Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

23 results about "Security layer" patented technology

A multi-level quantitative evaluation method for an electronic product information clearing, verifying and tracing credible closed loop system

PendingCN122346411ATechnology developmentAttack
The application discloses a kind of multi-level quantitative evaluation methods for electronic product information clearing, verification and traceable credible closed-loop system, comprising S100, evaluation framework establishment and test environment preparation step: S110, define evaluation model, the evaluation model includes clearing effect layer (L1), verification credible layer (L2), trace and authentication layer (L3), system behavior and security layer (L4) and performance and efficiency layer (L5).The application has the advantages that: from qualitative to quantitative: a large number of quantitative indicators such as KL divergence, bit recovery rate, throughput are introduced, and the evaluation results are objective, accurate and comparable.The method carries out deep security testing: not only test function, but also take the system itself as attack target, carry out penetration testing and process behavior monitoring, can find deeply hidden design defects and security vulnerabilities, which cannot be achieved by traditional function testing.At the same time, the method can guide technology development, and provide decision basis for procurement and supervision;And high automation and repeatability.
Owner:GUIZHOU UNIV

A hardware-software co-operated secure AI NAS storage system and access authentication method

PendingCN122120003ASecuring communicationAttackChain of trust
The application provides a soft and hard cooperative security AI NAS storage and calculation system and an access authentication method, and belongs to the technical field of network storage. The system comprises a hardware security layer, a lobster security core module, a compulsory authentication gateway, an encrypted storage engine, an intelligent access control module and a security audit and monitoring module. The hardware security layer comprises a lobster security chip and a hardware root of trust module. The lobster security chip is an independent security processor, and is internally provided with a true random number generator, an encryption acceleration engine and a security storage area. The hardware root of trust module is used for system startup verification and root key hardware protection. Through the soft and hard cooperative architecture and the compulsory authentication mechanism, the application realizes a complete trust chain from the hardware root of trust to the application layer, can effectively prevent ransomware attacks and data leakage risks, and improves data operation efficiency.
Owner:QUANTUM CORE CLOUD (BEIJING) MICROELECTRONICS TECH CO LTD

Electronic control system safety layer test method, device, equipment and readable storage medium

A method, apparatus, device, and readable storage medium for testing the security layer of an electronic control system are disclosed, relating to the field of electronic control technology for new energy vehicles. Specifically, the method includes an electronic control unit (ECU) receiving a test data packet from a HIL simulator via a hardware interface. This data packet includes scenario-based extreme operating condition parameters, encrypted interference signals, encrypted sensor signals corresponding to the hardware to be interacted with, and encrypted abnormal signals. The ECU performs integrity verification and signal threshold judgment on the test data packet to obtain a first result, and generates control commands based on the first result. The ECU encrypts and digitally signs the control commands based on a preset security key to obtain a target control command, which is then sent to the HIL simulator via a communication bus. The HIL simulator decrypts the target control command, timestamps it, and verifies the digital signature to obtain a second result, and executes the target control command based on the second result, thereby achieving security layer testing of the electronic control system. This application can improve the realism and anti-interference capability of security layer testing of electronic control systems.
Owner:ZHONGAN ZHIYAN (WUHAN) TRANSPORTATION TECHNOLOGY CO LTD

Method of enhancing cyber resilience and system thereof

A method and system of enhancing cyber resilience performed by a computing system is disclosed. According to one embodiment of the present disclosure, the method may comprise a step of acquiring vulnerability data of a target system based on resilience feature data including a quantitative assessment vector and a non-quantitative assessment text of the target system, a step of inputting input data including the vulnerability data into an artificial intelligence model and generating an enhancement strategy for the target system based on output of the artificial intelligence model and a step of controlling a security layer of the target system based on the enhancement strategy.
Owner:KOREA INTERNET & SECURITY AGENCY

Brain-computer interface driven full-scene neural rehabilitation management cloud platform system

PendingCN122455217AShardEngineering
The application relates to the technical field of neural rehabilitation and brain-computer interface, and discloses a brain-computer interface driven full-scene neural rehabilitation management cloud platform system, which comprises a perception layer, a processing layer, an application layer and a security layer. The perception layer collects basic signs and electroencephalogram data in a physical environment; the processing layer receives the data for pre-processing and denoising decoding, fuses multi-dimensional evaluation results to generate a dynamic rehabilitation scheme, adjusts control parameters in combination with a closed-loop feedback mechanism, and outputs control interaction instructions to external equipment through a general adaptation protocol; the application layer receives the instructions to render an interactive interface for hospital, community and family end users, and generates flow record data; and the security layer performs hierarchical protection based on the flow record data, and completes privacy calculation of a model by using block chain storage and federal learning. The application solves the problem of data fragmentation during cross-scene flow, improves the individual adaptability of a rehabilitation scheme, and guarantees the security of flow data.
Owner:XINXIANG MEDICAL UNIV

A Commercial Cryptographic Protection and Multi-System Integration Method for Power Demand-Side Management Systems

This invention discloses a method for commercial encryption protection and multi-system security integration in a power demand-side management system. The method involves: constructing a business-driven layered commercial encryption protection strategy and configuring differentiated commercial encryption protection schemes; building a three-tiered integration architecture consisting of a core layer, an interface layer, and a security layer; and achieving deep integration of commercial encryption protection and the integration process. During multi-system data interaction, interface authentication, encrypted data transmission, data decryption and verification, and storage and log protection are completed sequentially, with commercial encryption technology embedded throughout to ensure security. This invention offers advantages such as compliant commercial encryption protection, standardized and efficient multi-system integration, end-to-end security protection coverage, and deep integration with business needs.
Owner:GUANGZHOU POWER SUPPLY BUREAU GUANGDONG POWER GRID CO LTD

A SCADA configuration picture generation method and device based on generative AI, equipment and storage medium

PendingCN122284968ALinguistic modelConfiguration design
This application discloses a method, apparatus, device, and storage medium for generating SCADA configuration screens based on generative AI, relating to the field of industrial control technology. The method includes: collecting natural language design requirements using an intent understanding module and the perception layer in an AI Agent cognitive architecture; obtaining state acquisition data and integrating it before inputting it to the cognitive layer; the inference engine and large language model in the cognitive layer decompose the configuration design task of the integrated data, generating a configuration design operation instruction set and inputting it to the execution layer; the execution layer processes the operation instruction set to obtain each component to be laid out in the configuration screen and its configuration data; the layout engine determines the component layout result in the configuration canvas; the variable binding engine binds and maps each component to the real-time data points of the SCADA system; and the target configuration screen is generated by combining the Shell command security module and the security layered architecture to improve the efficiency of generating SCADA configuration screens.
Owner:XINTONG EMPOWERMENT (CHANGSHA) ARTIFICIAL INTELLIGENCE IND APPLICATION SYSTEM CO LTD

An artificial intelligence-based multi-layer network security collaborative protection method and system

This invention discloses a multi-layered network security collaborative protection method and system based on artificial intelligence, relating to the field of network security technology. The method acquires metadata events from multiple network security layers, constructs a cross-security layer time-series event correlation graph based on layer identifiers and timestamps, calculates the abnormal propagation energy value of nodes in the graph, and dynamically generates an anomaly judgment energy baseline based on the statistical distribution of energy values ​​within a sliding time window. When the energy value sequence of consecutive event nodes exceeds the baseline, a cross-layer collaborative attack is identified, and a collaborative attack chain identifier is generated. The target security layer and blocking strategy are then determined and executed based on the identifier. This invention accurately identifies covert cross-layer collaborative attacks through global correlation of cross-layer events and dynamic judgment of abnormal energy, eliminating blind spots in collaborative protection and improving the accuracy of attack detection. Simultaneously, by dynamically adjusting propagation attenuation weights, it strengthens attack chain identification and targeted blocking capabilities, improving the collaborative efficiency and defensive reliability of multi-layered network security protection.
Owner:JIANGSU DIXIN INTELLIGENT TECH CO LTD

A high-risk operation intelligent monitoring management system based on multi-element linkage

The present application relates to the technical field of monitoring high-risk operations, and particularly relates to a high-risk operation intelligent monitoring management system based on multi-element linkage. The present application constructs the mutual linkage of key elements of high-risk operations to achieve the technical standard of risk perception and control in the operation process at the safety level. At the same time, through an electronic fence automatic drawing algorithm and an electronic fence automatic validation algorithm, the operation risk state is determined in a limited space. Through micro-network data acquisition, deep learning and continuous training, an operation risk high-accuracy AI model is obtained to maximize the elimination of safety hazards in the work of operation personnel on the fan platform working surface and the fan tower working surface. The working state of the crane is determined by the proportion of time nodes of the crane outside the electronic fence within the preset time length, and corresponding adjustment is made when the working state is unqualified, thereby improving the working accuracy of the crane. The present application effectively monitors the operation risk and improves the work efficiency.
Owner:STATE POWER INVESTMENT CORP JIANGSU OFFSHORE WIND POWER +1

A static vulnerability mining intelligent agent system, method, and apparatus based on driving engineering.

This invention discloses a static vulnerability mining agent system, method, and apparatus based on the "Driving Engineering" framework, relating to the field of artificial intelligence, to address the problems of logical inaccessibility and lack of context in the autonomous execution of long-chain tasks by static vulnerability mining agents. It constructs a static vulnerability mining agent system comprising an environment perception and object representation layer, an execution layer, an orchestration layer, a memory layer, a semantic management layer, and a security layer. Based on the logic of global constraint pre-positioning – progressive information disclosure – full-link behavior control – autonomous closed-loop execution – standardized output of results, it leverages the core mechanisms of the "Driving Engineering" framework, such as event-driven interception and verification bus, dynamic loading of prompts, memory compression, autonomous task execution loop, and tool permission gating, to form a fully traceable static vulnerability mining solution. This application can solve the problems of logical inaccessibility and lack of context in long-chain static vulnerability mining and analysis tasks, improving task execution efficiency and accuracy.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

An internet-based intelligent campus platform intelligent operation and maintenance system

The application discloses an Internet-based intelligent campus platform intelligent operation and maintenance system, comprising a global data acquisition layer, an intelligent analysis and decision-making layer, an automatic execution layer and a zero-trust security layer; the global data acquisition layer is used for collecting multi-modal operation and maintenance data in real time through probes and Internet of Things gateways arranged at each node of the campus platform; the multi-modal operation and maintenance data at least comprises timing performance indexes of servers, unstructured log data, network traffic metadata and user behavior data; and the global data acquisition layer supports multiple protocols and edge pre-aggregation, and ensures data real-time performance and integrity. The application relates to the technical field of technical operation and maintenance management, and provides a campus dining hall fund whole-process closed-loop supervision system based on the Internet of Things; the system solves the technical problems of lagging fault response, difficult root cause positioning, low operation and maintenance automation, static security defense and unbalanced resource utilization in the prior art.
Owner:GUANGDONG LINKAGE ENTREPRENEURSHIP TECHNOLOGY CO LTD

A data encryption method, device, apparatus and storage medium

ActiveCN122001687BPlaintextCiphertext
This application discloses a data encryption method, apparatus, device, and storage medium, relating to the field of information security technology. The method includes: receiving a data encryption request sent by a business application, carrying a tenant identifier, an application identifier, and data to be encrypted; querying the application key ciphertext corresponding to the application identifier and the tenant key ciphertext corresponding to the tenant identifier from the tenant security layer, and obtaining the platform master key from the platform security layer; decrypting the target tenant key ciphertext using the platform master key in the tenant security layer to obtain the tenant key plaintext, and then decrypting the application key ciphertext using the tenant key plaintext to obtain the application key plaintext; sending the application key plaintext and the data to be encrypted to a virtual cryptographic machine pre-assigned to the current tenant to encrypt the data based on the application key plaintext to obtain data ciphertext, and then sending the data ciphertext to the business application. This application can improve the security of the data encryption process and prevent data leakage.
Owner:HANGZHOU FULANKE INFORMATION SECURITY TECH CO LTD

USB virtual multi-serial communication system based on domestic single-chip microcomputer

This invention discloses a USB virtual to multi-serial port communication system based on a domestically produced microcontroller, comprising a communication interface layer, a data management and routing layer, a hardware acceleration and peripheral layer, and a system security layer integrated within the same domestic microcontroller. The communication interface layer interacts with a host computer, enumerating multiple virtual interfaces in a composite device manner. These virtual interfaces include six communication CDC interfaces and a storage MSC interface. This invention uses a domestically produced low-cost microcontroller to implement a four-port USB virtual serial port, reducing the number of dedicated bridging chips, significantly lowering BOM costs, ensuring security and controllability, and providing more stable supply. The four UART ports transmit and receive data in parallel using an eight-channel DMA, resulting in low CPU usage and more stable throughput. Using a dropout detection combined with a self-recovery mechanism reduces downtime caused by freezes and dropouts. It also supports multiple CDC and MSC virtual USB drives, SD log storage, RS485 direction control, routing bridging, and filtering / rate limiting.
Owner:XIAN SAIERCOM CO LTD

Networking and security split architecture

Techniques for providing a networking and security split architecture are disclosed. In some embodiments, a system, process, and / or computer program product for providing a networking and security split architecture includes receiving a flow at a security service; processing the flow at a network layer of the security service to perform one or more networking functions; and offloading the flow to a security layer of the security service to perform security enforcement based on a policy.
Owner:PALO ALTO NETWORKS INC

A layered security system and method against quantum, side channel, and insider photographing and memory reconstruction

This invention discloses a layered security system and method resistant to quantum attacks, side-channel attacks, and insider filming / memory reconstruction. The system includes an access adaptation layer, a confidentiality isolation layer, a human-machine interface layer, an anti-side-channel module, an anti-quantum module, an anti-leakage module, a self-iterative module, and a fault rollback module. Real data is fragmented, encrypted, and written to an audit black box; the human-machine interface maintains stable semantics for critical operations, while non-critical attributes change dynamically and are overlaid with screen markers; operators can use the system normally, but filming or memorizing data cannot restore the real data. The system periodically performs self-attack simulations, and vulnerabilities are reinforced after manual approval; in the event of a security layer failure, the original service is automatically rolled back. This invention effectively combats quantum attacks, side-channel attacks, and insider filming / memory reconstruction leaks while maintaining availability and auditability.

A vulnerability exploitation agent system, method and apparatus based on steering engineering

PendingCN122365521AMemory profilingTerm memory
This invention discloses a vulnerability exploitation agent system, method, and apparatus based on the driving engineering framework, relating to the field of artificial intelligence, to address the vulnerability problem in the autonomous execution of long-chain tasks by vulnerability exploitation agents. It constructs a vulnerability exploitation agent system comprising an environment perception and object representation layer, an execution layer, an orchestration layer, a memory layer, a semantic management layer, and a security layer. Based on the logic of global constraint pre-positioning – progressive information disclosure – full-link behavior control – autonomous closed-loop execution – standardized output of results, it leverages the core mechanisms of the driving engineering framework, such as event-driven interception and verification bus, dynamic loading of prompts, memory compression, autonomous task execution loop, and tool permission gating, to form a fully traceable vulnerability exploitation scheme. This application can solve the problems of difficult binary semantic analysis and memory analysis in long-chain vulnerability exploitation tasks, improving task execution efficiency and accuracy.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

Cluster intralayer safety mechanism in an artificial neural network processor

ActiveUS12670233B2Data streamSpatial mapping
Novel and useful system and methods of functional safety mechanisms for use in an artificial neural network (ANN) processor. The mechanisms can be deployed individually or in combination to provide a desired level of safety in neural networks. Multiple strategies are applied involving redundancy by design, redundancy through spatial mapping as well as self-tuning procedures that modify static (weights) and monitor dynamic (activations) behavior. The NN processor incorporates several functional safety concepts which reduce its risk of failure that occurs during operation from going unnoticed. The mechanisms function to detect and promptly flag and report the occurrence of an error with some mechanisms capable of correction as well. The safety mechanisms cover data stream fault detection, software defined redundant allocation, cluster interlayer safety, cluster intralayer safety, layer control unit (LCU) instruction addressing, weights storage safety, and neural network intermediate results storage safety.
Owner:HAILO TECH LTD

A hierarchical modeling and combinatorial verification method based on UPPAAL for LwM2M protocols

PendingCN122316955APacket lossAttack
This invention discloses a layered modeling and combined verification method for the LwM2M protocol based on UPPAAL. Its key feature is the addition of attacker automata to the functional layer model to construct a security layer model. By selectively activating attacks through global attack mode variables, the security attributes of the protocol under attacks such as man-in-the-middle, replay, and denial-of-service are verified. The method introduces probabilistic semantics, packet loss, latency, and retransmission mechanisms into the upper-layer model to construct a performance layer model. Statistical models are used to detect and evaluate the protocol's performance indicators in real-world network environments. Compared with existing technologies, this invention decomposes the complex protocol verification problem into independent and composable layers, effectively reducing modeling complexity, avoiding state space explosion, and achieving comprehensive verification of the LwM2M protocol's functionality, security, and performance. The method is simple, effective, and has promising application prospects.
Owner:EAST CHINA NORMAL UNIV

Causal security layer calibration driven defense method for large model security target range

This invention discloses a causal security layer calibration-driven defense method for large-scale model security testbeds. First, a security layer localization algorithm is executed on the domain-fine-tuned model to identify a set of discontinuous layers that make key causal contributions to security decisions in a data-driven manner. Then, a bimodal gating-policy subdivision algorithm is used to subdivide the security layer into a gating layer responsible for triggering rejection and a policy layer responsible for compliance expression. During the calibration fine-tuning stage, only the parameters of the subdivided gating and policy layers are updated specifically, and a joint loss function including gating and policy regularization terms is introduced to constrain the model's rejection boundary and response granularity under both security-specific and general data modes. This invention, through a technical path of "precise localization first, then structural subdivision, and finally targeted calibration," significantly improves robustness against prompt injection attacks while ensuring availability for benign professional requests at the boundary.
Owner:BEIJING JIZHIXIN TECHNOLOGY CO LTD

A solid rocket engine vibration test local overheating remote early warning monitoring system

This invention discloses a remote early warning and monitoring system for localized overheating in solid rocket motor vibration tests. It adopts a layered architecture design, including a sensing layer, a transmission layer, a control layer, and an application layer. The sensing layer is equipped with an explosion-proof binocular sensing module, integrating a binocular infrared thermal imager and a visible light camera to achieve simultaneous acquisition of the entire temperature field and appearance status. The transmission layer ensures stable data transmission and human-machine isolation. The control layer, through digital-to-analog conversion and interlocking with the vibration controller, enables emergency shutdown in case of overheating. The application layer provides real-time display and control, intelligent analysis, and data storage functions. This system solves the problems of traditional contact temperature measurement, such as limited measuring points, poor vibration resistance, blind spots, and lack of interlocking protection. It achieves non-contact, full-domain monitoring, active safety protection, remote intelligent control, and multi-dimensional data support, thereby improving the safety level of the test.
Owner:XIAN CHANGFENG ELECTROMECHANICAL RES INST

Source code adaptive repair method and related device

The embodiment of the present application relates to the technical field of computer software, and discloses a source code self-adaptive repairing method and related equipment, which comprises the following steps: verifying the source code generated by an artificial intelligence code generation model through a layered verification engine in multiple layers, wherein the multiple layers comprise a syntax checking layer, a contract testing layer, a static security layer, a dynamic testing layer and a model checking layer; if an execution path does not satisfy a system-level attribute, a specific execution path indicating that the system-level attribute is not satisfied is generated as a counterexample, and a first repairing instruction is generated based on the counterexample; if the verification of any layer of the other layers except the model checking layer fails, a verification report is generated, and a second repairing instruction is generated based on the verification report to repair the source code; after the repairing, the repaired source code is verified again in multiple layers until the qualified source code is obtained by passing the verification at one time, and in the above manner, the reliability and security of the source code can be greatly improved.
Owner:GUOSEN SECURITIES

Hierarchical system architecture for controlling an automated vehicle

ActiveUS12679295B2Control signalAutopilot
A hierarchical system architecture for controlling an automated vehicle. The hierarchical system architecture includes: a performance layer; a safety layer; a hardware layer, wherein the safety layer is arranged between the performance layer and the hardware layer; the performance layer is configured to generate a first control signal and to transmit it to the safety layer; the safety layer is configured to detect whether a safety-critical driving situation is present for the vehicle, and a first system reaction is to be carried out to bring the vehicle into a safe state by transmitting a corresponding second control signal to the hardware layer instead of the first control signal, and the safety layer includes at least one detector module which detects whether a special case is present in the safety-critical driving situation of the vehicle which requires an associated second system reaction instead of the first system reaction.
Owner:ROBERT BOSCH GMBH