Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

227 results about "Secure computing" patented technology

Data-credible-oriented vehicle-mounted integrated security computing system and credible construction method

The invention relates to the technical field of confidential computing, and discloses a data credibility-oriented vehicle-mounted integrated security computing system and credibility construction method, which comprises the following steps of: establishing a static trust chain by using a hardware trust root, shielding external interruption in a credible execution environment, and controlling a performance monitoring unit; synchronously collecting real-time hardware micro-architecture events of the key business algorithm to generate a runtime feature vector; according to the method, the instruction stream during operation is anchored by utilizing the physical characteristics of the micro-architecture, the hijacking attack of the control stream is accurately identified in a ciphertext environment, the hijacking attack of the control stream is accurately identified, the hijacking attack of the control stream is accurately identified, the hijacking attack is accurately identified, and the hijacking attack of the control stream is accurately identified. Strong coupling verification of a calculation result and an execution behavior is realized, and logic safety of a vehicle-mounted platform is ensured.
Owner:SHANGHAI JUPO TECH CO LTD

Method, device and system for safely processing astronomical sensitive data based on privacy calculation and storage medium

The invention relates to the technical field of computers, discloses an astronomical sensitive data security processing method, device and system based on privacy calculation, and a storage medium, and aims to solve the problems that in astronomical data cross-mechanism joint analysis, original data is easy to leak, the cooperation efficiency is low, and a traditional desensitization or encryption method is difficult to consider security and availability at the same time. The method specifically comprises the following steps: each participant deploys a private computing agent node locally, and original data is not out of a domain; the task coordination center issues an analysis task; the proxy node extracts and preprocesses local data, and loads a corresponding secure multi-party computing protocol template; according to the method, share segmentation is carried out on multi-modal data such as images, spectrums and star catalogues by adopting addition homomorphic secret sharing, and distribution is carried out through a national secret SM4 encryption channel; and multiple parties cooperatively execute task-oriented security calculation in an encrypted state, and the result is aggregated and returned with the minimum information amount. The method has the effect of realizing high-precision safe collaborative analysis which is available and invisible.
Owner:HENAN ACADEMY OF SCIENCES GRAVITY WAVE ASTRONOMY RESEARCH INSTITUTE +1

Processing a payment, by a secure computing system, from a payer to a payee operating a merchant computing system

Processing a payment transaction from a payer (operating a payer computing system) to a payee (operating a merchant computing system) by a secure computing system. The secure computing system outputs a financial account registration request form to the payer computing system (e.g., within a window or frame that is displayed within an ecommerce webpage provided by the merchant computing system) for the payer to provide sensitive financial account information, securely stores the sensitive financial account information, maintains compliance with an information security standard (e.g., a Payment Card Industry Data Security Standard), and provides a non-sensitive electronic data token representing the sensitive financial account information to the merchant computing system. The merchant computing system can then process the payment transaction using the sensitive financial account information represented by the non-sensitive electronic data token without actually receiving—and, therefore, having to secure—the underlying sensitive financial account information.
Owner:AUTOSCRIBE CORP

Cloud edge cooperative processing device and processing method for information interaction

The invention discloses a cloud edge collaborative information interaction processing device, method and system with an endogenous security architecture. The equipment comprises a main processor, a hardware security chip, a programmable logic unit, a communication unit and an equipment management unit. A trusted execution environment is constructed in the hardware security chip and is in isolated communication with a common execution environment of the main processor through a security bus, a security computing engine, a remote attestation module and a trusted key warehouse are arranged in the trusted execution environment, and the programmable logic unit is directly controlled by the trusted execution environment to realize dynamic hardware acceleration. The communication unit is provided with independent interfaces which are connected with the two execution environments respectively, unification of hardware-level security isolation and efficient cooperative computing is achieved, and the problems of privacy disclosure and untrusted process in cloud edge collaboration are solved.
Owner:GUANGZHOU SIXI INFORMATION TECH CO LTD

High-performance reliable multi-party secure computing technology testing method and device and storage medium

The invention relates to the technical field of multi-party security computing, and discloses a high-performance reliable multi-party security computing technology test method and device and a storage medium, and the method comprises the steps: deploying a to-be-tested multi-party security computing platform and a corresponding preset test data set in a preset test system simulating multi-party participation; simulating multi-party calculation to obtain a ciphertext calculation result, and comparing an error between the ciphertext calculation result and the plaintext calculation result to obtain a first reliability confirmation result; the ciphertext calculation is repeatedly executed for multiple times, and time consumed by each time of calculation is obtained; comparing each time of time consumption with a preset time threshold to obtain a second reliability confirmation result; comparing the performance difference between the ciphertext training model and the plaintext training model to obtain a third reliability confirmation result; and when the three reliability confirmation results all meet the corresponding reliability judgment standards, confirming that the to-be-tested multi-party security computing platform is reliable. Therefore, the stability and credibility of the MPC platform in the actual service can be evaluated more comprehensively and accurately.
Owner:CHINA SOFTWARE TESTING CENT +1

Learning user tasks submitted to artificial intelligence applications via privacy preserving techniques

A data processing system implements obtaining user prompts s that include instructions to an AI application to perform one or more tasks; storing the user prompts in a prompts datastore in a secure computing environment; analyzing the user prompts using an LLM operating within the secure computing environment to generate normalized prompts based on the user prompts; extracting first n-grams from the normalized prompts using differentially private n-gram extraction that preserves user-level privacy; generating masked normalized prompts by comparing the normalized prompts with the first n-grams and replacing, with a placeholder n-gram, n-grams of the normalized prompts that do not match an n-gram of the first n-grams; extracting second n-grams from the masked normalized prompts using the differentially private n-gram extraction that preserves user-level privacy; outputting the second n-grams from the secure computing environment; and storing the second n-grams in an anonymized prompts datastore outside of the secure computing environment.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Multi-modal large model Deepfake detection method based on retrieval enhancement

The invention discloses a multi-modal large model Deepfake detection method based on retrieval enhancement, and relates to the frontier crossing field of artificial intelligence security, computer vision and multi-modal information processing, and the method comprises the steps: 1, carrying out two-stage labeling in sequence, constructing an evidence obtaining knowledge database through the first-stage labeling, constructing an evidence obtaining thinking chain data set through the second-stage labeling, and carrying out the second-stage labeling; wherein the evidence obtaining thinking chain data set is used for generating thinking chain data including a cross validation type, an evidence guide correction type and an adversarial sample type according to the validity of initial judgment and retrieval evidences; step 2, for an image to be detected, retrieving text evidences of Top-k similar cases from the evidence obtaining knowledge database by using a dynamic evidence obtaining retriever; and step 3, inputting an image to be detected and the retrieved text evidence into the critical reasoning multi-modal large model, performing multi-modal reasoning analysis, and outputting a detection result containing a reasoning process.
Owner:NINGBO ARTIFICIAL INTELLIGENCE RES INST OF SHANGHAI JIAOTONG UNIV

Intelligent storage system with edge computing and endogenous security mechanism

The invention relates to the technical field of information, in particular to an intelligent storage system with an edge computing and endogenous security mechanism, and aims to solve the problems of security action point lag, high response delay and static resource occupation of the existing security storage technology in an edge computing scene. The system comprises an edge security calculation module, an authentication state machine, a hard wire instruction filtering unit and a controlled instruction execution path, by means of a hardware-level authentication mechanism which is initialized after being powered on, a physical connection gating instruction execution clock and dynamic multiplexing of a security computing buffer area and an I / O memory, 'default rejection 'type endogenous security protection is achieved within microsecond-level delay. According to the invention, a safe vacuum period is effectively eliminated, and high safety, low time delay and efficient utilization of resources are considered.
Owner:SHENZHEN I4SEASON HONGSHENG TECH CO LTD

Information security comprehensive protection system of production enterprise

The invention discloses a production enterprise-oriented information security comprehensive protection system, which comprises a unified security management center, a region boundary protection module, a security computing environment module, a data full life cycle protection module, an authority management module, a threat active defense module and a network security situation awareness module, original dispersed and isolated safety capabilities are integrated into a linkage system through an integrated architecture of a unified safety management center and six functional modules through a unified interface / event bus, so that instant isolation and authentication of a transverse production control area, a management information area and a longitudinal remote operation and maintenance channel are realized, and the transverse penetration blocking rate is remarkably improved; role isolation and dynamic authorization are realized through the authority management module, the attack surface of a supply chain is greatly narrowed, the manual operation and maintenance workload is reduced by about six percent, and the overall safety toughness and operation efficiency of an enterprise are remarkably improved.
Owner:HENGTONG PRECISION COPPER FOIL TECHNOLOGY (DEYANG) CO LTD

Adaptive methods for routing data in a secure storage network

This disclosure is directed to a method comprising: initiating a first application, a second application, and a third application, which are associated with a secure computing network; routing a first computing input, a second computing input, and third computing input, respectively, to the first application, the second application and the third application; executing, using the first application and based on the first computing input, a first computing operation and thereby generating a first local computing result; executing, using the second application, based on the second computing input, a second computing operation and thereby generating a second local computing result; and executing, using the third application, based on the third computing input, a third computing operation and thereby generating a third local computing result. The method also includes leveraging the first local computing result, the second local computing result, and third local computing result to generate network resolution data.
Owner:VEEVA SYSTEMS INC

Structured query language-based multi-user data association method, device and equipment

The application discloses a multi-user data association method and device based on a structured query language and an equipment. The method is through a first data set association clause in a SQL statement for associating data sets of multiple users; a data set association security operator is obtained which corresponds to a data set association operator and complies with a multi-party security calculation protocol; a data set association ciphertext execution plan of each user is generated according to the data set association security operator; the data set association ciphertext execution plan of the user is executed through a privacy calculation engine of the user; and the multiple data set association security operators in the multiple data set association ciphertext execution plans are used to associate the data sets of the multiple users in a privacy calculation manner. In this way, the plaintext execution plan of the multi-user data association clause in the SQL statement is rewritten into the ciphertext execution plan of each user, the multiple ciphertext execution plans perform cross-user joint data analysis in a privacy calculation manner, and the security of multi-party data can be effectively ensured.
Owner:ALIBABA (CHINA) CO LTD +1

Device identifier composition engine 3-layer architecture

Implementations described herein relate to a device identifier composition engine (DICE) 3-layer architecture. In some implementations, a device may include a secure computing environment including a hardware root of trust (HRoT) DICE component. The secure computing environment may include a DICE layer 0 component configured to derive a DICE identity key. The secure computing environment may include a DICE layer 1 component configured to derive a DICE alias key based on the DICE identity key. The secure computing environment may include a controller configured to receive an update to firmware of a component. The controller may be configured to update the firmware of the component based on receiving the update. The controller may be configured to update one or more keys of the component or one or more keys of one or more components above the component in a layer stack.
Owner:MICRON TECHNOLOGY INC

Railway signal system based on trusted computing security computing protection technology

The application discloses a kind of railway signal system security computing protection technology and system based on trusted computing.The application takes hardware trusted module as trust root, constructs the end-to-end trusted verification chain covering operation and maintenance terminal, communication link and destination device;Through the trusted management platform of center, the trust measurement and white list management of operation and maintenance tool are realized;Deeply integrate railway "window time" and standard operation process, construct device dynamic trusted benchmark model, and generate operation and maintenance personnel behavior trusted model based on historical behavior data;Deploy lightweight trusted agent to monitor operation and maintenance behavior in real time, and implement hierarchical response and authority control to behaviors deviating from the two models.The application realizes dynamic trusted protection in the whole operation and maintenance process, effectively improves the active defense capability against internal and external threats, balances safety strength and operation and maintenance efficiency, and provides business-aware security protection for railway signal system and key infrastructure.
Owner:CHINA STATE RAILWAY GRP CO LTD +1

A method and system for multi-party secure computation of coefficient of variation

The application provides a method and system for multi-party secure calculation of coefficient of variation, belonging to the field of multi-party secure calculation, and used for providing a new scheme for achieving the task of securely calculating the coefficient of variation of a data group, wherein the multi-party includes an initiator of a calculation task, a referee and a plurality of participants, the participants and the initiator hold private data, the initiator and the referee are two different parties, and the method comprises the following steps: the participants pre-process the data, the referee generates a public key and a private key based on a self-developed homomorphic encryption algorithm, and sends the public key to the participants, so that the private data of all the participants is encrypted, all the participants collect the encrypted data to the initiator, the initiator calculates an encrypted sum, the referee decrypts the sum and sends it to the initiator to obtain a mean value, all the participants calculate variance elements according to the mean value, and the variance elements are segmented, recombined and collected to the initiator, so that the initiator can calculate a standard deviation and then calculate a coefficient of variation.
Owner:LONGTEL INC

A multi-party model training method, system and apparatus

The embodiment of the specification provides a multi-party participated model training method, system and device, the method comprises: a first party inputs a plurality of first features into a first feature extraction network, homomorphically encrypts an output result to obtain a plurality of first encrypted vectors and sends the plurality of first encrypted vectors to a second party; the second party inputs a plurality of second features into a second feature extraction network, homomorphically encrypts an output result to obtain a plurality of second encrypted vectors; the second party homomorphically calculates the plurality of first encrypted vectors and the plurality of second encrypted vectors to obtain a plurality of fusion encrypted vectors and sends the plurality of fusion encrypted vectors to the first party after being disordered, and records a first correspondence before and after disordering; the first party decrypts the plurality of fusion encrypted vectors and inputs the plurality of fusion encrypted vectors into a first part of a classification network to obtain a plurality of latent vectors; the first party uses the plurality of latent vectors and a classification label, and the second party uses network parameters of a second part of the classification network and the first correspondence to perform multi-party secure calculation and determine a first loss; the first party and the second party update the classification network according to the first loss.
Owner:ALIPAY (HANGZHOU) INFORMATION TECH CO LTD

SIL2 security level vehicle-mounted signal system and control method thereof

The invention discloses an SIL2 security level vehicle-mounted signal system and a control method thereof. The system comprises a security calculation core, a CLU3 module and an input and output VDU module. The safety calculation core comprises a CLU1 module and a CLU2 module, realizes a system safety function, and performs dual-channel data comparison and internal self-inspection; the VDU executes input acquisition and output control, a safe output channel of the VDU enters and maintains a non-output state when an internal fault is detected, and fault information is reported; the CLU3 is independently responsible for a non-safety function; wherein the security calculation core performs fault diagnosis and security level division by integrating self-inspection, dual-channel comparison and VDU report information, and generates alarm information; and the CLU3 outputs an alarm signal corresponding to the fault level to an external system or a driver according to the fault level, and final safety control is completed by the external system or the driver. Compared with the prior art, the system complexity and cost are effectively reduced on the premise of ensuring the SIL2 security level through fault grading, alarming and man-machine cooperative control mechanisms.
Owner:CASCO SIGNAL LTD

Computational analysis over distributed data

A method for secure analysis of distributed data includes receiving a request from a user to perform a data analysis operation. The data analysis operation utilizes first data accessible by a first secure research environment and second data accessible by a second secure research environment. The method further includes authenticating the user at the first secure research environment and the second secure research environment, communicating a first query for the first data to the first secure research environment, and communicating a second query for the second data to the second secure research environment. The method further includes receiving, from a secure compute environment in communication with the first secure research environment and the second secure research environment, results from the data analysis operation.
Owner:LIFEBIT BIOTECH LTD

Key vaults with active register banks

Systems and techniques are provided for secure computing. For instances, a process can include generating a master private key; generating a set of first dummy values; dividing the master private key into a first set of shares, wherein a sum of shares of the first set of shares equals a value of the master private key; initiating portions of an active memory bank with a sequence of integer modular additions, wherein the integer modular additions comprise: masking the first set of shares of the master private key; and adding the masked first set of shares of the master private key to portions of the active memory bank using a sequence of adds that adds and mixes the masked first set of shares of the master private key with dummy values.
Owner:QUALCOMM INC

Secret softmax function calculation system, secret softmax function calculation apparatus, secret softmax function calculation method, secret neural network calculation system, secret neural network learning system, and program

Techniques for performing secure computing of softmax functions at high speed and with high accuracy are provided. A secure softmax function calculation system that calculates a share ([[softmax (u1)]], . . . , [[softmax (uJ)]]) from a share ([[u1]], . . . , [[uJ]]) includes a subtraction means for calculating a share ([[u1−u1]], [[u2−u1]], . . . , [[uJ−uJ]]), a first secure batch mapping calculation means for calculating, [[exp (u1−u1)]], [[exp (u2−u1)]], . . . , [[exp (uJ−uJ)]], an addition means for calculating a share([[∑ j=1J⁢exp⁡(uj-u1)]],… ,[[∑ j=1J⁢exp⁡(uj-uJ)]],and a second secure batch mapping calculation means for calculating a share ([[softmax (u1)], . . . , [[softmax (uJ)]]).
Owner:NT T INC

Secure computing infrastructure for electronic messages

Secure computing infrastructure for electronic messages is described herein. A system can intercept an electronic message for transmission to a recipient device. The system can determine, prior to transmission of the electronic message for receipt by the recipient device, a category of the recipient device based on a domain name associated with an internet protocol address of the recipient device. The system can generate a plurality of content segments based on overlapping sequences of words in the electronic message. The system can identify, using machine learning models and based on the category of the recipient device, a security parameter to apply to the electronic message. The system can detect, using machine learning models, an incompatibility between a content segment and the security parameter. The system can block, responsive to the detection of the incompatibility, the transmission of the electronic message for receipt by the recipient device.
Owner:ADP INC

Multi-party data security calculation method and system based on TEE and encrypted mirror image

The invention relates to a multi-party data security computing method and system based on TEE and an encrypted mirror image, and belongs to the technical field of data security computing, and the system sequentially comprises an access layer, a security authentication and control layer, a data and mirror image security layer and a security computing environment layer from top to bottom, the method comprises the steps of encrypting and uploading a data demander program mirror image, encrypting and uploading participant data, performing safety calculation in TEE and encrypting and downloading a data demander result. In a word, the method has the advantages of realizing full-process security protection of multi-party data security calculation, effectively reducing the risk of data leakage, providing intellectual property protection of calculation codes, preventing algorithm leakage and reverse engineering, and ensuring commercial confidential security of users.
Owner:郑州埃文科技有限公司

Fast and secure memory address translation in a virtual machine computing system

Various embodiments include techniques for translating memory addresses in a virtualized computing system that hosts multiple virtual machines. In such a virtualized computing system, conventional approaches for translating a guest virtual address to a system physical address can involve a large number of memory accesses. With the disclosed techniques, address translation can be reduced to approximately 5 memory accesses. This performance savings results from storing two data structures in high-speed on-chip memory that indicate which system physical address segments are mapped to and valid for the virtual machine that is accessing the memory segment. A third data structure indicates whether a system physical address segment is a protected / secure system physical address segment. If the virtual machine already has access to the segment, then confidential / secure compute policies can be applied on the accesses from this virtual machine based on whether this system physical segment is protected / secure.
Owner:NVIDIA CORP

Secure and trustworthy bridge for transferring assets across different networks

Described herein are systems and methods for providing the secure transfer of assets between blockchain networks. The system can include a storage device that can store a bridge program that is programmed to perform (i) lock operations that lock native assets from a first blockchain network and mint synthetic assets representing the native assets in a second blockchain network, and (ii) unlock operations that unlock the native assets by transferring the native assets to an address in the first blockchain network in response to the synthetic assets being returned or destroyed. The system can include a computer system that loads and executes the bridge program in a secure computing enclave that provides a trusted execution environment. The computer system can then perform the lock operations and the unlock operations to provide a bridge between the first blockchain network and the second blockchain network.
Owner:AVA LABS INC

A doctor-patient privacy matching method based on secure computation in a digital health platform

The application provides a doctor-patient privacy matching method based on secure computation in a digital health platform, which is applied to a doctor-patient privacy matching system composed of a patient terminal, a first service platform and a second service platform, and the method comprises the following steps: the patient terminal performs secret sharing on a symptom vector, generates symptom vector secret shares and respectively sends the symptom vector secret shares to the first service platform and the second service platform; the first service platform and the second service platform calculate the similarity secret shares of each doctor based on the symptom vector shares received by the first service platform and the second service platform respectively, utilize a secure multi-party computation protocol, subsequently cooperatively perform secure order calculation, obtain the ranking order value secret shares corresponding to each doctor, and then cooperatively perform secure order retrieval according to each target order value in a preset Top-k order set to obtain the doctor index secret shares corresponding to each ranking and send the doctor index secret shares to the patient terminal; and the patient terminal combines the doctor index secret shares to reconstruct a plaintext Top-k doctor index set.
Owner:XIDIAN UNIV

Method and apparatus for determining whether query data belongs to a target data set

ActiveCN114969806BData setCiphertext
Embodiments of the present specification provide a method and device for determining whether query data belongs to a target data set, which is implemented by using multi-party secure computing technology to achieve privacy protection and achieve the purpose of anonymous query. The method comprises: a first party determines a preset number of target positions corresponding to the query data in a Bloom filter, extracts encrypted elements of the preset number of target positions in a first ciphertext array obtained from a second party, and obtains a preset number of encrypted values; the first ciphertext array is obtained by mapping the target data set to the Bloom filter by the second party, and each element in the first array is homomorphically encrypted; a homomorphic function operation is performed on the preset number of encrypted values to obtain a result ciphertext; the homomorphic function operation is used to aggregate the element values of the preset number of target positions; and the result ciphertext is sent to the second party, so that the second party decrypts the result ciphertext and determines whether the query data belongs to the target data set according to the decryption result.
Owner:ANT BLOCKCHAIN TECHNOLOGY (SHANGHAI) CO LTD

Secure multi-party computation method and electronic device

Provided in the present application are a secure multi-party computation method and an electronic device. The method comprises: a first device and a second device negotiating a pseudo-random number seed; first, in a trusted execution environment, the first device generating a random number on the basis of the pseudo-random number seed, and generating an auxiliary parameter on the basis of the random number, a first parameter Y, and a computation task corresponding to Y; then, receiving an encrypted data fragment x1 sent by the second device, and in the trusted execution environment, determining z1 on the basis of x1, Y, the auxiliary parameter and the computation task; and subsequently, sending z1 to the second device, and the second device determining a sum of M2 and z1 as a computation result of a computation task corresponding to X and Y. The technical solution provided in the present application can reduce the communication overheads during secure multi-party computation.
Owner:HUAWEI TECH CO LTD

Method and apparatus for secure computation of matrix multiplication

The embodiment of the present specification provides a kind of matrix multiplication security calculation method and device, it is suitable for the multi-party security calculation architecture of two participants, one party holds matrix, another party holds vector, and the product of the security calculation of the matrix and vector is calculated.The embodiment of the present specification makes full use of the characteristics that efficient homomorphic encryption mode can process polynomial data under the multi-party security calculation architecture, and each matrix and vector is encoded as polynomial, and the polynomial corresponding to the product of the matrix and vector is determined based on polynomial multiplication, and then each dimension element in the product vector of the matrix and vector is extracted from the polynomial of multiplication result.The implementation can improve the efficiency of the matrix security multiplication operation based on homomorphic encryption.
Owner:ANT BLOCKCHAIN TECHNOLOGY (SHANGHAI) CO LTD

Multi-party security computing method and system in gatekeeper mode

The invention discloses a multi-party security computing method and system in a gatekeeper mode. The method comprises the following steps: generating and storing a copy of network configuration information for each participant; in response to a starting instruction of a multi-party security computing task, traversing all participant pairs (Pi, Pj) which need to establish communication connection, i is not equal to j, for each pair, initiating a connection request by the participant Pi according to network configuration information stored in the participant Pi, and forwarding through gatekeeper equipment so as to establish a one-way communication link from Pi to Pj; constructing a virtual full-connection computing network covering all participants on the basis of the established multiple one-way communication links; the task initiator distributes the calculation task to the calculation platform through any participant in the virtual full-connection calculation network; and the computing platform coordinates the participants to perform secure multi-party cooperative computing through the virtual full-connection computing network according to the tasks. According to the invention, the multi-party security computing technology can be seamlessly deployed in a high-security environment with strict gatekeeper requirements.
Owner:LINGSHU TECH CO LTD