Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

66 results about "Security properties" patented technology

Artificial intelligence-enhanced database security systems and methods using semantic data proxies

Exemplary embodiments for data security include a data access proxy coupled with a database, further coupled with a server configured to operate the data access proxy to: identify a user and request to access a data item; validate the user and request, including inspecting the user's identity, evaluating the user's history, and evaluating permissions and restrictions associated with the user and the data item; access the database to retrieve the data item; inspect security attributes related to the data item; and transform the data item based on one or more privacy rules, including redacting the at least one data item, deleting information from the at least one data item, substituting information from the at least one private data item with other information, adding information to the at least one data item, providing synthetic data as a private data item, or providing proxy data for the data item.
Owner:DYMIUM INC

Trust-based crowd sensing distributed privacy protection method and system

The invention belongs to the technical field of crowd sensing, and discloses a trust-based crowd sensing distributed privacy protection method and system, and the method comprises the steps: constructing a detailed reputation evaluation system, covering the calculation of a reputation value and the setting of a reputation threshold value of a participating user, and integrating a game model in an evaluation stage, the user is guided to avoid malicious behaviors through an income incentive mechanism so as to obtain higher income; a dobby machine model is introduced to dynamically balance the decision-making process of'exploring 'new users and'utilizing' high-reputation users, so that the cold start problem of insufficient reputation of the new users is effectively solved; and finally, verifying the security of the scheme through theoretical derivation of the security attribute of the scheme, verifying the validity of the scheme in the aspects of data credibility, privacy protection effect and the like in combination with experimental analysis, and providing support for credible operation and privacy protection of the crowd sensing system.
Owner:GUIZHOU UNIVERSITY OF FINANCE AND ECONOMICS +1

Enabling large frames for secure virtual machines

The computer-implemented methods, computer program products, and computer systems include computer operations that include executing, in a trusted computing environment, a call from a host in an untrusted computing environment, where the call is to determine a status of a large page of memory for use by a secure guest, where the secure guest is managed by the host in the untrusted computing environment. The executing includes determining that all small pages comprising the large page and the large page meet pre-defined security requirements. The executing also includes, based on the determining, setting security properties of the large page and the small pages comprising the large page to enable translation for the large page for a given block of memory of the secure guest. The executing also includes storing in a computing element, a designation identifying the large page as belonging to the secure guest.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION +1

Book resource data security collection retrieval monitoring system based on big data

The invention discloses a book resource data security collection retrieval monitoring system based on big data, and relates to the technical field of information technology and data security, and the system comprises a permission-aware association reasoning retrieval module which is in communication connection with a knowledge graph and dynamic index construction module and is used for receiving a user retrieval request and sending the user retrieval request to a database; analyzing a retrieval intention and obtaining a real-time permission context of a user to determine a security level threshold value, verifying a security attribute voucher of the data when retrieving the mixed index, only putting the data with the security level not higher than the threshold value into a result set, and performing association reasoning based on the knowledge graph under permission constraint to expand a result. According to the method, the mixed index structure fusing the inverted index, the vector index and the graph index is constructed, the security attribute voucher is associated, efficient full-text retrieval, semantic retrieval and association reasoning are supported, meanwhile, it is ensured that the retrieval process and result are strictly constrained by permission, and maximum mining of data values on the premise of security is achieved.
Owner:GUANGDONG POLYTECHNIC OF IND & COMMERCE

Dynamic attachment of secure properties to machine identity with digital certificates

Technology is shown for dynamically attaching secure properties to an identity certificate. Claims determining secure properties for an identity are signed and embedded in an identity certificate. Both the identity certificate and the signed claims in the certificate are verified. When a service request is received from the identity, the signed claims from the identity certificate are checked to determine if the request is permitted. If the request is permitted, then the service request is processed. Some examples involve creating claims determining the secure properties for the remote machine, signing the claims to create the signed claims, distributing the signed claims to a certificate authority, embedding the signed claims in the remote machine identity certificate, and distributing the remote machine identity certificate. The claims can be embedded in the certificate as X.509 properties.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Method and apparatus for data access control

A method, device, equipment and storage medium for data access control are provided. The method described herein comprises: receiving a data query request for characterizing a first user's request for target data; obtaining a business data access capability attribute corresponding to the first user and obtaining a business security attribute corresponding to the target data; calling a data access security model to determine a data query processing strategy corresponding to the data query request according to the business data access capability attribute of the first user and the business security attribute of the target data; and calling the data query processing strategy to process the target data and generating a response message for feedback. According to the fact of the present disclosure, by providing a response to the request based on the business data access capability attribute of the user and the business security attribute of the target data, the access of the user to the data can be effectively controlled.
Owner:DOUYIN VISION CO LTD

Module security protection system and method, computer equipment and storage medium

The invention provides a module safety protection system and method, computer equipment and a storage medium, the system comprises a plurality of main control modules and a plurality of safety gate modules, and each safety gate module corresponds to an internal module; each master control module is used for initiating an access request to the internal module, and the access request carries a hardware identity label and an access security attribute of the master control module; each security gate module is used for receiving the access request and carrying out legality verification on the hardware identity identifier and the access security attribute based on a pre-configured security rule; and each security gate module is also used for allowing access to the corresponding internal module when the hardware identity identifier and the access security attribute pass verification, or blocking the access request. By adopting the scheme, illegal access can be accurately resisted, the data security of the internal module is protected, and the protection capability is improved.
Owner:CIX TECH (SHANGHAI) CO LTD

Operation ticket electronization and process automation method and system

The invention relates to the technical field of operation permission management, in particular to an operation ticket electronization and process automation method and system. Comprising an operation ticket data acquisition unit; a ticket template configuration and electronic generation unit; a process automation scheduling and execution unit; and an approval and authority verification unit. According to the invention, through deep linkage of a personnel positioning function and approval process circulation, the on-duty state of the approval personnel and the security attribute of the area where the approval personnel are located can be captured in real time; and dynamically adjusting the trend of the approval process and the substitution qualification of related personnel according to the information, namely automatically skipping the substitution qualification of the approval personnel in an operation dangerous area, and starting a substitution matching process for the approval personnel in a safe area. The method effectively avoids the stagnation of the examination and approval process caused by the fact that the examination and approval personnel are out of duty or cannot perform duty in a dangerous area, and fully meets the actual demands of flexible adjustment of the examination and approval process in a complex operation scene.
Owner:BEIJING HUAXIA ZHIBANG TECH CO LTD

Context-aware security policies and incident identification via automated cloud graph building with security overlays

Context-aware security policies and incident identification, via automated cloud graph building with security overlays, are determined and performed by systems and platforms. Graph nodes, of a graph associated with a computing system, that represent resources associated with the computing system and entities associated with the computing system that have respective associations to the resources are generated. Security attributes are determined and assigned to the graph nodes that represent the entities and resources, and static and dynamic connections between the graph nodes are added to the graph. Additionally, possible connections in the graph between the graph nodes are added based on heuristic relational determinations of the graph nodes. From the graph, security incidents and kill chains are identified, context-aware security policies are generated and validated, and scopes and relationships of applications are identified. Accordingly, security actions are taken for the computing system.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Generating synthetic signals by a security analytics platform

A response to a request initiated by a client is received by a processing device of a reverse proxy from an application of a plurality of applications associated with a specified entity. A header of a predefined type is identified within the response. One or more metadata items characterizing one or more security features of the application are retrieved from the header. An updated response is produced by removing the header from the response. The updated response is forwarded to the client. One or more synthetic signals characterizing security properties of the application is generated based on the one or more metadata items. The one or more synthetic signals is stored in a memory of a security analytics platform.
Owner:GOOGLE LLC

Government affair data classification and grading method

The invention discloses a government affair data classification and grading method, and relates to the technical field related to data government. Comprising the steps that 1, government affair data resource directories are sorted, and the sorted content comprises the names of the data resource directories, the departments of the data resource directories, the abstracts of the data resource directories, field names and example data; step 2, classifying the government affair data: according to attributes or features of the government affair data, distinguishing and classifying the government affair data according to preset rules and methods, and establishing a classification system and an arrangement sequence; 3, grading the government affair data: dividing the government affair data into four security levels according to influence objects and influence degrees caused after the security attributes of the government affair data are destroyed, the four security levels are a fourth level, a third level, a second level and a first level from high to low, and triggering any level to reach the corresponding lowest security level; and 4, outputting a government affair data classification and grading ledger: outputting the government affair data classification and grading ledger based on the government affair data resource basic ledger and the established data classification and grading standard.
Owner:浪潮智慧城市科技有限公司 +1

A hardware design security vulnerability qualitative analysis method and system

ActiveCN116484385BPlatform integrity maintainanceComputer hardwareSecure by design
The application discloses a hardware design security vulnerability qualitative analysis method and system, according to a mixed attribute label propagation logic element library and a mixed attribute model construction method based on discrete mapping, so that a corresponding mixed attribute model can be constructed for any HDL design in linear time; the label designed by the mixed attribute model integrates two types of attributes, so that the safety behavior related to the safety attribute and the clock attribute can be modeled simultaneously; the method provided by the application can realize effective discrimination of hardware Trojan horses and hardware time measurement channels by verifying the clock attribute and the safety attribute; the application is deployed in the design and verification stage of the EDA process, so that the HDL design security vulnerability can be detected early, and the design basis is provided for high-reliability hardware design.
Owner:XIAN TECH UNIV

Business process-oriented data processing method and device, equipment, storage medium

This invention relates to the field of artificial intelligence technology and discloses a data processing method, apparatus, device, and storage medium for business processes. The method includes: semantically registering each basic tool to obtain a tool capability catalog; parsing the target business process text to obtain a skill script, where the target business process text contains the business process; compiling the skill script based on the tool capability catalog to obtain a tool call graph; wherein, basic tools serve as nodes in the tool call graph, and the data flow relationships between basic tools serve as edges in the tool call graph; integrating information based on the security attribute information of the nodes to obtain a skill-level capability contract text used to constrain the business process; and executing the business process based on the tool call graph and the skill-level capability contract text. This method can be applied to process processing scenarios in fintech and healthcare, improving the execution efficiency of business processes.
Owner:PING AN TECH (SHENZHEN) CO LTD

A three-factor and puf-based vehicle and drone authentication method

PendingCN122661739AProtect against stolen attacksImprove the immunityEdge serverUncrewed vehicle
The application discloses a vehicle and unmanned aerial vehicle authentication method based on three factors and PUF, and comprises the following steps: S1, system initialization is completed by an edge server and a consortium chain network; S2, the unmanned aerial vehicle and the vehicle are registered respectively, and initial trust binding between the vehicle, the unmanned aerial vehicle and the edge server is completed; S3, in an online stage, the vehicle sends an access request to the edge server, the edge server sends authentication information to the unmanned aerial vehicle after verification, the unmanned aerial vehicle generates a response after verification, and a shared session key SK is obtained by negotiation between the vehicle and the unmanned aerial vehicle; and S4, after successful completion of authentication, the edge server calls an intelligent contract interface, and metadata of an authentication event is written into a consortium block chain. The application can realize two-way identity authentication and session key negotiation between the vehicle, the edge server and the unmanned aerial vehicle in a single-domain scenario of a low-altitude logistics park, and can guarantee multiple security attributes while controlling online authentication calculation overhead at a low level.
Owner:NANJING UNIV OF INFORMATION SCI & TECH

Resource processing method and apparatus, electronic device, and readable storage medium

Embodiments of the present application provide a resource processing method and device, electronic equipment and readable storage medium, in response to the target load sent resource processing request, obtain the target security attribute data corresponding to the to-be-processed resource indicated by the resource processing request; the target security attribute data includes a domain attribute field and a processing permission field; in the case of matching between the domain attribute field and the current execution mode corresponding to the target load, execute the resource processing request; in the case of not matching between the domain attribute field and the current execution mode corresponding to the target load, and the permission bit field in the control state register is the first value, if the processing permission field matches the resource processing operation corresponding to the resource processing request, execute the resource processing request. In this way, the flexible resource processing mode can improve the flexibility of resource processing request processing on the basis of maintaining resource security isolation, so that the system can better adapt to the operation requirements in different scenarios.
Owner:BEIJING INSTITUTE OF OPEN SOURCE CHIP

A processor branch prediction attack vulnerability formal verification method

This invention discloses a formal verification method for processor branch prediction attack vulnerabilities, comprising the following steps: S1, establishing the security attributes violated by the branch prediction attack, wherein the security attributes describe the security specifications that a secure branch predictor design should comply with; S2, establishing a branch prediction behavior model, describing the branch prediction attack as a combination of a series of abstract branch operations; wherein the branch operation is a quintuple consisting of operator, operation type, operation address, jump direction, and jump address, which is an abstract representation of a certain branch instruction; S3, modeling the branch predictor design as accepting branch prediction behavior instructions, and designing different variations of the branch prediction model state machine according to different input instructions, outputting the prediction result, checking the security specifications, and converting the branch prediction attack into a path specification on the state machine; S4, performing model verification on the state machine of the branch predictor design to determine whether it has a branch prediction attack vulnerability.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Network adaptive management system based on dynamic network security

The application belongs to the field of network security management, relates to data analysis technology, and is used for solving the problem that the prior art cannot linearly track from the perspective of an operation user and overall risk assessment of short-term behavior of the same network user, and particularly relates to a network adaptive management system based on dynamic network security, which comprises a behavior monitoring module, a security analysis module and a risk analysis module connected in sequence in communication, and the behavior monitoring module, the security analysis module and the risk analysis module are all connected in communication with a database; the application can finely and weightedly quantitatively evaluate the security of each combination element; the evaluation method fully considers the differentiated influence of different security attributes such as permission, privacy and network fluctuation on the security of network behavior, so that the finally calculated security coefficient of the combination element is more representative and accurate.
Owner:GUANGZHOU SIYUN DATA TECH CO LTD

Data storage method and device, equipment and storage medium

The embodiment of the invention provides a data storage method and device, equipment and a storage medium. The method specifically comprises the steps that the security attribute of to-be-stored data is obtained in real time; the security attributes comprise a data volume, a data security level, a data access frequency and a medium security level of the current storage medium; inputting the security attribute into a preset risk assessment model, and obtaining a security risk value and a security capacity threshold value output by the risk assessment model; under the condition that the security risk value exceeds a risk migration threshold value, determining a target security level according to the security risk value and a security capacity threshold value; wherein the risk migration threshold value is determined according to the safety capacity threshold value; and migrating the to-be-stored data to a target storage medium corresponding to the target security level for storage.
Owner:PICC INFORMATION TECH CO LTD

A method and system for lightweight privacy protection authentication of a UAV network

The application discloses a kind of unmanned aerial vehicle network lightweight privacy protection authentication method and system, comprising: obtaining initialization system parameter, unmanned aerial vehicle is registered with ground station based on physical unclonable function through secure channel;First unmanned aerial vehicle and second unmanned aerial vehicle complete three-party authentication with ground station by executing authentication algorithm, to realize secure communication session.The application improves the efficiency of key agreement, reduces the operation time, while meeting various security properties also realizes the anonymity and traceability requirements of unmanned aerial vehicle identity.
Owner:NANJING UNIV OF POSTS & TELECOMM

Formal verification methods, devices, equipment, media, and products for security protocols

PendingCN122093116AResolve verification resultsresolve the disconnectSecuring communicationConfidentialitySecurity properties
This invention discloses a method, apparatus, device, medium, and product for formal verification of security protocols. The method includes establishing a discrete-time model of the target protocol based on the formal description result and protocol model of the target protocol; performing formal verification of the target protocol based on the protocol model and the discrete-time model to obtain the verification result of the target protocol. By establishing a discrete-time model, the time dimension is incorporated into the verification system, solving the problem of existing technologies ignoring the time factor, which leads to a disconnect between verification results and reality. By combining the protocol model and the discrete-time model for verification, effective verification of non-time-limited security properties such as authentication and confidentiality, as well as time-limited security properties such as freshness, can be achieved. This overcomes the limitation of existing technologies that can only verify non-time-limited properties, meets the verification needs of more types of security protocols, and expands the applicability of protocol verification.
Owner:CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1

A method and system for modeling and quantitatively detecting time side-channel leakage of a secure microarchitecture

PendingCN122655063ARandomizationAttack strategy
The application discloses a time side channel leakage modeling and quantitative detection method of a secure micro-architecture, and comprises the following steps: constructing a secure micro-architecture model, including defining the core operation logic of the partition isolation design, the randomization mapping design and the mixed partition-randomization design of each micro-architecture component in the target processor micro-architecture; simulating the execution process of the time side channel attack strategy of each micro-architecture component based on the secure micro-architecture model, so as to obtain the hit or miss state of each micro-architecture component in the execution process, and obtain statistical data based on the hit or miss state of each micro-architecture component; and quantitatively evaluating the side channel security attribute of the secure micro-architecture design from the dimensions of the attacker cost and the information leakage by using a leakage quantization index based on the statistical data. Based on this, the application realizes unified evaluation of the efficiency of different defense mechanisms, realizes leakage risk quantization in the perspective of multiple component cooperation, and effectively identifies the time side channel leakage risk of the underlying micro-architecture.
Owner:WUHAN UNIV

Code security assessment method and related hardware

The embodiment of the invention provides a code security assessment method and related hardware, and relates to the technical field of code security assessment, and the method comprises the steps: generating a dependency structure directed graph based on an actual dependency item of a to-be-assessed target code; wherein the dependency structure directed graph comprises at least one dependency item node, each dependency item node corresponds to one actual dependency item of the target code, and the dependency item nodes are in directed connection according to the dependency relationship between the actual dependency items of the target code; and for any actual dependency item, determining the security degree of the actual dependency item in the target code according to the code security attribute of the actual dependency item and the structure of the dependency structure directed graph. Therefore, a quantitative analysis result can be effectively provided for the risk existing in each actual dependency item used by the target code, so that a developer of the software program code can carry out security maintenance on the software program code according to the analysis result.
Owner:CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1

Resource security management method, resource security management system, and chip

The embodiment of the application provides a resource security management method, a resource security management system and a chip, in the case that a processor resource processing request sent by a target non-safe load is received, a first memory management unit performs security detection on the processor resource processing request based on a first security attribute of a target memory resource indicated by the processor resource processing request and a load execution mode corresponding to the target non-safe load, and a first security detection result is obtained; in the case that an external device processing request sent by the target non-safe load is received, a second memory management unit performs security detection on the external device processing request based on a second security attribute of a target input / output resource indicated by the external device processing request and the load execution mode, and a second security detection result is obtained, potential malicious requests can be effectively identified and blocked, the risk of system attack is reduced, the availability, integrity and confidentiality of resources are ensured, and the security of resource access processing is improved.
Owner:BEIJING INSTITUTE OF OPEN SOURCE CHIP

Interrupt control method, artificial intelligence chip, system, device, medium and program product

This invention relates to the field of artificial intelligence chip technology, providing an interrupt control method, an artificial intelligence chip, a system, a device, a medium, and a program product. The method includes: receiving interrupt request information initiated by a target user; performing a first-stage verification on the interrupt request information; if the first-stage verification passes, performing a second-stage verification on the interrupt request information; and distributing the interrupt request information or corresponding generated abnormal interrupt information to the corresponding interrupt storage area of ​​the host based on the combined verification results of the first and second stages. This invention, by performing multi-level verification of the legality and security attributes of each user-initiated interrupt request at the source end, and combining the verification results with physical isolation-level distribution, not only achieves bidirectional defense from the source end to the underlying target storage end, but also allows for independent checking of the security of each user-initiated interrupt, thereby maximizing the data security and operational compliance of the entire chip system.
Owner:SHANGHAI BIREN TECH CO LTD

Method for implementing user plane security policy, apparatus, and system

A method for implementing a user plane security policy includes receiving, by a communication apparatus, user plane security indication information from a network device. The user plane security indication information indicates a user plane security attribute requirement of an application. The communication apparatus is a terminal apparatus or a chip for the terminal apparatus. The method also includes establishing, by the communication apparatus, a session based on the user plane security attribute requirement. The establishing, by the communication apparatus, the session based on the user plane security attribute requirement includes, in response to no session that meets the user plane security attribute requirement of the application existing in established sessions, sending, by the communication apparatus, session establishment request information, to request to establish a session that meets the user plane security attribute requirement of the application.
Owner:HUAWEI TECH CO LTD

Electronic document encryption and decryption system and method based on block chain, medium and equipment

The invention provides an electronic document encryption and decryption system and method based on a block chain, a medium and equipment, the system comprises a block chain evidence tracing layer, an electronic document security layer and a security access and identity management layer, and the block chain evidence tracing layer is used for tracing an evidence uploaded by data; the electronic document security layer comprises an uploading node processor and a downloading node processor, and is used for encrypting uploaded data by using an uploading data node and decrypting block data by using a downloading data node, and the encryption and decryption processes are processed based on a self-defined ciphertext policy attribute proxy re-encryption mechanism; and the security access and identity management layer is used for verifying the security attribute of the node and performing management. According to the method, while full-link traceability and tampering prevention of the document process are realized, dynamic and fine-grained regulation and control of the access permission of the encrypted document are supported, and authenticity, privacy and controllable sharing of data are comprehensively guaranteed.
Owner:SHANGHAI INTERNATIONAL PORT +1

Verification strategy optimization method and system for security protocol formal verification

The invention discloses a verification strategy optimization method and system for security protocol formal verification. The method comprises the steps of obtaining a to-be-verified security protocol model and security attributes; maintaining a to-be-explored verification path in the verification search tree; determining a target verification path and a next verification action by a reinforcement learning decision model based on the verification state; inputting the target verification path, the exploration depth parameter and the next verification action into a formalized verification rear end, executing depth limited path exploration, and outputting exploration intermediate information and an exploration result; updating the verification search tree and judging a termination condition; and executing loop detection based on exploration intermediate information when the detection is not ended, generating a negative reward mark for an action causing the loop and pruning the path if the loop is detected, and generating an experience sample and updating the reinforcement learning decision model if the loop is not detected. According to the scheme, under the controlled depth, path omission caused by premature pruning is reduced, the situations of false positive, false report and incapability of proving are reduced, and the verification terminability is kept.
Owner:UNIV OF SCI & TECH OF CHINA +1

Integrated circuit, method for controlling resource access, and device

Embodiments of the disclosure disclose an integrated circuit, a method for controlling resource access, and a device. A resource access request sent by a requester is received, whether the requester is permitted to access a resource party corresponding to an access address requested by the requester is determined based on access permission control information pre-configured, to obtain a first determining result. In response to that the requester is permitted to access the resource party, whether the requester is permitted to operate on the access address is determined based on security control information pre-configured and security attribute information in the resource access request, to obtain a second determining result. Moreover, the resource access request is processed based on the second determining result.
Owner:XG TECHNOLOGIES PTE LTD

A government affair interface authentication scheduling and digital certificate dynamic penetration method and system

The application relates to a government affair interface authentication scheduling and dynamic digital certificate penetration method and system, and the specific steps comprise the following steps: collecting authentication modes and security attribute information of government affair interfaces in a government affair platform, performing characteristic processing on the security attribute information, constructing an interface authentication capability model library based on a characteristic vector of the security attribute information; extracting context parameters of a business event, mapping the context parameters into authentication demand parameters, and generating an authentication demand vector; based on the interface authentication capability model library and the authentication demand vector, generating an authentication strategy for a target interface through matching calculation, and dynamically adjusting authentication strength according to real-time risk assessment results in the calling process of the target interface; determining the authentication strategy, and generating a unique identification code of a digital certificate; in the use process of the digital certificate, collecting context parameters of a business event in real time, and performing consistency verification on the use behavior of the digital certificate based on the context parameters.
Owner:国网福建省电力有限公司营销服务中心 +1

Method for implementing user plane security policy, apparatus, and system

A method includes receiving, by a policy control function entity, user plane security attribute requirement information that is of an application and that is from an application function. The user plane security attribute requirement information indicates a user plane security attribute requirement of the application. The method also include sending, by the policy control function entity, user plane security parameter information of a service data flow (SDF) to a session management function entity. The user plane security parameter information of the SDF is determined based on the user plane security attribute requirement of the application.
Owner:HUAWEI TECH CO LTD