Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

1712 results about "Protocol for Carrying Authentication for Network Access" patented technology

PANA (Protocol for Carrying Authentication for Network Access) is an IP-based protocol that allows a device to authenticate itself with a network to be granted access. PANA will not define any new authentication protocol, key distribution, key agreement or key derivation protocols. For these purposes, the Extensible Authentication Protocol (EAP) will be used, and PANA will carry the EAP payload. PANA allows dynamic service provider selection, supports various authentication methods, is suitable for roaming users, and is independent from the link layer mechanisms.

Control method of multi-protocol switching anti-quantum security gateway

The invention relates to a control method for a multi-protocol switching anti-quantum security gateway, and the method comprises the steps: carrying out the safety self-inspection of a hardware environment after the security gateway is powered on, generating a unique root key of equipment based on a physical unclonable function, continuously collecting and analyzing the network traffic characteristics, and carrying out the self-inspection of the hardware environment. Based on a machine learning model, a quantum attack mode is identified and an encryption algorithm mode is dynamically decided, protocol analysis is carried out on a communication data packet, dynamic conversion and adaptation are carried out between a traditional protocol and an anti-quantum cryptography protocol according to an instruction and a preset rule, and an anti-quantum cryptography engine is called to carry out encryption or signature operation. And dynamically deriving and managing a session key in a complete period based on a root key, switching an algorithm mode, a communication protocol and a key in a linkage manner according to a quantum attack detection result, and starting anti-side channel attack protection and hardware security response. According to the method, active protection of the security gateway on quantum attacks, multi-protocol seamless compatibility and full-life-cycle security management of keys are realized.
Owner:WEIDE GUANGDONG INFORMATION TECH CO LTD

Network security monitoring method and system based on distributed nodes

The invention provides a network security monitoring method and system based on distributed nodes, and the method comprises the steps: obtaining an inter-node interaction record of each node in a distributed network in a preset communication period and the identification information in a protocol interaction process, and obtaining a node communication data set; the method comprises the following steps: constructing a multi-dimensional phase space reconstruction matrix containing communication time sequence association features and protocol identifier association features, carrying out nonlinear dynamic feature analysis on the matrix, extracting a chaotic feature value set of node communication behaviors, constructing a topological association structure of node communication features through a local linear relationship, mapping the set to a topological space of a preset dimension, and constructing a topological structure of the node communication behaviors. And generating an attack mode topology expression vector, and finally analyzing an abnormal state propagation process in the distributed network through an inter-node energy propagation rule based on the attack mode topology expression vector to obtain a network security detection result. According to the invention, the accuracy and dynamic analysis capability of distributed network security monitoring can be effectively improved.
Owner:贵州华谊联盛科技有限公司 +1

System and Method for Direct, Structured, and Versioned Data Storage and Retrieval on a Blockchain Network

The present embodiment discloses a novel process and system for storing versioned data on the Bitcoin blockchain network. This process involves generating derived public keys linked to specific versions and data parts using a key tweaking method, and storing each data part on the blockchain using its associated derived public key. Information about versions and parts are stored in root transactions. An API is provided for managing the stored data, with options for encryption, checksums, data anchoring, timestamping, segmentation, and digital signatures. AIDIOS, a data protocol designed for direct storage and retrieval on the Bitcoin blockchain, is also included. This system allows for significant amounts of data to be stored directly on the blockchain.
Owner:DATAFAIR INC

WebSocket-based instant message task assigning system

The invention discloses a WebSocket-based instant message task assigning system. The system comprises two parts, i.e., a server and clients, wherein the server is deployed on an application server and configured with ports for providing external services, and the server is then started; the clients comprises an APP client and a PC client; and information data transmission among the server, the APP client and the PC client is achieved based on the WebSocket protocol, that is, the server provides the instant messaging service, and the clients achieve acquisition of data from the server. Compared with the prior art, the system provided by the invention has the advantages that WebSocket-based instant message task assigning is achieved, and information can be synchronized between the information acquisition clients, so that high timeliness, effectiveness and safety of the information are ensured.
Owner:合肥市智享亿云信息科技有限公司

Systems, methods, and protocols for zero knowledge proof user authentication

Systems and methods for performing zero knowledge proofs to prove a user's possession of secret data and / or biometric data without exposing such data. The methods can include receiving a certificate signing request and biometric data associated with a user; creating a stable key based at least in part on the biometric data; creating a private key based at least in part on the stable key; transmitting the private key to the user device for local storage thereon; creating a public key based at least in part on the private key; and forwarding the certificate signing request to an issuer.
Owner:T STAMP INC

Data encryption transmission method and system based on national cryptographic algorithm

The invention discloses a national secret algorithm data encryption transmission method and system. The method comprises the steps of obtaining to-be-encrypted data and network parameters, establishing a Bayesian network probability ablation model, performing Monte Carlo sampling ablation national secret encryption and evaluating attack risks, and generating a probability security encryption strategy; and extracting a Brinell feature set, constructing a long and short-term memory network time prediction model, and optimizing by using a simulated annealing algorithm to obtain an optimal encryption parameter configuration sequence. Generating a key pair according to the sequence and SM2, establishing a shared key by means of an elliptic curve Diffie-Hellman protocol, deriving an SM4 session key through SM3, and establishing a hybrid encryption key system; constructing a teacher and student network model, optimizing multi-thread scheduling through adversarial distillation training and a retrieval enhancement technology, and generating a multi-thread parallel encryption architecture; and network parameters are monitored in real time, a reinforcement learning adaptive decision engine is constructed, a strategy is dynamically adjusted, and adaptive encryption transmission is completed. According to the invention, the optimal balance between the security and the efficiency in the data encryption transmission process is realized.
Owner:GUIZHOU BLUESKY INNOVATIVE SCI & TECH CO LTD

Network encryption attack detection method based on deep learning

The invention discloses a network encryption attack detection method based on deep learning. The method comprises the following steps: acquiring encrypted network traffic to generate a target communication channel; constructing a micro-perturbation excitation set, and generating a micro-perturbation excitation record; acquiring response indexes of each protocol layer, and generating a cross-layer disturbance response time sequence; constructing a cross-protocol-layer associated disturbance trajectory diagram; calculating a cross-layer coupling matrix and a disturbance response topology fingerprint, sending the cross-protocol-layer associated disturbance trajectory diagram and the cross-layer coupling matrix into a cross-layer topology constraint Neural ODE for numerical integration evolution, and generating a disturbance response continuous time hidden state trajectory; and calculating an encryption attack risk score, and generating an encryption attack detection result. According to the method, active perturbation and cross-layer topology constraint Neural ODE modeling are adopted, encryption channel dynamic fingerprint extraction is realized, and the method has high-precision, high-sensitivity and strong-interpretation attack detection capability.
Owner:BEIJING ZHONGKUANG ZHIWANG TECHNOLOGY CO LTD

Instant messaging driving type automatic service processing method and system based on large language model and model context protocol (MCP)

PendingCN121334094ASecuring communicationLinguistic modelWebhook
The invention provides an instant messaging driving type automatic service processing method and system based on a large language model and a model context protocol (MCP), and relates to the technical field of computers, and the method comprises the following steps: a user sends a message in a group of an instant messaging platform and makes a group robot to form a Webhook event; the MCP client exposes an HTTP (Hyper Text Transport Protocol) interface to receive a Webhook event, completes authentication and analyzes a message; the MCP client sends the message to a large language model, ACL permission judgment is carried out, and an MCPServer method and parameters to be called are recognized; if the permission is judged to be'unauthorized ', stopping, and then submitting permission errors to a big language model organization and description and directly executing and returning'insufficient permission'; if the permission is judged to be'authorization ', the next step is carried out; and the MCP client calls the MCP server (through HTTP + SSE or stdio) to obtain a structured result. According to the method, the unstructured chat instruction is stably converted into the standardized MCP request, and coupling of dialect type APIs of all back-end systems is eliminated.
Owner:SHENZHEN SKIEER INFORMATION TECH CO LTD

SM2 collaborative signature, encryption and decryption system and method fusing anti-quantum characteristics

The invention discloses an SM2 collaborative signature and encryption and decryption system and method fusing anti-quantum characteristics, and relates to the field of cryptography and information security. According to the method, an anti-quantum cryptographic algorithm and a national cryptographic SM2 cooperative computing framework are deeply integrated, and a key security system is constructed: SM2 sub-private keys, anti-quantum key pairs and public keys are acquired and generated through an anti-quantum algorithm software and hardware enhancement module, and the private keys are encrypted and stored and are regularly alternated; on the basis of anti-quantum collaborative signature, encryption and decryption modules, an anti-quantum verification mechanism is embedded, and data is transmitted in combination with a national secret TLCP protocol, so that signature, encryption and decryption operations are completed; the equipment integration and dynamic security control unit monitors a security state, calculates a threat index to generate a protection strategy, and dynamically switches a security mode, so that the problems of insufficient security, vulnerability to attacks and data tampering of a traditional SM2 algorithm under the threat of quantum computing are effectively solved; and the long-term anti-attack capability and the operation reliability of the equipment in a high-security demand scene are remarkably improved.
Owner:ZHEJIANG ICINFO TECH

Multi-level Internet of Things equipment security management and access control method

The invention belongs to the technical field of Internet of Things security, and particularly relates to a multi-level Internet of Things equipment security management and access control method, which comprises the following steps of: performing bidirectional verification on a digital certificate and a hardware fingerprint through an edge node when equipment is accessed; calculating credibility in real time and dynamically dividing security levels by using a hybrid evaluation algorithm based on equipment operation context data; a fine-grained access strategy is generated in combination with equipment attributes and environmental risks, and cross-level collaboration is realized through a lightweight protocol; abnormal behaviors are detected in real time in the access process, and high-risk operation is blocked within milliseconds; and strategy conflict resolution and adaptive optimization are realized through formalized verification and deep reinforcement learning. According to the technical scheme, the identity authentication reliability, the authority dynamic adaptability, the strategy consistency and the threat response speed of the Internet of Things equipment are remarkably improved, and a systematic security guarantee is provided for large-scale Internet of Things applications with high security requirements.
Owner:XIANNING YUCHUANG TECHNOLOGY CO LTD

Internal and external network audio and video secure transmission method and system based on cloud platform

The invention relates to the technical field of audio and video transmission, in particular to an internal and external network audio and video secure transmission method and system based on a cloud platform. By combining the load balancing technology with the real-time load state and the audio and video stream characteristics of the cloud platform, the encrypted traffic can be dynamically distributed to a plurality of back-end servers, and the calculation overhead in the encryption process can be effectively reduced through selection of the lightweight asymmetric encryption algorithm and the optimized key exchange process; in a handshake stage, by optimizing a key negotiation process and adjusting a key exchange process according to segmentation characteristics, the execution efficiency of a protocol is further improved, and by dynamically adjusting the execution opportunity of encryption operation, it is ensured that the encryption operation is executed at a proper opportunity, and the encryption efficiency is improved. By monitoring and adjusting the load distribution strategy and the encryption parameters in real time, the system operation mode can be dynamically adjusted according to the distortion degree and the transmission state of the audio and video streams, and the distortion degree of the audio and video streams is effectively reduced.
Owner:HANGZHOU XUNCHUAN TECHNOLOGY CO LTD

Phase coding-based third-party quantum-free multi-party privacy set intersection method and application

The invention discloses a phase coding-based non-third-party quantum multi-party privacy set intersection method and application, and belongs to the technical field of quantum privacy calculation. An existing quantum private set intersection scheme mostly aims at a two-party scene or depends on a third party to realize confidential intersection, and potential safety hazards are easily caused by constructing a trusted third party in practical application. In order to solve the problem, the invention provides a quantum intersection protocol for multiple participants, and the protocol effectively realizes intersection calculation of private sets of the participants through a quantum state phase encoding technology. And meanwhile, comprehensive correctness and security analysis is performed on the protocol, and the feasibility and security of the protocol are verified through a Qiskit simulation protocol core process. The method not only can efficiently solve the problem of intersection of multi-party private sets and obtain public elements on the premise of protecting the privacy of each party, but also can be used as a basic module in a multi-party cooperative computing application scene, and is wide in application range.
Owner:HEILONGJIANG UNIV

Multi-protocol integration method and device, equipment, storage medium and program product

The invention relates to a multi-protocol integration method and device, equipment, a storage medium and a program product, which are applied to a bastion host, and the bastion host comprises a communication port. The method comprises the following steps: firstly, receiving a first access request generated based on a first protocol and sent by each client through a communication port, then, determining target equipment needing to be accessed by each client according to the first access request, then, determining a second protocol supported by each target equipment based on preset configuration of each target equipment, and finally, sending the second protocol to the client through the communication port. And converting each first access request based on the first protocol and the second protocol, determining a second access request of each client, and accessing the corresponding target device through the second access request. By adopting the method, the number of communication ports can be reduced, so that the network attack surface is reduced, potential security holes and threats are reduced, and the access security of the target equipment is improved.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Electric power multi-protocol data conversion method and system based on object model dynamic mapping

The invention discloses an electric power multi-protocol data conversion method and system based on object model dynamic mapping, and the method comprises the steps: receiving an original protocol message, recognizing a protocol type, extracting a logic name as a unique identifier of equipment, extracting an object identifier as a measurement point identifier, and extracting an electric energy array as a measurement point value; according to the protocol type and the equipment unique identifier, matching a corresponding object model template from a unified object model library; mapping the equipment unique identifier, the measuring point identifier, the measuring point numerical value and the acquisition timestamp obtained by analysis to corresponding fields in a template; and generating an object model data object conforming to a standard format, packaging the object into a message, executing an encryption authentication mechanism of a network layer and a transmission layer through the power Internet of Things security access gateway, and sending the message to an Internet of Things management platform. According to the invention, standardized, automatic and secure access of different protocol terminals is realized through protocol analysis and the unified object model library.
Owner:STATE GRID INFO TELECOM GREAT POWER SCI & TECH

Secure access control method and device of MCP protocol, storage medium and program product

The invention relates to the field of artificial intelligence, and discloses a security access control method and device of an MCP protocol, a storage medium and a program product. The method comprises the following steps: in a tool registration stage, performing digital signature on tool metadata registered in an MCP server, and signing and issuing an access token containing a client identity attribute to complete bidirectional identity authentication of a client and an external tool; a tool calling request initiated by the MCP client is acquired and intercepted, context information of the request is collected, the context information comprises at least one of a main body attribute, a resource attribute, an operation attribute and an environment attribute, and the tool calling request carries an access token; the context information is submitted to a strategy decision point, dynamic evaluation is carried out based on a preset attribute-based access control strategy rule, an authorization decision is generated, and the authorization decision comprises permission and rejection; and executing releasing or blocking operation on the tool calling request according to the authorization decision.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

Cross-platform fusion access method, system and device of equipment and electronic equipment

The invention provides a cross-platform fusion access method, system and device of equipment and electronic equipment, the method is applied to the technical field of Internet of Things, and the method comprises the following steps: a mobile terminal performs security authentication on target central control equipment; the mobile terminal sends a structured configuration file including the equipment information of the plurality of smart home equipment, the region division rule, the scene mode and the linkage rule to the target central control equipment; the target central control equipment receives and analyzes the structured configuration file, and updates the corresponding smart home equipment according to an analysis result; the target central control equipment receives a control instruction of the cloud platform, converts the control instruction into an internal protocol instruction and then issues the internal protocol instruction so as to control the corresponding smart home equipment to execute operation; the target central control device synchronizes the state information of the smart home device to the cloud platform; and when an upgrading instruction of the cloud platform is received, issuing an upgrading task to execute an upgrading process. According to the method, the real-time performance of remote control of the smart home equipment and the accuracy of state feedback are guaranteed.
Owner:XIAMEN LEELEN TECH CO LTD

Proxy-based secure model context protocol server access for artificial intelligence agents

A gateway securely executes model context protocol (“MCP”) processes for artificial intelligence (“AI”) agents by creating nano sandboxes in which the MCP processes execute. A server-sent events (“SSE”) bridge identifies a request to initialize an SSE channel with an MCP server, the request being sent from an MCP client that generates MCP-compliant commands in association with an AI agent. The SSE bridge instantiates a nano sandbox based on a definition extracted from the request, creating a custom and dynamic isolated execution environment. An MCP process is launched within the nano sandbox. The SSE bridge returns a session identifier, and receives a command and the session identifier. The SSE bridge authorizes the command and response by applying security rules, blocking either for non-compliance.
Owner:AIRIA LLC

Intelligent agent high-speed bus implementation method and system based on FPGA and dynamic smoothing technology

ActiveCN121585742ASecuring communicationCommunications securityLightweight protocol
The invention relates to the technical field of data communication, and discloses an intelligent agent high-speed bus implementation method and system based on an FPGA and a dynamic smoothing technology. The method comprises the following steps: constructing a single handshake message through a lightweight protocol, adjusting network indexes by adopting an exponential smoothing method, constructing a pipeline processing unit in an FPGA card by utilizing a VHDL, realizing key updating and encryption processing, constructing a three-layer adaptive structure connection subsystem, and optimizing algorithm parameters and resource allocation according to a running state. And a high-performance bus communication system is formed. On the premise of ensuring the communication security and reliability, the network transmission delay is remarkably reduced, and the data throughput is improved, so that the communication system can meet the requirements of emergency linkage and large data volume transmission in a scene (such as a rail transit station-level system) with a high real-time requirement.
Owner:SHANGHAI HOLLEYSOFT SYST

Certificateless post-quantum TLS handshake method based on KEM and IBE

The invention discloses a certificateless post-quantum TLS handshake method based on a KEM and an IBE. According to the method, the IBE public key is adopted to encrypt the temporary KEM public key, the key negotiation function and the identity authentication function are integrated in the single calculation operation, the protocol interaction structure is simplified, and certificateless two-way implicit authentication and forward security key negotiation are achieved. In a two-way identity authentication scene, the client can send the application data only by one round-trip delay, so that the connection establishment efficiency is effectively improved. By adopting the method disclosed by the invention, the attack of a quantum computer can be resisted, and the technical defects of the traditional and existing post-quantum TLS protocol in the aspects of quantum security resistance, communication overhead and handshake delay are overcome.
Owner:HANGZHOU POLYTECHNIC

Lightweight low-delay quantum key distribution method and system adaptive to electric power scene

The invention discloses a lightweight low-delay quantum key distribution method and system adaptive to an electric power scene, and belongs to the technical field of quantum communication and electric power communication crossing. The method comprises the steps cooperatively executed by a sending end and a receiving end: the sending end determines a basis vector based on a pre-associated quantum fingerprint sequence and a timestamp, sends a key through polarization-phase two-dimensional coding, generates a selection mark and executes privacy amplification; and a receiving end synchronizes a timestamp to determine a basis vector, compares the basis vector with the quantum fingerprint to complete authentication, decodes through an integrated module, performs collaborative error correction and executes privacy amplification. The system comprises functional modules of a sending end and a receiving end, is integrated on a miniaturized board card, and supports common-fiber transmission and protocol conversion. According to the method, the problems of high time delay, high deployment cost and poor adaptability of the traditional QKD are solved, the end-to-end time delay is reduced to 14 microseconds, the deployment cost is reduced by more than 60%, the requirements of high safety, low time delay and lightweight deployment of a power system are met, and the method is suitable for key services such as power dispatching and relay protection.
Owner:CHINA ELECTRIC POWER RESEARCH INSTITUTE CO LTD

System, method, device and equipment for safe communication between charging pile and BMS and storage medium

The invention relates to the field of electric vehicle charging control, and particularly provides a system, method, device and equipment for safe communication between a charging pile and a BMS and a storage medium, the system comprises a bidirectional authentication module, a communication encryption module, a verification module and an optimization module; the bidirectional authentication module is used for constructing a bidirectional authentication protocol between the charging pile and a battery management system (BMS) based on the hardware security module and authenticating the identity; the communication encryption module is used for customizing an integrated transport layer security protocol line through an open source tool and encrypting security communication data; the verification module is used for designing a three-level verification mechanism, blocking a malicious firmware injection path and verifying a secure communication process; and the optimization module is used for optimizing the key process by adopting a redundant backup scheme deployed in a containerization manner. Through the system, the effect of a safe communication process between the charging pile and the BMS can be realized.
Owner:CHINA FAW CO LTD

Encrypted domain name resolution protocol simulation and representation system

The invention discloses an encrypted domain name resolution protocol simulation and characterization system, and relates to the technical field of network security and network traffic analysis. The invention aims to simulate an encrypted domain name resolution process in a real network environment, collect the flow of the process and extract features to construct a data set, and ensure the quality of the generated data set through data enhancement and a data set evaluation scheme. The system comprises a traffic simulation module, a traffic representation module, a data enhancement module and a data set evaluation module. The flow simulation and characterization module simulates and encrypts domain name resolution flow and extracts a structured feature vector containing 34 side channel features; and the data enhancement and data set evaluation module is used for enhancing a feature set based on a conditional table generative adversarial network CTGAN so as to construct a feature data set which is closer to traffic in a real network environment, and ensuring that the constructed data set has engineering availability and theoretical rationality through evaluation. The system can be used for constructing a current scarce encrypted domain name resolution protocol side channel feature data set, and provides data support for related security detection and research.
Owner:HARBIN INST OF TECH

Secure communications implementing priority message queue management

PendingUS20260046259A1Securing communicationBus networksReal-time Control SystemStart time
The described techniques address issues related to compatibility and cost-effectiveness of in-vehicle networks. The described techniques may utilize security Ethernet-based protocols, for example, without the need to exchange separate key agreement messages and, consequently, meet the stringent starting time requirements for real-time control systems. Additionally, a membership tracking solution may be implemented in which each node within a membership group may request, or “challenge” other nodes with the same group to verify their online status, and this online status may be maintained over time. Finally, a transmission queue management process is described that deletes queued messages only when it is determined that every intended recipient node received the message, thereby providing atomicity. Retained queued messages may then be re-transmitted in accordance with a transmission schedule.
Owner:INFINEON TECHNOLOGIES AG

Multi-protocol dynamic adaptation and session management method based on TCP / IP

The invention discloses a multi-protocol dynamic adaptation and session management method based on TCP / IP (Transmission Control Protocol / Internet Protocol), and belongs to the technical field of computer network communication. Comprising the following steps: S1, receiving TCP / IP connection from a client, and identifying a specific application layer protocol type through a protocol feature code; s2, dynamically loading an adapter of a corresponding protocol based on the protocol type identified in the S1, decoding original data into a unified intermediate format, and realizing protocol-independent data processing; s3, on the basis of decoding in the S2, different protocols are connected and bound to the same session object based on the device identifier, and cross-protocol sharing of the authentication state and the context is achieved; and S4, monitoring a network quality index based on the session binding in the S3, and dynamically allocating a high-priority service to the optimal protocol channel. According to the method, the problems of poor multi-protocol compatibility, isolated session management, unreasonable network resource allocation and the like are solved, and the flexibility, the reliability and the resource utilization rate of the system are remarkably improved.
Owner:TIANJIN RICHSOFT ELECTRIC POWER INFORMATION TECH +1

API invoker authentication method and apparatus, communication device, and storage medium

A method for authenticating an application program interface (API) invoker enhances secure communication between API invokers and a Common Application Program Interface Framework (CAPIF). The method involves sending authentication information from the API invoker to the CAPIF function, which authenticates the invoker's identity. The process includes obtaining enrollment information to establish a secure transport layer security (TLS) connection with the CAPIF function. Advanced authentication mechanisms leverage an authentication and key management for applications (AKMA) anchor key, enabling secure derivation and verification of application function keys (KAF). Additionally, the CAPIF function uses received authentication data to retrieve API invoker configuration information, onboard signing keys, and certificates. These elements facilitate secure API access and interaction while ensuring compliance with authentication protocols.
Owner:BEIJING XIAOMI MOBILE SOFTWARE CO LTD

Zero-code protocol analysis and full-link visualization debugging and testing method for heterogeneous terminal

The invention relates to the technical field of software development, in particular to a zero-code protocol analysis and full-link visualization commissioning and testing method for a heterogeneous terminal, which comprises the following steps of: acquiring protocol configuration information of the heterogeneous terminal input by a user through a visual interface, analyzing communication parameters and message rules in the protocol configuration information, and performing full-link visualization commissioning and testing on the protocol configuration information. Constructing a standardized protocol model instance; and initializing a communication server according to the communication parameters in the protocol model instance, and establishing a one-to-one mapping binding relationship between the network monitoring port and the protocol model instance. According to the method, the data flow of a network monitoring port is monitored, the corresponding protocol model instance is called based on the protocol routing rule to execute bidirectional data automatic conversion and full-link adjustment and test, a transparent test channel which is running as configuration is constructed, and the black box operation defect that rule definition and effect verification are separated in the past is overcome; and fusion and integration of massive stock terminals to a unified service platform are realized.
Owner:GUANGZHOU TUOWEI DIGITAL TECHNOLOGY CO LTD

Identity authentication method and system based on national secret algorithm

The invention discloses an identity authentication method and system based on a national secret algorithm, and the method comprises the steps: building a hierarchical key management system based on a national secret IBE framework, generating a system master key pair through employing an SM2 algorithm, and achieving a decentralized key distribution mechanism; constructing a domain perception differential privacy protection module, defining a privacy budget allocation strategy according to the security level, and adding calibrated Laplace noise to the user identity feature vector; designing a distributed batch matrix multiplication protocol, and decomposing the distributed batch matrix multiplication protocol to a plurality of computing nodes for parallel processing through a secret sharing technology; a zero-knowledge proof verification mechanism is implemented, and identity verification is completed through a commitment scheme based on an SM3 hash algorithm; deploying a self-adaptive key updating strategy, and analyzing threat level change through a threat situation evaluation function; and establishing a secure communication channel based on SM4 symmetric encryption, and performing encryption processing by using the temporary session key. The security and expandability of the system are improved, the privacy of the user is effectively protected, and the system adapts to a dynamically changing network threat environment.
Owner:GUIZHOU BLUESKY INNOVATIVE SCI & TECH CO LTD

Cross-border data security detection method and device, equipment, storage medium and program product

The invention provides a safety detection method and device for cross-border data, equipment, a storage medium and a program product. The method comprises the following steps: acquiring transmission data of a cross-border network environment; performing cross-border data extraction processing on the transmission data to obtain cross-border session data; performing protocol analysis processing on the cross-border session data to obtain a protocol analysis result of the cross-border session data; performing dual-channel privacy data identification processing on the protocol analysis result to obtain a privacy data identification result; generating a security detection result according to the protocol analysis result and the privacy data identification result; performing data desensitization processing on the privacy data according to the security detection result to obtain desensitized privacy data; establishing a secure communication link according to the desensitized privacy data; and sending the desensitized privacy data to a preset compliance decision subsystem through the secure communication link to determine a compliance evaluation result of the desensitized privacy data. The accuracy of safety detection can be improved.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD +2

Property asset digital operation and intelligent security linkage cooperative processing system and implementation method

The invention discloses a property asset digital operation and intelligent security linkage cooperative processing system and an implementation method, and relates to the technical field of Internet of Things, and the system comprises a protocol adaptive gateway layer which solves the problem of compatibility of multi-manufacturer equipment, and outputs a standardized data stream based on a dynamic protocol sniffing and fingerprint feature library, SDK-free access control, fire protection, monitoring and IoT equipment; the method comprises the following steps: constructing a millimeter-level precision three-dimensional space model by a digital twinborn middle table layer, fusing a security event and operation data, and ensuring that the operation is compliant and audible through blood relationship tracking; the intelligent decision execution layer combines a rule engine and machine learning to generate a linkage instruction, drives a work order to be automatically distributed and positions an equipment fault responsible party; and the edge cooperative computing node locally realizes video millisecond-level analysis, and starts localized linkage according to an emergency plan when the network is disconnected, so as to ensure that the core security function is not interrupted.
Owner:BEIJING TIANRUI CHUANGXIN TECHNOLOGY CO LTD

A cryptographic flow-based security protocol for aerospace communication

A satellite receives, from a ground station, multiple first commands out-or-order for replicating a conflict-free replicated dataset at the satellite. An authority to access the conflict-free replicated dataset is retrievable from a block of a blockchain. The multiple first commands are reordered based on an ordering specified by a causal tree received from the ground station. A global state of the conflict-free replicated dataset is replicated locally at the satellite based on the multiple first commands reordered in accordance with the causal tree. From the ground station, multiple second commands are received for performing operations on the conflict-free replicated dataset. The operations are performed on the conflict-free replicated dataset, using the multiple second commands, based on the authority retrieved from the blockchain.
Owner:SPIDEROAK INC