Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

1461 results about "Session key" patented technology

A session key is a single-use symmetric key used for encrypting all messages in one communication session. A closely related term is content encryption key (CEK), traffic encryption key (TEK), or multicast key which refers to any key used to encrypt messages, as opposed to other uses, like encrypting other keys (key encryption key (KEK) or key wrapping key).

Distributed intelligent authentication method based on dynamic multi-modal fusion

A distributed intelligent authentication method based on dynamic multi-modal fusion relates to the field of network security, and adopts an alliance chain + DAG hybrid block chain architecture, combines a threshold signature to realize secret key fragment management, and switches among PBFT, Raft and probabilistic algorithms through a dynamic consensus mechanism to improve authentication efficiency. The multi-mode authentication module is based on a dynamic weight distribution algorithm, integrates biological characteristics, behavior analysis, equipment fingerprints and environmental factors, and combines an LSTM-GAN model and a quantum random number driven challenge-response mechanism to realize zero-trust verification under environmental perception. The session management module generates a session key by using a chaotic mapping algorithm. In the aspect of privacy protection, CKKS homomorphic encryption, zero-knowledge proof and attribute-based encryption are fused. According to the method, the block chain technology, the secure multi-party computing technology, the machine learning technology and the quantum cryptography technology are fused, and a high-performance, high-security and strong-privacy-protection distributed authentication solution is provided.
Owner:JINLING INST OF TECH

High-security method for negotiating temporary session key based on national secret algorithm

The invention relates to the technical field of commercial password detection methods, and discloses a high-security method for negotiating a temporary session key based on a national secret algorithm, and the commercial password detection method comprises the following steps: initialization and identity authentication: two communication parties generate an SM2 public and private key pair, and the identity is verified through a digital certificate and an SM2 signature; temporary key negotiation: generating a shared key point based on an SM2 key exchange protocol; session key derivation: generating a temporary session key by using an SM3 hash algorithm; key confirmation and encrypted communication: verifying the key through an SM4 algorithm and encrypting communication data; according to the high-security method for negotiating the temporary session key based on the national secret algorithm, efficient key negotiation of both communication parties in an unsecure channel is realized through an SM2 key exchange protocol, an SM3 hash algorithm and an SM4 symmetric encryption algorithm. The method combines digital certificate authentication, dynamic random numbers and timestamps, has forward security, replay attack resistance and man-in-the-middle attack resistance, and is suitable for high-security scenes such as finance and government affairs.
Owner:SHAANXI QINGSHAN SIJI INFORMATION TECH CO LTD

Secure communication method between edge server and terminal equipment

The invention relates to a secure communication method between an edge server and terminal equipment. The secure communication method comprises the following steps: establishing a physical layer channel state information database, generating a multi-dimensional feature vector and encoding the multi-dimensional feature vector into a terminal equipment identifier, generating an identity authentication request by the terminal equipment, and performing hash operation to obtain a first hash value; the identity authentication request and the first hash value are sent to the edge server, the edge server verifies the identity authentication request and queries a corresponding device key, performs hash operation to obtain a second hash value, generates an authentication response message after successfully comparing the second hash value with the first hash value, encrypts the authentication response message by using the device key, and sends the encrypted authentication response message to the edge server; and sending the encrypted authentication response message to the terminal equipment. And the terminal equipment decrypts by using the equipment key to obtain the session key, and communicates with the edge server based on the session key. By using the physical layer channel information and the equipment hardware characteristics, the security communication method fusing dynamic identity authentication and efficient key management improves the security, reliability and anti-attack ability of communication between the edge server and the terminal equipment.
Owner:BEIJING HUAKUN ZHENYU INTELLIGENT TECH CO LTD

RFID anti-tracking bidirectional authentication method and system based on lightweight hash chain

The invention discloses an RFID anti-tracking bidirectional authentication method and system based on a lightweight hash chain, and relates to the technical field of wireless radio frequency identification security. The system comprises a label initialization module, a bidirectional authentication module, an anti-tracking mechanism module, a hash chain updating module, a secure communication module and a system feedback optimization module. The label initialization module generates initial hash chain data; the bidirectional authentication module adopts a bidirectional challenge-response mechanism to generate a dynamic authentication certificate; the anti-tracking mechanism module generates an untraceable session key through Hash chain value dynamic rotation and randomization mask technology; the Hash chain updating module iteratively updates the Hash chain value; the secure communication module adopts a lightweight encryption algorithm to protect communication data; and the system feedback optimization module dynamically adjusts the hash chain length and the key strength. The real-time performance and the anti-attack capability of the RFID system are remarkably improved, and a high-safety and low-power-consumption bidirectional authentication solution is provided for Internet of Things equipment.
Owner:NANJING UNIV OF POSTS & TELECOMM

Control method of multi-protocol switching anti-quantum security gateway

The invention relates to a control method for a multi-protocol switching anti-quantum security gateway, and the method comprises the steps: carrying out the safety self-inspection of a hardware environment after the security gateway is powered on, generating a unique root key of equipment based on a physical unclonable function, continuously collecting and analyzing the network traffic characteristics, and carrying out the self-inspection of the hardware environment. Based on a machine learning model, a quantum attack mode is identified and an encryption algorithm mode is dynamically decided, protocol analysis is carried out on a communication data packet, dynamic conversion and adaptation are carried out between a traditional protocol and an anti-quantum cryptography protocol according to an instruction and a preset rule, and an anti-quantum cryptography engine is called to carry out encryption or signature operation. And dynamically deriving and managing a session key in a complete period based on a root key, switching an algorithm mode, a communication protocol and a key in a linkage manner according to a quantum attack detection result, and starting anti-side channel attack protection and hardware security response. According to the method, active protection of the security gateway on quantum attacks, multi-protocol seamless compatibility and full-life-cycle security management of keys are realized.
Owner:WEIDE GUANGDONG INFORMATION TECH CO LTD

Interface authentication method, system and equipment based on national cryptographic algorithm and medium

The invention discloses an interface authentication method, system and device based on a national cryptographic algorithm and a medium, belongs to the technical field of computer security, and aims to solve the technical problem of how to realize identity authentication, data encryption, integrity verification and replay attack protection of interface interaction and meet the security requirement of a key information system. According to the technical scheme, the method comprises the following steps: system initialization: a server and a client respectively generate SM2 key pairs, the client and the server exchange public keys through a secure channel, and a mapping relation between the public key of the opposite side and an identity label is stored; session key negotiation: exchanging a temporary public key based on an SM2-ECDH algorithm, calculating a shared secret value, and deriving an SM4 session key through a KDF; the client side carries out SM3 hash and SM2 signature on request parameters, and the server side verifies the signature and verifies a timestamp and a random number to resist replay attacks; and session key updating: triggering key updating according to a preset condition, and encrypting the new key negotiation message by using the original session key.
Owner:SHANDONG INSPUR DIGITAL BUSINESS TECHNOLOGY CO LTD

Enabling cellular based zero trust network access

PendingUS20250203367A1Security arrangementGeneric Bootstrapping ArchitectureInternet privacy
A method performed by a user equipment to establish a secured connection with an application entity in an enterprise network. The method comprises sending an establishment request to a secure access secure edge (SASE) entity: receiving an establishment response from the application entity if the SASE entity determines to allow the establishment request and authorizes Generic Bootstrapping Architecture / Authenticated Key Management for Application (GBA / AKMA) platform to share a session key with the application entity; and establishing a connection with the application entity based on the session key.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Secure communication method for edge node and terminal equipment based on dynamic key negotiation

The invention relates to a secure communication method for an edge node and terminal equipment based on dynamic key negotiation. The method comprises the following steps: the terminal equipment sends an initial signal when initiating a communication request; the edge node generates a scenarized first key negotiation parameter and feeds back the scenarized first key negotiation parameter after passing dual identity and state verification; after the terminal device decrypts the parameter, a dynamic entropy value is collected by combining a network adaptive sensor, and a second key negotiation parameter associated with the first parameter feature is generated; the two parties calculate session keys based on an ECDH algorithm, and the consistency of the keys is ensured through dynamic entropy verification and Hash comparison; and after the key negotiation succeeds, entering a hierarchical encrypted data transmission stage, and dynamically updating a session key based on a multi-dimensional trigger mechanism. According to the method, through hardware credibility verification, a scenarized key strategy, dynamic entropy enhancement and national secret algorithm adaptation, dynamic management of keys and adaptive matching of terminal resources are achieved, attacks such as equipment counterfeiting and parameter tampering are effectively resisted, and the high-security and compliance requirements in the fields of industrial control and the like are met.
Owner:BEIJING HUAKUN ZHENYU INTELLIGENT TECH CO LTD

File digitalization full life cycle encryption integrity verification method and system

The invention discloses an archive digitization full-life-cycle encryption integrity verification method and system, relates to the field of digital archive safety management, and is used for solving the problem of integrity and safety guarantee in archive digitization management. Logic units are divided through a semantic analysis engine, non-uniform blocks are generated based on sensitivity dynamic partitioning, local hash values are calculated, and a multi-level verification tree is constructed to generate root hash and a hash path mapping table; acquiring visitor identities, terminal environments and timestamps in each stage of an archive life cycle, generating state snapshots in combination with a hash path, and constructing a life cycle state snapshot chain; reconstructing a target logic unit verification path according to the access request, analyzing the structural difference between a current path and a historical snapshot chain through a path reconstruction type difference verification algorithm, and identifying structural offset, node tampering or path loss; and response control is triggered for abnormal verification, including session key updating and permission freezing, so that the security integrity guarantee of the digital archive in the full life cycle is improved.
Owner:FOSHAN POWER SUPPLY BUREAU GUANGDONG POWER GRID

Distributed node unified identity authentication method and system based on QUIC protocol

The invention relates to a QUIC protocol-based distributed node unified identity authentication method and system, belongs to the technical field of network security, is applied to a client, and comprises the following steps: registering a client domain name identity through a certificate authority, obtaining a client certificate, and pre-storing a server certificate chain; generating a QUIC initial data packet according to the target server domain name identifier and the client certificate, and sending the QUIC initial data packet to the server; receiving a QUIC handshake data packet returned by the server; verifying the legality of the server certificate based on the server certificate chain, and if the server certificate is legal, calculating a pre-master key according to the client DH private key and the server DH public key; deriving a 1-RTT session key based on the pre-master key; generating a signature verification message, and sending the client certificate and the signature verification message to a server; and synchronously using the 1-RTT session key to encrypt the application layer data with the server, and transmitting the data to the server in the 1-RTT encryption space of the QUIC protocol. According to the invention, the reliability of node identities and the confidentiality of data are ensured.
Owner:BEIJING LIUJINSUIYUE TECH CO LTD

Real estate full life cycle intelligent management method and system based on Internet of Things perception

The invention provides a real estate full life cycle intelligent management method and system based on Internet of Things perception, and the method comprises the steps: distributing a unique hardware identifier of equipment, combining a lightweight digital certificate with a pre-shared key to achieve two-factor authentication, and storing a root certificate in a cloud end; an access authentication process is optimized, an identity label and a certificate signature request need to be submitted when a node accesses for the first time, a temporary session key is generated after the gateway verifies, and abnormal access is immediately isolated and reported; data integrity verification is implemented, and after a sensor collects data, an abstract is generated and data encryption transmission is carried out; after decryption, the receiving end recalculates the abstract for comparison, and if not, the abstract is discarded and nodes are marked to be abnormal; a data anomaly detection model is constructed, energy consumption fluctuation is determined based on historical data, a frequency baseline is collected, data reasonability is monitored in real time, secondary authentication is triggered when the data is abnormal, and node data access is suspended if the data fails; a hierarchical key system is established, hardware is solidified by a root key, session keys are alternated for 24 hours, and data encryption keys are dynamically derived and distributed through encryption channels.
Owner:LERUAN CENTURY (BEIJING) INFORMATION TECHNOLOGY CO LTD

Communication authentication method and system of train on-board network, storage medium and equipment

The invention provides a communication authentication method and system for a train-mounted network, a storage medium and equipment, and the method only completes the key negotiation operation in the process of executing the communication authentication of the train-mounted network, enables the subsequent communication process to be executed based on a session key obtained through the negotiation of a first verification party and a second verification party, and improves the communication authentication efficiency. According to the method and the device, identity information of two communication parties is mutually verified, only a request carrying identity information of a verification party needs to be sent once in a primary communication process, only a session key generated by negotiation needs to be carried in a subsequent communication process, lightweight processing is performed on a communication authentication protocol, and the communication authentication protocol can be obtained by introducing a pairing-free password system based on an identity label. According to the method, a complex pairing process does not need to be executed, the number of calling times of Hash is reduced, the protocol calculation overhead is reduced, the communication efficiency is improved on the basis of ensuring the credible access authentication of a train-mounted network and the credible transmission of a control message, and the influence on the real-time performance of a train network monitoring management system is avoided.
Owner:NAT HIGH SPEED TRAIN QINGDAO TECH INNOVATION CENT

OBD tamper-proof two-way verification method

The invention discloses an OBD tamper-proof two-way verification method, which comprises the steps of obtaining OBD equipment data and vehicle sensor data, registering to a cloud end based on the OBD equipment data, obtaining registration data, obtaining key data and non-key data according to the vehicle sensor data, symmetrically encrypting the key data by using a session key in the registration data, and verifying the key data and the non-key data. Performing approximate homomorphic encryption on the non-key data, obtaining a double-entropy source dynamic salt value according to the time entropy of the ciphertext and the OBD equipment operation entropy, reversely reconstructing the dynamic salt value by the cloud according to the timestamp and the registration data, verifying the ciphertext structure by using the dynamic salt value and generating a random challenge containing a salt value check code, and sending the random challenge to the cloud; the equipment verification result and the challenge value are signed and then transmitted back, the OBD equipment carries out reverse verification on the salt value according to the signature and the equipment verification result, and the cloud generates an authority token based on the reverse verification result. According to the method, the data authenticity and integrity of the diagnostic equipment are guaranteed through packet encryption, dynamic salt value generation and bidirectional identity verification of transmission data.
Owner:INST OF ACOUSTICS CHINA ACAD OF TESTING TECH

Anti-quantum security data transmission authentication method based on SLH-DSA

The invention discloses an anti-quantum security data transmission authentication method based on an SLH-DSA, and aims to cope with communication security challenges in a quantum computing environment. The device generates a key pair locally in a registration phase and applies for an anti-quantum identity certificate from a certificate agent. In the authentication stage, a user exchanges an identity certificate and a key parameter to realize identity authentication and negotiate a shared key. In the data transmission stage, a session key is dynamically derived by using a shared key, data is encrypted in combination with a national secret symmetric encryption algorithm SM4, and integrity verification is performed by using an anti-quantum signature algorithm. The method gives consideration to security, lightweight and performance, has quantum attack resistance and forward security, is suitable for application scenarios with high data security requirements, such as industrial Internet of Things and smart power grids, and has good application prospects and popularization values.
Owner:CHENGDU MOJIA INFORMATION TECH CO LTD

IKE protocol security enhancement method based on PUF dynamic authentication and post quantum hybrid key

The invention provides an IKE (Internet Key Exchange) protocol security enhancement method based on PUF (Physical Unclonable Function) dynamic authentication and a post-quantum mixed key, which organically combines a PUF, a post-quantum cryptographic algorithm (PQC, especially Kyber KEM) and an improved Internet Key Exchange Protocol (IKE) to realize key exchange of post-quantum security and enhanced identity authentication. The method comprises the following steps: generating a dynamic pre-shared key (PSK) by utilizing the PUF; the method comprises the following steps: integrating a Kyber KEM to an IKE protocol, and replacing traditional Diffie-Hellman key exchange; the PUF-driven dynamic PSK is used as an identity authentication method of the IKE; meanwhile, Kyber KEM and ECDH are adopted for key exchange, and a final session key is generated through joint participation of a Kyber negotiation key, an ECDH negotiation key and PSK derived by PUF; and an IKE protocol process is optimized, and Kyber key exchange and PUF (Physical Unclonable Function) authentication are completed in an IKESAINIT stage and an IKEINTERMEDIATE stage. According to the method, key exchange is post-quantum secure, identity authentication is also post-quantum secure, and the final key integrates three key components of Kyber, ECDH and PUF, so that triple security assurance is provided.
Owner:MIXUAN TECHNOLOGY (HANGZHOU) CO LTD

Server, terminal and security system

Provided in the present application are a server, a terminal and a security system. The server comprises an authentication and key management module, a secure multi-party computation engine and a secure-channel management module, wherein the authentication and key management module is used for performing identity verification on a terminal, generating a first private key corresponding to the terminal and a first public key corresponding to the first private key, and generating a first session key on the basis of a second public key of the terminal and the first private key; the secure multi-party computation engine is used for verifying fingerprint information of the terminal and cooperating with a plurality of terminals to perform identity verification on a server; and the secure-channel management module is used for establishing a secure channel with the terminal, encrypting communication data on the basis of the first session key, and using the secure channel to send the encrypted communication data to the terminal. The solution of the present application can effectively solve the security problem of communication between a terminal and a server, and has the advantages of high flexibility and a low cost.
Owner:TSINGHUA SHENZHEN INTERNATIONAL GRADUATE SCHOOL +1

Browser tab page data storage method supporting data encryption

The browser tab page data storage method supporting data encryption comprises the steps that browser tab page interaction behaviors are monitored in real time to generate a dynamic factor, and a session key dynamically changing along with the life cycle of a tab page is generated in combination with a process ID of the tab page; based on a self-adaptive encryption strategy, respectively encrypting structured data and unstructured data of the label page; wherein the structured data are encrypted according to field sensitivity levels, and the unstructured data are encrypted through mapping binding of a secret key and the data; the encrypted data and a timestamp voucher of the session key are stored in an associated mode, decryption operation is only allowed to be completed in a label page process memory generating the session key, and the session key is not stored in a landing mode; and when the label page is closed, synchronously clearing the decryption data in the session key and the process memory. According to the method and the device, the defects that the dynamic generation of the key cannot be realized and the key cannot fall to the ground at present are overcome.
Owner:BEIJING NORTH LATITUDE 30 DEGREE NETWORK TECH CO LTD

Internet of Things data transmission security enhancement method combined with quantum random number generation

The invention discloses an Internet of Things data transmission security enhancement method combined with quantum random number generation, which comprises the following steps of: generating a high-security and unpredictable random number seed through a quantum random number generator, and generating a dynamic binding key in combination with a unique identifier of equipment and a timestamp, the binding key is used for generating a shared session key between devices through a quantum secure handshake protocol, so that the confidentiality and integrity of data transmission are ensured, a dynamic key updating mechanism is introduced, the binding key and the session key are updated regularly, the security risk caused by long-term use of the same key is avoided, a key destruction mechanism is designed, and the security of data transmission is ensured. A session key is completely destroyed after a session is ended, a malicious attacker is prevented from recovering the key, and a standby key generation and synchronization mechanism ensures that the system can automatically switch to a standby key when key synchronization fails or communication is abnormal, so that data transmission is not affected. The method has the advantages of good expandability and high safety.
Owner:ZHONGHUITONG ECOLOGICAL TECH (SHANDONG) CO LTD

Medical data circulation and storage method based on block chain

The invention relates to the technical field of medical data circulation and storage, in particular to a block chain-based medical data circulation and storage method, which comprises the following steps of data storage, data circulation and data auditing. The medical data storage security is remarkably improved, the blockchain storage performance bottleneck is avoided, the non-tampering property of the blockchain ensures that the data operation record is traceable in the whole process, the malicious tampering risk of internal personnel is completely eradicated, a mixed encryption mechanism is adopted, a session key is chained after being encrypted by a public key of a patient, a private key is only held by the patient, the cracking difficulty is extremely high, and the safety is high. According to the method, high-efficiency and de-intermediary data circulation is achieved, patient privacy control and compliance are enhanced, fragmented PBFT consensus is adopted, the medical transaction throughput can reach 2000 + TPS, clinical real-time requirements are met, breakthrough is achieved in the aspects of safety, efficiency and privacy protection, and a trusted infrastructure is provided for medical data value circulation.
Owner:JIANGSU CHUANGYI CLOUD TECHNOLOGY CO LTD

Remote data rapid transmission system and method based on Internet

The invention discloses a remote data rapid transmission system and method based on the Internet, a client initiates a session establishment request containing a session type identifier and a transmission protocol identifier to a server, receives a session response message after transmitting an initial data packet, obtains a temporary session key through verification of a key distribution center, and transmits the session response message to the server; an authorization identifier and a protocol verification symbol are generated through hierarchical decryption, a security enhancement data packet is constructed and sent, an end-to-end encryption transmission channel is further established, and meanwhile, a session maintenance mechanism is provided. And the server verifies a session type identifier and a transmission protocol identifier of the client, generates a session response message containing a dynamic confusion strategy and a trap identifier, submits the session response message to a key distribution center for signature, returns the session response message to the client, activates a secure transmission service instance after verifying a security enhancement data packet, and implements a series of security control strategies. According to the invention, the problems of low transmission efficiency and poor security of the existing remote data transmission system are effectively solved, and efficient and secure data transmission is realized.
Owner:GUANGZHOU KAIYAS TECHNOLOGY CO LTD

Encryption transmission and self-healing control cooperation system facing virtual power plant terminal

The invention discloses a virtual power plant terminal-oriented encryption transmission and self-healing control cooperative system, which comprises a dynamic encryption module, a hierarchical encryption system is constructed on the basis of a quantum chaos sequence and a national secret SM9 algorithm, a dynamic session key is generated in real time through an edge node, and terminal power data is subjected to hierarchical encryption; the self-healing control module integrates a block chain distributed account book and a deep reinforcement learning model, constructs a health degree portrait of the terminal equipment in real time, monitors a link state through a topology sensing algorithm, predicts a fault propagation path, and triggers communication link reconstruction and computing resource elastic scheduling for self-healing; the collaborative optimization module constructs an optimization objective function, balances encryption strength and self-healing efficiency, adopts a quantum topology photonic crystal optimization algorithm to determine a weight coefficient in the optimization objective function, and realizes global optimal matching of an encryption-self-healing strategy; and the edge computing node performs terminal-edge cloud cooperative training according to the global optimal matching strategy of the encryption-self-healing strategy.
Owner:HUAIYIN INSTITUTE OF TECHNOLOGY

NFC encrypted IMS server security data exchange method

The invention belongs to the technical field of communication, and particularly relates to an NFC (Near Field Communication) encrypted IMS (IP Multimedia Subsystem) server security data exchange method, which comprises the following steps of: in response to a near field communication connection event, acquiring an original service data message of service equipment to be opened and physical environment data monitored when the event occurs, forming a seed data set, executing Hash operation to generate an initial data fingerprint, and sending the initial data fingerprint to a server; and generating a symmetric session key through a key derivation algorithm by combining a device identifier in the original service data message, so as to encrypt the original service data message, packaging an encrypted data packet and the initial data fingerprint into a transmission data packet, sending the transmission data packet to an IMS server, reconstructing the session key by the server based on expected service parameters stored locally, and sending the session key to the IMS server. According to the method, decryption verification of the encrypted data packet is carried out, and service opening is executed after the verification is passed, so that deep binding of an encryption process and data integrity verification is realized, and the security of data exchange and the system processing efficiency are improved.
Owner:SHANXI ELECTRIC POWER CO POWER COMM CENT

Communication encryption method and device, equipment, storage medium and computer program product

The invention relates to the technical field of communication security, in particular to a communication encryption method and device, equipment, a storage medium and a computer program product. The method comprises the following steps: dynamically generating a main session key between two communication parties based on a preset key negotiation protocol; dynamically generating sub-keys according to a preset time interval based on the main session key and the key sequence; performing encryption processing on each data block in the communication data stream based on the sub-key and the encryption strategy; generating a message authentication code for each encrypted data block; adding timestamp information based on the message authentication code, and introducing a random offset into the timestamp information; and the encrypted data blocks, the message authentication code and the timestamp information are packaged into the target data message, so that the transmission security of the communication data is improved.
Owner:SHENZHEN DINSTAR TECH

Stable transmission method for server data encryption and rapid authentication

The invention discloses a stable transmission method for server data encryption and rapid authentication, and belongs to the technical field of data security. The method comprises the following steps: dividing data into three levels of core sensitive data, important data and common data by utilizing a semantic analysis model; performing encryption protection on different levels of data by adopting a hierarchical encryption strategy; a master key is generated based on a chaotic system, a session key is generated in combination with a timestamp and a device fingerprint and is regularly alternated, and secure distribution is performed through a trusted execution environment and a block chain; multi-modal features are fused, the identity is verified through zero-knowledge proof, and the authentication strength is adjusted through dynamic risk assessment. The method is suitable for cloud computing, the Internet of Things and a distributed storage system, through deep fusion of a multi-level hybrid encryption algorithm, a dynamic key management mechanism and a self-adaptive authentication strategy, data security encryption, rapid authentication and stable transmission are achieved, and security, efficiency and adaptability are improved.
Owner:SHANGHAI GUIHENG TECHNOLOGY CO LTD

API service management method and device and medium

The invention discloses an API service management method and device and a medium, and relates to the technical field of software development. The method comprises the following steps: receiving and verifying API service registration information through a standardized interface to generate service metadata based on the API service registration information, and storing the service metadata to a service directory; wherein the service metadata comprises a service name, an interface address and a version number; when the API calling request arrives at the gateway, performing dual verification on the API calling request; wherein the dual verification comprises calling party identity key authentication and verification of types, ranges and necessary items of request parameters; under the condition that the verification is passed, asymmetrically encrypting and negotiating a session key, and performing symmetric encryption transmission on the request and response data by using the session key; and after the transmission is completed, collecting and calling log data to generate a multi-dimensional monitoring chart, and dynamically adjusting the service priority based on the interface error rate of the service provider.
Owner:天元大数据信用管理有限公司

Inter-core communication method, system and device based on heterogeneous asymmetric processor and medium

The invention discloses an inter-core communication method, system and device based on a heterogeneous asymmetric processor and a medium, and the method comprises the steps: carrying out the classification and feature extraction of a target task, constructing a task feature vector, and mapping the target task to a processor core; the load is detected in real time, when the real-time load exceeds a threshold value, a task migration strategy is executed through atomic operation and a breakpoint management mechanism, and the voltage and frequency of a processor core are adjusted according to a target task; a trusted execution environment is divided in a processor core, a dynamic session key is generated, the dynamic session key is transmitted through a physical isolation bus, cross-core communication data is encrypted, resources are allocated according to a three-dimensional dynamic resource matrix, and cross-core data synchronization is achieved through a two-channel redundancy transmission protocol. According to the method, the software collaboration framework of the heterogeneous asymmetric processor is optimally designed, so that the performance of the heterogeneous asymmetric processor is improved, and the method can be widely applied to the technical field of inter-core communication.
Owner:GUANGZHOU KETENG INFORMATION TECH

Satellite portable station data encryption authentication method and system

The invention discloses a satellite portable station data encryption authentication method and system, and belongs to the technical field of wireless communication network security, and the method comprises the steps: collecting power amplifier nonlinear harmonic spectrum data and environmental noise frequency domain energy distribution data of a satellite terminal, and carrying out the XOR confusion processing, and generating a dynamic key parameter; generating a cross-network authentication pre-distribution parameter based on a preset satellite link stability threshold and the signal quality parameter of the current satellite network; and when the signal quality parameter of the satellite network is reduced to a preset switching threshold, extracting a target network session key parameter, and encrypting and sending uplink data in combination with the dynamic key parameter and the cross-network authentication pre-distribution parameter. According to the invention, a power amplifier harmonic wave and environmental noise fusion key generation technology and a link stability and space-time parameter linkage pre-distribution mechanism are adopted, so that high-safety and low-delay communication protection can be realized in a complex electromagnetic environment and a multi-satellite network switching scene.
Owner:JIANGSU ANRUIXUN INFORMATION TECH CO LTD

Dual-mode communication encryption synchronization method of power internet of things and power internet of things system

The invention provides a dual-mode communication encryption synchronization method of power internet of things and a power internet of things system, and the method comprises the steps: a power terminal sends an identity authentication request to a master station after completing initialization, so as to carry out the bidirectional identity authentication with the master station; after the bidirectional identity authentication is completed, the power terminal and the master station negotiate to generate a session key for encrypting transmission data; the power terminal encrypts the collected service data through the session key to obtain encrypted service data, and sends the encrypted service data to the master station; and the master station decrypts the received encrypted service data based on the session key to obtain and store the service data. In the mode, through bidirectional identity authentication and session key negotiation between the power terminal and the master station, end-to-end encryption protection of service data can be realized, so that the security and stability of equipment communication in the power Internet of Things system are effectively improved.
Owner:HOLLEY METERING LTD

Switch secure communication encryption method based on quantum key distribution

The invention discloses a switch secure communication encryption method based on quantum key distribution. The method comprises the following steps: a service party submits a'security-delay-bandwidth 'intention to a zero-trust brain through a quantum policy intention description language; evaluating the real-time quality, key margin and topology accessibility of an optical fiber quantum channel, a classical ultra-high-speed channel and a radio frequency space channel according to intention requirements; triggering a QKD transmitting end and a receiving end to perform quantum state transmission of polarization and OAM coding along the optimal quantum path, completing basis vector comparison, error code verification and privacy amplification, generating a root quantum key, and injecting the root quantum key into an on-chip quantum memory; when a data packet arrives at a switch port, the assembly line takes out Kroot from the first-level key pool, and derives a one-time session key through the HMAC-SHA3; continuously monitoring a quantum channel bit error rate, a key pool margin and an AI abnormal score; and the transmitting and receiving parties synchronously confirm and destroy the session key, write all key life cycle events into a quantum invariant account book, and realize second-level auditing evidence obtaining through block chain hash anchoring.
Owner:SHENZHEN TIANBO COMM EQUIP CO LTD

Dynamic incentive federal learning method based on trusted execution environment and block chain

The invention belongs to the technical field of block chains and federated learning, and particularly discloses a dynamic incentive federated learning method based on a trusted execution environment and a block chain. The method comprises the following steps: firstly, constructing a core computing security area by utilizing TEE, and executing key links such as model aggregation, client screening and contribution measurement in a hardware isolated trusted environment; and then, a block chain and an intelligent contract technology are adopted as a decentralized trust root to realize effective management of identities of participants, tamper-proof records of key certificates and automatic distribution of economic incentives. Secondly, establishing a set of dynamic excitation and reputation mechanism executed in the TEE, and performing credible quantification and automatic reward on the contribution of the client based on multi-dimensional indexes such as model quality, historical reputation, asset pledge, participation stability and the like; and finally, end-to-end data encryption is realized through a session key mechanism in the TEE, so that the data privacy of the client is effectively protected.
Owner:CHINA UNIV OF PETROLEUM (EAST CHINA)