Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

31 results about "Security enhancement" patented technology

Method and system for transforming security advisories into targeted mitigation strategies

PendingUS20260181010A1Securing communicationSecurity enhancementInteraction model
A computer-implemented method for transforming security advisories into targeted actionable mitigation strategies is provided. The method includes receiving a security advisory describing a vulnerability, processing the security advisory using a first language learning model (LLM) to extract vulnerability characteristics, generating an interaction model of sub-systems within a target system based on a topology of the target system, generating at least one actionable mitigation strategy for the vulnerability using a fine-tuned second LLM based on the extracted vulnerability characteristics and the interaction model, and outputting the actionable mitigation strategy as a security enhancement implementable on the target system. The method enables customized security enhancements for systems lacking official patches or manufacturer support.
Owner:SIEMENS INDUSTRY INC

Intelligent Security Situation Awareness Method and System Based on Multidimensional Data Analysis

This application provides an intelligent security situation awareness method and system based on multidimensional data analysis, relating to the field of network security technology. The method includes: classifying, filtering, and fusing attack event databases of wireless communication networks to determine multidimensional attack drill schemes; conducting attack drills on virtual communication networks according to the multidimensional attack drill schemes; performing attack and defense situation fusion modeling based on the multidimensional drill dataset to obtain a multidimensional drill attack and defense confrontation model; introducing a security situation assessment index system to conduct security situation awareness on the multidimensional drill attack and defense confrontation model, constructing a multidimensional drill security situation profile; and performing enhanced security management of the wireless communication network. This application solves the technical problem in existing technologies where the disconnect between attack and defense drills and the actual network environment leads to the inability to timely identify complex new attacks, affecting the accuracy of security situation awareness. It comprehensively improves attack identification capabilities, enhances the practicality of attack and defense drills, and improves network security protection efficiency.
Owner:ZHEJIANG CHUANGZHI TECH CO LTD

AI and security enhancements to a secure, compliant electronic trading platform using the open outcry methodology

A secure, compliant trading platform for securities exchange using the open outcry methodology within a secure electronic exchange environment that reduces or eliminates unfairness and opportunities for fraud within the marketplace. Enhancements to the system include the addition of an exchange blockchain for recording all trade events, smart contracts that allow the use of digital currencies for monetary transactions associated with trades, and an intelligent exchange assistant that monitors the exchange member's activity and offers contextual notifications and makes recommendations in real-time to assist the exchange member. The system assures that private information is retained private and the blockchain records immutable data that is used for compliance checking and performance analytics.
Owner:MELKOMIAN RAYMOND MICHAEL

A Hybrid Quantum-Resistant Security Enhancement Method for IPSec VPN

PendingCN122372190AKey exchangeData pack
This invention proposes a hybrid quantum-resistant security enhancement method for IPSec VPNs. The method includes: intercepting Internet Key Exchange (ITE) packets and adding a proxy header between the transport layer header and the ISE payload of the packets; obtaining a quantum key from a key pool using quantum key distribution technology and generating a first-stage session key based on the quantum key; protecting the ISE key negotiation process using a quantum-resistant cryptographic algorithm to generate a second-stage session key; and using the first-stage and second-stage session keys as input parameters for a key derivation function to generate a final session key for encrypted data transmission. This invention, without modifying the original IPSec negotiation process, supports dynamic key combinations of different security levels, enhancing the quantum security protection capability of VPN data transmission while maintaining system flexibility and performance.
Owner:CHINA MOBILE COMM GRP CO LTD +3

Proxy interception and double encryption system and methods

A method of enabling custom cryptography is provided. The method can include sending, by a first computing device and to a second computing device, instructions to initiate a proxy. The proxy can be configured to intercept a message of a user agent. The user agent may be associated with the second computing device. The proxy can be further configured to perform custom cryptography based on the message to obtain a modified message. The custom cryptography may comprise post-quantum cryptography. The proxy can be further configured to send the modified message to at least one of the user agent, a reverse proxy, or a third computing device. The post-quantum custom encryption and / or decryption can comprise Quantum Secure Layer (QSL), Post-Quantum Transport Layer Security (PQTLS), Kyber, SABER, Enhanced McEliece, RLCE, or a National Institute of Standards and Technology (NIST) candidate post-quantum algorithm.
Owner:QUSECURE INC

A safe and efficient model co-construction method

ActiveCN116488906BEdge serverData mining
The application relates to a safe and efficient model co-construction method, and belongs to the field of artificial intelligence. The method comprises the following steps: regional division: each edge server divides a responsible management region according to the range coverage capacity thereof; system initialization: a global model and a key generation are initialized; local model training: model updating is calculated according to local data of equipment, and gradient information is disturbed and returned; edge security robust aggregation: a communication-efficient security-enhanced aggregation protocol is designed to support the implementation of an asynchronous grouping robust aggregation algorithm based on disturbed gradients; cloud global model aggregation: local model aggregation results returned by each edge server are received, and a federal average algorithm is executed to perform global model aggregation. The application can effectively improve the robustness and security of a global model under the condition that a client exists device heterogeneity and resource limitation.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

A method and device for unmanned aerial vehicle group communication based on data privacy protection

PendingCN122458015AInformation spaceData privacy protection
The application provides a kind of unmanned aerial vehicle group communication method and device based on data privacy protection, belong to network security technical field, corresponding method includes: the layered unmanned aerial vehicle group network communication model of pre-generation is trained in coordination strategy;In the communication physical layer of layered unmanned aerial vehicle group network communication model, the layered unmanned aerial vehicle group network communication model after multi-agent reinforcement learning is physically encrypted according to the difference of maximum legal channel and eavesdropping channel;In the algorithm layer of layered unmanned aerial vehicle group network communication model, the lower cluster head is monitored by the upper cluster head, and the lower cluster head is switched according to whether the lower cluster head is attacked.This application provides a kind of data and algorithm security and evaluation method for unmanned cluster communication for the attack form of complex information space, realizes the security enhancement of data available invisible and intelligent algorithm, to effectively improve the security and survivability of unmanned cluster under the security threat of complex information space.
Owner:YUNSHAN INTELLIGENT CONTROL (BEIJING) TECHNOLOGY CO LTD

Quantum security enhanced zero-trust encryption tunnel construction method and system

The application relates to the field of quantum key distribution and network security technology, in particular to a zero-trust encryption tunnel construction method and system based on quantum security enhancement. In the system, a QKD key management unit binds a global timestamp to a pre-distributed key by using the natural synchronization characteristics of quantum key generation, realizing high-precision time synchronization at both ends of communication; a local AI risk inference unit deploys a lightweight model optimized by quantitative distillation, completing real-time inference of local security risks at the edge; a double-rail encryption tunnel unit constructs parallel double tunnels and realizes adaptive scheduling of encryption resources through dynamic bandwidth allocation; a dynamic switching control unit realizes seamless switching of the encryption tunnel through handshake-free tunnel switching and state verification rollback; and a mobile adaptation processing unit completes high-probability link key pre-distribution based on trajectory prediction, realizing efficient adaptation of the key of the mobile terminal, so that the real-time performance, stability, bandwidth utilization and key resource use efficiency of the encryption communication are improved.
Owner:BEIJING XINDA WANGAN INFORMATION TECH CO LTD

Client-server security enhancements using information accessed from access tokens

PendingCN122072722ADigital data authenticationSecuring communicationInformation accessServices computing
A service computing system receives an API call, where an authorization token is included in a header of the API call, the authorization token including an identifier in content. The identifier is also included as a parameter that is introduced with the API call. The service computing system parses the API call to obtain an authorization token, and an identifier included in the authorization token. It also obtains an identifier that is introduced as a parameter of the API call. The service computing system compares an identifier obtained from the authorization token to an identifier introduced as a parameter of the API call to determine if they match. If they do not match, the API call will be processed as an unauthorized API call. A security system in the service computing system authorizes the API call based on the comparison.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Systems, methods, devices, processors, and media for implementing intrinsic dynamic security enhancements to the MCP protocol based on commercial cryptographic algorithms.

This invention relates to a system for implementing intrinsic dynamic security enhancement of the MCP protocol based on commercial cryptographic algorithms. The system includes an internet client, an internet access gateway cluster, an MCP server, and a backend API. The internet client includes an AI application unit and an MCP client. The internet access gateway cluster includes a Layer 4 load balancing gateway and a Layer 7 load balancing gateway. The MCP server receives and processes securely verified MCP requests, encapsulates and invokes tools and data sources. The system, method, apparatus, processor, and computer-readable storage medium employing this invention, based on national commercial cryptographic algorithms, provide intrinsic dynamic security enhancements for MCP protocol interaction between AI clients and AI servers, including identity authentication, data transmission encryption, and integrity protection. This system is widely applicable to AI interaction scenarios with high security requirements, such as fintech and smart government, building a secure, reliable, and compliant communication foundation.
Owner:GUOTAI JUNAN SECURITIES CO LTD

Implementation method and system of a fully reference frame independent quantum key distribution protocol

This invention discloses a method and system for implementing a completely reference-frame-independent quantum key distribution protocol, belonging to the field of quantum information technology. Alice and Bob, the communicating parties, randomly select mutually unbiased basis vectors to prepare quantum states and send them to a third party, Charlie. Charlie performs Bell state projection measurements and announces the success. Both parties publish the basis vector information, divide the dataset, and calculate the gain and bit error rate. A 3×3 correlation tensor matrix is ​​constructed and singular value decomposition is performed to obtain three reference-frame-independent singular values. The secure key rate is calculated based on the bit error rate. Finally, key negotiation and security enhancement are performed to extract the secure key. This invention does not require basis vector alignment, completely eliminating the dependence on reference frame calibration. It can still stably generate keys even with basis vector drift, and the amount of information required by eavesdroppers is lower, significantly improving the practicality and security of the quantum key distribution system.
Owner:JIANGSU OPEN UNIVERSITY (THE CITY VOCATIONAL COLLEGE OF JIANGSU)

Security enhancement methods and systems for the IEC 104 protocol on the master station side of power monitoring systems

PendingCN122339686AIEC 62351Embedded system
This invention discloses a security enhancement method and system for the IEC 104 protocol on the master station side of a power monitoring system, comprising: generating input data, dynamically selecting a security mode and issuing configuration commands, generating original ASDU messages, calling application-layer security plugins to generate enhanced ASDU messages, encapsulating them into complete APDUs, generating security messages via transport-layer security plugins, and sending them to the station. This invention adopts a plug-in embedded architecture, integrating IEC 62351-5 application-layer and IEC 62351-3 transport-layer security plugins into the protocol processing module and communication processing module respectively, achieving decoupling of security functions and business functions; establishing a policy-driven mechanism, adding a security policy management module and an operation monitoring module, and providing port differentiation to adapt to different terminals to meet the needs of gradual transformation; controlling terminal concurrent connection latency at the millisecond level to meet the needs of large-scale high-concurrency access at the master station, and establishing a layered security protection system that coordinates the transport layer and application layer, ensuring message security even if transport layer security fails.
Owner:NARI NANJING CONTROL SYSTEM CO LTD +1

A processor data prefetch security enhancement method to mitigate cache side-channel attacks

ActiveCN116720191BHigh degree of securitysuppress interferenceMemory addressLoad instruction
This invention discloses an Aware+Fuzz method for enhancing processor data prefetch security to mitigate cache side-channel attacks, belonging to the field of processor chip microarchitecture design. This method includes an attack awareness module and an observation obfuscation module. During program execution, the attack awareness module dynamically detects key load instructions that may belong to the first stage of a cache side-channel attack and activates the observation obfuscation module. In subsequent program execution, the observation obfuscation module dynamically detects key load instructions that may belong to the third stage of the attack, records and learns the memory addresses probed by the attacker, triggers corresponding prefetching, and obfuscates the attacker's memory observations. The prefetched data disrupts the attacker's judgment of the victim program's memory usage, thereby significantly reducing the attacker's success rate and improving the security performance of the processor system.
Owner:SOUTHEAST UNIV

A webassembly model protection system for browser security inference

PendingCN122241686APlatform integrity maintainanceProgram/content distribution protectionBrowser securityComputational logic
This invention provides a WebAssembly model protection system for browser-based secure inference. The system, through the collaborative work of a model parsing and storage module, a model conversion and compilation module, a security enhancement module, and a front-end API generation module, converts model files from different machine learning training frameworks into WebAssembly model files that can run independently in the browser. During the conversion process, it integrates and encapsulates model structure information, model weight information, and model computation logic, and enhances their security, achieving comprehensive security protection for the front-end model. This invention, by integrating model format conversion, WebAssembly compilation, and customized obfuscation technologies, constructs a highly secure and practical Web model protection system, significantly improving the resistance to reverse engineering of Web machine learning models, effectively preventing model theft and tampering risks, and is suitable for the secure deployment of AI applications on various browsers.
Owner:NANJING UNIV OF AERONAUTICS & ASTRONAUTICS

An AI large model-oriented sharded blockchain federated learning method

The application discloses a kind of sharding blockchains federated learning methods for AI big model, belong to information security field, the application designs the scalable big model training architecture based on sharding blockchains and federated learning, with the aid of sharding blockchains technology, the scalability of federated learning system is guaranteed from architecture level.Based on the multi-piece collaborative model aggregation scheme SP of four-pipeline two-stage commitment, which includes multi-signature aggregation protocol MASign, pipeline mode intra-chip consensus protocol MulPipe-BFT based on improved BLS multi-signature, and inter-chip transaction processing protocol QuadPipe-Sharding based on four-pipeline mode multi-signature aggregation.The application designs a federated learning endogenous security enhancement technology composed of uniform noise adding technology, phased encryption technology and Bipole double filter, which resists data recovery attacks, free riding attacks and poisoning attacks and other risks faced during federated learning training process.
Owner:BEIHANG UNIV

Front-end full-link data burying method and system based on worker pool intelligent scheduling for xinchuang environment, medium, program product and terminal

This application provides a method, system, medium, program product, and terminal for front-end end-to-end data tracking based on intelligent scheduling using a Worker pool for the domestic IT innovation environment. It obtains multi-dimensional features and constructs an environment profile in the main thread; creates an intelligent Worker pool based on the environment profile; obtains end-to-end tracking tasks in the main thread or the intelligent Worker pool; dynamically routes the end-to-end tracking tasks to the intelligent Worker pool using a preset intelligent dispatcher; constructs a data processing flow based on security information in the environment profile; performs data security processing operations on the tracking data of the end-to-end tracking tasks in the intelligent Worker pool to obtain processed tracking data; detects the network status of the domestic IT innovation environment; and performs upload processing or storage waiting operations on the processed tracking data based on the detection results. This application achieves adaptive scheduling, security enhancement processing, and reliable reporting of end-to-end front-end tracking tasks in the domestic IT innovation environment.
Owner:SHANGHAI NAT GRP HEALTH TECH CO LTD

Methods and systems for encryption and integrity protection of page tables in input / output memory management units

ActiveCN122020694BConfidentialityAttack
This application proposes a method and system for encrypting and protecting the integrity of page tables in an Input / Output Memory Management Unit (IOMMU), relating to computer technology and data processing technology. The method includes: allocating page tables for a new security domain Input / Output Address Space Identifier (IOASID) and generating plaintext basic page table entries; determining the corresponding page table protection key based on the security domain IOASID and obtaining a hardware-maintained monotonic security version number; obtaining the encryption result and message authentication code through hardware encryption and integrity calculations of the security-enhanced IOMMU based on the page table protection key, IOASID, and monotonic security version number; and encapsulating the encryption result, message authentication code, and monotonic security version number into an enhanced encrypted page table entry and writing it into system memory. This application protects the confidentiality and integrity of the IOMMU page tables in a trusted execution environment, performs low-latency page table decryption and integrity verification without software intervention, and defends against malicious attacks.
Owner:BEIJING VCORE TECH CO LTD

A method and system for controlling the permission of a container cross-domain access to a host hardware service

PendingCN122119938ASecuring communicationComputer hardwareConfigfs
The application provides a permission control method and system for a container to access a host hardware service across domains, determines the number of slots in a host system configuration file, and generates slot identifiers, hardware service context mapping rules, security enhanced Linux type definition files, access control permission rules, and cross-slot prohibition rules to compile the host system, to generate a host system image; modifies key functions in a hardware interface definition language base library on the container side and compiles them into a container system image; when any container is started, an idle slot is found from a slot allocation table, the corresponding slot identifier is allocated to the started container, and all processes in the container are controlled to run in a security domain of the idle slot; a verification hook function is registered in a hardware service manager of the host system to perform consistency verification on caller process information and slot information in a complete service name, to obtain a verification result; and the risk of out-of-bound access and privilege escalation is reduced.
Owner:HUNAN XIAOSUAN TECH INFORMATION CO LTD

Methods and Systems for Security Enhancement in Artificial Intelligence Model Interactions via Automated Injection and Proxy Server Implementation

The present technology relates to a computer-implemented method for enhancing enterprise-wide security when using Artificial Intelligence (AI) models. Embodiments involve a JavaScript injection process facilitated by a proxy server. This process does not require manual installation as it is automatically injected during operation. The JavaScript injection process operates by intercepting unsecured AI input and output data provided by users interacting with AI websites. The input and output data are sent to a security Application Programming Interface (API) which applies an enterprise security policy to the data in real time, thereby transforming unsecured input and output into secure data. Embodiments provide a robust framework for safe interaction with Artificial Intelligence models while mitigating the risks associated with the transmission of sensitive information over the internet.
Owner:WITNESSAI INC

Blockchain data provenance protection and contribution calculation system

PendingCN122268564Aachieve fairnessimprove objectivitySecuring communicationResearch dataData scheduling
The application belongs to the technical field of military research data management, and discloses a data right protection and contribution calculation system of a block chain, which comprises: an application layer, which is used for providing trusted military research data based on a block chain core layer to realize data evidence, whole-process operation tracing, multi-dimensional contribution calculation and auditing functions for a collaborative research and development scene; an enhanced component layer, which is used for providing management services, data scheduling, user access and security enhancement support for the application layer; a block chain core layer, which is used for providing block chain basic capabilities supporting multi-chain collaboration, high-throughput consensus, automatic execution of intelligent contracts, national secret level security protection and trusted node management; and an infrastructure layer, which provides computing, storage and network resources for the application layer, the enhanced component layer and the block chain core layer. The application realizes data right protection and contribution calculation by adopting block chain encryption algorithms, consensus mechanisms, distributed ledgers and intelligent contracts and other technologies.
Owner:姚远

A random number generation security enhancement method and device based on a degenerate state mapping

PendingCN122308791ALinear relationshipComputational physics
This invention belongs to the field of information security and random number generation technology, and relates to a method and apparatus for enhancing the security of random number generation based on degenerate state mapping. The method includes: establishing the parameter space and energy level boundaries of a virtual quantum system in a classical computer, and initializing a basic pseudo-random number generator (PRNG); compressing and mapping the integer output of the PRNG to virtual quantum state indices; calculating feedback perturbations using the output values ​​of the previous round, correcting the indices, and dividing the energy levels and degenerate indices to obtain virtual quantum state labels; obtaining new random numbers from the PRNG, generating different degenerate indices within the same energy level, and constructing new virtual quantum states; calculating observable eigenvalues ​​in conjunction with measurement perturbations, processing them according to the measurement mode, and outputting the random numbers for the current round; iterating until the quantity requirement is met. It can sever linear relationships and has advantages such as time-varying mapping, removal of deterministic correlations, irreversible enhancement, configurable parameters, low hardware dependence, and compatibility with existing PRNGs.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Password security enhancement detection method and device, terminal and storage medium

Embodiments of the present application disclose a password security enhancement detection method, device, terminal and storage medium, the method comprising: receiving a login request, starting a core daemon process of user login; loading a PAM module by using the core daemon process of user login; parsing the login request to obtain login user information; finding a corresponding Linux system login record file according to the login user information by using the PAM module; judging whether the login user is a first-time login according to the Linux system login record file; and triggering password expiration setting when it is the first-time login. The method does not depend on manual setting by an administrator, and reduces the complexity of system management and operation and maintenance cost.
Owner:KYLIN CORP

Method and system for transforming security advisories into targeted mitigation strategies

PCT designated stageWO2026142817A1Security enhancementInteraction model
A computer-implemented method for transforming security advisories into targeted actionable mitigation strategies is provided. The method includes receiving a security advisory describing a vulnerability, processing the security advisory using a first language learning model (LLM) to extract vulnerability characteristics, generating an interaction model of sub-systems within a target system based on a topology of the target system, generating at least one actionable mitigation strategy for the vulnerability using a fine-tuned second LLM based on the extracted vulnerability characteristics and the interaction model, and outputting the actionable mitigation strategy as a security enhancement implementable on the target system. The method enables customized security enhancements for systems lacking official patches or manufacturer support.
Owner:SIEMENS INDUSTRY INC

Privacy preserving data aggregation method for safety enhancement in intelligent transportation systems

The application discloses a privacy protection data aggregation method for security enhancement in an intelligent transportation system, which realizes vehicle position privacy and data privacy protection by adopting the Chinese remainder theorem, a Paillier encryption system and T-N threshold secret sharing technology, and simultaneously obtains statistical results of mean and variance; in addition, the threshold secret sharing improves the security of a server, and ensures that an attacker cannot obtain aggregation data of the server in the case of compromising less than a threshold number of servers; finally, identity signature technology with batch verification is adopted to realize data integrity and identity authentication in a communication process. On the basis of realizing data aggregation, protecting vehicle position privacy and data privacy, the method obtains more data analysis results, and improves the ability of the server to resist single-point attacks.
Owner:ANHUI NORMAL UNIV

A multi-level hash chain hybrid signature method and device

PendingCN122457259AData packAlgorithm
The application provides a multi-level hash chain hybrid signature method and device, and belongs to the field of digital signature. The method comprises the following steps: generating a unique session ID and session context, reading a homologous quantum root key; obtaining a PUF negotiation root key and deriving a PUF session key; combining the unique session ID, the session context and the homologous quantum root key, performing a hash operation, and generating a unique session base key seed; performing heterogeneous splitting on an original signed message, and constructing a multi-level hidden salt hash chain; performing grouping on two message fragments and the multi-level hidden salt hash chain, performing compliance signature operation and post-quantum signature operation on the grouped data respectively, generating an inner layer national secret signature, and generating an outer layer anti-quantum trusted signature; packaging the above data to generate a signature data packet, and sending the signature data packet to a signature verification party. The application realizes the comprehensive goals of anti-quantum security enhancement, hardware-level identity traceability verification, national secret compliance signature verification and multi-factor collaborative in-depth protection.
Owner:SICHUAN LIANGSHANSHUILUOHE ELECTRICITY DEV CO LTD

Intelligent subsidy calculation and security enhancement method and device based on multi-agent cooperation

PendingCN122334262ADocument Object ModelOperations research
The application discloses a kind of based on the intelligent subsidy calculation and security enhancement method and equipment of multi-agent cooperation, the text and structure information of policy document and historical experience are extracted by the method through OCR tool, construct the document object model of original semantic reservation, establish high-precision vector knowledge base;Security enhancement agent is deployed at input end, and malicious query is identified and intercepted semantic deviation request;After detection, the conflict detection of user input and policy and the dynamic completion of field missing are realized by multi-agent cooperation engine;Subsidy calculation agent generates optimal subsidy scheme according to the priority strategy of user active selection, and models the decision-making process as traceable causal chain;Output side monitors the trajectory of large model hidden state in real time through time convolution network, and blocks sensitive information leakage risk.The application realizes the flexible adaptation of subsidy calculation strategy, whole-process transparent and credible and enterprise data full-link protection, solves the three major pain points of rigid scheme, black-box decision and weak security in prior art.
Owner:HANGZHOU JUNTONG FUTURE TECHNOLOGY CO LTD

A ris-assisted common-sensing dual-security enhancement method

This invention discloses a RIS-assisted dual-security enhancement method for sensing, relating to the field of communication security technology. By introducing RIS to regulate the wireless propagation environment and combining the channel state information of legitimate users with the coarse-grained distance, angle, and other positional information of Eve, the method jointly designs the base station transmit beamforming matrix, the dedicated sensing signal covariance matrix, and the RIS phase shift. This reduces Eve's eavesdropping and sensing capabilities while ensuring legitimate communication and sensing performance, thereby improving the overall security performance of the system with lower hardware overhead.
Owner:BEIJING UNIV OF POSTS & TELECOMM