Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

391 results about "Security domain" patented technology

A security domain is the determining factor in the classification of an enclave of servers/computers. A network with a different security domain is kept separate from other networks. Examples: NIPRNet, SIPRNet. JWICS, NSANet are all kept separate.

Automatically Investigating Security Incidents and Generating Security Incident Reports Using a Large Language Model (LLM)

Automatically investigating security incidents and generating security incident reports using a Large Language Model (LLM). A computerized system receives an incoming Security Alert Message pertaining to a possible security-related incident. The system automatically feeds into the LLM at least: the content of the Security Alert Message; the metadata of the Security Alert Message; context information describing a security domain; and organization context information pertaining to users and machines of that organization. The system automatically prompts the LLM to automatically investigate the Security Alert Message and to automatically generate a detailed Incident Report pertaining to the Security Alert Message.
Owner:VARONIS SYSTEMS INC

Power distribution network bearing capacity evaluation system based on dynamic correction

The invention relates to the technical field of power distribution network evaluation, and discloses a power distribution network bearing capacity evaluation system based on dynamic correction. The system comprises a dynamic data acquisition module, a multi-dimensional state space construction module, a security domain analysis module, a partition coupling degree calculation module and a bearing capacity evaluation engine module. The dynamic data acquisition module acquires a power injection quantity sequence, a voltage deviation ratio sequence and uncontrollable parameter fluctuation data of each partition node of the power distribution network; a multi-dimensional state space construction module performs dimension raising mapping on the sequence to generate a linearized power flow state space model containing a power-voltage Jacobian matrix; the security domain analysis module corrects the boundary of the model according to uncontrollable parameter fluctuation and generates a dynamic security operation constraint set; the partition coupling degree calculation module quantifies an electrical independence index by means of a spectrum radius; and the bearing capacity evaluation engine constructs a chance constraint optimization model, outputs the photovoltaic maximum accessible capacity of each partition and a safety guarantee supply control strategy set, and improves the evaluation accuracy and practicability.
Owner:国网甘肃省电力公司金昌供电公司

Digital twin hydraulic engineering operation and maintenance monitoring system and method

The invention relates to the technical field of computers, and discloses a digital twin hydraulic engineering operation and maintenance monitoring system which comprises a data acquisition module, a twin modeling module, a principal stress extraction module, a stress evolution prediction module, a safety domain judgment module, a regulation and control decision module, a control execution module and a state feedback module. The invention also discloses a digital twin hydraulic engineering operation and maintenance monitoring method, which comprises the following steps: data acquisition: real-time sensing data of a hydraulic engineering structure area is acquired through the data acquisition module, and the sensing data comprises strain, water pressure, temperature and displacement information and is used for representing the current state of the structure; and carrying out twin modeling, and receiving the real-time sensing data transmitted by the data acquisition module. According to the method, intelligent sensing and dynamic regulation and control of the structure state are realized by constructing a closed-loop system of principal stress prediction, regulation and control decision, control execution and state feedback.
Owner:张航钒

Layered optimization scheduling method for deep peak regulation of thermal power generating unit

The invention discloses a hierarchical optimization scheduling method for deep peak regulation of thermal power generating units, and the method comprises the following steps: system layering: dividing a power system into a plurality of subsystems, each subsystem comprising a thermal power generating unit cluster and differentiated load demands; subsystem-level prediction: generating a basic scheduling plan; dynamic preference-driven multi-target collaborative optimization: receiving multi-target data from each subsystem, carrying out multi-target collaborative optimization, modeling three targets of a power grid company, an environmental protection department and a terminal user as game participants, quantifying the priority of each party by adopting a fuzzy membership function, generating a dynamic game solution through a Nash equilibrium solver, and carrying out multi-target collaborative optimization; screening out a Pareto optimal solution giving consideration to interests of multiple parties; performing online verification on the dynamic security domain; virtual synchronous machine cooperative support: simulating operation characteristics of a synchronous generator; and global coordination and iterative optimization: uploading the optimal scheduling scheme of each subsystem to a scheduling center through a message queue telemetry transmission protocol, and performing global constraint verification.
Owner:STATE GRID GANSU ELECTRIC POWER CORP +1

Network security and data security comprehensive analysis method and system based on large model

The invention provides a network security and data security comprehensive analysis method and system based on a large model, and the method comprises the steps: collecting multi-source heterogeneous security data of a network communication link, a data storage node and an application interaction interface, carrying out the risk behavior atomization association processing, and constructing a dynamic risk association hypergraph; based on a preset security domain knowledge graph, calling the large model to execute multiple rounds of risk attribution reasoning, performing attack chain fragment matching and evidence chain completion on a behavior hyperedge set in the dynamic risk association hypergraph, and generating a risk attribution reasoning chain; and constructing a risk evolution probability model according to the risk attribution reasoning chain and the time sequence constraint set of the dynamic risk association hypergraph, and calculating a short-term diffusion probability and a long-term evolution trend vector of each association risk path based on the risk evolution probability model to obtain a risk evolution path prediction result. The pertinence and the dynamic adaptability of protection measures can be improved, and the problem that a static protection strategy is difficult to deal with the hysteresis quality of dynamic risk changes is solved.
Owner:贵州华谊联盛科技有限公司

Marine multi-mode environment perception and intelligent ship navigation decision-making method based on double-branch vision-semantic encoder

The invention discloses an ocean multi-mode environment perception and intelligent ship navigation decision-making method based on a double-branch vision-semantic encoder. The method comprises the following steps: S1, acquiring a multi-source data image containing a ship and a surrounding environment thereof from an existing public maritime data set or platform; s2, training a double-branch vision-semantic encoder by using the multi-source data image, and inputting a to-be-processed image extracted in real time into a multi-modal feature matrix in the trained double-branch vision-semantic encoder; s3, based on the multi-modal feature matrix, obtaining positioning information of the ship and surrounding environment elements, and constructing a dynamic security domain model; and S4, in combination with the dynamic security domain model and the multi-ship relative position relationship, carrying out quantitative evaluation on the navigation risk, and generating a self-adaptive navigation strategy based on an evaluation result. According to the invention, high-precision ship positioning and environment element identification under complex weather and illumination conditions are realized by using all-weather characteristics and multi-scale visual feature coding of SAR imaging.
Owner:HARBIN ENG UNIV

Mass data cross-security domain transmission high-low priority queue hierarchical scheduling method based on Internet of Things equipment

The invention relates to the technical field of Internet of Things data transmission, in particular to a mass data cross-security domain transmission high-low priority queue hierarchical scheduling method based on Internet of Things equipment, which comprises edge computing node classification, independent channel design, a dynamic weight distribution algorithm and a block chain encryption watermark technology. The timeliness is improved through a preemptive and compensation mechanism, and the reliability is enhanced in combination with queue degradation protection and a dynamic adjustment strategy. The method can effectively solve the problems that timeliness is insufficient and safety and efficiency are difficult to balance in a traditional method, the key data transmission efficiency and the system self-adaptive capacity are remarkably improved in a complex network environment, and the method has wide application prospects.
Owner:GUANGZHOU KETENG INFORMATION TECH

Power distribution automation terminal safety debugging method based on Bluetooth communication

The invention provides a power distribution automation terminal security debugging method based on Bluetooth communication, and the method comprises the steps: extracting a historical operation record and a current task context from an operator identity identifier, calculating a real-time permission range of resource access, and adjusting an initial access boundary according to the real-time permission range; a security gateway module is embedded in a Bluetooth communication channel, a cross-domain data exchange request is intercepted and analyzed, whether the request exceeds the adjusted access boundary is judged, and if yes, transmission is refused; analyzing the cross-domain data exchange request, extracting a source domain identifier and a target domain identifier of a data packet from the cross-domain data exchange request, and encrypting the data packet to obtain encrypted cross-domain transmission data; and obtaining a decryption key distribution record of the encrypted cross-domain transmission data in the security domain of the receiving end, judging whether the key is matched or not, if so, decrypting the data and transmitting the data to the target domain, and otherwise, discarding the data.
Owner:STATE GRID SHANDONG ELECTRIC POWER CO

Power distribution network and data center collaborative planning method based on security domain analysis

The invention relates to the field of power distribution network planning, and discloses a power distribution network and data center collaborative planning method based on security domain analysis, and the method comprises the following steps: S1, constructing a power distribution network-data center system security domain model containing a distributed power supply; s2, based on the constructed power distribution network-data center system security domain model, constructing a power distribution network-data center system double-layer collaborative optimization model; s3, solving the double-layer collaborative optimization model by using an algorithm solver to obtain a collaborative planning result of the power distribution network and the data center; in the step S2, the power distribution network-data center system security domain model represents a set of all working points meeting normal operation N-0 constraint and N-1 security constraint of the system. By constructing the power distribution network-data center security domain model and proposing the joint quantitative index, the continuous representation of the system security margin is realized, the anti-disturbance capability and the operation stability of the system are improved, and the local overload risk is avoided.
Owner:NORTH CHINA ELECTRIC POWER UNIV

Intra-day look-ahead scheduling rapid solving method considering large-scale new energy cluster power generation volatility

The invention relates to the technical field of power system scheduling, and discloses an intra-day look-ahead scheduling rapid solving method considering large-scale new energy cluster power generation volatility. Comprising the following steps of S1, new energy cluster space-time fluctuation scene generation based on a neuron cellular automaton, S2, power grid dynamic security domain definition and simplification based on a physical information neural network, S3, scheduling rapid optimization solution based on model prediction path integration, and S4, scheduling scheme dynamic elasticity and stability evaluation based on a Kupman operator theory. The new energy cluster space-time fluctuation scene generation method based on the neuron cell automaton can effectively generate a space-time scene reflecting large-scale new energy cluster power generation volatility, supports uncertainty analysis, has the advantages of being high in calculation efficiency and scene authenticity, and is suitable for large-scale new energy cluster power generation. The problem that scene generation is inaccurate due to the fact that a traditional statistical model ignores space-time coupling is solved.
Owner:MAINTENANCE & TEST CENTRE CSG EHV POWER TRANSMISSION CO +2

Cross-heterogeneous security domain hybrid identity authentication method and system based on block chain

The invention provides a cross-heterogeneous security domain hybrid identity authentication method and system based on a block chain, and the method comprises the steps: initializing each heterogeneous security domain Di, and carrying out the identity registration of an Internet of Things device Dei and an edge server ESi based on an intra-domain authentication system; adding the ESi into the block chain; constructing cross-domain trust, and determining smart contract and cross-domain data sharing channel division; transmitting the data to an intra-domain database DBi or uploading the data to a block chain; the Dei sends a cross-domain data access request message to an intra-domain ESi; the ESi verifies the legality of the cross-domain access; if the request data is linked, the ESi directly pulls the data from the block chain locally and forwards the data back to the Dei; otherwise, the ESi forwards the cross-domain request to a target domain ESj; and the ESj verifies the legality of the cross-domain request, and forwards the corresponding data back to the Dei through the ESi after the verification is passed. According to the method, a heterogeneous cross-domain identity authentication mechanism based on the block chain is constructed to form hybrid cross-domain sharing channel support, so that interconnection and intercommunication of security domains and secure and efficient sharing of data in the industrial internet are promoted.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Electro-hydrogen system safety domain dynamic regulation and control method based on digital twin-reinforcement learning

The invention discloses an electro-hydrogen system safety domain dynamic regulation and control method based on digital twinning-reinforcement learning, and belongs to the field of power grid safety operation, and the method comprises the following steps: S1, constructing a multi-energy flow coupling model comprising new energy power generation, an electrolytic cell and a hydrogen storage tank; s2, decomposing a new energy original output sequence by adopting a method of combining continuous wavelet transform and an autoregressive moving average model to form time-frequency characteristics; s3, state space modeling considering space-time coupling; s4, generating a dynamic security domain based on digital twinning; s5, constructing a multi-target reward function, and solving by taking the dynamic security domain as a constraint; and S6, performing closed-loop verification and model evolution. By adopting the electric hydrogen system safety domain dynamic regulation and control method based on digital twinborn-reinforcement learning, safety domain dynamic adaptation and intelligent control of the electric hydrogen system under new energy fluctuation are realized, and the operation safety and economy of the system are remarkably improved.
Owner:STATE GRID SHANGHAI INTEGRATED ENERGY SERVICE CO LTD +1

ARM-based embedded image decoding display system

The invention discloses an embedded image decoding display system based on an ARM, and relates to the technical field of computers, and the system comprises a dynamic sensing module which is used for monitoring the CPU occupancy rate, the cache hit rate and the memory bandwidth utilization rate of an ARM processor in real time, establishing a three-dimensional resource vector containing a dynamic weight coefficient, and calculating a threshold boundary; the adaptive decoding engine comprises an optimization unit which is used for reconstructing a bit stream processing channel and a register data exchange mechanism based on an SIMD expansion instruction of an ARMv8.2 instruction set; the prediction unit is used for predicting instruction-level hotspot distribution of the decoding task by adopting a TinyLSTM model and generating an instruction transmitting strategy; the hardware optimization module is used for executing a heterogeneous collaboration strategy of the NEON coprocessor and the MaliGPU, and the heterogeneous collaboration strategy comprises the following steps: dividing DCT / IDCT (discrete cosine transform / inverse discrete cosine transform) calculation granularity; determining a mixing precision conversion assembly line of the GPU shader according to the color gamut of the display equipment; and the display driving module is used for implementing a decoding parameter dynamic confusion algorithm in the security domain and forming a tamper-proof closed loop with the optimization unit.
Owner:TRONLONG

Trusted data space connector layer data flow method and system

The invention is suitable for the technical field of data circulation, and provides a trusted data space connector layer data circulation method and system, and the method comprises the steps: enabling data to access a trusted data space connector, and carrying out the preprocessing of the data; dynamically configuring an access control strategy according to the identity and authority of the data requester; data are virtualized and circulated among different security domains through a data cross-domain virtualization technology, and in the data circulation process, an end-to-end data encryption transmission technology is adopted; after a data requester obtains the data, the data is processed and analyzed by using a micro-isolation data cross-domain fusion processing technology. According to the method, the fusing index is generated by dynamically fusing the aging feature vector, the frequency risk spectrum and the sensitivity matrix, so that real-time parameter customization and risk adaptive adjustment of the access control strategy are realized, and time sequence change, frequency anomaly and data sensitivity difference in a complex access scene are effectively dealt with; and the dynamic protection capability of cross-domain data circulation is obviously improved.
Owner:CLOUD (NANCHANG) BIG DATA OPERATION CO LTD

Shipborne intelligent network security protection architecture and method

The invention provides a shipborne intelligent network security protection architecture and method, and relates to the technical field of network security, and the architecture comprises a security domain division module which is used for dividing a shipborne network into three physically isolated security domains, including a key task domain, an operation management domain and a crew life domain; the longitudinal protection strategy module is used for generating a longitudinal strategy comprising a protection instruction, a communication control instruction and a risk quantification instruction based on the security domain structure; and the risk calculation module is used for detecting intra-domain equipment access behaviors by trapping addresses in the key task domain, collecting intra-domain network traffic and service unit logs, and outputting a service asset quantized value, a vulnerability severity quantized value and a threat behavior deviation degree according to a risk quantization instruction. According to the invention, accurate identification, graded response and efficient disposal of shipborne network threats are realized, and the safety of a ship key system is guaranteed.
Owner:SHANGHAI JINGZHI INTELLIGENT TECH CO LTD

Edge security interaction method for electric power Internet of Things

The invention discloses an electric power internet of things edge security interaction method, which comprises the following steps: by taking an initial interaction request initiated by a request security domain to a response security domain as a processing object, establishing a cross-domain interaction basic framework through a HotStuff consensus control center, fusing node historical trust data and authentication information of a trusted identity basic trust facility, and establishing a cross-domain interaction framework through the HotStuff consensus control center; constructing a multi-dimensional security protection strategy covering identity verification, authority control and data encryption; a multi-dimensional security protection strategy is used as a processing object, a cross-domain interaction process is executed based on a HotStuff consensus mechanism, and a quantitative trust evaluation result is generated through a hierarchical model of distributed trust calculation, joint trust calculation, total trust calculation, link reliability calculation and fuzzy trust calculation; and when a trust evaluation result meets a security threshold, executing an interaction operation, performing coordinate fuzzification processing on a physical position of the accessed resource to hide a real address, and after interaction is completed, generating a performance verification report through communication overhead and a false alarm rate index.
Owner:ZHEJIANG ZHENENG LANXI POWER GENERATION CO LTD

Transverse isolation and secure data transmission method and system for power system

The invention relates to the technical field of power system network and information security, and discloses a power system transverse isolation and secure data transmission method and system.The method comprises the steps that a production control security domain and a management information security domain are determined, and cross-domain service flow information is configured; when transmission between a production control security domain and a management information security domain is needed, cross-domain service flow information to which service data belongs is collected and packaged into a security self-description data unit; on the transverse isolation path, acquiring header information to generate a session token; when the secure self-description data unit is forwarded, feature data are obtained and compared with the associated session token, and forwarding is carried out when limiting conditions are met; and maintaining a sliding time window, carrying out statistics on the forwarded security self-description data unit, and identifying an abnormal behavior. According to the invention, semantic-level access control and dynamic protection of cross-domain services between a production control security domain and a management information security domain are realized.
Owner:BEIJING ZHONGDIAN YUBANG TECH CO LTD

Dynamic reactive power control method and device for new energy plant station

The embodiment of the invention relates to a dynamic reactive power control method and device for a new energy plant station, and the method comprises the steps: calculating a dynamic safety domain of virtual impedance based on a real-time estimation value of power grid impedance; based on a multi-time scale reinforcement learning algorithm, generating a virtual impedance control quantity under the constraint of the dynamic security domain; obtaining a reactive power output error value, and correcting the virtual impedance control quantity by using the reactive power output error value; and performing reactive power output control on the inverter of the plant station based on the corrected virtual impedance control quantity. According to the technical scheme provided by the embodiment of the invention, the power grid impedance is predicted through the multi-time scale reinforcement learning algorithm, the virtual impedance control quantity is generated accordingly, the upper layer prediction model can predict the impedance change trend in advance and provide a prospective reference for lower layer dynamic correction, and the lower layer dynamic correction model can realize instantaneous disturbance suppression. And rapid fine tuning of the virtual impedance is realized, so that more accurate virtual impedance control quantity can be obtained.
Owner:JIANGZHOU JINGLI ENG DESIGN CONSULTING CO LTD

Variable constraint control method for stage equipment based on risk perception and dynamic security domain

The invention belongs to the technical field of stage equipment boundary safety protection control, and particularly relates to a variable constraint control method for stage equipment based on risk perception and a dynamic safety domain. The characteristic that stage equipment is usually in a fixed application scene in the performance process is utilized, the inherent safety level and active protection capacity of a stage equipment system are greatly improved through tight combination of real-time collection and variable constraint, and therefore safer, more accurate and more smooth control is achieved. According to the method, a construction algorithm is embedded in software, a dynamic region division and segmentation threshold adjustment strategy is utilized, and a multi-stage braking redundancy cooperation mechanism is triggered, so that the anti-interference capability and fault tolerance performance of the control system are effectively enhanced, the implementation cost is low, a large amount of manpower and material debugging can be saved, and the system is suitable for large-scale popularization and application. And a high-precision and high-robustness safety control scheme is provided for large stage machinery such as a seat vehicle platform and a rotating stage.
Owner:BEIJING BEITE SHENGDI TECH DEV CO LTD

User side resource aggregation scheduling method, system and related device

The invention discloses a user side resource aggregation scheduling method and system and a related device, and belongs to the technical field of power system scheduling, and the method comprises the steps: determining a security domain of a power distribution network under the condition of not violating any operation constraint conditions, and obtaining a flexible resource adjustment model combined with the operation constraint boundary of the power distribution network; a convex polyhedron is used to describe the precise security domain of a single resource, then a sino polyhedron is used to describe the precise security domain aggregation user side flexible resource of the single resource, and based on the flexible resource potential model under the power distribution network operation constraint requirement and the flexible resource adjustment model combined with the power distribution network operation constraint boundary, the power distribution network operation constraint boundary is adjusted. Constructing a user side resource aggregation model considering the operation security domain of the power distribution network; and solving the user-side resource aggregation model considering the operation security domain of the power distribution network through a sino polyhedron, and carrying out user-side resource aggregation scheduling based on a solving result. According to the method, the problem of concurrent scheduling of numerous small-scale distributed resource clusters can be solved.
Owner:POWER RES INST OF STATE GRID SHAANXI ELECTRIC POWER CO LTD +1

Red and black isolation system and method for realizing dynamic switching of encryption algorithm based on FPAG dynamic configuration technology

The invention provides a red and black isolation system and method for realizing encryption algorithm dynamic switching based on an FPAG dynamic configuration technology, and aims to solve the problems of rigid isolation strategy, high switching response delay, encryption algorithm solidification and the like of a traditional red and black isolation architecture. The system comprises a red area CPU unit, a black area CPU unit and an isolation area FPGA access control unit, and automatic switching of protection strategies is achieved through FPGA local dynamic configuration. According to the invention, the encryption algorithm can be rapidly and dynamically switched according to the identified network threat level, and efficient and secure transmission of data among different security domains is ensured. The method has the characteristics of file encryption storage and integrity verification, key security processing, dynamic region isolation, multi-algorithm support and the like, is suitable for cross-security domain information interaction scenes needing to ensure information security, and has good social benefits and wide application prospects.
Owner:CHINA STATE SHIPBUILDING CORP NO 707 RES INST

Cross-security domain computing power resource federation and privacy protection system

The invention provides a cross-security domain computing power resource federation and privacy protection system. The system comprises a scheduling management node, a communication gateway, a plurality of computing nodes, a verification node and a key management node. The scheduling management node decomposes the calculation general task into a plurality of subtasks and plans different node execution paths; the communication gateway encapsulates the subtask data into an encrypted data packet containing a position identification segment and an encrypted data segment which can be independently decrypted; the computing node is integrated with the trusted execution environment to provide hardware-level security isolation; the summarizing node is used for receiving sub-task results which are processed by the computing nodes and comprise encrypted data segments; the verification node realizes calculation integrity verification; and the key management node confirms a task completion state by collecting the position identification segment, and coordinates and starts a data segment aggregation decryption process. According to the method, the data and code privacy of the computing task is ensured while the computing power island is broken, and a cross-domain computing power resource sharing mechanism with balanced safety and performance is established.
Owner:HANHOU (BEIJING) TECH CO LTD

Expert strategy constrained blast furnace smelting safety reinforcement learning decision optimization method

The invention discloses a blast furnace smelting safety reinforcement learning decision optimization method based on expert strategy constraint. According to the method, an optimization strategy can be learned from an off-line expert track on the premise that operation safety is ensured. Specifically, a conditional generative adversarial mechanism is introduced to realize the alignment of strategy distribution and expert decision, and the exploration ability in a security domain is retained while the expert experience is inherited. And an independent state-action safety evaluation network is designed and a discount factor is introduced, so that the long-term accumulation risk caused by the large hysteresis characteristic of the blast furnace is effectively dealt with. In addition, memory is adopted to enhance network coding historical information, incomplete state observation is supplemented, and information deviation in decision is reduced. According to the method, effective integration of triple guidance mechanisms is realized, knowledge inheritance is realized through distributed alignment, performance improvement is driven through reward optimization, and risk prevention and control are ensured through explicit security constraints.
Owner:CENT SOUTH UNIV

Secure element comprising a virtual terminal security domain and corresponding terminal

PCT designated stage expiredWO2025153653A1TransmissionSecurity arrangementVirtual terminalSecurity domain
The invention proposes a secure element (40) cooperating with a device (30), the secure element (40) comprising a GSMA eUlCC function comprising an ECASD eUlCC Controlling Authority Security Domain - (46), an ISD-R Issuer Security Domain - Root - 43 and at least an ISD-P Issuer Security Domain - Profile - (44), the secure element (40) also comprising a Virtual Terminal Security Domain (42) having a direct access to the GSMA eUlCC function via a virtual APDU interface, the Virtual Terminal Security Domain (42) interacting with the GSMA eUlCC function with the same APDUs as the device (30).
Owner:THALES DIS FRANCE SA

ARM processor-oriented microkernel operating system confidential computing environment construction method

The invention relates to an operating system environment construction technology, and discloses an ARM (Advanced RISC Machines) processor-oriented micro-kernel operating system confidential computing environment construction method, which is characterized in that a hierarchical system architecture is constructed, a virtual machine monitor and a confidential domain management monitor are decoupled at an ARM exception level EL2, and the virtual machine monitor and the confidential domain management monitor run in mutually isolated address spaces. The RMM is used as an independent module for dynamic loading, a management mechanism of a confidential computing domain is specially used, and the Hypervisor is only responsible for strategy scheduling, so that the defect that the Hypervisor is bloated in function in a traditional scheme is overcome. According to the method, the RMM is loaded through the security startup process during startup, the confidential virtual machine is dynamically created during running, mirror image security verification, memory encryption and other mechanisms are integrated, and finally the security domain is destroyed after the application is finished. The method has the advantages that a flexible and safe confidential computing environment conforming to the minimum privilege principle is provided for the microkernel system, and the method is particularly suitable for embedded scenes with high safety requirements such as the Internet of Things and industrial control.
Owner:CHENGDU TIANRUAN TECHNOLOGY CO LTD

Data transmission method and device between security domains, storage medium and electronic equipment

The invention discloses a data transmission method and device between security domains, a storage medium and electronic equipment. Relates to the field of data transmission, and the method comprises: in a front-end application of a first security domain, in response to an interaction request triggered by a user, generating a request message containing a unique identifier, and issuing the request message to a message queue service in the first security domain, the message queue service being used for a large model processing service in a second security domain, consuming the request message according to a pre-configured security access strategy, and writing response data of the large model into a shared cache service of a first security domain; and initiating a query request to the shared cache service to obtain response data corresponding to the interaction request from the shared cache service, and displaying the response data to the user through a user interface of the front-end application. The problem that data transmission efficiency is low when data transmission between security domains in a one-way network isolation environment is realized by depending on a manual or semi-automatic off-line ferry mode in the prior art is solved.
Owner:TRAVELSKY TECHNOLOGY LIMITED

Systems and methods for cryptographic authentication of contactless cards

Example embodiments of systems and methods for data transmission in a contactless card are provided. The contactless card may include a processor, and a memory. The memory may contain a first applet, a second applet, and a plurality of keys. The first applet and the second applet may be stored within a shared security domain. The second applet may be configured to communicate with the first applet to perform one or more cryptographic services. The second applet may be configured to transmit one or more requests to the first applet to encode one or more payload strings based on the plurality of keys to perform the one or more cryptographic services. The first applet may be configured to perform the one or more cryptographic services on behalf of the second applet based on the one or more requests.
Owner:CAPITAL ONE SERVICES LLC

One-way off-line security intelligent decision center system with local deployment as main and external network services as auxiliary and control method of one-way off-line security intelligent decision center system

The invention discloses a one-way off-line security intelligent decision center system with local deployment as a main and external network service as an auxiliary and a control method, and belongs to the technical field of artificial intelligence security and edge intelligent decision. A three-level security domain physical and logic dual isolation architecture is adopted, extranet multi-model intelligent security enablement is performed on a local core decision domain through a physical one-way import channel, the local core decision domain completes reasoning calculation in combination with an enablement result in a non-extranet interaction state, a top-layer task scheme is generated, and a top-layer task scheme is generated. Through a multi-mode man-machine interaction mode, after human rigid authorization, issuing to an intranet equipment scheduling domain for execution, and feeding back a state in real time to form a full-link closed loop; the method realizes external network multi-model intelligent security enabling, local agent professional decision and rigid closed loop dominated by human beings in the whole process, aims to solve the problems of cloud dependence, data leakage, out-of-control AI, high cost, poor adaptability and the like, and is suitable for families, industries, confidential scenes, field non-support operation and other scenes.
Owner:吕明成

Partitioned power grid new energy consumption capability assessment method considering power-carbon collaborative optimization

The invention relates to the field of power system operation, and discloses a partition power grid new energy consumption capability evaluation method considering power-carbon collaborative optimization, and the method comprises the following steps: S1, carrying out the modeling of power grid time sequence data and topological information based on a time sequence channel decoupling lightweight graph convolutional network, and obtaining a power grid dynamic partitioning result; s2, on the basis of a semantic perception feature enhancement network, calculating a partitioned power grid security domain on the basis of the partitioning result; and S3, under the constraint of the security domain, carrying out power-carbon collaborative optimization scheduling by using a colistia colony intelligent optimization algorithm. According to the method, a lightweight graph convolutional network is constructed based on a space-time decoupling principle of power grid topology and new energy output, and node electrical association strength is dynamically weighted based on a graph attention mechanism; through a time sequence channel separation method, adaptive optimization of a minute-level power grid partition structure is realized, and the mismatch problem of a fixed partition mode under source load fluctuation is solved.
Owner:NORTH CHINA ELECTRIC POWER UNIV +3

Double-layer collaborative energy management and control method and system for cold plate type liquid cooling data center

The invention discloses a double-layer collaborative energy management and control method and system for a cold plate type liquid cooling data center, and belongs to the technical field of data center energy management. The method comprises the steps that upper-layer day-ahead economic dispatching is based on time-of-use electricity price and outdoor environment temperature prediction, and a server load scheme and a cooling system reference flow track are generated with the minimum total operation cost as the target; in lower-layer intraday dynamic regulation and control, model prediction control is adopted to track the trajectory, the load rate of a server and the rotating speed of a secondary pump are adjusted in real time, and it is ensured that the temperature of a chip is within the safety range of 45-70 DEG C; and the lower layer feeds back the actual chip temperature and energy consumption to the upper layer for online correction of dynamic thermodynamic model parameters to form closed-loop optimization. The system comprises a data acquisition module, a dynamic thermodynamic modeling module, an upper and lower layer optimization control module and an information interaction and feedback module. According to the invention, the overall operation cost and the PUE value of the data center are reduced on the premise of ensuring the temperature safety of the chip.
Owner:BEIJING INST OF TECH