the bit value to Alice, and correcting the LLR value by Alice according to bit information sent by Bob. According to the method disclosed by the invention, the code rate of the LDPC code can be flexibly adjusted along with the change of the state of the time-varying channel, and the negotiation efficiency is improved, so that the key rate of the system is improved. The method is excellent in performance in a time-varying channel environment, negotiation efficiency under a low signal-to-noise ratio condition can be remarkably improved, and an efficient and reliable information negotiation scheme is provided for practical application of a quantum secret communication system.
Owner:DONGHUA UNIV +2

Industrial data security processing method and system based on Internet of Things key distribution

The invention discloses an industrial data security processing method and system based on Internet of Things secret key distribution, and relates to the field of data processing, and the system comprises a generation module which is used for dynamically generating an initial secret key adaptive to the current operation state of an industrial Internet of Things device by applying real-time working condition parameters and a historical data encryption format of the industrial Internet of Things device; the distribution module is used for receiving the initial key, and constructing an encryption transmission channel to directionally transmit the initial key to the corresponding industrial equipment based on the unique identity identifier of the equipment and a multi-equipment cooperative authentication mechanism; according to the method, the initial key adaptive to the current operation state is dynamically generated through the real-time working condition parameters of the industrial equipment and the historical data encryption format, the matching degree of the key and the equipment state is improved, an encryption transmission channel is constructed based on the unique identity of the equipment and a multi-equipment cooperative authentication mechanism, and the directional transmission safety of the initial key is guaranteed.
Owner:GUIYANG BUREAU OF CHINA SOUTHERN POWER GRID CO LTD EHV TRANSMISSION CO

Semantic communication security enhancement system based on SIM (Subscriber Identity Module) card quantum key presetting

The invention relates to the technical field of mobile communication, and particularly provides a semantic communication security enhancement system based on SIM card quantum key presetting, comprising an SIM card security base module configured to generate physical unclonable function characteristics and preset quantum security keys by using SIM card hardware characteristics; the lightweight authentication protocol module is in communication connection with the SIM card security base module and is configured to realize dynamic identity authentication based on physical unclonable function characteristics and a quantum security key; the semantic security enhancement module is configured to perform privacy protection processing on the semantic communication data; the trusted execution environment optimization module is in communication connection with the SIM card safety base module and the lightweight authentication protocol module and is configured to construct a hardware-software collaborative trusted execution environment; the quantum security enhancement module is integrated on the SIM card security base module and is configured to provide quantum attack resistance and dynamic key management; according to the invention, the real-time performance and anti-quantum computing capability of key distribution are significantly improved.
Owner:CHINA MOBILE INTERNET CO LTD +1

Drug use correlation analysis early warning method

The invention discloses a drug use correlation analysis early warning method, and the method comprises the steps: firstly building a drug use correlation analysis early warning interaction platform which is used for constructing a plurality of databases, evaluating drug prediction consumption, selecting a dispensable pharmacy, and encrypting transmission information; and obtaining a callable drug database in a logistics range through a union set fusion strategy, and generating a predicted consumption threshold through a drug predicted consumption strategy. And when the medicine consumption exceeds the threshold value, selecting the dispensable drugstores according to the drugstore selection strategy. The method comprises the following steps of: receiving a key pair, transmitting coordination information containing the key pair by means of a key distribution strategy, encrypting data by a public key, decrypting the data by a pharmacy by using a private key, comparing a hash value, distributing if the data are consistent, and feeding back and starting a retransmission checking mechanism if the data are different. The inventory risk is effectively reduced, the ability to deal with clinical demand fluctuation is improved, and the safety and timely supply of clinical medication are guaranteed.
Owner:TIANJIN HUAYAO HEALTH IND DEVELOPMENT CO LTD

Film and television copyright one-key distribution and promotion full-automatic transaction system and method based on AI evaluation and smart contract

The invention discloses a film and television copyright one-key distribution and popularization full-automatic transaction system and method based on AI evaluation and a smart contract. The method comprises the following steps: receiving copyright content; calling an AI model to carry out value evaluation and originality verification, and generating an evaluation report; generating an electronic protocol based on the validated evaluation report; converting the protocol into a smart contract and deploying the smart contract to a block chain; responding to the one-key distribution instruction, and distributing the content and the contract interface to a playing platform; obtaining under-chain income data through an oracle machine; and the smart contract automatically verifies and executes account division. According to the system, the AI and the block chain technology are deeply fused, automation, intelligence and transparency of the whole movie and television copyright transaction process are achieved, the transaction cost and the trust cost are greatly reduced, and a new generation of infrastructure is provided for the movie and television copyright transaction market.
Owner:杨剑

Encryption communication system based on multistage key distribution

According to the encryption communication system based on multi-level key distribution provided by the invention, the environment sensing layer acquires target environment parameters in real time and forms closed-loop feedback with a dynamic security score generated by the strategy control layer, and the key management layer is driven to realize three-stage dynamic switching from an initial key to a session key to a master key; a key fragmentation bidirectional authentication mechanism of a secure transmission layer and a double-key pool non-inductive updating strategy of a password service layer are matched, under the quantum resistance storage guarantee of a hardware isolation layer, an annular defense system with a space-time adaptive characteristic is constructed, and the security and availability are greatly and comprehensively improved.
Owner:HUANENG SHANXI ENERGY SALES CO LTD +1

Source device independent quantum key distribution and network method, device and system

The invention discloses a source device independent quantum key distribution method, device and system and a network thereof, and belongs to the technical field of quantum key distribution. In order to solve the problem that an existing quantum key distribution protocol depends on a source end security hypothesis and is difficult to defend unknown source side attacks, the invention provides a source equipment-independent quantum key distribution protocol. Through the physical characteristics of the non-classical quantum light source and a pairing method after measurement, the security hypothesis of source end equipment is removed, known and unknown source side attacks can be effectively resisted, and the quantum advantages in the aspects of security and performance expression compared with a classical laser source are realized. The invention further provides a method for directly expanding the point-to-point protocol to the multi-user quantum key distribution network, compared with an existing quantum network based on an entangled photon source, the complexity of an experiment system and the requirement for equipment are reduced, and the method is suitable for long-distance and high-safety quantum communication and quantum network deployment.
Owner:RENMIN UNIVERSITY OF CHINA

Network security knowledge graph construction method and system

The invention relates to the technical field of network security, in particular to a network security knowledge graph construction method and system, and the method comprises the following steps: extracting information from original network traffic, logs and threat intelligence, extracting attack features, classifying and storing the attack features in a knowledge base, screening high-risk nodes, judging weak points, generating dynamic keys, and distributing and storing the dynamic keys. The method comprises the following steps of: extracting attack characteristics, carrying out logic classification, constructing a multi-dimensional associated security data system, identifying a threat path and a high-risk node, combining abnormal detection and path complexity comparison, encrypting basic data, verifying and decrypting, adjusting a security policy rule according to an environment, and executing dynamic adjustment of a network security protection policy. According to the method, hidden weak points are accurately judged, a dynamic key generation and distribution mechanism is adopted, encryption consistency and security are improved, distributed encryption exchange and real-time verification are matched, confidentiality and integrity of data transmission and storage are guaranteed, protection self-adaptive adjustment is achieved according to an environment state matching strategy, and response efficiency and flexibility are improved.
Owner:SICHUAN POLICE COLLEGE

Quantum key distribution system and method

The invention discloses a quantum key distribution system and method. According to the system, a phase coherence monitoring mechanism is innovatively introduced, and early attack detection is realized through a dynamic consensus sampling protocol; a zero-trust relay network is constructed by adopting a wavefront fragmentation principle, and trust dependence on relay nodes is eliminated; self-adaptive safety monitoring is realized based on a finite state automaton, and a system safety strategy is dynamically adjusted. According to the method, the problems of resource consumption type attack, relay trust dependence, static protocol limitation and the like faced by an existing QKD system are solved through a strict mathematical framework, and long-distance quantum key distribution with efficient resources, endogenous security and elasticity and physical layer security guarantee is realized. Experiments show that compared with a traditional scheme, the detection delay of the system is reduced by about 38%, the resource waste is reduced by about 40%, and the availability of the system reaches 99.995% or above.
Owner:CHIZHOU JIAYIN MOTOR & CONTROL SYSTEM CO LTD

Quantum key distribution protocol

A method for performing a quantum key distribution protocol among a first device, a second device, and an intermediary device (ID), the method including the ID transmitting a first secret symbol string to the first device via a quantum channel and a second secret symbol string to the second device via another quantum channel; the first and second devices demodulate their respective symbol strings and transmit reported symbol numbers to the ID; the ID shares basis state sets with both devices and generates a third symbol string by combining subsets of the first and second secret symbol strings corresponding to the reported symbol numbers; the ID transmits this third symbol string to the second device; and the first and second devices perform quantum key exchange by sifting validly received symbols in common positions.
Owner:ARQIT LTD

Quantum key distribution network routing method and system

The application discloses a quantum key distribution network routing method and system, comprising: dividing a quantum key pool in an SDN-QKD network; based on key service requests of different security levels and the divided quantum key pool, a maximum key service request success model is constructed, and the maximum key service request success model is used to approve the key service requests; based on a minimum key consumption model, the approved key service requests are screened; based on the screened key service requests, a key resource consumption routing optimization algorithm is used to generate a final path; and based on the final path, key distribution is performed. The application improves key resource utilization, guarantees high-priority business transmission success rate, and effectively improves network load balancing degree.
Owner:NANJING HUADUN ELECTRIC POWER INFORMATION SAFETY EVALUATION CO LTD

Industrial internet of things multi-key fuzzy search method based on walsh matrix

The application discloses a kind of industrial internet of things multi-key fuzzy search method based on Walsh matrix, comprising the following steps: S1, system initialization is carried out;S2, based on system initialization result, key distribution is carried out;S3, based on key distribution result, generate ciphertext index;S4, based on key distribution result, generate security query trapdoor;S5, according to ciphertext index and security query trapdoor, carry out ciphertext matching and authorized interception.The application realizes the bottom unification of retrieval and access control, effectively resists structured information disclosure attack, and seamlessly nests the polynomial coefficient of role-based access control into the data structure of encryption matrix.
Owner:NORTH CHINA UNIVERSITY OF TECHNOLOGY