Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

114 results about "Security level" patented technology

In cryptography, security level is a measure of the strength that a cryptographic primitive — such as a cipher or hash function — achieves. Security level is usually expressed in "bits", where n-bit security means that the attacker would have to perform 2 operations to break it, but other methods have been proposed that more closely model the costs for an attacker. This allows for convenient comparison between algorithms and is useful when combining multiple primitives in a hybrid cryptosystem, so there is no clear weakest link. For example, AES-128 (key size 128 bits) is designed to offer a 128-bit security level, which is considered roughly equivalent to 3072-bit RSA.

Method for verifying the setting of predefined safety functions of a field device in process and automation technology

A method for verifying the setting of predefined safety functions (SF1, ..., SFn) of a field device for process and automation technology, wherein the predefined safety functions (SF1, ..., SFn) relate in particular to access to at least one function of the field device by an unauthorized person, wherein the method provides the following steps: - Determining a security level required at the measuring point and / or at the field device, wherein the determined security level defines the target setting of the predefined safety functions (SF1, ..., SFn) of the field device (1), - Identifying a user by means of an authentication protocol (2), - Starting a query about the actual setting of the safety functions (SF1, ..., SFn) of the field device specified at the measuring point by the user (3), - Comparing the actual setting of the predefined safety functions (SF1, ..., SFn) of the field device with the target setting of the specified safety functions (SF1, ..., SFn) defined by the specified safety level (4),- Issuance of an electronic report to the user regarding a conformity or deviation between the actual setting and the target setting of the specified safety functions (SF1, ..., SFn) of the field device (5),- in the case of conformity between the actual setting and the target setting of the specified safety functions (SF1, ..., SFn) of the field device, the following step is provided:â—¯ Storage of the electronic report (6), or- in the case of deviation between the actual setting and the target setting of the specified safety functions (SF1, ..., SFn) of the field device, the following steps are provided:â—¯ Proposal of at least one measure to adjust the actual setting of at least one specified safety function (SF1, ..., SFn) of the field device to the target setting (7), whereby at least one measure is shown to the user,â—¯ Implementation of the at least one proposed measure to adapt the actual setting to the target setting of the specified safety functions (SF1, ..., SFn) of the field device by the user (8),â—¯ Repetition of the query about the actual setting of the specified safety functions (SF1, ..., SFn) of the field device by the user (3).
Owner:ENDRESS & HAUSER GMBH & CO KG

A Method for Integrity Protection of Access Control Records Based on Commercial Cryptographic Algorithms

This invention discloses a method for protecting the integrity of access control record storage based on commercial cryptographic algorithms, comprising: collecting access control records and concatenating them into complete record data A1 according to a predetermined format; calling a PCI-E cryptographic card and calculating the MAC value M1 of A1 using HMAC technology based on the SM3 national cryptographic algorithm, and storing A1 and M1 together in a background database; when it is necessary to verify the integrity of the access control record, reading the current record data A2 and the originally stored MAC value M1 from the background database; calling a PCI-E cryptographic card and calculating the MAC value M2 of A2 using the same algorithm; comparing M1 and M2, if they match, the record is determined to be complete; if they do not match, the record is determined to have been tampered with and an alarm message is generated. This invention has the advantages of high security, strong compliance, superior performance, and good economy, and can be widely used in access control systems with security levels of Level 3 and above.
Owner:TOEC ANCHEN INFORMATION TECH

User identity authentication method and device, electronic equipment and storage medium

This application discloses a user authentication method, apparatus, electronic device, and storage medium, belonging to the field of authentication technology. The method includes: obtaining a user's authentication request; determining a target authentication scenario from multiple preset authentication scenarios based on the authentication request, each authentication scenario corresponding to a security level threshold; obtaining a user's historical behavior dataset, where each historical behavior data entry is configured with a basic security level and a weight; determining candidate behavior data in the historical behavior dataset whose basic security level meets the target security level threshold corresponding to the target authentication scenario; determining target behavior data from each candidate behavior data according to the weight; generating a authentication question based on the target behavior data and outputting the authentication question to the user; obtaining user response information corresponding to the authentication question; and determining the authentication result based on the user response information. This application enables scenario-adaptive authentication strategies, ensuring that high-security-level historical behavior data is used in high-risk scenarios.
Owner:HANGZHOU NETEASE CLOUD MUSIC TECH CO LTD

A hierarchical encryption storage method and system for a drone

PendingCN122339765ANo-fly zoneSmart contract
The application discloses a hierarchical encryption storage method and system for a UAV. The method comprises the following steps: obtaining a dynamic security policy coded as a smart contract from a block chain network, and calling a static security policy from a local; the dynamic security policy and the static security policy both comprise a no-fly area and an execution action; obtaining a three-dimensional position of the UAV in real time, and judging whether the three-dimensional position of the UAV is in or near the no-fly area of the dynamic security policy or the static security policy; if yes, calling a pre-configured flight task type from the local, and determining a security level according to the flight task type; executing the corresponding dynamic security policy or static security policy according to the security level, and performing hierarchical data encryption storage. When the UAV enters a sensitive area, not only corresponding flight control is implemented, but also encryption of a corresponding level is triggered automatically and in real time, so that linkage protection of flight safety and data safety is realized, and data protection and flight state are ensured to be performed synchronously.
Owner:NANJING QUFEIPAI TECHNOLOGY CO LTD

Agent security assessment and dynamic sandbox protection method and system, and related device

A method, system, and related equipment for intelligent agent security assessment and dynamic sandbox protection are disclosed. The method includes: generating an attack task based on an attack task template using a large language model; inputting the attack task into a target intelligent agent in a controlled environment, causing the target intelligent agent to execute the attack task and collect behavioral data during execution; performing a risk assessment based on the behavioral data to determine the security level under the current attack task; triggering a dynamic sandbox protection mechanism based on the security level to adapt and adjust the permissions and resources of the target intelligent agent; obtaining feedback on abnormal samples, adjusting the risk judgment threshold in the risk assessment process based on the feedback on abnormal samples, and simultaneously generating a new attack task template and entering the next round of adversarial assessment; through multiple rounds of adversarial assessment, stabilizing the security level of the target intelligent agent and meeting preset security requirements. This invention achieves adversarial assessment of intelligent agent security risks and realizes hierarchical protection and policy adjustment through a dynamic sandbox mechanism.
Owner:CHINA ELECTRIC POWER RESEARCH INSTITUTE CO LTD +2

Blockchain based security system and method using WAAP / API level management

ActiveUS12676838B2Security solutionWeb application
Disclosed is a blockchain-based security method that is performed by an integrated web security solution (web application and API protection, WAAP) and using WAAP and application programming interface (API) level management. The blockchain-based security method may comprise: receiving an API safety grade check request from the blockchain under a session establishment with the blockchain, wherein, in the checking of the API safety grade, a security level for vulnerability of the API is checked by itself in management API data of the WAAP with a highest level of safety; and transmitting information on the API safety grade to the blockchain.
Owner:PENTA SECURITY SYST INC

Security processing methods, apparatus and electronic devices in multi-trusted execution environments

This application provides a security processing method, apparatus, and electronic device in a multi-trusted execution environment. In the aforementioned security processing method, after the electronic device obtains a first request from a first CA, it sends the first request to a first TA according to the first security level required by the first request, and the first TA performs security processing on the first request. After the electronic device obtains a second request from the first CA, it can send the second request to a second TA through a second TEE according to the second security level required by the second request, and the second TA performs security processing on the second request. The second security level is higher than the first security level. Since the first TEE and the second TEE are two isolated TEEs, different security applications used for key management in the electronic device can run in isolated TEEs, reducing coupling and improving the security of the electronic device.
Owner:HONOR DEVICE CO LTD

A background multi-application customizable SaaS configuration method

This invention relates to a customizable SaaS configuration method for multiple backend applications, specifically in the field of custom configuration for multiple backend applications. It defines basic database configuration, basic server configuration, basic security configuration, basic network configuration, basic storage configuration, and basic log configuration for different application systems. Based on single responsibility and application system components, the application system is divided into multiple independent modules. Dependencies between modules are identified by recording the call order and time relationships between modules through time-series analysis. Parameters and configuration items are categorized and defined according to their module and function, applicable environment, importance and scope of influence, security level, and data type. Resource templates are freely combined to form an overall architecture based on the functional requirements of different applications. The behavior and style of modules are controlled by parameters and configurations corresponding to the functional requirements of the applications within the architecture, establishing an efficient and reliable application hosting system.
Owner:BEIJING BAILONG MAYUN TECH CO LTD

A Hybrid Quantum-Resistant Security Enhancement Method for IPSec VPN

PendingCN122372190AKey exchangeData pack
This invention proposes a hybrid quantum-resistant security enhancement method for IPSec VPNs. The method includes: intercepting Internet Key Exchange (ITE) packets and adding a proxy header between the transport layer header and the ISE payload of the packets; obtaining a quantum key from a key pool using quantum key distribution technology and generating a first-stage session key based on the quantum key; protecting the ISE key negotiation process using a quantum-resistant cryptographic algorithm to generate a second-stage session key; and using the first-stage and second-stage session keys as input parameters for a key derivation function to generate a final session key for encrypted data transmission. This invention, without modifying the original IPSec negotiation process, supports dynamic key combinations of different security levels, enhancing the quantum security protection capability of VPN data transmission while maintaining system flexibility and performance.
Owner:CHINA MOBILE COMM GRP CO LTD +3

Quantum key distribution system and method for on-demand adaptation of output quantum keys

The application provides a quantum key distribution system and method for on-demand adaptation of output quantum keys, wherein the original quantum keys are allowed to be expanded on demand, so as to meet the end-to-end key demand in various scenes on the basis of balancing the key security level; meanwhile, by monitoring the key output in real time, the imbalance between the key output and the key rate requirement is comprehensively considered, and the key output rate is dynamically adjusted to guarantee the stability of the production and consumption of the whole key network. In addition, the application supports both the active pushing mode of single quantitative distribution to the network distribution device and the request mode of requesting the specified single key amount from the network distribution device, and can output the key to the network distribution device in a more flexible way.
Owner:CAS QUANTUM NETWORK CO LTD +1

A secure communication method and system based on wireless transmission

This invention discloses a secure communication method and system based on wireless transmission, comprising the following steps: acquiring data to be transmitted and mapping it to generate a complex data sequence; inputting an improved CVNN, weighting and fusing it by phase and amplitude branches to generate a multi-branch feature sequence; performing multi-scale residual stream diffusion to construct a high-dimensional secure tensor in time, frequency, and space; extracting endogenous features and channel statistical features to form a secure feature matrix; generating an initial dynamic key and iteratively updating it to form a hierarchical dynamic key coupled with the channel; combining the key with the complex data sequence for encryption and redundant encoding to generate an encrypted data frame; the receiving end decrypts and verifies the data, and when the security level is lower than a threshold, triggering the sending end's DropConnect to randomly block and iteratively update the key and encryption strategy until transmission is complete. This invention achieves dynamic key iteration, physical layer protection, and low-error-rate reliable transmission for secure wireless data transmission.
Owner:DATANG SHENGYE TECH CO LTD

A dynamically configurable isolated link unidirectional data security transmission method

This invention relates to a dynamically configurable method for secure unidirectional data transmission via isolated links, belonging to the field of network security technology. The method includes: acquiring isolation security rules and network boundary constraint parameters for the target scenario; parsing unidirectional transmission constraints and isolation requirements; establishing dual independent unidirectional transmission channels and initializing the node environment to generate a physical layer-level absolutely unidirectional isolation architecture; constructing a dynamic configuration model for unidirectional transmission; inputting service and security level requirements to generate full-link configuration rules and perform compliance verification; achieving closed-loop verification of configuration without reverse data using non-digital optical signals; subsequently collecting and encapsulating on-site service data according to the rules; distributing the data via the unidirectional channel; and having the external network side complete compliance verification and format conversion to form a closed-loop transmission link; real-time acquisition of full-link data for iterative optimization of configuration strategies; synchronously updating the rule set; and performing emergency response to transmission anomalies and link failures. This achieves adaptive dynamic configuration of isolated links and secure control over the entire unidirectional data flow.
Owner:SHANGHAI QIXIANG INTELLIGENT TECH CO LTD

Automatic networkselection based on security criteria

PCT designated stageWO2026143436A1Web siteSecurity level
Automatic network selection based on security criteria is discussed herein. Security criteria for an application (or a website or data) is determined. One or more wireless networks accessible to the computing device are identified and a first wireless network of the one or more wireless networks having a security level that satisfies the security criteria is automatically selected. Data is communicated to or from a first device via the selected wireless network.
Owner:LENOVO (BEIJING) LTD

Information processing apparatus and non-transitory computer readable medium storing program for notifying existence of usable but non-held data

An information processing apparatus installed inside a local network system that provides a service to a user, includes a processor configured to acquire data used in a case of providing the service and security level information indicating whether the data is first data of a first security level which is capable of being held and used by another information processing apparatus that provides the service outside the local network system, second data of a second security level which is not held but is capable of being used, or third data of a third security level which is not capable of being held and used; hold the acquired data in association with the security level information of the data in the local network system; and, when performing synchronization processing on usage data, which is used in the case of providing the service and includes one or more of the data, with the other information processing apparatus, transmit the first data included in the usage data and second data presence / absence information indicating whether the second data is included in the usage data.
Owner:FUJIFILM BUSINESS INNOVATION CORP

Communication methods and devices

A communication method and apparatus, belonging to the field of communications, are disclosed. The method includes: a first module receiving a first parameter from a first network, the first parameter being a calculation parameter of a first security mechanism; the first module obtaining a second hidden identity identifier based on the first parameter, the second hidden identity identifier being a hidden identity identifier obtained by processing plaintext identity information according to the first security mechanism and the first parameter. A terminal-side device includes a first module supporting the first security mechanism and a second module not supporting the first security mechanism. The terminal-side device can first use the hidden identity identifier calculated by the second security mechanism to access the network, thereby using an anonymized identity identifier during network access to protect user privacy. The network side can issue calculation parameters of a first protection mechanism with higher security strength, enabling the terminal-side device to provide a higher level of security for user identity privacy protection during subsequent access processes.
Owner:HUAWEI TECH CO LTD

Space-time fence-based cyber physical attack and defense drill method and system for geographic information security of internet of vehicles

The application discloses a kind of based on space-time fence's car networking geographic information security attack and defense drill method and system, belong to intelligent network connection car and geographic information security technical field.To solve the problem of existing attack and defense scene solidification, static geographic fence no elasticity and encryption resource allocation unreasonable, the application constructs the mixed simulation environment including real hardware and virtualization component, obtains space-time fence data with security level;Data is encrypted using encryption algorithm and data features, encryption algorithm features and node performance features are extracted to form a joint feature vector;Using Bi-LSTM energy consumption prediction model outputs allocation probability, and based on security level constraint decision, force high-security level data to be allocated to high-performance nodes, finally generate analysis report for real environment policy update.The application realizes the significant improvement of geographic information security protection and resource allocation efficiency through the cooperation of dynamic space-time fence, format preservation encryption and intelligent scheduling model.
Owner:CHINESE ACAD OF SURVEYING & MAPPING

Data security level identification methods and devices, electronic equipment, and software products

This invention discloses a method, apparatus, electronic device, and program product for identifying data security levels, relating to the field of artificial intelligence technology. The identification method includes: acquiring the data to be classified and the field names of the data to be classified, and constructing initial prompt words based on the field names; constructing target prompt words based on the initial prompt words; inputting the target prompt words into a language model, and outputting a security level label for the data to be classified. The language model obtains compliance level constraints corresponding to the field names by calling a target knowledge graph, and determines the security level label based on the compliance level constraints. This invention solves the technical problem of low accuracy in data security level identification in related technologies.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Secure access methods, devices and vehicles

This application provides a secure access method, apparatus, and vehicle. The method includes: receiving a first message sent by a server, the first message indicating at least one service that the server can provide, the first message including a first random number; determining at least one second key based on a first key, a first security policy option, and the first random number, wherein the first key is a symmetric key, the first security policy option indicating the security level corresponding to at least one interface of at least one service in the service, and the at least one second key used to verify a second message sent by the server, the second message including data corresponding to the first service, and the at least one service including the first service. Through this method, different protection strategies and communication keys can be adopted for different interfaces in the SOME / IP service, ensuring secure communication between the server and client while avoiding over-protection or poor processing performance.
Owner:YINWANG INTELLIGENT TECHNOLOGIES CO LTD

Anti-quantum intent perception intelligent agent hierarchical resource control system and method

This invention discloses a quantum-resistant intention-aware agent hierarchical resource control system and method, comprising: performing local semantic analysis on the target resource requested by the agent, dynamically classifying the target resource into multiple security sensitivity levels based on a preset semantic hierarchical strategy; concatenating the agent's execution instructions, target object, and specific operation purpose, and generating an operation intention digest using a hash algorithm; calling a preset algorithm vector according to the security level to perform identity and intention binding signature; verifying the signature at the agent gateway, and authorizing execution only when the operation intention digest is consistent, the anti-replay identifier is verified, and the hybrid signature is verified. This invention ensures that identity and authorization information possess quantum attack resistance characteristics through hybrid quantum cryptography, strongly binds the execution instructions, target resource, and operation purpose through the operation intention digest to prevent obfuscation proxy attacks, and achieves instantaneous erasure of the authorization key after the task is completed through physical anchoring.
Owner:SUZHOU LANGKONGHOU QUANTUM TECHNOLOGY CO LTD

Information processing device

To provide an information processing device that can reduce development man-hours and lower vulnerabilities. [Solution] The memory 10 of the information processing device 1 stores a secure function module 111a that contains instructions to be executed by the processor 20 in the performance of a function and is restricted from external interference. The memory 10 also stores a processing function module 131 that contains instructions common to the secure function module 111a, has less restrictive external interference than the secure function module 111a, and is processed into a disabled state in which the processor 20 cannot execute instructions. The memory 10 also stores a release module 112 that has more restricted external interference than the processing function module 131 and can release the disabled state in the processing function module 131. The memory 10 also stores a security request determination flag 115 that defines the security level required in the performance of a function.
Owner:DENSO CORP

Edge video analysis dynamic negotiation authentication method and device fusing quantum key

The present application relates to the technical field of edge video analysis, and more particularly to an edge video analysis dynamic negotiation authentication method and device fusing quantum keys, which acquires multi-dimensional data of edge nodes, constructs a dynamic negotiation key pool through identity coding and key synchronization, performs quantum entropy source inspection and integrity analysis on the key pool, constructs a trust degree coupling model and a cross-node association network, generates an identity trust mapping network, verifies the legality of the network and evaluates the security level by using a dynamic trust updating model, forms a security authentication graph, establishes an evaluation index system to comprehensively quantitatively evaluate the graph, outputs a dynamic negotiation authentication report, generates an early warning decision according to the report, and realizes real-time identity authentication and dynamic adjustment of access rights in combination with quantum key distribution, thereby solving the problems of insufficient randomness of traditional edge authentication keys and lagging trust evaluation, and significantly improving the anti-attack capability, real-time response speed and active defense level of the system in a complex environment.
Owner:GUANGDONG ZHIYIXU TECHNOLOGY CO LTD

Communication method and apparatus

PCT designated stageWO2026145665A1Privacy protectionEngineering
A communication method and apparatus, relating to the field of communications. The communication method comprises: a first module in a terminal-side device acquires a first concealed identity identifier from a second module in the terminal-side device, the first concealed identity identifier being obtained by the second module by using a second security mechanism to process plaintext identity information; the first module, by using a first security mechanism, processes the first concealed identity identifier to obtain a second concealed identity identifier; and the first module sends the second concealed identity identifier to a first network, the second concealed identity identifier being used to access the first network. The first module can use the first security mechanism with higher security strength to further process the first concealed identity identifier computed by the second module, so as to obtain the second concealed identity identifier. In this way, when the first module accesses a network, the second concealed identity identifier computed by the first module can provide subscriber identity privacy protection with a higher security level.
Owner:HUAWEI TECH CO LTD

A method for secure encryption of medical data

PendingCN122087844ADigital data protectionComputer hardwareKey space
This invention discloses a method for secure encryption of medical data, relating to the field of data encryption technology. The method includes implementing access control based on security levels, acquiring original medical images after authorization verification, stacking the images into a three-dimensional cube by channels, dynamically dividing them into blocks according to security levels, generating a chaotic encryption key based on the block information, and performing encryption operations on each three-dimensional block to obtain encrypted ciphertext. By destroying pixel correlation through channel stacking and segmentation, combined with differentiated keys generated by chaotic mapping, the key space and encryption efficiency are significantly improved, effectively resisting brute-force and statistical attacks. Permutation and substitution operations enhance the randomness of the ciphertext, ensuring encryption adapts to security levels and operates in a closed loop, guaranteeing controllable access permissions, improving the targeting and security of medical image encryption, and enabling flexible access for authorized users while ensuring efficient data encryption.
Owner:WUHAN AIYANBANG TECH CO LTD

A method and system for controlling multi-level security classification of cloud users

ActiveCN119363416BSecuring communicationCloud userBiba Model
The application relates to a method and system for controlling multi-level security classification of cloud users, and belongs to the technical field of computers.The method comprises the following steps: judging whether a scanning server is normally running; in the case that the scanning server is normally running, determining the security levels of a subject and an object based on a BLP model and a Biba model, the subject being used for indicating a user or a process that sends an access resource request, and the object being used for indicating data or resources that are accessed; performing read-write operations on the subject according to the security levels of the subject and the object; in the case that the read-write operations are performed on the subject, setting the permissions of the subject, and adjusting the security level of the object based on abnormal alarm information.The method can significantly improve the security of a cloud environment, enhance the access control accuracy, optimize the cloud environment management, and promote compliance.Commonly, a safer, more reliable and efficient cloud service environment is provided for cloud users.
Owner:CHINA TELECOM DIGITAL INTELLIGENCE TECH CO LTD

Intelligent file cabinet data exchange management method

The application provides a kind of intelligent file cabinet data exchange management and control method, belongs to intelligent file cabinet technical field, the intelligent file cabinet data exchange management and control method, it includes the following steps: data standardization and protocol formulation: standardized format: the data model of international or industry standard (such as ISO / IEC 23081-1 archive metadata standard) is adopted, ensure the consistency of archive description, classification and index;Guarantee the security and compatibility of data transmission, solve the interoperability problem caused by the non-uniform data format, sensitive data is encrypted by using AES, RSA encryption technology, ensure the safety of data in the process of transmission and storage, combined with biometric identification and traditional password two-factor authentication mode, greatly improve the security level of user identity verification, plus the deployment of firewall and intrusion monitoring system, form a multi-level network security protection system, effectively resist external attack, solve the problem of insufficient data transmission security measures.
Owner:NANTIAN DIGITAL (YUNNAN) TECHNOLOGY CO LTD

Cyber-security in heterogeneous networks

A method and a computer program product and an apparatus for securing communication in heterogeneous networks that include devices with different protection levels. The method comprises monitoring, by a security agent installed on a device, communication between the device and external devices. The method comprises determining a level of in-device protection for each device based on available protection thereof. The method further comprises employing, by the security agent, an associated security policy for communications originating from the device, based on the level of in-device protection; such as resources utilized for employing security policies for communications originating from devices are correlated with the protection levels thereof. The method may further comprise enabling sharing security workload between device having trusted security agents to improve performance efficiency thereof.
Owner:JFROG LTD

Communication method and apparatus

Provided in the present application are a communication method and apparatus, which are used for preventing a key of a terminal from being stolen by an attacker, thereby ensuring the communication security of the terminal. The method comprises: a network function production entity serving a terminal sending a first message to a first security function entity, receiving a second message from the first security function entity, and sending ciphertext information to a network function consumption entity, wherein the network function production entity and the first security function entity are deployed in the same hardware environment, the network function production entity operates in a first operating environment, the first security function entity operates in a second operating environment, and the security level of the second operating environment is higher than the security level of the first operating environment; the first message is used for requesting the generation, for the network function consumption entity serving the terminal, of a key shared by the network function consumption entity and the terminal; and the second message comprises the ciphertext information, and the ciphertext information is ciphertext obtained by means of the first security function entity encrypting the key shared by the network function consumption entity and the terminal.
Owner:HUAWEI TECH CO LTD

Method and apparatus for dynamically changing security algorithm

Embodiments of the present disclosure provide a method and an apparatus for dynamically changing security algorithm. An apparatus operating as a terminal device comprises: at least one processor; and at least one memory including computer program code. The at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus operating as the terminal device at least to perform: receiving, from a network entity, a first message for configuring security mode, wherein the first message comprises a list of security algorithms and an indication of a change pattern of security algorithm; and transmitting, to the network entity, an accept message, when the apparatus operating as the terminal device supports the list of security algorithms and the change pattern of security algorithm. With the dynamical change, the number of permutations and combinations of algorithms and keys may be increased. The security level may be further improved.
Owner:NOKIA TECHNOLOGIES OY

A multi-level secure RAG retrieval method, system, device and storage medium

This invention belongs to the interdisciplinary field of artificial intelligence and information security, and provides a multi-level secure RAG retrieval method, system, device, and storage medium to address the risk of leakage of security management data during the retrieval process. The method includes acquiring user-input query content, user security level, and user business scope; converting the user security level and user business scope into scalar filtering conditions recognizable by a vector database; executing a hybrid retrieval instruction in the vector database, wherein the hybrid retrieval instruction includes a query vector and the scalar filtering conditions, to prune vector data that does not meet permissions during the indexing scan phase; calculating the similarity between the query vector and the remaining document vectors based on the pruned logical subspace, and returning the retrieval results. This invention is applicable to RAG systems in a multi-level data hierarchical isolation environment and can reduce the risk of leakage of security management data during the retrieval process.
Owner:THINKING CHAIN (TIANJIN) INTELLIGENT TECH CO LTD

Database knowledge graph construction method and device and electronic equipment

The application discloses a database knowledge graph construction method and device and electronic equipment, and relates to the technical field of big data processing and mining. A specific embodiment of the method comprises: obtaining metadata information of a database, performing semantic analysis on the metadata information; assigning at least one category label to the metadata information, inputting the metadata information subjected to semantic analysis and the corresponding category label into a pre-training model for training, thereby obtaining a private model through training; wherein the at least one category label comprises a security level label; based on the security level label corresponding to the metadata information, performing vectorization on the metadata information by using a natural speech processing large model and / or the private model, thereby obtaining feature vectors of each word segmentation in the metadata information; and constructing a knowledge graph according to the feature vectors of each word segmentation. The embodiment can solve the technical problem of data leakage danger.
Owner:CCB FINTECH CO LTD