Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

51 results about "Link encryption" patented technology

Link encryption is an approach to communications security that encrypts and decrypts all traffic at each network routing point (e.g. network switch, or node through which it passes) until arrival at its final destination. This repeated decryption and encryption is necessary to allow the routing information contained in each transmission to be read and employed further to direct the transmission toward its destination, before which it is re-encrypted. This contrasts with end-to-end encryption where internal information, but not the header/routing information, are encrypted by the sender at the point of origin and only decrypted by the intended receiver.

Large model corpus data interaction system and interaction method based on trusted execution environment, terminal and medium

The invention discloses a large model corpus data interaction system and method based on a trusted execution environment, a terminal and a medium. The system comprises a data provider, a data demander and a trusted data space service platform. And the data provider is used for encrypting the corpus data, and performing preprocessing, directory sorting and packaging on the corpus data in the data provider connector to obtain the data capsule. And the data demander is used for submitting a calculation task in the data demander connector and obtaining corpus data of the data capsule for calculation after authorization. And the trusted data space service platform is used for storing the encrypted corpus data, controlling access of a data user, scheduling a calculation task, managing a key and generating an audit log. Through trusted execution environment hardware isolation and full-link encryption, it is ensured that corpus data only exists in a plaintext form in the trusted execution environment in the full life cycle from access to destruction, and unauthorized access and leakage are completely eradicated.
Owner:SHENZHEN CONFIDENTIAL COMPUTING TECH CO LTD

Vehicle-mounted terminal control method and system and vehicle

The invention relates to the technical field of vehicle-mounted terminals, and discloses a vehicle-mounted terminal control method and system and a vehicle, and the method comprises the following steps: S1, multi-dimensional environment perception and scene judgment: collecting GPS signal intensity, Beidou signal intensity, mobile network signal intensity, vehicle altitude and environment illumination intensity through a perception module; through Beidou + inertial navigation integrated positioning + null shift calibration, the basement positioning precision is higher, the parking position monitoring and vehicle searching requirements are met, the three-level redundant link (mobile network + LoRa + Bluetooth) and distributed gateway design is adopted, the basement information transmission success rate is higher, emergency information is not interrupted, data security is guaranteed through full-link encryption, and the service life of the system is prolonged. Misjudgment of temporary weak signals on the ground is avoided through multi-dimensional sensing (signal + altitude + illumination + duration), the mode switching accuracy is higher, bandwidth waste is reduced through a priority dynamic adjustment mechanism, the emergency information response speed is increased, and link congestion is avoided through a common information caching strategy.
Owner:JIANGSU SHIHANG IOT TECH CO LTD

Link encryption and key diversification on a hardware security module

A Hardware Security Module (HSM) (900), and method thereof, suitable for use in securely servicing cryptographic requests from multiple tenant applications to preserve end-to-end privacy is provided. A Link Encryption and Key Diversification interoperability (43) between two processors provides cryptographic and logical isolation between multiple tenant applications on the HSM (900) that use and share more than one PCIe Physical Function (30) over more than one Virtual Function (VF) (21) to one or more Crypto Units (CU) (61) for satisfying a request (46) of an HSM cryptographic services. An Output Feedback (OFB) block with CRC support is further provided with encryption and decryption. The HSM as configured is more resistant to side channel attacks.
Owner:THALES DIS CPL USA INC

Monitoring method for tail gas emission of aircraft refueling vehicle

The invention discloses a method for monitoring tail gas emission of an aircraft refueling vehicle, and solves the problem that PM quantitative data acquisition is inaccurate in a complex environment of an airport. The method comprises the following steps: stably sampling and removing aviation kerosene steam through a sampling probe integrating sensing and flow guide adjustment; synchronously detecting and deducting background gas interference; performing secondary dehumidification and constant-temperature pretreatment on the tail gas; the double detection units are linked to collect multi-dimensional data, and a nonlinear interference correction model is constructed through fusion; and adopting an exclusive calibration mode and marking invalid data. The method further comprises the design of wind speed adaptation, condensation backflow prevention, working condition and area label optimization, double-link encryption transmission, safe installation, optical signal compensation, graded maintenance and the like. The method can resist multiple environmental interferences, PM detection errors are controllable, data updating is efficient, and airport safety operation and compliance monitoring requirements are met.
Owner:中国航空油料有限责任公司

Product oil supervision data security protection method and system based on block chain

The invention discloses a block chain-based product oil supervision data security protection method and system, and relates to the technical field of data security. Aiming at the problems of easy data tampering, early warning lag and the like in a traditional product oil supervision system, the scheme is adopted as follows: deploying an alliance chain architecture and realizing distributed storage to provide bottom support for a subsequent process; full-link encryption is carried out in the links of data acquisition, data transmission and evidence storage, and safe data is provided for block chain storage; identity registration and authority configuration of equipment and a user are completed, and a safety basis is provided for safe access and subsequent operation of encrypted data; the consistency of on-chain and off-chain data is ensured by establishing a real-time evidence storage mechanism, a terminal verification mechanism and a full-amount verification mechanism, full-amount data identification abnormity is analyzed in combination with an association graph model and a space-time graph convolutional network, and an abnormity detection basis is provided for intelligent early warning; and executing a hierarchical response strategy based on an on-chain early warning rule and an anomaly detection result to form a supervision closed loop. The method and the device are used for realizing data full-link security protection.
Owner:浪潮智慧城市科技有限公司

Unique initialization vectors for secure communication over multipath networks

Techniques described herein can allocate respective unique secure channel identifiers (SCIs) to respective uplink encryptor interfaces which provide intersite connectivity over multipathing internet protocol (IP) networks between a first data center site and a second data center site. A respective uplink encryptor interface can then use the unique SCI allocated thereto, along with a packet number counter value to encrypt and generate an integrity check value for at least a portion of a packet. The encryption can comprise using the SCI and the packet number counter value to generate a unique packet initialization vector for the packet, which is then used to encrypt and integrity protect the packet. The respective uplink encryptor interface can send the encrypted packet via a tunnel to a second data center site via a secure communication channel spanning across multiple encryptors and multiple decryptors. The encrypted packet can be decrypted at the second data center site and forwarded along to its destination within the second data center site.
Owner:CISCO TECHNOLOGY INC

Bluetooth remote trust interaction channel establishment method and device for intelligent machine body

This invention discloses a method and apparatus for establishing a Bluetooth remote trust interaction channel for intelligent devices, relating to the field of Bluetooth communication security technology. The method can be implemented through pure software, pure hardware, firmware, or a combination of both. It includes: entering a Bluetooth discoverable state in response to a master recognition trigger operation and outputting a pairing confirmation credential; completing Bluetooth secure pairing with out-of-band credential verification and exchanging link encryption keys; extracting the terminal device's hardware identity identifier and strongly binding it with the key as a trust anchor point for storage; and exiting the discoverable mode after master recognition is complete, accepting data interaction only from trusted devices. The apparatus includes a Bluetooth pairing module, a trust anchor point management module, and a channel access control module, which are sequentially connected in communication. This invention achieves secure management of the entire lifecycle of Bluetooth pairing and interaction channels, reducing the risk of unauthorized access and unauthorized operations. It has wide adaptability and can cover various implementation scenarios.
Owner:陈立波

Unmanned aerial vehicle flight control and data transmission integrated safety protection system

The invention provides an unmanned aerial vehicle flight control and data transmission integrated safety protection system, which comprises an unmanned aerial vehicle terminal and a ground terminal, and is characterized in that the unmanned aerial vehicle terminal comprises a safety flight control module used for controlling the flight of an unmanned aerial vehicle and executing a safety flight instruction; the multi-link encryption communication module is used for establishing encryption data transmission with a ground end through a plurality of communication links; and the environment sensing module is used for acquiring flight state, environment state and electromagnetic spectrum state data of the unmanned aerial vehicle. According to the invention, the dynamic trust evaluation model is constructed, and multi-dimensional state information such as flight control, data transmission and environmental perception is combined, so that the real-time evaluation of the system safety condition is realized, and passive protection is changed into active intelligent defense. Based on the same real-time trust value, key management, encryption algorithm switching and a flight control strategy are dynamically linked and regulated, so that each security unit in the system realizes cooperative protection, and the overall security of the unmanned aerial vehicle in a complex confrontation environment is improved.
Owner:CIVIL AVIATION FLIGHT UNIV OF CHINA +1

A method and system for secondary encryption in a full link tls encrypted channel

The application discloses a kind of secondary encryption in full-link TLS encryption channel, and the method specifically includes establishing TLS communication link;Using current system time generates first key, as AES-256-GCM algorithm key, after the data needing transmission is encrypted by AES-256-GCM algorithm and the key, second ciphertext is obtained after using custom algorithm secondary encryption;Send to receiving party, after receiving second ciphertext, custom algorithm decryption;Using current system time generates second key, using AES-256-GCM algorithm and second key as key to decrypt first plaintext, if decryption is not successful, change the time of generating second key to regenerate second key decryption, if decryption is not successful, discard second ciphertext and prompt error.The application realizes dynamic key, decryption fault tolerance, improves security, does not need unified management key, as long as keeping time relatively consistent, time difference can be dynamically controlled.
Owner:SHENZHEN XIYUE ZHIHUI DATA CO LTD

Automatic key rolling for link encryption

Automatic key rolling for link encryption is described. In accordance with the described techniques, data packets are encrypted at a first endpoint of a communication link using a first data encryption key. The encrypted data packets are communicated over the communication link to a second endpoint. A key rolling event that is known by both the first endpoint and the second endpoint is detected at the first endpoint. Responsive to detecting the key rolling event, the first data encryption key is rolled to a second data encryption key for encrypting data packets communicated over the communication link. In one or more implementations, the second endpoint is also configured to roll from the first data encryption key to the second data encryption key responsive to the key rolling event in order to decrypt data packets encrypted with the second data encryption key which are received from the first endpoint.
Owner:ADVANCED MICRO DEVICES INC

Webpage address link sharing method and device, computer equipment and storage medium

The invention relates to the technical field of data security, and discloses a webpage address link sharing method and device, computer equipment and a storage medium in the fields of financial science and technology and medical health. The method comprises the following steps: acquiring a link sharing request sent by an initiator, and determining a to-be-shared address link, sharing request time and a receiver according to the link sharing request; determining a link version parameter according to historical sharing information of the to-be-shared address link; determining an object identification parameter according to the to-be-shared address link, determining a target time key according to the sharing request time, and performing encryption processing on the object identification parameter and the target time key according to a preset symmetric encryption rule to obtain a link encryption parameter; and determining a basic path parameter according to the to-be-shared address link, determining a target sharing link according to the basic path parameter, the link version parameter and the link encryption parameter, and sending the target sharing link to a receiver. According to the invention, the dynamic sharing of the webpage address link is realized, and the availability and security of link sharing are ensured.
Owner:CHINA PING AN PROPERTY INSURANCE CO LTD

Audit data full-link encryption traceability cooperative tracking method and system

PendingCN122660958ANode clusteringOriginal data
The application discloses an audit data full-link encryption traceability cooperative tracking method and system, relates to the technical field of auditing, and collects audit full-process multi-source heterogeneous data and builds an audit process knowledge graph to extract a benchmark knowledge correlation path; a bidirectional index field of a graph atlas identifier and a block chain storage address is built, a distributed block chain network node cluster is deployed, audit business disturbance information is used to correct node real resource load, and an encryption traceability cooperative scheduling strategy is generated; audit original data is processed according to the cooperative scheduling strategy, and the processed original data is stored on a chain and solidified; when a traceability query instruction is received, real circulation records stored in the block chain are called, the benchmark knowledge correlation path is corrected with actual data on the chain, real and complete full-link data is generated, and full-process traceability verification is completed without decryption.
Owner:ZHEJIANG NORMAL UNIV

Layered encryption storage method for hot and cold data of Internet of Vehicles with post-quantum security

The invention relates to the technologies of Internet of Vehicles, block chains, consensus algorithms and the like, discloses an Internet of Vehicles cold and hot data hierarchical encryption storage method with post-quantum security, and relates to the technical field of Internet of Vehicles data security and post-quantum cryptography. According to the method, full-link encryption of cold and hot data is realized through cooperation of a Kyber-512 key encapsulation mechanism and AES symmetric encryption, on-chain evidence storage and identity authentication are completed in combination with an ML-DSA-44 signature algorithm, hot data are stored by adopting a local cache, and cold data are stored by adopting IPFS distributed storage and a block chain. According to the method, the problems of insufficient quantum attack resistance, low storage efficiency, complicated key management and the like in the traditional Internet of Vehicles storage are solved, unification of data confidentiality, integrity and traceability is realized, and vehicle-mounted resource constraint characteristics are adapted.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Method and system for mysql proxy full-link encryption connection based on national secret algorithm

The application discloses a MySQL proxy full-link encryption connection method and system based on a national secret algorithm, belongs to the technical field of databases, and aims to solve the technical problem of how to ensure full-link data encryption from a MySQL client initiating a query request to a server returning a response to the client based on the national secret algorithm. The MySQL client encrypts data in a request based on an SSL certificate and a client private key, and sends the encrypted request to a MySQL proxy server; the MySQL proxy server encrypts the decrypted data based on an SSL certificate and a server private key, and sends the re-encrypted data as a request to a MySQL server; the MySQL server sends encrypted response data to the MySQL client; and the MySQL proxy server encrypts the response data based on an SSL certificate and a server private key, and sends the encrypted response data to the MySQL client.
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

Terminal protection system and method for domain name hijacking prevention

The invention provides a terminal protection system and method for domain name hijacking prevention. The terminal protection system for domain name hijacking prevention comprises a domain name security evaluation module configured to perform static feature analysis and dynamic behavior analysis on a domain name to obtain a domain name risk score; the environment perception control module is configured to dynamically adjust a protection strategy based on the network security situation and the user behavior; the multi-layer DNS verification module is configured to dynamically adjust DNS verification strategies of a local verification layer, a network verification layer and a cloud verification layer based on a protection strategy and a domain name risk score, and the local verification layer has a security DNS caching function, a host file monitoring function and a network configuration monitoring function; the full-link encryption communication module is configured to construct encryption protection from an application layer to a transmission layer according to a protection strategy; and the offline security guarantee module is configured to guarantee the security of the terminal in the offline mode.
Owner:E-SURFING DIGITAL LIFE TECH CO LTD

A large-scale model corpus data interaction system, interaction method, terminal, and media based on a trusted execution environment.

This invention discloses a large-scale model corpus data interaction system, interaction method, terminal, and medium based on a trusted execution environment. The system includes: a data provider, a data requester, and a trusted data space service platform. The data provider encrypts the corpus data and preprocesses, catalogs, and packages the corpus data in its connector to obtain data capsules. The data requester submits computation tasks in its connector and, after authorization, obtains the corpus data from the data capsules for computation. The trusted data space service platform stores the encrypted corpus data, controls access for data users, schedules computation tasks, manages keys, and generates audit logs. This invention, through hardware isolation and end-to-end encryption within the trusted execution environment, ensures that the corpus data exists only in plaintext form within the trusted execution environment throughout its entire lifecycle, from access to destruction, preventing unauthorized access and leakage.
Owner:SHENZHEN CONFIDENTIAL COMPUTING TECH CO LTD

A chaining encryption method, apparatus, device and storage medium

The application relates to the fields of computer technology and digital medicine, and discloses a link encryption method, device and equipment and a storage medium, the method comprising the following steps: obtaining a to-be-encrypted link comprising an inner layer link and an outer layer link; reading an inner layer link parameter from the inner layer link and performing encryption processing to obtain an encrypted string; filling the encrypted string to the inner layer link to obtain an encrypted inner layer link; reading an outer layer link parameter from the outer layer link and performing encoding processing on the outer layer link parameter and the encrypted inner layer link according to the same encoding rule to obtain an encoded outer layer parameter and an encoded inner layer link, and filling the encoded outer layer parameter and the encoded inner layer link to the outer layer link to obtain a target encrypted link. The method solves the problem of poor link encryption effect in the prior art, effectively improves the compatibility, complexity and uniqueness of link encryption by combining encryption, encoding and filling, eliminates the decryption risk when the link is intercepted, effectively improves the security of link transmission, and has the characteristics of high security and strong applicability.
Owner:KANG JIAN INFORMATION TECH (SHENZHEN) CO LTD

Safe communication authentication method for electric energy meter

The invention discloses a secure communication authentication method for an electric energy meter, and aims to solve the problems that only link encryption is carried out in a multi-level network from an electric meter to a collector to a master station, the collector is visible and changeable, and packets are easy to lose in small-frame fragmentation. According to the method, the entity proof token and the mixed public key are packaged and bound in a hard manner, the key tree is constructed from the object level to the fragment level, the Merkel fragment commitment is used for generating the fragment level initialization parameter and the authentication related data, and the authentication encryption algorithm with the synthesis initialization vector characteristic is used for encryption and integrity protection. And meanwhile, a trusted execution environment monotonic counter is used for preventing rollback, and a system type forward error correction enhancement recovery capability is introduced, so that the technical effects of real end-to-end authentication and encryption, fragment-level insertion modification prevention, rearrangement prevention, truncation prevention, whole message consistency verification and adaptation to out-of-order and packet loss scenes are realized.
Owner:LIYANG HUAPENG ELECTRIC POWER METER

An Access Control-Based Unmanned Aerial Vehicle (UAV) Communication Link Encryption System

This invention discloses an access control-based encryption system for UAV communication links, comprising: a link establishment request module for initiating a communication link establishment request; an identity authentication module for performing identity authentication; an access decision module for performing pre-access authorization assessment using an improved UCON+ model; a key authorization module for outputting session key authorization credentials and session key materials to establish the communication link; a link encryption module for performing control operations based on the session key authorization credentials and performing encryption and integrity protection; a status verification module for collecting link status and environmental status and generating obligation execution evidence; a continuous control module for performing continuous authorization assessment during use; and a post-use audit module for performing post-use processing. This invention employs access control-driven link encryption to achieve encryption of UAV communication links.
Owner:BEIJING XIONGFENG TECHNOLOGY CO LTD

Water Conservancy Integrated Database Multi-Source Sensing Automatic Construction System

This invention relates to the field of water resources data technology, specifically disclosing an automatic multi-source sensing construction system for integrated water resources databases. This system includes a multi-source sensing feature calculation module, a data link encryption and encapsulation module, a self-evolving heterogeneous topology reconstruction center module, a spatiotemporal semantic holographic fusion engine module, and a blockchain trust anchoring mechanism module. The invention calculates environmental fluctuation entropy and dynamically solves for the optimal sampling frequency using a logistic function. Based on the principle of electrochemical corrosion, it uses an exponential decay model to adjust the sensor calibration cycle according to real-time soil salinity, achieving adaptive adjustment of the sampling frequency to accurately capture transient features. It also provides automatic compensation for sensor drift in highly corrosive environments, significantly improving the spatiotemporal accuracy and reliability of long-term monitoring data. This overcomes the shortcomings of existing technologies that lack dynamic calibration compensation mechanisms in highly corrosive environments, leading to severe sensor zero-point drift, distortion of long-term monitoring data, and thus misleading decision-making.
Owner:INNER MONGOLIA AGRICULTURAL UNIVERSITY

Post-quantum cryptography security networking and data protection device for space-based orbit data center

ActiveCN122001581AMake up for the shortcomings of insufficient trust foundation in distributionSecurity balance against quantum attacksKey distribution for secure communicationRadio transmissionPathPingKey (cryptography)
The invention provides a space-based orbit data center post quantum cryptography security networking and data protection device, and belongs to the technical field of spatial information networks and information security. The device comprises a heterogeneous key fusion management module used for receiving and storing a QKD key and generating a PQC key pair, and generating a session key through a key fusion algorithm; the integrated post quantum cryptography security gateway module is used for acquiring a session key to execute network access authentication and link encryption; a situation awareness unit of the dynamic networking strategy engine module collects a link state and a threat signal, and a strategy decision unit is internally provided with a deep reinforcement learning model to output an optimal networking path and a password suite; the on-satellite data quantum security protection module is used for on-satellite data encryption and trusted execution environment isolation; and the inter-satellite block chain module is used for constructing a block chain network to realize strategy distributed collaboration. According to the method, the QKD and PQC technologies are fused, and dynamic strategy adjustment and satellite data full-life-cycle protection are achieved.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

Multi-mode fusion communication intelligent terminal and communication method thereof

The invention discloses a multi-mode fusion communication intelligent terminal and a communication method thereof, and relates to the technical field of multi-mode communication, the multi-mode fusion communication intelligent terminal comprises a dynamic adjustment module which senses an environment state parameter and an equipment state parameter, and dynamically tunes an antenna parameter based on the environment state parameter and the equipment state parameter; the determination module determines a supportable communication mode of the terminal according to the tuned antenna parameters, and determines wide-narrow band communication configuration parameters in the supportable communication mode; the encryption module sets a double-link voice encryption task weight according to the wide-narrow band communication configuration parameters and encrypts a terminal voice frame according to the double-link voice encryption task weight through a double-link encryption strategy; and the power module determines intelligent power supply parameters according to the current communication mode of the terminal and supplies power to the terminal according to the intelligent power supply parameters. The communication mode can be intelligently adjusted through external conditions, so that the adaptability of the communication mode and antenna parameters and the communication stability are ensured, and the communication efficiency and stability are improved.
Owner:SHENZHEN TINFULL TECH CO LTD

Vehicle cloud collaboration method and device and related products

The invention discloses a vehicle cloud cooperation method and device, and a related product. And establishing an encryption tunnel between the vehicle side and the cloud side, and before each service call, performing session key negotiation between the cloud side and the vehicle side through the encryption tunnel to obtain a session key corresponding to a single service call request. And a dynamic negotiation mode is adopted to limit the validity period of the key as single call, so that the risk of long-term key leakage is avoided. And after the service calling request is encrypted by using the session key, request issuing between the cloud end and the vehicle end is carried out through the encryption tunnel, so that the service calling request is executed after the vehicle end decrypts the service calling request by using the session key, and the packaged vehicle function is called. Two-layer encryption of a transmission layer and a service layer is constructed, the outer layer establishes vehicle cloud link encryption based on an encryption tunnel to guarantee transmission security, and the inner layer performs end-to-end encryption on a service request at a service calling level based on a session key. The two layers of encryption mechanisms are mutually independent, deep defense is achieved, and high-safety guarantee is provided for vehicle-cloud cooperation.
Owner:SAIC MOTOR

Method, device and system for reading embedded electronic tag

The invention provides a method, a device and a system for reading an embedded electronic tag, and relates to the technical field of embedded electronic tags, the method comprises the following steps: receiving tag initial signals, screening invalid signals with signal intensity lower than-80dBm, and optimizing reading frequency by using an adaptive frequency adjustment algorithm; and the deep signal analysis is realized by combining AES-128 and RSA-2048 multi-layer encryption, JSON format conversion and CRC-32 verification. The device comprises a signal receiving module, a preliminary screening module, a frequency adjusting module and a deep analysis module, the system is composed of an electronic tag, a reading device and a service processing system, and a TLS1.3 encryption protocol is adopted for data transmission. Compared with the prior art, the method is low in bit error rate, high in reading success rate and short in data processing time in a complex electromagnetic environment, realizes safe and efficient reading and business value mining of label data through full-link encryption and intelligent data analysis, is suitable for logistics storage, intelligent manufacturing, medical asset tracking and other scenes, and has wide application prospects. And the intellectualization and the reliability of the Internet of Things system are obviously improved.
Owner:SHANGHAI ZIYU PRINTING CO LTD

A link encryption device, system and method with self-load cascading hot standby function

This invention discloses a link encryption device, system, and method with self-loaded cascaded hot standby functionality, relating to the field of network security technology. The device, based on conventional optical communication service interfaces, integrates a physical routing switching module and cascaded redundant interfaces. The physical routing switching module monitors the device status and, when the device is functioning normally, directs service traffic to its local encryption module for encryption before direct output. In the event of a power outage or failure, it automatically switches the physical link, redirecting traffic from the service interfaces to the cascaded redundant interfaces. Through this invention, the primary device acts as a traffic-driving node at the physical media layer in a faulty state, transparently transmitting external traffic to the backup device for encryption, and then transmitting the processed traffic back through the primary device. This invention eliminates the dependence on external load balancers and complex network configurations in dual-machine hot standby networking, achieving high availability under single-node physical access and reducing network construction costs and complexity.
Owner:BEIJING GUOLING TECH CO LTD

A ste encoding construction method based on proportion philosophy origin and national security encryption system

PendingCN122293406ATimestampAlgorithm
This invention discloses a STE (Spectrum-Tensor-Encoding) encoding construction method and a national security encryption system based on the fundamental principles of proportionality, solving the problems of fixed encryption keys, reproducible encoding, single security levels, and poor chip and AI scenario adaptability in traditional encryption. The technical solution uses the fundamental principles of proportionality as its underlying axiom, defining the golden ratio coefficient α and the fundamental reference P₀ to generate a hierarchical set of fundamental ratio parameters. It combines a unique user identifier with hash operations to generate uncopyable STE encoding primitives, which are then recursively concatenated and checked against CRC to construct multi-level STE encoding. A timestamp and the fundamental ratio are introduced to generate a 128-bit dynamic key, achieving a three-dimensional binding of encoding, key, and time. This invention extends a dedicated encryption instruction set at the chip level and implements weighted encryption and trusted verification of the inference link at the AI ​​large-scale model level. It possesses fundamental uniqueness, dynamic anti-cracking capabilities, hardware-level acceleration, and full-link AI encryption capabilities, supporting national-level information security, vehicle networking, government communications, and large-scale model security deployment. Its security strength and operational efficiency are significantly superior to traditional symmetric / asymmetric encryption systems.
Owner:ZHUHAI GONGZHENG TECHNOLOGY CO LTD

Asynchronous federated learning distributed gradient coordination system and method based on Apache Kafka

The invention relates to the technical field of distributed machine learning, in particular to an Apache Kafka-based asynchronous federated learning distributed gradient coordination system and method, which adopts a three-layer distributed architecture and comprises a participant node, a Kafka coordination cluster and a global aggregation layer, the system realizes dynamic time window control, a priority partitioning strategy, a double-link encryption mechanism and an edge collaborative architecture by deeply integrating the flow processing capability and federated learning requirements of Apache Kafka; the method has the beneficial effects that a decentralized asynchronous communication mode is adopted, the cross-mechanism cooperative training efficiency is remarkably improved, flexible access and exit of participants are supported, and the single-point fault risk of a centralized architecture is thoroughly avoided.
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

Building fire operation and maintenance data asset management platform based on star flash and national secret

The application provides a building fire-fighting operation and maintenance data asset management platform based on star flash and national secret, comprising: a star flash access gateway, used for connecting with an existing building fire-fighting system, realizing analysis and conversion of heterogeneous fire-fighting protocols and fire-fighting data collection; a star flash self-organizing network communication module, used for establishing a low-delay and high-concurrency star flash wireless self-organizing network; a full-link encryption module, used for performing end-to-end encryption and decryption, integrity hash calculation and digital signature verification on fire-fighting sensing data and control instructions; a device digital identity and storage module, used for generating a digital identity for each fire-fighting device, and hashing and storing key data of the fire-fighting device in a whole life cycle to form a tamper-proof trusted audit chain; and a data asset operation module, used for performing three rights distribution and right confirmation on fire-fighting operation and maintenance data based on dynamic contribution of the fire-fighting device, generating a standardized digital asset certificate, and completing income distribution among multiple subjects based on a smart contract.
Owner:JINGTAI QINGYUAN ENVIRONMENTAL TECH (XIAN) CO LTD

Data reporting full-link encryption system, method and device

The present disclosure belongs to the technical field of nuclear power and specifically relates to a data reporting full-link encryption system, method and device. The present disclosure adopts a link process of ciphertext transmission, realizing high security of data transmission. In the whole data flow process, all data are transmitted in the form of ciphertext, effectively preventing sensitive data from being leaked in the transmission process. The ciphertext data and the key are not stored in the same area, fundamentally reducing the risk of data being cracked caused by key leakage. By separately storing the key and the data, the security protection capability of the overall system is improved. Each piece of sensitive data is independently set with a unique key, ensuring that even if a key is leaked, the security of other data will not be affected. This design enables each piece of data to have an independent protection mechanism in the encryption process, enhancing the flexibility and security of data management.
Owner:CHINA NAT NUCLEAR POWER CO LTD +1

Link-layer communication encryption method and system

The present disclosure relates to a link-layer communication encryption method and system, wherein for communication between service terminals and service systems, a terminal-side link encryption gateway and a service-side link encryption gateway are designed, and on the basis of device authentication, identity authentication and session key agreement are integrally designed and used, thereby implementing security authentication, and also obtaining a session key of an application between the terminal-side link encryption gateway and the service-side link encryption gateway, that is, a lightweight security authentication mechanism is implemented, and a dynamic session key is generated for each accessed service terminal, thereby enhancing the security of data communication and transmission. In the design solution, the communication data of the service terminals at a link layer is encrypted, thereby ensuring that intranet information is concealed, and protecting intranet service systems and devices from attacks; moreover, no real IP and MAC is configured for each gateway, thereby ensuring that a malicious user cannot perform targeted attacks on the gateway.
Owner:XINLIAN TECH (NANJING) CO LTD +1