Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

120 results about "Side channel attack" patented technology

In computer security, a side-channel attack is any attack based on information gained from the implementation of a computer system, rather than weaknesses in the implemented algorithm itself (e.g. cryptanalysis and software bugs). Timing information, power consumption, electromagnetic leaks or even sound can provide an extra source of information, which can be exploited.

Control method of multi-protocol switching anti-quantum security gateway

The invention relates to a control method for a multi-protocol switching anti-quantum security gateway, and the method comprises the steps: carrying out the safety self-inspection of a hardware environment after the security gateway is powered on, generating a unique root key of equipment based on a physical unclonable function, continuously collecting and analyzing the network traffic characteristics, and carrying out the self-inspection of the hardware environment. Based on a machine learning model, a quantum attack mode is identified and an encryption algorithm mode is dynamically decided, protocol analysis is carried out on a communication data packet, dynamic conversion and adaptation are carried out between a traditional protocol and an anti-quantum cryptography protocol according to an instruction and a preset rule, and an anti-quantum cryptography engine is called to carry out encryption or signature operation. And dynamically deriving and managing a session key in a complete period based on a root key, switching an algorithm mode, a communication protocol and a key in a linkage manner according to a quantum attack detection result, and starting anti-side channel attack protection and hardware security response. According to the method, active protection of the security gateway on quantum attacks, multi-protocol seamless compatibility and full-life-cycle security management of keys are realized.
Owner:WEIDE GUANGDONG INFORMATION TECH CO LTD

Chip security key protection method and system capable of resisting side channel attack

The invention provides a chip security key protection method and system capable of resisting side channel attack, and relates to the technical field of chips, which comprises the following steps of: obtaining a key operation request, performing address space mapping based on a dynamic mapping rule to obtain encrypted key data, decrypting the encrypted key data, fragmenting key intermediate data, and allocating an independent processing channel to perform decoupling operation; and injecting a time-varying noise signal to cover the association between the key and the physical characteristics, and finally performing recombination and reverse conversion to generate a final key output. According to the method, side channel attacks such as power consumption analysis and electromagnetic analysis are effectively resisted, and the security of key storage and operation processes is improved.
Owner:WING SHIELD (SHANGHAI) INTELLIGENT TECH CO LTD

Multi-level security protection method taking persistent memory as core level

The invention discloses a multi-level security protection method taking a persistent memory as a core level, and relates to the technical field of computer storage security. The method comprises the following steps: constructing a cross-level security abstract model, and implementing NUMA perception encryption on the basis of the cross-level security abstract model, including a localization encryption strategy and an intelligent key distribution system; based on a cross-hierarchy security abstract model and NUMA perception encryption, dynamic key hierarchical derivation is realized, a tree topology structure is adopted in the derivation process, generation of a root key and sub-keys of each hierarchy depends on a hierarchical key derivation engine, and cross-node synchronization is completed through an intelligent key distribution system during key cascade update; a side channel attack resisting system is constructed, support for CXL equipment is matched with establishment of a CXL metadata consistency group in NUMA perception encryption, and the security of data transmission and storage of the CXL equipment is guaranteed. According to the invention, the encryption performance is obviously improved.
Owner:Shanxi Taihang Laboratory Co., Ltd.

Safe starting method, device and equipment and readable storage medium

The invention provides a safety starting method, device and equipment and a readable storage medium, and the method comprises the steps: responding to a request for starting chip firmware, and building communication connection with a safety chip through inter-core communication; obtaining a trusted key root from the security component according to the security chip, and performing mutual challenge authentication with the security chip; according to a mutual challenge authentication with the security chip, a mutual legal authentication result is obtained, and the security chip is requested to start security signature verification; and starting the chip firmware according to a result fed back by the security chip that the signature verification is legal through security starting of the security component. Through the technical scheme of the specification, the isolation security component forms a hardware-level protection island, the risk of physical detection or bypass attack is eradicated, the security chip agents all operations to ensure that the root key cannot be directly accessed by the main MCU, the two-way challenge authentication is combined with the dynamic session key to realize tamper-proofing of inter-core communication, and on the premise of completely eradicating the tamper-proofing process from being hijacked, the security of the main MCU is improved. And the starting reliability and timeliness of the chip are ensured.
Owner:XINHUASAN INFORMATION TECH CO LTD

Link encryption and key diversification on a hardware security module

A Hardware Security Module (HSM) (900), and method thereof, suitable for use in securely servicing cryptographic requests from multiple tenant applications to preserve end-to-end privacy is provided. A Link Encryption and Key Diversification interoperability (43) between two processors provides cryptographic and logical isolation between multiple tenant applications on the HSM (900) that use and share more than one PCIe Physical Function (30) over more than one Virtual Function (VF) (21) to one or more Crypto Units (CU) (61) for satisfying a request (46) of an HSM cryptographic services. An Output Feedback (OFB) block with CRC support is further provided with encryption and decryption. The HSM as configured is more resistant to side channel attacks.
Owner:THALES DIS CPL USA INC

SMBA encryption algorithm side channel attack method based on CPA and related equipment

The invention relates to the technical field of data security, in particular to a CPA-based SMBA encryption algorithm side channel attack method and related equipment, and the method comprises the steps that a collection probe and a programmable oscilloscope are used to collect side channel leakage information when a cryptographic chip runs an SMBA algorithm, and the side channel leakage information comprises a power consumption curve, a current curve or an electromagnetic signal; selecting a result of whitening transformation in a round function of the SMBA encryption algorithm as an intermediate value, calculating the result of whitening transformation in the encryption process for each input data and the assumed encryption sub-key, and constructing an intermediate value set; performing correlation analysis by using the side channel leakage information and the intermediate value set to deduce an encryption sub-key of an SMBA encryption algorithm; the invention provides an effective security assessment means for the practical application of the SMBA encryption algorithm.
Owner:GUANGDONG VOCATIONAL & TECHNICAL COLLEGE

Quantum key generation method and device, electronic equipment and storage medium

The invention provides a quantum key generation method and device, electronic equipment and a storage medium. The method comprises the following steps: receiving a generation request of a quantum key sent by first equipment; in response to the generation request, obtaining a plurality of random numbers, and based on the random numbers, marking polynomials in the polynomial set and sorting an operation sequence; performing time equalization operation on the polynomial set to obtain a time equalization factor; based on the time equalization factor and the polynomial set, performing key generation according to the operation sequence to obtain a quantum key; and sending the quantum key to the first device, wherein the quantum key is used for encrypting data and / or messages to be sent by the first device. Therefore, according to the scheme, the quantum key is used for encryption, and the security of information encryption can be enhanced. In the generation process of the quantum key, side channel attacks can be protected through time balancing operation, the randomness of encryption operation can be increased by marking through random numbers, and the security of key generation is improved.
Owner:CHINA MOBILE INTERNET CO LTD +1

Commercial password evaluation system and evaluation method

The invention belongs to the technical field of information security, and particularly relates to a commercial password evaluation system and method, and the system comprises a protocol dynamic analysis layer, a multi-modal knowledge center, and an evaluation engine. The protocol dynamic analysis layer comprises a protocol grammar feature library used for defining protocol features; the SM-BERT semantic understanding module is used for protocol logic semantic extraction; the multi-modal knowledge center comprises a data modal fusion module used for integrating data and executing cross-modal alignment; the dynamic relation inference engine is used for performing incremental learning, generating association rules and filtering invalid rules; the evaluation engine comprises a multi-modal feature extraction module used for analyzing cipher suite configuration and a secret key life cycle; the compliance rule engine executes national cryptographic algorithm coverage detection and sensitive data protection verification; the physical security enhancement module simulates side channel attacks; according to the method, the problems of a static rule base, data splitting and high misjudgment rate in traditional password evaluation are solved, and the safety and evaluation efficiency of commercial password application can be remarkably improved.
Owner:FUJIAN JINMI NETWORK SECURITY EVALUATION TECH CO LTD

Implementation method and system of dual access control mechanism based on block chain and encryption machine

The invention relates to the technical field of data security and access control, in particular to an implementation method and system of a dual access control mechanism based on a block chain and an encryption machine, and the implementation method comprises the steps of authority management based on a smart contract, encryption machine dynamic key generation, dual access control, and exception handling and auditing. The method has the beneficial effects that the non-tampering property of authority distribution and operation records is ensured through a distributed account book technology of the block chain, and a double-layer security barrier of logic credibility and physical isolation is formed in combination with hardware-level key protection (such as a security chip HSM) of an encryption machine. And the anti-attack capability is improved, the block chain resists data tampering and insider disintegration, the encryption machine prevents key side channel attacks, and the double mechanisms can cope with complex attack modes such as man-in-the-middle attacks, replay attacks and advanced persistent threats (APT).
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

Low-overhead processor cache micro-architecture defense method and device and computer equipment

The invention relates to a low-overhead processor cache micro-architecture defense method and device and computer device.The low-overhead processor cache micro-architecture defense method comprises the steps that when a missing state keeping register module takes out a loading instruction waiting for data from a replay queue, a target branch mask of the loading instruction is obtained; the replay queue is used for storing an instruction which is stagnated due to miss of the cache; judging whether the loading instruction is in a speculative execution state or not according to the target branch mask; and when the loading instruction is in the speculative execution state, stopping a cache write-in operation corresponding to the loading instruction. Through the method and the device, the problem of sensitive information leakage caused by incapability of defending against the cache side channel attack is solved, defending against the cache side channel attack is realized, and sensitive information leakage is prevented.
Owner:HANGZHOU HIGH-TECH ZONE (BINJIANG) INSTITUTE OF BLOCKCHAIN & DATA SECURITY +1

Binomial sampling circuit for side-channel attack resistance in post-quantum cryptography

The application discloses a binomial sampling circuit applied to post-quantum cryptographic algorithm and resisting side channel attacks, comprising a random number generation unit, a binomial sampling unit and a control logic unit; the random number generation unit is used for generating pseudo random numbers according to input data; the pseudo random numbers comprise true data and false data; the binomial sampling unit is used for synchronously performing binomial sampling on the true data and the false data; and the control logic unit is used for controlling the random number generation unit and the binomial sampling unit to operate according to external instructions. The binomial sampling circuit applied to post-quantum cryptographic algorithm and resisting side channel attacks disclosed by the application increases the difficulty of analysis of attackers by generating pseudo random numbers, synchronously samples the true data and the false data to interfere with the attackers, and jointly realizes the protection against side channel attacks, thereby effectively improving the security of a Kyber cryptographic system and reducing the risk of being attacked by side channels.
Owner:HUAZHONG UNIV OF SCI & TECH +1

A private AI model calling method and system based on encrypted data interaction

The application belongs to the technical field of artificial intelligence, and particularly relates to a private AI model calling method and system based on encrypted data interaction, which comprises the following steps: S1, a client generates a series of structured random numbers through a key derivation function based on a main random number seed and each dimension index, encrypts an original input vector into an initial ciphertext vector by using a partial homomorphism encryption public key and the structured random numbers, generates a conditional re-encoding key pair for nonlinear calculation in the AI model, and sends a re-encoding public key to a server. The application can eliminate the confusion ciphertext, so that the server side constructs a quasi-gradient noise based on the intermediate state of the calculation process and injects the result, resisting side channel attacks on the output ciphertext; and the client can reconstruct and remove the noise, so that the lossless calling result is obtained without sacrificing any calculation accuracy, and end-to-end privacy protection of the whole model reasoning process is realized.
Owner:XIAN MINGFU CLOUD COMPUTING CO LTD

Satellite-borne safe intelligent computing system

A satellite-borne safety intelligent computing system is used for guaranteeing safety of a satellite edge computing system and comprises a host processor, an AI accelerator and a safety bus connected with the host processor and the accelerator. The satellite-borne safe intelligent computing system further comprises a bus stream encoding and decoding engine which is embedded in the interface controller of the data bus and used for encrypting and decrypting transmission data of the data bus. By encrypting the cache stream on the data bus, key data such as Bias bias cache and the like can be protected. In addition, an attacker can be prevented from stealing structural information of the neural network model through interrupt signals by interrupting obfuscated codes, dual protection of'signal + data 'is formed, and time sequence detection Trojan horse and side channel attacks can be effectively resisted.
Owner:BEIJING BLUE TOWER OPTICAL TRANSMISSION INTELLIGENT TECHNOLOGY CO LTD

Physical-level anti-quantum key packaging device and method

The invention discloses a physical-level anti-quantum key packaging device and method, and the method comprises the steps: cutting off a byte stream to a first modulus through a bit mask operation, and generating a polynomial matrix in a constant physical clock period; calculating an inner product of a private key vector of the polynomial matrix, executing logic combination operation, compressing modulus, and generating a public key vector; after receiving the public key vector, the second communication node reconstructs a system state by using the temporary private key and outputs a ciphertext; and the first communication node receives the ciphertext, performs fault-tolerant restoration and re-encryption, drives a bottom multiplexer to generate a mask, and selects one of a real session key and a random noise key to be output in a constant physical clock period. According to the anti-quantum cryptography algorithm, logic combination operation, algebraic divide-and-conquer and physical circuit characteristics are utilized, hardware simplification is achieved, meanwhile, safety is improved, strategic expansion capacity is achieved, and the problems that an existing anti-quantum cryptography algorithm faces the computing power bottleneck and the side channel attack risk in a low-power-consumption node lacking a hardware divider circuit are solved.
Owner:SUZHOU LANGKONGHOU QUANTUM TECHNOLOGY CO LTD

Chip security key protection method and system against side-channel attacks

The application provides a chip security key protection method and system against side channel attacks, relates to the technical field of chips, and comprises the following steps: obtaining a key operation request, performing address space mapping based on a dynamic mapping rule to obtain encrypted key data and decryption, fragmenting key intermediate data and allocating independent processing channels for decoupling operation, injecting a time-varying noise signal to mask the association between the key and physical characteristics, and finally recombining and reversely converting to generate a final key output. The application effectively resists side channel attacks such as power analysis and electromagnetic analysis, and improves the security of the key storage and operation process.
Owner:WING SHIELD (SHANGHAI) INTELLIGENT TECH CO LTD

Training method and device of side channel attack identification model, and prediction method and device

This specification provides a method and apparatus for training a side-channel attack identification model, as well as a method and apparatus for predicting side-channel attacks. In this method, a device is deployed as a simulated target device, and a side-channel information acquisition device is deployed within a predetermined distance range outside the device. The side-channel information acquisition device collects side-channel information generated during device operation; it collects first side-channel information generated when the device is running but the acquisition device is not running; it collects second side-channel information generated when both the device and the acquisition device are running. Using the first and second side-channel information, a side-channel attack identification model is trained. This model is then used to predict side-channel attacks. This specification's embodiments can more accurately predict whether a side-channel attack has occurred against a device.
Owner:ALIPAY (HANGZHOU) INFORMATION TECH CO LTD

Encryption chip random mask generation system and method for preventing side channel attack

The invention discloses an encryption chip random mask generation system and method for preventing side channel attacks, and belongs to the technical field of encryption chip information security protection. Comprising an encryption operation unit, a mask generation unit, an FPGA real-time power consumption anomaly detection unit, an attack risk level identification unit, a mask order adjustment unit and an anti-shake stabilization unit. The FPGA real-time power consumption anomaly detection unit collects and filters power consumption trajectory data, the attack risk level identification unit judges the attack risk level accordingly, the mask order adjustment unit dynamically adjusts the mask order according to the risk level, the anti-shake stabilization unit avoids timing sequence disorder caused by frequent order switching, and encryption operation is not interrupted in the adjustment process. According to the method, the dynamic adaptation of the mask order is realized, the security protection and the chip performance are balanced, the continuity and the stability of the encryption operation are ensured, and the side channel attack resistance of the encryption chip is effectively improved.
Owner:SHENZHEN BOSSTON TECHNOLOGY CO LTD

A hardware implementation method and application of SM4 S-box based on redundant tower domain

The application discloses a kind of SM4 S box hardware implementation method and application based on redundant tower area, belong to information security technical field, including: using redundant tower area to express AES S box, and using little end order to express affine transformation;Give the conversion relationship between the S box of AES and SM4, and express affine transformation and constant offset using little end order;Based on step 1 and step 2, give the SM4 S box expression based on redundant tower area;Combined with the mask implementation of three-stage inverse of redundant tower area, complete the complete SM4 hardware design.The application first maps SM4 S box to the redundant tower area implementation framework of AES S box, by optimizing and merging multiple affine transformation layers and constant offset, realize high compact RTF-SM4.The S box is very easy to combine with mask class and double-track class and other gate-level side channel attack protection schemes, realize compact and anti-side channel attack SM4 hardware implementation, ensure the side channel security of encryption hardware.
Owner:NANJING UNIV OF SCI & TECH +2

A method and apparatus for generating random clock against side channel attack

ActiveCN117010033BRandom number generatorsCounting chain synchronous pulse countersAlgorithmParallel computing
The application relates to a random clock generation method and device against side channel attacks, wherein the method comprises the following steps: S1, selecting a reference clock as an input clock of a first round of multi-path frequency multiplication to obtain frequency multiplication clocks with different frequency multiplication coefficients; S2, randomly selecting a frequency multiplication clock from the frequency multiplication clocks, performing spur filtering, and then outputting the frequency multiplication clock as a system clock; S3, performing multi-path frequency division on the randomly selected frequency multiplication clock to obtain frequency division clocks with different frequency division coefficients; S4, randomly selecting a frequency division clock from the frequency division clocks, and performing multi-path frequency multiplication on the frequency division clock as an input clock of a next round of multi-path frequency multiplication to obtain frequency multiplication clocks with different frequency multiplication coefficients; and S5, repeating steps S2 to S4, and obtaining a system clock with various and random frequencies through multiple rounds of iteration. The application effectively improves the side channel attack protection effect.
Owner:XINGTANG TELECOMM TECH CO LTD +2

Digital management method and device based on intelligent door lock

The invention relates to the field of smart home, in particular to a digital management method and device based on an intelligent door lock, and the method comprises the following steps: constructing a multi-modal biological behavior identity identifier of a user, and generating a one-time dynamic token bound with a context for a temporary user based on the identifier; dynamic arbitration is carried out on multi-person concurrent requests according to real-time risk scores; for the suspected false triggering behavior, starting non-inductive authentication based on a behavior mode to complete secondary verification; after the user passes the initial authentication and before the operation is executed, continuous behavior monitoring is carried out, and the process is immediately interrupted once the identity is recognized or the behavior is abnormal; when the main verification fails, a request is initiated to a preset collaborative verification node, and auxiliary verification is completed through a distributed voting mechanism; when the control instruction is executed, random cryptographic delay is injected to resist side channel attacks, and graph calculation is carried out on the temporary permission to analyze the associated risk of the temporary permission.
Owner:HANGZHOU QIANTANG WASU DIGITAL TV CO LTD

Network based side channel attack (SCA) detection

Some embodiments include a method for detecting and interrupting a cache-based side-channel attack. The method includes: (1) at least calibrating one or more chiplets of a network by calculating a threshold; (2) determining one or more device heartbeat vectors of the one or more chiplets, the one or more device heartbeat vectors being derived at least part from one or more measurements of activity of one of more dedicated security processors associated with the one or more chiplets; (3) determining that a particular chiplet of the one or more chiplets is being attacked with a cache-based side-channel attack, the determining being based at least in part on a computed disparity exceeding the threshold; and (4) employing countermeasures against the cache-based side-channel attack of the particular chiplet, the countermeasures including revoking one or more access rights of the particular chiplet on the network.
Owner:CEREMORPHIC INC

Acoustic side channel attack detection and identification method and device based on multi-dimensional information fusion

This application relates to the field of industrial manufacturing technology, specifically, to a method and device for detecting and identifying acoustic side-channel attacks using multi-dimensional information fusion. This method can, to a certain extent, address the problem of acceleration and audio sensors in industrial environments being attacked by acoustic side-channels, leading to false alarms in predictive maintenance systems, as well as the scarcity of fault sample data. The method first dynamically adjusts the trust score through a target detection algorithm to monitor physical intrusions to defend against non-physical contact attacks, enhancing the system's security protection capabilities. It then performs multimodal data fusion on acceleration and audio data to generate a new dataset to train the fusion algorithm. The algorithm uses a deep separable convolutional network and a residual network architecture to perform in-depth analysis of the acceleration and audio data, respectively, and inputs the extracted relevant feature information into an autoencoder and a convolutional attention mechanism to derive a relevant score, thereby improving the detection capability of acoustic side-channel attacks.
Owner:CHANGZHOU UNIV

A secret key signature method against side channel attacks

PendingCN122372215AKey (cryptography)Attack
This invention relates to a commercial cryptographic signature method resistant to side-channel attacks, comprising the following steps: Step 1: Network configuration initialization: Key generation and transaction signing in the system both occur within a designated network; Step 2: Private key conversion and public key generation: Incoming data is converted to an integer using the private key sk and a private key sk object is constructed. The corresponding public key is derived based on elliptic curve cryptography rules; Step 3: Public key and address generation: A hash operation is performed on the public key to generate a public key hash value. Combined with the address format generated by the version, a locking script is constructed based on the public key hash; Step 4: Noise injection operation: A delayed random noise is added during the commercial signature process. By injecting random noise into the signature algorithm, side-channel information is disrupted, preventing attackers from inferring the user's secret data based on the time information leaked during the transaction process, thus improving the system's ability to resist side-channel attacks.
Owner:GUIZHOU WUJIANG HYDROPOWER DEV

Network side channel attack protection system based on differential privacy

The invention relates to a network side channel attack protection system based on differential privacy. The system comprises a differential privacy shaping module and a data packet conversion control module, at a sending end, a differential privacy shaping module divides a fixed time window, dynamically injects Gaussian noise based on preset privacy intensity, performs filling or delay operation on outbound traffic, and destroys time sequence and packet size characteristics of original traffic, so that an attacker cannot infer user behaviors through metadata; in the transmission process, timing sequence constant control and tunnel-level confusion packaging are combined, a traffic burst mode is covered, and confidentiality is guaranteed; and at a receiving end, the system accurately restores data through a flow recombination and de-shaping mechanism to ensure that a service layer is completely non-perceived to the privacy protection process. The device realizes end-to-end quantifiable network side channel defense through confusion transmission of a dynamic Gaussian noise interference original flow mode and a time sequence constant protocol stack.
Owner:XIDIAN UNIV

Ocean location privacy protection task offloading method based on improved laplace mechanism

ActiveCN121665226BEffectively resist collusive inference attacksDefend against collusive inference attacksNetwork traffic/resource managementSecurity arrangementPrivacy protectionBuoy
The application discloses a marine position privacy protection task offloading method based on an improved Laplace mechanism. First, a system model considering the collusion threat of multiple buoy servers is constructed, the feasible angle interval is determined in combination with the buoy coverage range and the transmission power constraint, and the user pseudo position with geographical indistinguishability is generated in the constraint area by using the clipping Laplace mechanism. Secondly, under the condition of the virtual channel corresponding to the pseudo position, the weighted sum of offloading energy consumption and delay is modeled as a discrete optimization problem, and the grey wolf optimization algorithm is used to realize the task offloading decision. Finally, through a power control-based offshore received signal strength simulation method, the signal strength received by the buoy server is consistent with the user pseudo position. The application can effectively reduce the position privacy leakage risk in the task offloading process under the multi-side channel attack scene, and realize safe and reliable marine task offloading.
Owner:NANJING UNIV

Terminal information security protection system and method

The invention discloses a terminal information security protection system and method, and relates to the technical field of information security. The encryption round number is dynamically determined through terminal hardware state data and to-be-protected data attributes, and self-adaptive matching of encryption strength and terminal resources is achieved; generating an initial key and a secret parameter according to the key material, and driving key expansion and encryption structure configuration through the secret parameter to obtain a key matched with the size of the data block; and performing multi-round encryption on the data by adopting a preset encryption strategy, and adding the meta-information to a ciphertext header for verification and decryption. The dynamic nature and the unpredictability of the secret key and the encryption structure are enhanced while light weight is guaranteed, the resistance to differential analysis, linear analysis and side channel attacks is effectively improved, and the reliability and the practicability of terminal information security protection are improved.
Owner:STATE NUCLEAR POWER NETWORK SECURITY TECHNOLOGY (SHANGHAI) CO LTD

Virtual machine construction method and device capable of resisting side channel attack and virtual machine

The invention discloses a side channel attack resistant virtual machine construction method and device and a virtual machine. A virtual machine monitor is configured with a security partition module, and a virtual machine operating system is configured with a virtual machine security cache module; the security partitioning module is used for statically partitioning a third-level cache of the physical host into a common region and a security region which are isolated from each other; reserving a continuous physical memory as a host security memory, and forcibly enabling the host security memory to correspond to the security area; based on the virtual machine starting request, a certain number of host security memories are distributed to the virtual machine to create a virtual machine security memory for the virtual machine; and the virtual machine security cache module is configured to access and manage the virtual machine security memory, respond to the security resource allocation request and allocate the virtual machine security memory for the corresponding application process. According to the scheme, the cache space of the virtual machine process is partitioned and isolated by utilizing the security capability of hardware layer extension, so that various side channel attacks implemented by utilizing the cache are effectively resisted.
Owner:NANHU LAB

Cross-device modeling side channel attack monitoring system and method based on adversarial learning

The invention discloses a cross-equipment modeling side channel attack monitoring system and method based on adversarial learning, and relates to the technical field of information security, and the method comprises the steps: labeling curve data of modeling equipment; pre-training the curve feature extraction model by using the labeled curve data of the modeling equipment to obtain a preliminary curve feature extraction model; constructing an adversarial training framework, and performing iterative training by taking the labeled curve of the modeling equipment and the unlabeled curve of the target equipment as input; the discriminator judges the source of the equipment by taking the feature vector and the output of the classifier as conditions; jointly optimizing parameters of the encoder and the classifier, and learning feature representation with unchanged equipment; monitoring the relative distance or overlapping degree of the feature distribution of the modeling equipment and the target equipment in the hidden space in real time; when the relative distance or the overlapping degree tends to be stable and exceeds a preset threshold value, determining that the curve feature extraction model is converged; and analyzing the attack curve of the target equipment by using the curve feature extraction model.
Owner:SHANGHAI JIAOTONG UNIV