Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

283 results about "Security enhancement" patented technology

Multi-node carbon emission intelligent contract verification method based on block chain

The invention relates to the technical field of data processing, provides a multi-node carbon emission intelligent contract verification method based on a block chain, and aims to solve the problems that data verification in an existing carbon asset transaction system is non-transparent, high in trust cost and difficult to adapt to policy changes. Distributed storage and dynamic verification of data are realized by constructing a hierarchical block chain architecture, the data are collected by using edge computing nodes, and third-party verification data are obtained through an oracle machine node cluster. The dynamic rule engine monitors data changes in real time, triggers a multi-stage verification process, and improves the data accuracy. And meanwhile, an improved Byzantine fault-tolerant mechanism is adopted to reach a consensus, and the system has the functions of strategy dynamic updating and security enhancement, so that the flexibility and security of the system are improved. According to the method, multi-party consensus and real-time verification of the carbon emission data are realized, trust cost of cooperation among enterprises is reduced, and healthy development of a carbon emission permit trading market is promoted.
Owner:LONGYUAN (BEIJING) CARBON ASSET MANAGEMENT TECH CO LTD

Multi-source heterogeneous data dynamic protocol secure exchange adaptation system and method

The invention discloses a multi-source heterogeneous data dynamic protocol security exchange adaptation system, which comprises a protocol analysis engine, a data encryption module, a data format standardization engine and a routing strategy engine, and is characterized in that the protocol analysis engine is respectively connected with a data source, the data encryption module and the data format standardization engine; the data format standardization engine is connected with the routing strategy engine, and the routing strategy engine is connected with the nodes. The invention discloses a multi-source heterogeneous data dynamic protocol secure exchange adaptation method. Comprising the following steps of protocol analysis and data conversion, data encryption and sensitive data desensitization, integrity verification and anomaly detection, routing strategy and intelligent scheduling, data distribution and storage, and dynamic extension and protocol adaptation, and the dynamic conversion of different protocol data ensures that various types of data can be smoothly interacted. Meanwhile, an advanced data security enhancement technology is integrated, multiple protections such as encryption and authentication are carried out on transmitted and stored data, and the data security is effectively improved.
Owner:GUIZHOU AUTO FEDERATION NETWORK TECH CO LTD

Adaptive interference suppression carrier communication system based on complex electromagnetic environment

The invention provides an adaptive interference suppression carrier communication system based on a complex electromagnetic environment, relates to the technical field of communication systems, and solves the problems that an existing communication system is poor in adaptability, weak in anti-interference capability and lack of collaboration and safety in the complex electromagnetic environment. The system comprises an environment perception module used for deeply perceiving an environment and identifying known and unknown interferences by using AI; the cognitive decision engine is used for generating a multi-domain control instruction by utilizing AI according to environment, internal, cooperation and safety states; the self-adaptive transceiving control module is used for executing cross-multi-domain parameter self-adaptive adjustment; the distributed collaborative module is used for realizing information sharing among nodes, federated learning and collaborative resource management; and the endogenous security enhancement module is used for executing active security mechanisms such as dynamic heterogeneous redundancy, mimicry defense and physical layer authentication. The invention further discloses a corresponding communication method. According to the method, the robustness, adaptability, efficiency and safety of a communication system in a complex electromagnetic environment can be remarkably improved.
Owner:SHENZHEN YICHUANG XINGYE TECH CO LTD

Low-sample NL2SQL intelligent generation method and device

The invention relates to the technical field of artificial intelligence, and particularly provides a low-sample NL2SQL intelligent generation method and device, and the method comprises the following steps: S1, enabling a dynamic sample extension module to solve a training data sparse problem in a small sample scene through an intention clarification and data enhancement technology; s2, the clause dependency chain type generation framework converts natural language query into structured query language (SQL) statements with clear structures through semantic analysis, clause generation and dependency modeling; s3, the multi-agent cooperation platform performs iterative optimization through intention recognition, SQL generation and code execution; s4, enabling an automatic evaluation and iteration mechanism to pass a standardized test and continuous optimization; and S5, carrying out field adaptation and security enhancement. Compared with the prior art, the complex query processing capacity can be improved, and the stability and safety of the system are guaranteed through automatic evaluation and a safety mechanism.
Owner:SHANDONG INSPUR CLOUD GOVERNMENT INFORMATION TECHNOLOGY CO LTD

Block chain smart contract cross-domain authentication security enhancement method and system based on AI

The invention relates to the technical field of block chains and artificial intelligence, and discloses an AI-based block chain smart contract cross-domain authentication security enhancement method and system.The AI-based block chain smart contract cross-domain authentication security enhancement method comprises the steps that a hierarchical security architecture comprising a sensing layer, an analysis layer, a decision-making layer and an execution layer is constructed, collecting cross-domain authentication data and transmitting the cross-domain authentication data to an analysis layer; realizing a threat detection model based on deep learning, receiving feature data collected by the sensing layer, and outputting a threat score and an abnormal index; establishing a dynamic trust evaluation mechanism, receiving an output result of the threat detection model, and calculating a real-time trust value between entities; and designing an adaptive authentication strategy optimization algorithm, and dynamically selecting an optimal authentication strategy based on a trust evaluation result, so that the problem of security authentication between heterogeneous block chain networks can be solved, and an efficient and secure cross-domain authentication solution is provided.
Owner:ZHEJIANG HULUWA NETWORK GRP CO LTD

K8s-based intelligent AI platform resource management and scheduling system

The invention belongs to the technical field of resource management and scheduling, and particularly relates to an intelligent AI platform resource management and scheduling system based on K8s. Comprising a dynamic resource prediction module, a K8s cluster management and resource scheduling module, a resource monitoring and analysis module, a resource isolation and sharing module, a computing power resource allocation module, a security enhanced mirror image warehouse and a reasoning early warning system. Through the synergistic effect of the modules, the technical problems of inflexible resource scheduling, insufficient resource monitoring, incomplete user resource isolation, limited computing power distribution, complex mirror image management and incomplete operation and maintenance management of an AI platform in the prior art are solved.
Owner:四川华鲲振宇智能科技有限责任公司

IKE protocol security enhancement method based on PUF dynamic authentication and post quantum hybrid key

The invention provides an IKE (Internet Key Exchange) protocol security enhancement method based on PUF (Physical Unclonable Function) dynamic authentication and a post-quantum mixed key, which organically combines a PUF, a post-quantum cryptographic algorithm (PQC, especially Kyber KEM) and an improved Internet Key Exchange Protocol (IKE) to realize key exchange of post-quantum security and enhanced identity authentication. The method comprises the following steps: generating a dynamic pre-shared key (PSK) by utilizing the PUF; the method comprises the following steps: integrating a Kyber KEM to an IKE protocol, and replacing traditional Diffie-Hellman key exchange; the PUF-driven dynamic PSK is used as an identity authentication method of the IKE; meanwhile, Kyber KEM and ECDH are adopted for key exchange, and a final session key is generated through joint participation of a Kyber negotiation key, an ECDH negotiation key and PSK derived by PUF; and an IKE protocol process is optimized, and Kyber key exchange and PUF (Physical Unclonable Function) authentication are completed in an IKESAINIT stage and an IKEINTERMEDIATE stage. According to the method, key exchange is post-quantum secure, identity authentication is also post-quantum secure, and the final key integrates three key components of Kyber, ECDH and PUF, so that triple security assurance is provided.
Owner:MIXUAN TECHNOLOGY (HANGZHOU) CO LTD

Remote data rapid transmission system and method based on Internet

The invention discloses a remote data rapid transmission system and method based on the Internet, a client initiates a session establishment request containing a session type identifier and a transmission protocol identifier to a server, receives a session response message after transmitting an initial data packet, obtains a temporary session key through verification of a key distribution center, and transmits the session response message to the server; an authorization identifier and a protocol verification symbol are generated through hierarchical decryption, a security enhancement data packet is constructed and sent, an end-to-end encryption transmission channel is further established, and meanwhile, a session maintenance mechanism is provided. And the server verifies a session type identifier and a transmission protocol identifier of the client, generates a session response message containing a dynamic confusion strategy and a trap identifier, submits the session response message to a key distribution center for signature, returns the session response message to the client, activates a secure transmission service instance after verifying a security enhancement data packet, and implements a series of security control strategies. According to the invention, the problems of low transmission efficiency and poor security of the existing remote data transmission system are effectively solved, and efficient and secure data transmission is realized.
Owner:GUANGZHOU KAIYAS TECHNOLOGY CO LTD

Devices, systems, and methods for autonomous threat response and security enhancement

Systems and methods are disclosed for autonomous security enhancement of a tenant network via a managed security service provider (MSSP) server comprising a processor and a memory, with information from a plurality of data sources, the method comprising querying a database or server, upon an encounter with an indicator of compromise (IoC), by a security system, to identify data sources of a plurality of data sources, wherein the data sources include information on the IoC; generating, via the processor, an IoC threat score for the IoC; generating, at least one actionable security enhancement notification based on the IoC threat score; and deploying an automated security response that can comprise displaying the IoC threat score and an actionable security enhancement notification to a user, allowing triggering or disabling of at least one action based on the single IoC threat score.
Owner:BLUEVOYANT LLC

Internet of Things equipment monitoring data stream processing method and system

The invention discloses an Internet of Things equipment monitoring data stream processing method and system. The method comprises the following steps: step 1, collecting and preprocessing multi-source heterogeneous data; step 2, dynamic routing distribution; step 3, edge calculation processing; 4, performing real-time feedback regulation and control; 5, performing anomaly detection and fault tolerance; step 6, data persistence storage; step 7, performing multi-dimensional analysis; and step 8, security enhancement processing. According to the method, intelligent distribution of data streams is realized through the dynamic routing engine, optimal nodes are matched, and resource waste is reduced; the edge computing node cluster completes preliminary screening and filtering, reduces core pressure, adopts an active-active storage subsystem, combines hot and cold storage, reduces cost and guarantees access performance, a safety protection module constructs a full-link safety system, and cooperates with a dual-mode redundancy architecture to improve system availability and fault switching second-level response.
Owner:NANJING NANDA SIWEI TECHNOLOGY DEVELOPMENT CO LTD

Internal and external network security service passing method and system based on edge computing

The invention discloses an internal and external network security service passing method and system based on edge computing, and belongs to the technical field of network security, and the method comprises the steps: obtaining multi-dimensional attribute information of an edge node, generating a security policy basic data set, generating a traffic feature fingerprint and a self-adaptive environment adaptive fingerprint, and calculating a fusion matching degree; edge security entity nodes are generated in combination with service scene adaptive threshold clustering, and then a security policy meta-model with a security policy blueprint as a core is constructed; analyzing the security policy meta-model through a multi-modal semantic analysis engine, generating a dynamic security enhancement model, and mapping the dynamic security enhancement model to a hierarchical security control model; based on the hierarchical model, outputting edge node internal and external network safety passage configuration and a corresponding safety passage ledger through a scenarized configuration generation algorithm; according to the method, adaptive generation, dynamic optimization and accurate execution of the security policy are realized, and the security, the automation level and the operation and maintenance efficiency of internal and external network passing in the edge computing environment are effectively improved.
Owner:HANGZHOU XUNCHUAN TECHNOLOGY CO LTD

Methods and Systems for Security Enhancement in Artificial Intelligence Model Interactions via Automated Injection and Proxy Server Implementation

The present technology relates to a computer-implemented method for enhancing enterprise-wide security when using Artificial intelligence (AI) models. Embodiments involve a JavaScript injection process facilitated by a proxy server. This process does not require manual installation as it is automatically injected during operation. The JavaScript injection process operates by intercepting unsecured AI input and output data provided by users interacting with AI websites. The input and output data are sent to a security Application Programming Interface (API) which applies an enterprise security policy to the data in real-time, thereby transforming unsecured input and output into secure data. Embodiments provide a robust framework for safe interaction with Artificial intelligence models while mitigating the risks associated with the transmission of sensitive information over the internet.
Owner:WITNESSAI INC

Action strategy security enhancement method and device, equipment and medium

The invention relates to the technical field of artificial intelligence, can be applied to business scenes such as agent autonomous decision making, financial science and technology and medical health, and discloses an action strategy security enhancement method, device and equipment and a medium. And generating an initial action strategy through a strategy generation module based on the task target and the fused security perception feature, projecting the initial action strategy to a security constraint space to obtain a security action strategy, monitoring state data of the controlled object in an execution process, and executing an intervention measure when the state data triggers a monitoring threshold. And collecting execution process data and updating a strategy generation module based on the execution process data. According to the method, the initial action strategy is generated through fusion of the multi-modal sensing information and the task target, and the safety of task execution of the robot in a complex environment is improved by combining the safety constraint space projection, the state monitoring and the data feedback updating strategy generation module.
Owner:PING AN TECH (SHENZHEN) CO LTD

Public multi-mode cloud network resource software security enhancement method based on neural symbol fusion reasoning

The invention relates to a public multi-mode cloud network resource software security enhancement method based on neural symbol fusion reasoning, which comprises the following steps: an intermediate representation generation stage: generating and optimizing an intermediate representation of a program through a fine-tuned large language model, and establishing semantic mapping from a source code to a structured logic representation; in the symbol language conversion stage, the intermediate representation generated by the large language model is converted into a domain-specific language fact set which can be recognized in the symbol logic reasoning stage, and formal and logic expression of program semantics is achieved; and a symbol logic reasoning stage: matching the fact set with the rule base through a symbol logic reasoning engine, performing detection and verification according to the safety rule, generating a structured report, and feeding back a result for optimization. The method is suitable for security enhancement of various core software systems in a public cloud network multi-modal network environment, high-precision security analysis is carried out on cross-modal and cross-subsystem fragmented codes in a compiling-free environment, and verifiable technical support is provided for public cloud network security control.
Owner:PEKING UNIV

Dynamic double-layer hidden watermark and encryption binding file protection method and system based on deep learning

The invention relates to a dynamic double-layer hidden watermark and encryption binding file protection method and system based on deep learning, and belongs to the technical field of digital content security. The problems of attack resistance, traceability obstruction and key-watermark unhooking in document cross-platform circulation are solved. According to the scheme, the method comprises the following steps of: extracting semantic fingerprints by using a sentence vector model Sentence-BERT; the fuzzy extractor generates a master key and derives a time key chain; the authentication encryption algorithm AEAD encrypts and binds the source and the timestamp load; container layer structure rearrangement and document layer zero-width character double embedding are carried out; the generative adversarial network or diffusion model adversarial training improves the optical character recognition and transcoding resistance; version binding and tracing are achieved through the watermark hash chain. The technical effects cover anti-counterfeiting migration, cross-layer fault-tolerant guarantee recoverability, rearrangement attack resistance, full-period accurate traceability and post-quantum security enhancement.
Owner:SOUTHWEST UNIV

Modbus protocol security enhancement method in multicast communication scene

The invention discloses a Modbus protocol security enhancement method in a multicast communication scene, which comprises the following steps: when a master node initiates an identity authentication request, the master node calculates a first message authentication code of a first random number according to a session key; wherein the session key is obtained according to random numbers pre-generated by the master node and the slave node; broadcasting and sending the encrypted session key and the first message authentication code to each slave node; the slave node decrypts the encrypted session key, and calculates a second message authentication code of the first random number according to the obtained session key; when the message authentication codes are the same, authenticating the identity of the main node; the slave node calculates a third message authentication code of the second random number by using the session key, and sends the third message authentication code to the master node; the main node uses the session key to calculate and obtain a fourth message authentication code of each second random number; and when the message authentication codes are the same, authenticating the identity of the corresponding slave node. According to the invention, the identity verification efficiency is improved, and the safety and reliability are improved.
Owner:XIDIAN UNIV

Large model content security multi-level defense method

The invention provides a large-model content security multi-level defense method. The method comprises the steps that an input-processing-output full-link multi-stage cooperative defense framework is constructed, and the full-link multi-stage cooperative defense framework receives to-be-detected user input data and transmits sensitive word detection passing content to an intention recognition module; the intention identification module judges the risk level of the user input data, and routes the user input data identified as medium and high risks to the risk label classification module; the risk label classification module performs risk category classification on the user input data, and transmits the user input data subjected to risk category classification to the security enhancement module; and the security enhancement module generates compliant system response content through a domain fine tuning and reinforcement learning strategy, and returns the system response content to the user after performing security interception processing on the system response content. Through hierarchical defense, dynamic routing and security enhancement module training, a large model security enhancement scheme covering the whole process of input, reasoning and output is constructed.
Owner:BEIJING ZERO ONE EVERYTHING INFORMATION TECHNOLOGY CO LTD

Intelligent agent system and method based on MCP technology

The invention relates to the technical field of computer networks, in particular to an intelligent agent system and method based on the MCP technology, and the system comprises an MCP intermediate layer protocol engine, an intelligent scheduling module, a channel management system, a security enhancement mechanism and an edge node self-learning mechanism. The method has the beneficial effects that support for various communication protocols (such as HTTP, MQTT, gRPC and the like) is realized through the MCP technology. Through the protocol adapter module, the system can automatically identify and load different protocol adapters, and parallel work of multiple protocols can be supported without manual intervention. The multi-protocol support greatly improves the flexibility of the system, so that the system can be seamlessly connected with equipment of different manufacturers and standards, and the requirements of complex and diverse application scenes are met.
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

Policy control security enhancement method and device, computer equipment and storage medium

The invention relates to a policy control security enhancement method and device, computer equipment, a computer readable storage medium and a computer program product. The method comprises the following steps: acquiring a policy request initiated by an external entity to a policy control plane in a cross-multi-cloud or cross-domain environment; extracting multi-dimensional features from request data carried in the strategy request, and constructing a multi-dimensional feature map according to the multi-dimensional features; performing anomaly detection on the strategy request according to the multi-dimensional feature map to generate a threat judgment result; under the condition that the threat judgment result shows that the strategy request is normal, performing semantic, resource and authority triple verification on the strategy request to generate a verification judgment result; and under the condition that the verification judgment result shows that the strategy request is verified successfully, issuing the strategy to the target execution point and enabling the strategy to take effect, thereby completing strategy life cycle management. By adopting the method, the security robustness, privacy compliance and cross-domain cooperation efficiency of the strategy control system can be improved.
Owner:CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1

Quantum-resistant security enhancement method for transport layer security protocol

A quantum-resistant security enhancement method for a transport layer security protocol, comprising: (011) acquiring a first quantum key and a quantum key identifier from a serving node; (012) performing post-quantum cryptographic encryption on the quantum key identifier to obtain a first encryption result, and sending the first encryption result to a network device; (013) decrypting a received second encryption result to obtain a second decryption result; (014) obtaining a first terminal handshake key and a first network device handshake key on the basis of the first encryption result and the second decryption result; and (015) generating a second terminal handshake key and a second network device handshake key on the basis of the first quantum key, the first terminal handshake key, the first network device handshake key, the first encryption result and the second decryption result, so as to encrypt communication between the terminal and the network device.
Owner:CHINA TELECOM QUANTUM INFORMATION TECH GRP CO LTD

Cloud instance privacy security enhancement method based on security channel dynamic measurement

The invention discloses a cloud instance privacy security enhancement method based on security channel dynamic measurement, and the method comprises the steps: building a secure and credible communication channel through a secure communication client, and connecting the communication channel to a local user side through the Internet; a local user side deploys a TPCM secure communication module which is responsible for secure communication with the multi-cloud service rental instance. And the trusted software base is responsible for maintaining a measurement strategy and performing measurement judgment and control when a user process runs in the cloud service lease instance. The system specifically comprises a judgment mechanism module, a control mechanism module, a measurement mechanism module and a credible reference library. On the premise that infrastructures of cloud service providers are not trusted, in order to achieve safety and credibility of user remote cloud service lease instance data and application during operation and privacy protection of users, a measurement agent and a safety communication client are deployed in a cloud service lease instance; meanwhile, the tenant can perform deep monitoring on the process in the cloud instance, and it is ensured that sensitive information such as a monitoring strategy and reference data is not exposed to a cloud service provider.
Owner:BEIJING UNIV OF TECH

Methods and systems for security enhancement in artificial intelligence model interactions via automated injection and proxy server implementation

The present technology relates to a computer-implemented method for enhancing enterprise-wide security when using Artificial intelligence (AI) models. Embodiments involve a JavaScript injection process facilitated by a proxy server. This process does not require manual installation as it is automatically injected during operation. The JavaScript injection process operates by intercepting unsecured AI input and output data provided by users interacting with AI websites. The input and output data are sent to a security Application Programming Interface (API) which applies an enterprise security policy to the data in real-time, thereby transforming unsecured input and output into secure data. Embodiments provide a robust framework for safe interaction with Artificial intelligence models while mitigating the risks associated with the transmission of sensitive information over the internet.
Owner:WITNESSAI INC

In-memory encryption method based on cross-point array ferroelectric capacitor array

The invention discloses an in-memory encryption method based on a cross-point array ferroelectric capacitor array, and belongs to the field of data security and computing security. According to the invention, a cross-point array ferroelectric capacitor FeCAP array is respectively adopted as a key array and a complementary key array, and array-level XOR operation is executed between a plaintext and a key by the generated operation through a diagonal data coding mode and a coupling signal subtraction circuit, so that high-parallel XOR encryption in a memory is realized. And data decryption can be symmetrically realized by applying the ciphertext to the input and using the same key array and the complementary key array. In combination with the artificial intelligence calculation accelerator based on the cross point array ferroelectric capacitor array, high-density, high-energy-efficiency and data security enhanced in-memory calculation application can be realized.
Owner:PEKING UNIV

Systems and methods for financial risk assessment and digital security enhancement

Provided are methods, systems, and devices for financial risk assessment and digital security enhancement. This includes receiving, at the host processor via the computing network, a plurality of input signals from a plurality of primary systems, the input signals corresponding to a client identifier to generate a corresponding first record; analyzing the corresponding first record, to extract a corresponding second record by implementing a plurality of predefined tags and generating a categorized record; receiving physical asset signals, associated to the client identifier, from an external asset system; generating a qualifier score based on a predictive algorithm applied to the categorized record and the physical asset signals, the predictive algorithm assigning weights to the plurality of data categories in the categorized record; and determining whether the qualifier score meets a one or more threshold range.
Owner:CLOSERLY INC

Dynamic cybersecurity scoring and operational risk reduction assessment

A system and method for operational and cyber risk assessment that utilizes a data-driven approach to evaluate the current security posture and identify areas for improvement based on the user's desired target profile. This process involves estimating the costs and benefits associated with various security program enhancements, increased, hiring, and control uplifts. The system and method then quantify these benefits in terms of reduction in tail value at risk, expected losses, cyber insurance premiums, and the amount of risk capital set aside. The system simulates attack paths associated with various risk scenarios and uses a risk scenario model to compute losses associated with each attack path for each risk scenario. The results of the simulation may be used to determine one or more business outcomes associated with the costs and benefits of implementing security enhancements.
Owner:QOMPLX INC

TLS1.3 protocol security enhancement method and system based on homologous cryptographic algorithm

The invention discloses a TLS1.3 protocol security enhancement method and system based on a homologous cryptographic algorithm, and the method comprises the steps: 1), certificate generation: signing and issuing a certificate through an SQISign signature algorithm, and guaranteeing the verification and use of a post-quantum security signature algorithm through the certificate; and 2) protocol design: the client and the server complete identity verification through certificate verification based on an SQISign signature algorithm in a handshake stage of a TLS 1.3 protocol. And the server uses a FleS public key encryption algorithm to carry out key encapsulation and send the key encapsulation to the client, completes key exchange and establishes secure encryption connection with the client. The step 1) and the step 2) comprise compatibility design, and a homology-based post-quantum algorithm and a traditional cryptographic algorithm are allowed to coexist, so that the compatibility of an existing system is ensured. Through the method provided by the invention, the TLS 1.3 protocol can effectively resist security threats brought by quantum computing, the security of network communication in the quantum era is ensured, and meanwhile, the smooth transition of the existing system is ensured.
Owner:WUHAN UNIV

Semantic communication security enhancement system based on SIM (Subscriber Identity Module) card quantum key presetting

The invention relates to the technical field of mobile communication, and particularly provides a semantic communication security enhancement system based on SIM card quantum key presetting, comprising an SIM card security base module configured to generate physical unclonable function characteristics and preset quantum security keys by using SIM card hardware characteristics; the lightweight authentication protocol module is in communication connection with the SIM card security base module and is configured to realize dynamic identity authentication based on physical unclonable function characteristics and a quantum security key; the semantic security enhancement module is configured to perform privacy protection processing on the semantic communication data; the trusted execution environment optimization module is in communication connection with the SIM card safety base module and the lightweight authentication protocol module and is configured to construct a hardware-software collaborative trusted execution environment; the quantum security enhancement module is integrated on the SIM card security base module and is configured to provide quantum attack resistance and dynamic key management; according to the invention, the real-time performance and anti-quantum computing capability of key distribution are significantly improved.
Owner:CHINA MOBILE INTERNET CO LTD +1

Card binding security enhancement system and method fusing radio frequency fingerprint and PUF (Physical Unclonable Function)

The invention provides a radio frequency fingerprint and PUF fused machine card binding security enhancement system and method, the system comprises a terminal side device and a network side device deployed at a 5G mobile communication system air interface, the terminal side device is provided with an SIM card and an interaction processing module, and the SIM card comprises a PUF processing module and a password and data processing and forwarding module; after the terminal side device obtains the special identity identification code of the terminal, the identification code is used for generating a private key through a physical unclonable function (PUF) of the SIM card; the network side device is provided with a base station and a core network, a radio frequency fingerprint processing module, a password and data processing and forwarding module and a functional module are added inside or outside the core network, and secondary identity authentication, encryption and forwarding of the terminal are realized based on radio frequency fingerprint identity feature information; the special identity identification code of the terminal does not need to be stored for a long time, and the private key does not need to be locally stored, is easy to pad at a time, is regenerated by the PUF every time and is deleted after being used, so that an attacker cannot obtain the key, and the overall security is improved.
Owner:MILITARY SECRECY QUALIFICATION EXAMINATION & CERTIFICATION CENT +1

Simplified duplicate removal and security enhancement system and method for AI mirror image

The invention belongs to the technical field of AI and containers, and discloses a simplified duplicate removal and security enhancement system and method for an AI mirror image. The method comprises the steps of recording an access event of a container to a file system, and performing file clipping; partitioning and storing the mirror image file based on a content partitioning algorithm; an index structure is optimized, so that the data retrieval efficiency is improved; when a user requests the container mirror image, the system performs security scanning on the container mirror image through a parallel processing and static analysis method, and automatically updates the outdated software package in the container, thereby preventing potential security risks caused by the outdated software package. According to the method, through triple technologies of dynamic behavior monitoring, three-mask content block deduplication and parallelization vulnerability repair, edge node mirror image pulling time delay is effectively reduced, and distributed training deployment is accelerated; the storage pressure of a mirror image warehouse is reduced and the resource utilization rate is improved; and the method is suitable for scenes such as AI model cloud edge collaborative deployment and the like.
Owner:NANJING INFORMATION HIGH-SPEED RAILWAY RES INST OF SCI AND TECH

Anti-quantum security enhancement method for SSL VPN protocol

An anti-quantum security enhancement method for an SSL VPN protocol of a communication network. The method comprises: (011) acquiring a first quantum key and a quantum key identifier from a first network node that has accessed a network device; (012) performing post-quantum cryptographic encryption processing on the quantum key identifier, and sending a first encryption result of the post-quantum cryptographic encryption processing to a terminal; (013) decrypting a received second encryption result sent by the terminal, so as to obtain a second decryption result; (014) obtaining a first master key on the basis of the first encryption result and the second decryption result; and (015) generating and obtaining a second master key on the basis of the first master key, the first encryption result, the second decryption result, and the first quantum key, so as to encrypt communication between the network device and the terminal.
Owner:CHINA TELECOM QUANTUM INFORMATION TECH GRP CO LTD