Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

160 results about "Secure channel" patented technology

In cryptography, a secure channel is a way of transferring data that is resistant to overhearing and tampering. A confidential channel is a way of transferring data that is resistant to overhearing (i.e., reading the content), but not necessarily resistant to tampering. An authentic channel is a way of transferring data that is resistant to tampering but not necessarily resistant to overhearing.

Path planning and hierarchical cooperative control method and system for unmanned aerial vehicle cluster

The invention discloses a path planning and hierarchical cooperative control method and system for an unmanned aerial vehicle cluster. The system comprises a path planning module and a formation motion control module. The method comprises the steps that firstly, an improved RRT * algorithm is adopted by a path planning module, through a multi-strategy heuristic node expansion mechanism fusing target bias and artificial potential field guidance and comprehensively considering path length, channel volume and Z-axis height change, a center path and a three-dimensional safe channel which take into account safety and smoothness are planned for an unmanned aerial vehicle cluster; and then, based on the central path, the formation motion control module adopts a distributed model prediction control framework, designs different optimization targets for a navigator and a follower, and solves an optimal control instruction on line, so that a cluster is guided to complete trajectory tracking, collision avoidance among individuals and self-adaptive formation reconstruction in a secure channel. According to the invention, the navigation problem of the unmanned aerial vehicle cluster in a complex obstacle environment is solved, and the path planning efficiency and the robustness of cooperative control are improved.
Owner:NANJING UNIV OF SCI & TECH

Cross-industry data sharing method and system using trusted data space

The invention discloses a cross-industry data sharing method and system using a trusted data space, and relates to the technical field of data sharing, and the method comprises the steps: obtaining a cross-industry data dimension relation; obtaining a sharing request, and carrying out dimension migration analysis on the sharing request to obtain a dimension migration path set; according to the dimension migration path set, adaptive reorganization operation is executed on the to-be-shared data, and reorganized shared data is obtained; according to the cross-industry data dimension relationship and the dimension migration path set, performing cross-industry confidence evaluation on the recombined shared data to generate a shared decision result; and performing data sharing on the recombined shared data through a secure channel of the trusted data space. The technical problems that existing cross-industry data sharing is difficult, and data resources are wasted are solved.
Owner:LINGSHU TECH CO LTD

Student psychological assessment data sharing method and system based on block chain

The invention relates to the technical field of block chain data sharing, and discloses a student psychological assessment data sharing method and system based on a block chain. The method comprises the following steps: when a user logs in through a browser client, a system triggers a zero-knowledge proof generation process; and the client signs the timestamp and the random number by using a local false identity private key to form a zero-knowledge proof request packet, and submits the zero-knowledge proof request packet to the alliance chain node through a secure channel. And the node calls an identity verification contract to verify the signature, generates a session token containing a role type and a validity period after the signature passes, writes the token in an alliance chain account book in a hash manner and returns the token to the client. The client encrypts and stores the token, and a subsequent data request is carried through an HTTP header; and when it is detected that the token is expired or abnormal, the client automatically re-triggers the zero-knowledge proof process. The method depends on the block chain and zero knowledge proof technology, optimizes identity verification and session management, guarantees data sharing safety, compliance and stability, and is suitable for student psychological assessment data sharing among multiple subjects.
Owner:WUXI ZHENGZE INFORMATION CO LTD

Cloud instance privacy security enhancement method based on security channel dynamic measurement

The invention discloses a cloud instance privacy security enhancement method based on security channel dynamic measurement, and the method comprises the steps: building a secure and credible communication channel through a secure communication client, and connecting the communication channel to a local user side through the Internet; a local user side deploys a TPCM secure communication module which is responsible for secure communication with the multi-cloud service rental instance. And the trusted software base is responsible for maintaining a measurement strategy and performing measurement judgment and control when a user process runs in the cloud service lease instance. The system specifically comprises a judgment mechanism module, a control mechanism module, a measurement mechanism module and a credible reference library. On the premise that infrastructures of cloud service providers are not trusted, in order to achieve safety and credibility of user remote cloud service lease instance data and application during operation and privacy protection of users, a measurement agent and a safety communication client are deployed in a cloud service lease instance; meanwhile, the tenant can perform deep monitoring on the process in the cloud instance, and it is ensured that sensitive information such as a monitoring strategy and reference data is not exposed to a cloud service provider.
Owner:BEIJING UNIV OF TECH

Application certificate provisioning process using connected vehicle

An example operation includes one or more of establishing a secure channel between a host platform and a vehicle based on a transport layer security (TLS) handshake between the host platform and the vehicle, downloading an authorization code to the vehicle through the secure channel between the host platform and the vehicle, receiving the authorization code from a mobile application installed on a mobile device, generating a mobile application certificate for the mobile device and transmitting the mobile application certificate to the mobile application on the mobile device, and establishing a secure connection between the host platform and the mobile application on the mobile device based on the mobile application certificate.
Owner:TOYOTA MOTOR NORTH AMERICA INC +1

OTA upgrading method based on dynamic security and credibility verification and related equipment

The invention relates to the technical field of vehicles, in particular to an OTA upgrading method and related equipment based on dynamic security and credibility verification, and the method comprises the steps: a cloud end obtains an original upgrading package, dynamically fragments the original upgrading package, and outputs an upgrading file; a secure channel is established between the vehicle end and the cloud end, and the upgrade file is downloaded through the secure channel and temporarily stored; the vehicle end triggers TEE intervention, credibility verification is carried out on the upgrade file, and after verification is passed, fragmented data is decrypted and recombined into a complete upgrade package; installing the recombined upgrade package to a vehicle end, and triggering a rollback process based on backup mirror image hash verification when the installation fails; according to the invention, the safety and reliability of vehicle OTA upgrading can be improved.
Owner:CHINA FAW CO LTD

Safe closed-loop circulation and physical output control method and system for ultra-large raster image

The invention discloses a secure closed-loop circulation and physical output control method and system for an oversized raster image. The method comprises the following steps: a client adaptively calculates fragmentation granularity according to a network state, fragments an image and encrypts and transmits the image; the server performs secondary encryption and distributed storage on the received data; the preview end constructs a multi-resolution hierarchy based on a viewport mapping technology, only extracts visual slices and superposes watermarks, and transmits the visual slices and the watermarks to a client memory for zero-cache rendering; and the printing end constructs a secure channel bound with a hardware fingerprint, carries out streaming decryption on the data, embeds traceability information, and injects a printing drive in real time. According to the method, the problems of unstable GB-level image transmission and unsmooth preview are solved, and high-efficiency circulation and strict protection of design assets are realized through full-process data non-landing streaming control.
Owner:XINJIANG UNIVERSITY

Ship loading method based on multi-intelligent optimization algorithm

The invention provides a ship loading method based on a multi-intelligent optimization algorithm, and relates to the technical field of shipping loading optimization, and the method comprises the following steps: S1, stowage request receiving and data preprocessing: receiving a stowage request and carrying out data processing on ship parameters, cargo information and loading rules; s2, deck virtual area division and functional area mapping: dynamically dividing a deck into a plurality of functional sub-areas according to loading rules and cargo attributes; s3, region-level multi-algorithm collaborative loading: for each sub-region, dynamically matching based on region characteristics and cooperatively executing at least two different types of intelligent optimization algorithms to carry out cargo loading; s4, performing global scheme verification and dynamic fine adjustment, including summarizing loading schemes of each sub-region, and performing global weight balance and security channel connectivity verification; and S5, outputting and visualizing a loading result. According to the method, multiple constraint conditions can be automatically processed, the optimization strategy is dynamically matched, and global optimization is realized.
Owner:CNOOC ENERGY LOGISTICS CO LTD +1

Keystone-based deep ground security heterogeneous data fusion method and system

The invention relates to a Keystone-based deep ground security heterogeneous data fusion method and system, and the method comprises the steps: deploying a Keystone trusted execution environment on a deep ground edge computing node, creating a security enclave, carrying out the encryption access of multi-source heterogeneous data on the basis of remote authentication and key agreement, completing the space-time alignment and feature extraction after decryption in the enclave, and carrying out the fusion of the multi-source heterogeneous data. And performing cross-modal association analysis and risk assessment based on a preset model or a rule engine to obtain a fusion result, encrypting and signing the fusion result in the enclave, distributing the fusion result to an authorized receiver through a secure channel, and realizing one-time task destruction, long-term task cycle reconstruction and key refreshing in combination with enclave full life cycle management. According to the method, the credibility and the real-time performance of heterogeneous data fusion processing in a complex scene can be improved while the confidentiality and the integrity of deep operation and maintenance data are guaranteed.
Owner:CHINA RAILWAY FIRST SURVEY & DESIGN INST GRP

Security channel entrance guard

The utility model discloses a security channel entrance guard, and relates to the technical field of security channels. The safety channel entrance guard comprises gate machines, a protection assembly and a flow dividing assembly, the tops of the gate machines are fixedly connected with face recognition equipment, the number of the gate machines is two, the gate machines are oppositely arranged, the protection assembly is located on the gate machines, the protection assembly comprises winding equipment, an elastic net, a clamping plate, a mounting rod and a connecting belt, the winding equipment is fixedly mounted on one group of gate machines, and the elastic net is fixedly mounted on the other group of gate machines. The elastic net winding device is installed in the winding device, and the flow dividing assembly is also located on the gate. The gate can be protected, through the arrangement of the elastic net, a layer of additional protection is provided, interference of the external environment to the gate and access control equipment is prevented, the elastic net can provide physical isolation, the equipment is protected against damage, unintentional or intentional collision of pedestrians can be effectively reduced, and the safety of the gate is improved. The equipment is prevented from being damaged due to misoperation or overuse, and the service life of the equipment is prolonged.
Owner:SHENZHEN CHANGBO INTELLIGENT ELECTRONICS CO LTD

Remote login and control method and system based on virtual serial port and MQTT protocol

The invention belongs to the field of remote management and control, and discloses a remote login and control method and system based on a virtual serial port and an MQTT protocol, and the method comprises the steps: building a safety publishing and subscribing data channel with a pseudo terminal APP through the MQTT protocol based on a unique code and a national secret algorithm of a remote device, generating a working key, and carrying out the data interaction through the key, and meanwhile, a control command and response data are transmitted between the data transfer service and the terminal simulator by utilizing a pre-created virtual serial port, so that remote login and control are realized. The unique code ensures the uniqueness of the equipment identity, and illegal access is prevented; a national cryptographic algorithm such as SM2 replaces traditional RSA, and encryption efficiency and safety balance are optimized; a working key and a secure channel mechanism guarantee data transmission confidentiality; the virtual serial port integrates a terminal access process, and supports potential user authentication and an authority control layer.
Owner:XIDIAN POWER RECTIFIER XIAN +1

An unmanned aerial vehicle end-side privacy perception and data desensitization processing system and method

PendingCN122286826AData streamNerve network
This application discloses a privacy-aware and data de-identification system and method for unmanned aerial vehicles (UAVs). The system includes an airborne edge computing unit, multi-source sensors, a dual-channel data processor, a security encryption and transmission module, and a policy management interface. It is implemented through three parallel pipelines: a real-time privacy-aware pipeline uses a lightweight neural network to detect sensitive targets such as faces and license plates and outputs bounding boxes; a dynamic and precise de-identification pipeline calls a policy library to perform context-aware de-identification on the target area; and a dual-stream split-path controllable transmission pipeline transmits the de-identified data stream to the business platform in real time via a public network, while simultaneously transmitting the encrypted original data stream to a trusted data port through an independent secure channel.
Owner:BEIJING QIANFANG INNOVATION TECH CO LTD

Remote monitoring system based on single-chip microcomputer and control method thereof

The application belongs to the technical field of single-chip microcomputer, and particularly relates to a remote monitoring system based on a single-chip microcomputer and a control method thereof. The system comprises a single-chip microcomputer, a sensor acquisition unit, a wireless communication unit and an execution mechanism. When the single-chip microcomputer, the sensor acquisition unit, the system initialization, the wireless communication unit and the execution mechanism are sequentially powered on, the single-chip microcomputer sends a handshake instruction to the wireless communication unit after completing hardware self-checking, establishes a secure channel with a remote control terminal, and writes a unique identity code into the single-chip microcomputer and enters a standby state after the handshake is completed. The single-chip microcomputer polls the sensor acquisition unit according to a preset sampling period to obtain an original data frame. The remote control terminal analyzes error correction compressed data blocks, generates a control instruction according to a threshold strategy and returns the control instruction. The single-chip microcomputer drives the execution mechanism to act after receiving the control instruction, and records an execution state log. The application has the advantages of high communication efficiency, strong link fault tolerance and fast remote control response.
Owner:SHANDONG HUAJIE HYDROGEN ENERGY TECHNOLOGY CO LTD

Fusion media-text travel-rural special product full-link intelligent supply chain collaboration method

The invention discloses a convergence media-text travel-rural special product full-link intelligent supply chain cooperation method, and relates to the technical field of intelligent supply chain management, and the method specifically comprises the steps: building a real-time entrance, connecting convergence media, rural special e-commerce and order interfaces, setting an idempotent mark in a key field, carrying out the time alignment, carrying out the desensitization, and carrying out the access control; extracting multi-modal features and performing incremental updating, and calculating a content quality score and a popularity index through a content quality scoring device of a dynamic threshold value; through content-batch mapping, high confidence is automatically bound, manual recheck is triggered for low confidence, and degradation and alarm are executed during abnormal fluctuation; on the basis of grading and pricing of multi-modal input, triggering an on-demand picking task, entering multi-objective optimization of joint scheduling, and triggering degradation and rollback in case of abnormality; and on the basis of batch-level reversible instruction packet issuing and state machine management, receipt confirmation and real-time snapshot are completed in a secure channel, and sorting / transportation instruction and health detection are carried out.
Owner:BEIJING LIUJINSUIYUE TECH CO LTD

Method to establish a secure channel

Method to establish a secure channel between the owner of a software payload and the software payload itself when running into a hardware-based trusted execution environment, HW TEE, at the instance of a cloud service provider, including sending, by the owner, a nonce to the software payload; generating, by the software payload, a payload key pair: public key and private key; mixing, by the software payload, the payload public key with the nonce; computing, by the HW TEE, an attestation using this nonce mixed with the payload public key; sending, by the software payload, the attestation, and the payload public key to the owner; verifying, by the owner, the attestation using the sent nonce mixed with the received payload public key; generating, by the software payload and the owner, a session key; and establishing a secure channel between the owner and the software payload running into the HW TEE.
Owner:THALES DIS FRANCE SA

Key management method, mobile device for digital currency transaction, apparatus, system, and storage medium

Embodiments of the present disclosure provide a key management method, a mobile device for a digital currency transaction, an apparatus, a system, and a storage medium. The mobile device serves as an acceptance terminal, and comprises a digital currency acquirer application executable in a first execution environment and a digital currency trusted application executable in a second execution environment, and the second execution environment is securely isolated from the first execution environment. The digital currency acquirer application is configured to send a key application request to a digital currency background system, receive core key data by means of a secure channel between the digital currency background system and the mobile device, and when it is detected that the mobile device has the second execution environment and the executable digital currency trusted application is installed in the second execution environment, send the core key data to the digital currency trusted application. The digital currency trusted application is configured to receive the core key data sent by the digital currency acquirer application and store the core key data in the second execution environment.
Owner:THE PEOPLES BANK OF CHINA DIGITAL CURRENCY INST

Methods and systems for micro edge applications and grouping

A method for establishing connections and forming groups in an edge computing system includes detecting and identifying devices attempting to connect to the network using a processor. The method involves authenticating detected devices with a common pre-shared key (PSK) stored in memory, forming groups of connected devices based on predefined criteria, and sharing the PSK within each group via a secured channel. It also includes creating a subnetwork or private LAN for each subscriber using network configuration data, assigning virtual pre-shared keys (vPSKs) to devices based on service requirements, determining device capabilities by analyzing received device-specific information, and identifying supported applications based on device capabilities and application compatibility data stored in memory.
Owner:VEEA INC

File security monitoring method, device and equipment

The invention provides a file security monitoring method, device and equipment. The method comprises the following steps: acquiring a plurality of to-be-monitored target servers which are input by a user and are provided with different operating systems; according to the target server, obtaining a target file probe installed on the target server; acquiring a file real-time monitoring strategy of a target file probe installed on the target server, and transmitting the file real-time monitoring strategy to the target file probe through a secure channel; through the secure channel, obtaining a monitoring result of real-time monitoring and warning of the file operation state on the target server by the target file probe according to the file real-time monitoring strategy; and decrypting the monitoring result and displaying the decrypted monitoring result on a display interface of the platform end. According to the scheme, the communication security and the data integrity can be ensured, the specified file range is monitored, efficient and flexible alarm aggregation and remote strategy management capability can be provided, and false alarm caused by a large number of conventional operations is prevented.
Owner:HEFEI TANOVO INFORMATION SECURITY TECH CO LTD

Electricity utilization information collection terminal with multi-layer security isolation

The application discloses a power utilization information acquisition terminal with multi-layer security isolation and relates to the technical field of power utilization information acquisition. The terminal comprises the following steps: power line carrier, micro-power wireless, cellular and Ethernet are used to bear acquisition indexes, and evidence packages containing link fingerprint summaries, health scores and interference categories are generated; a security chip is used to issue a token, and the link fingerprint summaries, object permission gears and minimum password strength thresholds are bound; a security channel is first built on a backup bearing, and the consistency of fingerprints, the validity of tokens and the non-downgrade are checked, and double-bearing consistency is performed on high-risk writing; the link fingerprint summaries and sequence check roots in the token are used to unlock object gates, and evidence object driving minimum access control and parameter setting are periodically uploaded; the method improves copy stability, reduces switching delay, avoids downgrade and miswriting, and is more convenient for operation and maintenance supervision and network acceptance.
Owner:LIYANG HUAPENG ELECTRIC POWER METER

Standardized transaction method and system based on NFC card simulation

The invention provides a standardized transaction method and system based on NFC card simulation, and belongs to the technical field of intelligent automobile digital keys, and the method comprises the steps: sending a selection instruction to a terminal device according to a digital key application AID to select a digital key application, and receiving a selection instruction response returned by the terminal device; sending an authentication instruction to the terminal equipment, and establishing a secure channel with the terminal equipment; sending a certificate acquisition instruction to the terminal equipment, and receiving certificate chain data returned by the terminal equipment; verifying that the certificate chain data is valid, sending a control instruction to the terminal equipment, and receiving an instruction execution response returned by the terminal equipment; wherein the selection instruction, the authentication instruction, the certificate acquisition instruction and the control instruction are instructions in a predefined APDU instruction set. According to the invention, through the standardized APDU instruction and certificate format, interoperation of mobile phones and vehicles of different brands is realized, and the adaptation cost is reduced by more than 50%. According to the invention, the transaction efficiency is optimized.
Owner:DONGFENG MOTOR GRP

Hub-based token generation and endpoint selection for secure channel establishment

Systems and processes are described for establishing and using a secure channel. A shared secret may be used for authentication of session initiation messages as well as for generation of a private / public key pair for the session. A number of ways of agreeing on the shared secret are described and include pre-sharing the keys, reliance on a key management system, or via a token mechanism that uses a third entity such as a hub to manage authentication, for example. In some instances, the third party may also perform endpoint selection (e.g., load balancing) by providing a particular endpoint along with the token.
Owner:AMAZON TECH INC

Network security protection method and device for Ethernet, equipment and medium

The invention discloses a network security protection method and device for Ethernet, equipment and a medium, relates to the technical field of data communication, is applied to a link cipher machine deployed on the periphery of the Ethernet, and comprises the following steps: determining a first virtual local area network, and sending a first service data message to a first security entity so as to match a first security policy; if the strategy is a plaintext forwarding strategy, sending the first service data message to the peripheral equipment; if the strategy is a security protection strategy, determining a security channel type; performing first security label packaging and encryption processing on the first service data message according to the security alliance of the security channel type, and sending the first processed message to the peripheral equipment; determining a second virtual local area network, sending the second service data message to a second security entity, and performing security processing operation on the second service data message to obtain a second processed message; and sending or discarding the second processed message according to the second security policy. And the security protection of the service data is realized.
Owner:CETC CYBERSPACE SECURITY TECH CO LTD

Dynamic pressure adjusting method based on container

The invention relates to the technical field of data processing, in particular to a container-based pressure dynamic adjusting method, which comprises the following steps of: acquiring network protocol calling relation data and service semantic information; constructing a dynamic load portrait comprising protocol calling topology and resource competition characteristics by using a graph neural network; generating a load adjustment strategy based on the dynamic load portrait, injecting an analog flow execution strategy into the mirror image copy of the service system, and recording response delay distribution; when the delay exceeds a threshold value, topology scheduling resources are called to the associated container group according to a protocol, and the pressure measurement task is bound to the container group in the same area; establishing a secure channel and a hardware-level isolation environment according to the position of the container group, and collecting full-link calling data; and positioning performance bottleneck nodes through a causal inference model, optimizing load adjustment strategy parameters, and constructing a pressure measurement scene knowledge base in combination with historical load data to realize strategy migration. The problems of incomplete scene modeling, low high-concurrency simulation efficiency and bottleneck positioning delay of a distributed system are solved.
Owner:HUANENG ZHAOCAI DIGITAL TECHNOLOGY CO LTD +1

A space-time trusted event sequence forced recording and anti-tampering system and method based on a hardware root of trust

PendingCN122451958AData OriginTamper resistance
The application discloses a space-time trusted event sequence forced recording and anti-tampering system and method based on a hardware root of trust. The system comprises an absolute timing recording unit, an event causal chain forced construction unit, a causal chain integrity verification unit and a timing anomaly detection and response unit. The absolute timing recording unit uses a hardware crystal oscillator physical beat independent of a programmable clock source as a unique time reference, and the firmware thereof is signed and solidified by a hardware root of trust at the factory, and any modification must be experienced signing; the causal chain forced construction unit generates a causal chain record package containing a previous hash, a current hash, a hardware timestamp and an identity signature for each event; the integrity verification unit verifies the event sequence integrity by comparing the previous hash value. The identity signature key of the absolute timing recording unit is generated by an anti-quantum AI security chip, the private key is stored in the OTP area inside the chip, and is transmitted through the TrustZone Secure World secure channel when called. The application stipulates linkage with a continuous behavior entropy monitoring system and an AI Agent behavior auditing system, and ensures that the data source of AI autonomy determination and Agent behavior auditing has high credibility in the time dimension.
Owner:廖长林

Differential privacy-based data calling method and system in trusted data space

The invention discloses a differential privacy-based data calling method and system in a trusted data space, and relates to the technical field of trusted authentication. The method comprises the following steps: performing classification division on target data based on sensitivity and configuring differentiated privacy budget; receiving a calling request and determining a real-time data calling level according to identity verification and trust evaluation; performing hierarchical data calling according to the level and applying corresponding differential privacy processing to generate releasable data; transmitting data through a secure channel and collecting use feedback information; and performing multi-dimensional credible verification on the requester based on the feedback information, and driving iterative calling according to a verification result and a calling request to realize dynamic lifting of a data level. According to the method, through a progressive data release and closed-loop trust evaluation mechanism, the dynamic balance between privacy protection strength and data use effectiveness is realized, the exposure risk of sensitive data is effectively reduced, and the controllability of data circulation is improved.
Owner:LINGSHU TECH CO LTD

System and method for building a trusted network of devices

Systems and methods for building a trusted network of devices with intrusion detection system (IDS) using blockchain IoT (BIoT) technology are provided. The method includes registering an IoT device on a plurality of blockchain network channels. The plurality of blockchain network channels include an authentication channel, data channel, remote channel, and security channel connected to corresponding servers to perform dedicated operations such as device authentication, data management, remote operation / access control, and intrusion detection. On successful authentication, the IoT device is allowed to access, store and retrieve data stored on the blockchain. The blockchain ledger is updated after each data transaction and a new wallet identity or encrypted keys for the IoT device are issued after each transaction. The method further includes receiving an operational instruction from a front-end device and authenticating from the blockchain record, the wallet identity, user permissions and validity of operation's parameters based on an organization's policies.
Owner:B DATA SOLUTIONS INC

Distribution room data sharing method based on federated learning

The invention discloses a power distribution room data sharing method based on federated learning. The method comprises the following steps: S1, collecting local operation data in a plurality of power distribution rooms and preprocessing the local operation data; s2, locally constructing a multi-layer perceptron model based on the preprocessed data and completing training; s3, local model parameters obtained through training are uploaded to a central server through a secure channel, and original data are not transmitted; s4, the central server performs weighted aggregation on the uploaded parameters according to the sample size to generate global model parameters; s5, issuing global model parameters to each distribution room, updating the local model and continuing to train; s6, repeating the uploading, aggregation and issuing processes until the global model is converged; and S7, the global model is used for local reasoning after convergence, and state prediction, classification or anomaly detection are realized. According to the invention, a federated model system is constructed, encryption communication and a dynamic aggregation mechanism are fused, and power distribution data sharing and intelligent analysis are realized.
Owner:STATE GRID (BEIJING) INTEGRATED ENERGY SERVICES CO LTD

Transaction encryption and identity authentication method for self-service payment terminal

The invention relates to the technical field of self-service terminal safety, in particular to a transaction encryption and identity authentication method for a self-service payment terminal, which comprises a system consisting of the self-service payment terminal, an encryption authentication gateway, a business server and a monitoring server, and is used for automatically reading own hardware identification information and sending the self-service payment terminal to the encryption authentication gateway. Comprising a terminal data unique ID and a device MAC address, a secret key based on the SM2 cryptographic algorithm is generated, after the secret key is generated, the terminal sends a certificate application request to the encryption authentication gateway, after the terminal encryption authentication gateway receives the request, identity verification is carried out through a preset CA certificate, a digital certificate is signed and issued after verification is passed, the digital certificate is fed back to the terminal, and terminal initialization is completed. And if the bidirectional authentication is passed, the encryption authentication gateway inputs a trusted device list and establishes a secure channel to realize identity authentication verification of the two parties, and if the authentication fails, connection is directly refused, an abnormal log is recorded, and an abnormal reason is displayed. According to the invention, transaction encryption and identity authentication of the self-service terminal are remarkably improved.
Owner:HEBEI BENSHENG TECHNOLOGY CO LTD

Service transparent secure network channel establishment mechanism and system

The present invention relates to a service transparent secure network channel establishment mechanism. On the basis of a terminal transparent security module and a service transparent security gateway, and on the basis of a service request data frame sent by a terminal, a secure channel is established by designing an identity authentication data frame that has the same Ethernet header and the same source IP and destination IP. By means of a secure service data communication mechanism, it is ensured that service data with different security requirements can be protected on demand. Transparent access of the terminal to a service system is realized by means of an encrypted and encapsulated service request data frame that has the same Ethernet header and the same source IP and destination IP and undergoes encryption and encapsulation processing. In a corresponding design system, by means of the modular decomposition design of the terminal transparent security module and the service transparent security gateway, functions such as a secure communication protocol, service communication packet parsing, and secure data packet processing and forwarding are specifically implemented, thereby implementing transparent service access and improving the security protection capability of applications.
Owner:XINLIAN TECH (NANJING) CO LTD