Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

2737 results about "Protocol for Carrying Authentication for Network Access" patented technology

PANA (Protocol for Carrying Authentication for Network Access) is an IP-based protocol that allows a device to authenticate itself with a network to be granted access. PANA will not define any new authentication protocol, key distribution, key agreement or key derivation protocols. For these purposes, the Extensible Authentication Protocol (EAP) will be used, and PANA will carry the EAP payload. PANA allows dynamic service provider selection, supports various authentication methods, is suitable for roaming users, and is independent from the link layer mechanisms.

Analyzable anti-attack network security method and system based on AI unified model

The invention provides an analyzable anti-attack network security method and system based on an AI unified model. The method comprises the following steps: S1, carrying out attack source tracing and attack mode identification on an input data stream; s2, performing protocol structure analysis and grammar element extraction on the input data stream in a grammar verification layer, and starting a grammar rule matching process to obtain a grammar exception perception set; s3, fusing attack vector information on the basis of a grammar anomaly perception set in a semantic analysis layer, constructing a semantic relation graph, and outputting a semantic risk vector; s4, taking the semantic risk vector as input, combining a business scene, resource constraint and strategy preference, modeling a defense target, and outputting an optimal response path; and S5, forming a model evolution path based on local feedback and global collaboration. Through a three-layer full-information analysis mechanism and behavior feedback driving, interpretable recognition of attack intentions and collaborative optimization of defense paths are realized, attack recognition is comprehensive, response decision is accurate, and strategy evolution is controllable.
Owner:SHENZHEN CESTBON TECH CO

AI dynamic secure transmission system based on SASE framework

The invention relates to the technical field of integration of artificial intelligence security and network security, and discloses an AI dynamic security transmission system based on an SASE framework, which realizes security access control based on AI dynamic identity verification through an SASE integration access module, acquires and predicts network performance change in real time by using a network state sensing module, and transmits the network performance change to a network server. Equipment, environment and data content are subjected to multi-dimensional analysis by means of a security risk assessment module, a quantitative risk score is generated, and a transmission protocol, parameters and encryption strength are dynamically adjusted according to a network state and the risk score by means of a dynamic transmission optimization module and a self-adaptive encryption module; the problem that safety protection and transmission efficiency are difficult to cooperate in a traditional architecture is effectively solved, low-delay and high-reliability data transmission service can be provided for AI application in a complex network environment, meanwhile, self-adaptive dynamic protection of the whole data transmission process is achieved, and data safety is comprehensively guaranteed.
Owner:BEIJING XINDA WANGAN INFORMATION TECH CO LTD

Financial data privacy protection system based on block chain security multi-party computing

The invention discloses a financial data privacy protection system based on block chain security multi-party computing, and belongs to the technical field of data protection, and the system specifically comprises the steps that a data preprocessing module segments original financial data, and adds a unique watermark identifier; the distributed account book stores the Hash abstract and watermark mapping relation of the encrypted logic data fragment, and the digital signature and the timestamp are fused to ensure reliability; the computing node cluster receives data through a special interface, dynamically builds a computing group according to a service rule and outputs an encrypted computing result; bidirectional authentication is carried out on the zero-knowledge proof verifier and the computing node cluster to verify the data holding right; the encryption proxy gateway processes an output result of the computing node cluster to complete format conversion and ciphertext superposition; the cross-link routing module constructs a virtual coverage layer, cross-link transmission of encryption results is achieved through protocol conversion and three-way handshake verification, and a heterogeneous chain protocol converter and a verification assembly guarantee transmission safety; the financial data privacy security is comprehensively guaranteed, and the data processing efficiency and reliability are improved.
Owner:王蓓蓓

Trusted management and control network platform construction method and device, electronic equipment and storage medium

The invention belongs to the field of network security, and relates to a trusted management and control network platform construction method and device, electronic equipment and a storage medium, the method comprises the following steps: constructing a basic security architecture and a trusted base, the basic security architecture being used for providing a unified root of trust and a management core for collaborative operation of upper security components; based on the basic security architecture and the trusted base, implementing multi-dimensional trusted verification and dynamic access control; an intelligent boundary protection and depth detection system is deployed and is used for constructing an intelligent, three-dimensional and self-adaptive security defense line at the boundary of each region of the network, and various known and unknown threats can be identified and blocked; constructing a unified secure communication tunnel and a cross-domain transmission guarantee; defining and realizing a standardized security function interface and a collaboration protocol; and a continuous trust evaluation and automatic operation management and control closed loop is established. The overall security is enhanced, the secure transmission of data is ensured, the compatibility and collaboration of the system are improved, and the security operation intelligence is realized.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Computer network data secure transmission system and method

The invention discloses a computer network data secure transmission system and method, and particularly relates to the technical field of network data secure transmission, and the system comprises a dynamic key management module which generates a key seed through a quantum random number generator, generates a dynamic key bound with a data packet in combination with a timestamp, and transmits the dynamic key to a server; after being encrypted by a receiving end public key, the data are transmitted through an independent verification channel; the dual-path transmission control module is used for establishing dual channels of a main path and a shadow path, a data packet of the main path is embedded into a random camouflage protocol header to simulate a non-sensitive protocol, and a blank data packet is filled in the shadow path to maintain traffic characteristics; according to the real-time verification engine, a receiving end constructs an encrypted hash tree to achieve fragment-level integrity verification, and meanwhile, requests key state three-state verification from the key management module. Through key dynamic generation and separation transmission, dual-path adaptive fragmentation distribution, fragmentation hash tree reconstruction and key linkage verification, and abnormal triggering fragmentation level retransmission, the problems of long-term effectiveness of a static key, predictable transmission path and verification lag are solved.
Owner:陈俊奕

Automatic protocol adaptation method for real-time access system of multi-source equipment

The invention relates to an automatic protocol adaptation method for a real-time access system of multi-source equipment. The data acquisition layer receives original protocol data sent by equipment and transmits the original protocol data to the protocol adaptation layer. And the protocol metadata analysis module extracts, analyzes, compares and matches the data, and automatically identifies the protocol type of the equipment. The rule engine converts original protocol data into a system unified internal data format according to a conversion rule and then transmits the original protocol data to the data processing layer, and after cleaning, integration, analysis and other operations are carried out, the original protocol data are transmitted to the application interface layer to be called by an upper-layer application system. And when new protocol equipment is accessed, the hot plug function allows the system to dynamically load the new protocol adapter module in a state of not stopping running. According to the method, automatic adaptation of a new protocol is achieved through rapid deployment of the containerized micro-service architecture in combination with newly added protocol rules and metadata of the protocol management module, the whole process does not need to compile and publish the system again, and efficient and stable operation of the multi-source equipment real-time access system is guaranteed.
Owner:JIANGSU JARI GROUP CO LTD

Power Internet of Things equipment access registration method and system in multi-protocol environment

The invention discloses a method and a system for accessing and registering power Internet of Things equipment in a multi-protocol environment. The method comprises an original communication protocol identification step, a communication data semantic identification step, a target communication protocol conversion step and a device registration step. According to the invention, protocol identification, dynamic protocol conversion and equipment unique ID registration are carried out on equipment accessed to the electric power Internet of Things for the first time, intelligent identification and semantic level conversion of heterogeneous protocols are realized, incremental learning of unknown protocols is supported, real-time communication between equipment and a platform and between equipment is supported, and the real-time communication between equipment and platform is realized. And the compatibility and the adaptive capability of the electric power Internet of Things system are improved.
Owner:GUANGDONG POWER GRID CO LTD +1

Control method of multi-protocol switching anti-quantum security gateway

The invention relates to a control method for a multi-protocol switching anti-quantum security gateway, and the method comprises the steps: carrying out the safety self-inspection of a hardware environment after the security gateway is powered on, generating a unique root key of equipment based on a physical unclonable function, continuously collecting and analyzing the network traffic characteristics, and carrying out the self-inspection of the hardware environment. Based on a machine learning model, a quantum attack mode is identified and an encryption algorithm mode is dynamically decided, protocol analysis is carried out on a communication data packet, dynamic conversion and adaptation are carried out between a traditional protocol and an anti-quantum cryptography protocol according to an instruction and a preset rule, and an anti-quantum cryptography engine is called to carry out encryption or signature operation. And dynamically deriving and managing a session key in a complete period based on a root key, switching an algorithm mode, a communication protocol and a key in a linkage manner according to a quantum attack detection result, and starting anti-side channel attack protection and hardware security response. According to the method, active protection of the security gateway on quantum attacks, multi-protocol seamless compatibility and full-life-cycle security management of keys are realized.
Owner:WEIDE GUANGDONG INFORMATION TECH CO LTD

Encrypted traffic detection method based on multi-dimensional feature parallel fusion

The invention relates to an encrypted traffic detection method based on multi-dimensional feature parallel fusion, and belongs to the technical field of network security. According to the method, when a multi-dimensional feature parallel fusion framework is constructed, the limitation of traditional statistical features on dynamic evolution characterization of encryption behaviors and the dependency of graph neural network topology modeling on computing resources are fully considered; through collaborative optimization of a Markov chain dynamic quantization protocol interaction state transition rule and a lightweight graph attention hierarchical compression mechanism, a detection model gives consideration to deep feature perception capability and efficient reasoning capability at the same time; based on the classification decision realized by the fusion mechanism, the recognition robustness and real-time defense efficiency of the encrypted malicious traffic are remarkably improved, and the active security protection level of the network is effectively enhanced.
Owner:ZHENGZHOU UNIV

Distributed node unified identity authentication method and system based on QUIC protocol

The invention relates to a QUIC protocol-based distributed node unified identity authentication method and system, belongs to the technical field of network security, is applied to a client, and comprises the following steps: registering a client domain name identity through a certificate authority, obtaining a client certificate, and pre-storing a server certificate chain; generating a QUIC initial data packet according to the target server domain name identifier and the client certificate, and sending the QUIC initial data packet to the server; receiving a QUIC handshake data packet returned by the server; verifying the legality of the server certificate based on the server certificate chain, and if the server certificate is legal, calculating a pre-master key according to the client DH private key and the server DH public key; deriving a 1-RTT session key based on the pre-master key; generating a signature verification message, and sending the client certificate and the signature verification message to a server; and synchronously using the 1-RTT session key to encrypt the application layer data with the server, and transmitting the data to the server in the 1-RTT encryption space of the QUIC protocol. According to the invention, the reliability of node identities and the confidentiality of data are ensured.
Owner:BEIJING LIUJINSUIYUE TECH CO LTD

Property registration core data security protection method based on block chain technology

The invention relates to the technical field of data integrity protection, in particular to a property right registration core data security protection method based on a block chain technology, which comprises the following steps: acquiring an anchor point on an identity data generation chain, verifying a historical block to construct a topological structure, and matching a permission mapping field write-in path. And verifying the node permission and generating a data integrity verification report. According to the method, identity anchoring data is generated by binding a registrant identity credential with an address on a chain, structured identity mapping is realized, historical blocks form a logic closed loop through pointer and serial number verification, the integrity of data circulation is enhanced, a field access boundary is established by matching a field set with a node identifier through an authority level, and the accuracy of access control is enhanced. Field contents are written into nodes according to an addressing protocol and a distributed path index is generated, the flexibility and addressability of data positioning are improved, a verification link is fused with a certificate and an authority label to match and screen credible nodes, and integrated verification of path compliance and access security is realized.
Owner:MINXUN TECHNOLOGY (HAINAN) GROUP CO LTD +2

Network security monitoring method and system based on distributed nodes

The invention provides a network security monitoring method and system based on distributed nodes, and the method comprises the steps: obtaining an inter-node interaction record of each node in a distributed network in a preset communication period and the identification information in a protocol interaction process, and obtaining a node communication data set; the method comprises the following steps: constructing a multi-dimensional phase space reconstruction matrix containing communication time sequence association features and protocol identifier association features, carrying out nonlinear dynamic feature analysis on the matrix, extracting a chaotic feature value set of node communication behaviors, constructing a topological association structure of node communication features through a local linear relationship, mapping the set to a topological space of a preset dimension, and constructing a topological structure of the node communication behaviors. And generating an attack mode topology expression vector, and finally analyzing an abnormal state propagation process in the distributed network through an inter-node energy propagation rule based on the attack mode topology expression vector to obtain a network security detection result. According to the invention, the accuracy and dynamic analysis capability of distributed network security monitoring can be effectively improved.
Owner:贵州华谊联盛科技有限公司 +1

Contextual orchestration and scoped memory protocol with decentralized memory wallet for adaptive artificial intelligence systems

The embodiments disclose a cryptographically governed system for contextual memory management in artificial intelligence including a Contextual Orchestration and Scoped Memory Protocol (COSMP) and a Decentralized Memory Wallet (DMW), which enforce secure, auditable, and policy-driven access to AI memory. Traditional token-based memory tracking is replaced by memory capsules secure data units with embedded access policies and tamper-evident logs 5400 organized via a distributed ledger. Access control is managed through decentralized identifiers (DIDs) and private cryptographic keys, ensuring that all memory interactions are signed, verifiable transactions. This architecture establishes a universal trust layer for AI, enabling post-hoc compliance checks and privacy-preserving audits. Applicable across domains such as national security, healthcare, and autonomous systems, the invention enforces rigorous behavioral constraints and access governance within AI memory and decision-making processes.
Owner:LEWIS SADEIL JAMES +1

Communication authentication method and system of train on-board network, storage medium and equipment

The invention provides a communication authentication method and system for a train-mounted network, a storage medium and equipment, and the method only completes the key negotiation operation in the process of executing the communication authentication of the train-mounted network, enables the subsequent communication process to be executed based on a session key obtained through the negotiation of a first verification party and a second verification party, and improves the communication authentication efficiency. According to the method and the device, identity information of two communication parties is mutually verified, only a request carrying identity information of a verification party needs to be sent once in a primary communication process, only a session key generated by negotiation needs to be carried in a subsequent communication process, lightweight processing is performed on a communication authentication protocol, and the communication authentication protocol can be obtained by introducing a pairing-free password system based on an identity label. According to the method, a complex pairing process does not need to be executed, the number of calling times of Hash is reduced, the protocol calculation overhead is reduced, the communication efficiency is improved on the basis of ensuring the credible access authentication of a train-mounted network and the credible transmission of a control message, and the influence on the real-time performance of a train network monitoring management system is avoided.
Owner:NAT HIGH SPEED TRAIN QINGDAO TECH INNOVATION CENT

Financial data processing method and system based on machine learning and storage medium

The invention discloses a financial data processing method and system based on machine learning, and a storage medium. The method comprises the following steps: encrypting customer credit data of a financial institution through Paillier homomorphic encryption and extracting a risk feature vector; performing secret sharing segmentation on the local gradient parameters and then safely aggregating the local gradient parameters into global gradient parameters through a BGW protocol; on the basis of the privacy level, global gradient parameter differential privacy noise is injected and subjected to federal training to obtain a cross-institution credit evaluation result; calculating risk characteristics and evaluation results through homomorphic encryption to obtain an encrypted credit score, and performing secure multi-party calculation and decryption to generate a customer credit report; and block chain supervision compliance verification is carried out to generate an audit record, and a privacy budget optimization scheme is dynamically adjusted according to the business emergency degree. The technical problems that in an existing financial data processing method, information is incomplete due to data islands, data leakage risks are caused by insufficient privacy protection mechanisms, and an effective supervision compliance verification mechanism is lacked are solved.
Owner:ICBC SANMENXIA BRANCH

System and Method for Direct, Structured, and Versioned Data Storage and Retrieval on a Blockchain Network

The present embodiment discloses a novel process and system for storing versioned data on the Bitcoin blockchain network. This process involves generating derived public keys linked to specific versions and data parts using a key tweaking method, and storing each data part on the blockchain using its associated derived public key. Information about versions and parts are stored in root transactions. An API is provided for managing the stored data, with options for encryption, checksums, data anchoring, timestamping, segmentation, and digital signatures. AIDIOS, a data protocol designed for direct storage and retrieval on the Bitcoin blockchain, is also included. This system allows for significant amounts of data to be stored directly on the blockchain.
Owner:DATAFAIR INC

Communication module low-delay switching control method based on HPLC and HRF

The invention provides a communication module low-delay switching control method based on HPLC and HRF, and relates to the technical field of data processing, and the method comprises the following steps: when an index continuously exceeds a dynamically adjusted judgment threshold, a switching judgment unit generates a mode switching enable signal, and initializes an HRF channel pre-synchronization sequence; based on a pre-stored HRF channel feature vector table, HRF channel negotiation and authentication handshake processes are executed in parallel while HPLC link state monitoring is maintained; through a dual-channel redundancy transmission mechanism, the key fault information is packaged into a final priority protocol data unit before the establishment of the HRF link is not completed, and redundancy forwarding is carried out through a reserved time slot window of the HPLC link; and after the handshake of the HRF link is completed, the switching control unit executes seamless switching of the data transmission channel. According to the invention, the accuracy of channel state judgment is improved.
Owner:SHANDONG ZHIYANG ELECTRIC

Mimicry encryption method and system for communication data transmission

The invention relates to the technical field of communication data security, and discloses a mimicry encryption method and system for communication data transmission. The method comprises the following steps: synchronizing a high-precision timestamp through an NTP protocol and generating a standardized environment parameter; temperature, voltage and signal strength indexes are extracted based on the environmental parameters, entropy hybrid calculation and dynamic splicing coding are carried out, and a dynamic encryption key is generated; performing multi-layer mimicry permutation and diffusion confusion on plaintext data after the plaintext data is partitioned by using the key to generate a final ciphertext; performing protocol encapsulation and transmission optimization on the ciphertext; and the receiving end realizes decryption through de-encapsulation and inverse mimicry transformation, and dynamically adjusts the key in combination with environmental parameter feedback. According to the method, key dynamics is enhanced through environment randomness, multi-layer encryption and integrity verification are combined, the anti-attack ability and safety of data transmission are remarkably improved, and the method is suitable for communication scenes with high real-time performance requirements.
Owner:CHONGQING DACHENG ZHIXIN TECH DEV CO LTD

Government affair data dynamic authorization management method based on secure multi-party computing

The invention discloses a government affair data dynamic authorization management method based on secure multi-party computing, and relates to the field of government affair data security authorization management, and the method comprises the steps: distributing a unique identity identifier for each participant, generating an asymmetric key pair through employing a national secret SM2 algorithm, registering a public key and mechanism attribute information to an alliance chain smart contract, and generating an identity certificate package; and based on attribute information in the identity credential packet, the participants cooperatively generate anti-quantum dynamic attribute-based encryption key fragments through a secure multi-party computing protocol, and the anti-quantum dynamic attribute-based encryption key fragments are distributed to the participants by adopting a threshold secret sharing technology. Threshold decryption and token verification are achieved through an alliance chain verification intelligent contract, an authorization record is generated, an access control strategy of an edge computing node is configured according to the authorization record, an oblivious transmission protocol is adopted to respond to data query, and an audit node monitors an access log, dynamically adjusts attribute weight parameters and synchronizes the attribute weight parameters to a key fragment.
Owner:CHINA NAT INST OF STANDARDIZATION

Safety transmission system based on multimedia short message

The invention discloses a secure transmission system based on a multimedia short message, and relates to the technical field of communication and network security, and the system comprises a protocol stack security reinforcement module which carries out the hierarchical reconstruction of an MMS protocol stack, comprises a preprocessing layer, is used for intercepting and filtering illegal characters, and verifies the legality of a message structure through a finite-state machine; the analysis layer is used for pre-judging memory requirements based on message types and lengths by adopting a dynamic memory allocation strategy; the execution layer is integrated with a null pointer checking mechanism, and the validity of a pointer is forcibly verified before a protocol stack calls a function; the encryption and signature module is used for carrying out end-to-end encryption on a message body and metadata by adopting a hybrid encryption algorithm and carrying out message integrity verification through a lightweight hash tree; and the vulnerability real-time monitoring module is embedded into an abnormal behavior detection model based on machine learning and is used for dynamically identifying memory occupation abnormity and illegal instruction calling high-risk operation when the protocol stack runs.
Owner:BEIJING XUNYIN TECH CO LTD

Automated rule-based smart contract approval via blockchain cybersecurity authentication services

In one embodiment, a method includes accessing transaction data associated with a protected first function of a first blockchain transaction protocol by a cybersecurity authentication service of a blockchain cybersecurity platform, accessing a transaction protocol runbook comprising preconfigured conditions associated with the protected first function, determining that the protected first function is eligible to be analyzed by an automated decisional logic module based on the transaction protocol runbook, determining each preconfigured condition is satisfied based on the transaction data by the automated decisional logic module, generating an authentication object for the protected first function, generating signed transaction data based on the accessed transaction data and a private encryption key, wherein the signed transaction data is configured to update a second blockchain transaction protocol to indicate that the protected first function is authenticated, and transmitting a transaction bundle comprising the accessed transaction data and the signed transaction data.
Owner:HALBORN INC

Communication encryption method and device, equipment, storage medium and computer program product

The invention relates to the technical field of communication security, in particular to a communication encryption method and device, equipment, a storage medium and a computer program product. The method comprises the following steps: dynamically generating a main session key between two communication parties based on a preset key negotiation protocol; dynamically generating sub-keys according to a preset time interval based on the main session key and the key sequence; performing encryption processing on each data block in the communication data stream based on the sub-key and the encryption strategy; generating a message authentication code for each encrypted data block; adding timestamp information based on the message authentication code, and introducing a random offset into the timestamp information; and the encrypted data blocks, the message authentication code and the timestamp information are packaged into the target data message, so that the transmission security of the communication data is improved.
Owner:SHENZHEN DINSTAR TECH

Decentralized multi-agent information interaction method and system

PendingCN121173831ABiological modelsTransmissionContract Net ProtocolHybrid protocol
The invention discloses a decentralized multi-agent information interaction method and system, and the method comprises the steps: generating a subtask carrying a unique identifier and metadata based on mixed dimension task decomposition, and embedding a global utility function; sub-task-agent mapping is dynamically adjusted through Kafka and Flink, and a utility function weight coefficient is broadcasted; the sub-agent determines an executor through contract network protocol bidding, and performs execution permission arbitration on key resources in combination with a token bucket algorithm; metadata are transmitted by adopting a Gossip protocol, and intermediate data are transmitted by P2P direct connection (abnormal degradation to Kafka); key metadata are synchronized through lightweight Raft consensus, and non-key metadata are merged by adopting CRDT; and after a final result is written in through Kafka, duplicate removal, sorting and aggregation are carried out through Flink, and key states are synchronized through Gossip. According to the method, the problem of message disorder under a hybrid protocol is solved; and high-reliability message transmission and state synchronization are realized by combining the strong consistency bottom of Kafka and the conflict resolution of lightweight Raft and CRDT.
Owner:LANZHOU UNIV

Network attack cross-platform collaborative protection processing method and device

The invention discloses a network attack cross-platform collaborative protection processing method and device, and relates to the technical field of network security. The method comprises the following steps: each heterogeneous security device captures security log data in real time, converts the security log data into an uplink protocol message containing security event semantic description, and sends the uplink protocol message to a central server; analyzing and reasoning the uplink protocol message through a built-in large language model to construct an attack chain of a network attack behavior, generating a downlink protocol message containing an action intention based on the attack chain and a preset disposal strategy library, and sending the downlink protocol message to the target heterogeneous security device; and the target heterogeneous security equipment converts the downlink protocol message into an operation instruction which can be executed by the target heterogeneous security equipment through a built-in translation engine. According to the method, different types of safety equipment logs and instructions are converted into unified semantic information which can be understood by a machine in the interaction process, and real-time association, intention recognition and automatic two-way cooperation of safety events are achieved.
Owner:BEIJING CHAITIN TECH CO LTD

WebSocket-based instant message task assigning system

The invention discloses a WebSocket-based instant message task assigning system. The system comprises two parts, i.e., a server and clients, wherein the server is deployed on an application server and configured with ports for providing external services, and the server is then started; the clients comprises an APP client and a PC client; and information data transmission among the server, the APP client and the PC client is achieved based on the WebSocket protocol, that is, the server provides the instant messaging service, and the clients achieve acquisition of data from the server. Compared with the prior art, the system provided by the invention has the advantages that WebSocket-based instant message task assigning is achieved, and information can be synchronized between the information acquisition clients, so that high timeliness, effectiveness and safety of the information are ensured.
Owner:合肥市智享亿云信息科技有限公司

Systems, methods, and protocols for zero knowledge proof user authentication

Systems and methods for performing zero knowledge proofs to prove a user's possession of secret data and / or biometric data without exposing such data. The methods can include receiving a certificate signing request and biometric data associated with a user; creating a stable key based at least in part on the biometric data; creating a private key based at least in part on the stable key; transmitting the private key to the user device for local storage thereon; creating a public key based at least in part on the private key; and forwarding the certificate signing request to an issuer.
Owner:T STAMP INC

Data encryption method for multilevel key stream control in industrial gateway

The invention discloses a data encryption method for multilevel key stream control in an industrial gateway, and particularly relates to the technical field of data encryption and network security. The method comprises the steps of obtaining a session identification code and communication context information; generating a first-level basic key based on the session identification code, and generating a multi-level key stream control matrix in combination with communication context information and a multi-source dynamic random factor; according to the hierarchical relationship of the matrix, key stream sequences of corresponding levels are distributed to data packets of different priorities, and the key stream sequences are switched or combined in real time according to data packet types, transmission paths and security policies in the encryption process, and time fragmentation processing and disturbance coding are executed; the encrypted data packet is sent through a multi-protocol forwarding module of the industrial gateway, and the receiving end carries out decryption by using the key stream control matrix; according to the invention, dynamic generation, hierarchical calling and safe switching of the key stream can be realized, and the data confidentiality, integrity and anti-attack capability of the industrial gateway in a complex network environment are remarkably improved.
Owner:NORTHWESTERN POLYTECHNICAL UNIV

Machine learning-based protocol knowledge base construction method, apparatus and device, and medium

The present application relates to the technical field of network security, and specifically relates to a machine learning-based protocol knowledge base construction method, apparatus and device, and a medium. The method comprises: acquiring network environment traffic data, and inputting the network environment traffic data into a traffic detection machine learning model for parsing processing to obtain protocol parsing data corresponding to the network environment traffic data; performing protocol comparison on the protocol parsing data and a protocol knowledge base to screen for an unknown protocol in the network environment traffic data; and performing protocol parsing on the unknown protocol using the traffic detection machine learning model, extracting unknown protocol features, naming the unknown protocol on the basis of the unknown protocol features, and storing the named unknown protocol into the protocol knowledge base to construct a new protocol knowledge base. According to the method, an unknown protocol is discovered reversely, so that a protocol knowledge base is expanded, thereby improving the security and reliability of network communication.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD

Network protocol intelligent extraction method based on large language model and application

The invention relates to a network protocol intelligent extraction method and application based on a large language model, and the method comprises the steps: taking a network protocol specification text as an analysis object, and initializing each candidate prompt word; a large language model is constructed, scoring consideration of three indexes including accuracy, format compliance and coverage rate under network protocol specification text extraction application is achieved according to the candidate cue words, cue word variants under a preset cue word variant mechanism are matched under loop iteration, all target cue words are obtained in an optimized mode, and then the target cue words are obtained on the basis of all the target cue words; analysis and extraction of chart description are deepened, efficient and accurate acquisition of a target network protocol text about a protocol message format and a protocol interaction process is achieved by applying a large language model, and compared with a traditional method, the design scheme has obvious advantages in the aspects of accuracy, generalization ability, information utilization, complex protocol processing and the like. And a more efficient and reliable way is provided for extraction of protocol specifications.
Owner:信联科技(南京)有限公司 +1

Switch security protocol interaction method, device and equipment and storage medium

The invention provides a switch security protocol interaction method and device, equipment and a storage medium, and the method comprises the steps: carrying out the protocol type recognition of a received network data frame, and generating first intermediate data according to the recognized protocol type; according to the protocol type identifier of the first intermediate data, converting the format of the network data frame through a protocol mapping rule to generate second intermediate data; determining a security processing strategy corresponding to a preset strategy rule set according to the strategy identification field of the second intermediate data; reconstructing the original content of the second intermediate data into a target data frame conforming to a target protocol format according to a security processing strategy; and according to the security level field and the communication direction of the target data frame, performing path screening through the trusted path list, and determining a target interaction path. According to the scheme, the trusted interaction path can be dynamically screened based on the protocol type and the security level field of the target data frame, and controllable data transmission between switches under security protocol cooperation is realized.
Owner:SHENZHEN SCODENO TECH CO LTD