Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

58 results about "SM4 Algorithm" patented technology

SM4 (formerly SMS4) is a block cipher used in the Chinese National Standard for Wireless LAN WAPI (Wired Authentication and Privacy Infrastructure). SM4 was a cipher proposed to for the IEEE 802.11i standard, but has so far been rejected by ISO. One of the reasons for the rejection has been opposition to the WAPI fast-track proposal by the IEEE.

Handwriting dynamic encryption and electronic signature method and system based on national secret algorithm

The invention relates to the technical field of information security, and discloses a handwriting dynamic encryption and electronic signature method based on a national secret algorithm, and the method comprises the steps: obtaining the handwriting data of a user, and carrying out the preprocessing of the data to remove noise and errors; carrying out feature extraction on the preprocessed handwriting data, extracting corresponding track features, speed features and pressure features, and generating a feature hash value of a unique identifier through a cryptographic SM3 hash algorithm; splicing and combining the feature hash value and a user private key, deriving a dynamic key through a national secret SM2 algorithm, and generating an electronic signature by using the dynamic key; an electronic signature is combined with a timestamp to form a structured signature packet, and the signature packet is hierarchically encrypted and stored in a database through a national cryptographic SM4 algorithm. According to the method and the system, the handwritten signature picture, the digital signature technology, the electronic signature technology and the biological recognition and layout file processing technology are fused, so that the safety and the reliability of electronic document signing are improved.
Owner:HENAN INFORMATIZATION GRP CO LTD

Clinical nursing patient information monitoring and recording method and system

According to the clinical nursing patient information monitoring and inputting method and system, the data accuracy, the data inputting efficiency and the privacy protection safety are improved; the method comprises the following steps: firstly, collecting and preprocessing vital sign data of a patient in real time through various physiological sensors; then, acquiring a nursing record image, acquiring nursing record data through an OCR model, acquiring nursing information voice, transwriting the nursing record data and the nursing information voice into nursing information data through a medical scene voice transwriting model, and performing unified standardization processing on the three groups of data to generate patient information data; and finally, when patient information data is input, symmetric encryption is carried out by adopting a national cryptographic SM4 algorithm, encrypted data is obtained, a dynamic encryption key is generated through an ECDH key distribution technology, and the dynamic encryption key can be called to carry out decryption operation after authentication of a dual protection mechanism of Hash value pre-verification and identity authentication is passed.
Owner:DUHUI HEALTH (CHENGDU) MEDICAL TECH CO LTD

Solid state disk data encryption method and solid state disk

The invention relates to the technical field of electric digital data processing security, and discloses a solid state disk data encryption method and a solid state disk. According to the method, a national cryptographic algorithm hardware encryption and decryption co-processing module is serially arranged on a data bus between a main control chip and a flash memory particle array, so that transparent encryption of write-in data and transparent decryption of read-out data are realized; the module performs encryption and decryption based on an SM4 algorithm and an XTS advanced encryption standard mode in combination with a logic address as an adjustment value, and securely injects a root key through an out-of-band interface to derive a data key. The system comprises a main control chip, a flash memory array and the co-processing module, wherein the co-processing module is integrated with a hardware encryption and decryption engine, a key management unit and data flow control logic. On the premise that a general main control chip is not changed, high-performance, high-compatibility and high-security national cryptographic hardware-level full-disk encryption is realized.
Owner:深圳市彦胜科技有限公司

State cryptographic algorithm acceleration system supporting SM4-ZUC dual-core dynamic collaboration

The invention discloses a national cryptographic algorithm acceleration system supporting SM4-ZUC dual-core dynamic collaboration, and belongs to the technical field of information security and hardware acceleration. The system comprises an AXI read-write module, a configuration register module, an SM4 algorithm module and a ZUC algorithm module. The configuration register receives and distributes information such as a secret key, an initial vector and a mode through an APB interface; the AXI read-write module supports burst transmission and dynamic scheduling data read-write; the SM4 algorithm module supports three modes of GCM, CTR and ECB; and the ZUC algorithm module is compatible with ZUC-128 / 256. And the corresponding ZUC-128 / 256 and SM4 algorithms can be dynamically selected for operation by judging an encryption mode in the ZUC and SM4 algorithms. The system adopts a three-level assembly line architecture, space-time multiplexing of read-write data and encryption is realized, and throughput rate is improved.
Owner:BEIJING TECH & BUSINESS UNIV

Node communication adaptive encryption method and system for high-availability cluster

The invention discloses a node communication adaptive encryption method and system for a high-availability cluster. The method comprises the following steps: a source node and a destination node perform SM2 key negotiation to generate a shared session key SK; the application layer of the source node sends a message to a high-availability trunking communication service; a high-availability trunking communication service firstly calls a hook function serving as a universal encryption signature interface on a message outbound path by using a communication protocol module, if a specified encryption mode is SM4 encryption, a message is encrypted by using a shared session key SK through an SM4 encryption module to generate an encrypted data packet, otherwise, other encryption modules are called to generate the encrypted data packet; sending the encrypted data packet to a destination node; and the destination node decrypts the generated plaintext data packet and sends the plaintext data packet According to the method, the SM4 algorithm is seamlessly integrated into a communication system of a high-availability cluster, and the performance overhead is controlled within an acceptable range while security encryption is provided through optimization.
Owner:HUNAN KYLIN XINAN TECH CO LTD

Multi-receiver data asset verification transmission method and system based on national secret algorithm

The invention discloses a multi-receiver data asset verification transmission method and system based on a national cryptographic algorithm, and relates to the technical field of information security, and the method comprises the steps: a cloud carries out the value evaluation of original data assets, calculates a hash value through a national cryptographic SM3 algorithm, and generates a value voucher; calling a national cryptographic SM4 algorithm and a data encryption key to encrypt original data to obtain a data ciphertext, and encrypting the data encryption key by using a national cryptographic SM2 public key of each receiving edge node to obtain a corresponding key ciphertext; signing the value voucher by using the SM2 private key to generate a digital signature; the data ciphertext, the key ciphertext, the value voucher and the digital signature form a transmission data packet to be issued; and each receiving edge node executes multi-stage verification after receiving. The technical problems that in traditional data asset transmission, data are prone to being tampered and stripped, and the receiver is difficult to trust the value declared by the receiver are solved, and the technical effects of safe transmission, controllable value and efficient verification in multi-receiver data asset transmission are achieved.
Owner:BEIJING SCI & TECH PATENT OFFICE +1

Video front-end device authentication method and system based on SM9 algorithm

The application provides a video front-end device authentication method and system based on a national secret SM9 algorithm, which comprises the following steps: a front-end video device downloads an SM9 identification key; the front-end video device and a video encryption subsystem are authenticated bidirectionally based on an identification password algorithm; the front-end video device encrypts monitoring video data by using an SM4 algorithm, and transmits the encrypted monitoring video data to the video encryption subsystem; and the video encryption subsystem decrypts the encrypted monitoring video data and transmits the decrypted monitoring video data to a video user terminal. By using the national secret technology, the standardization degree can be effectively improved, and technical weaknesses can be reduced; the front-end video device and the video encryption subsystem are authenticated bidirectionally based on the SM9 algorithm, so that the authenticity of the access device is ensured, and the access of malicious devices and the illegal control of the front-end device are effectively prevented; the monitoring video data is encrypted based on the national secret algorithm and is transmitted in an encrypted mode, so that the risk of data leakage can be effectively avoided, and the problem of poor safety performance of the existing video monitoring system is solved.
Owner:CHINA UNICOM (GUANGDONG) IND INTERNET CO LTD

Intelligent lock system of cash internet of things management terminal

The application discloses a kind of intelligent lock systems of cash internet of things management terminal, comprising: portable terminal, at least one digital lock and background system;The portable terminal includes: communication module, configured to interact logistics task data and verification instruction with background system in real time;Security processing chip, built-in national secret SM2 / SM4 algorithm encryption and decryption unit;Digital key interface, the passive lock cylinder of digital lock is connected by physical plug;Multi-modal acquisition module, integrated double-sided camera, fingerprint instrument, RFID reader and non-contact certificate reader;Positioning module, support Beidou / GPS dual-mode positioning and electronic fence function;Dynamic key generation unit, based on logistics task identifier, terminal real-time position coordinates and time stamp generates disposable dynamic key.The application can more comprehensively carry out cash internet of things management terminal security protection.
Owner:BANK OF COMM CO LTD ANHUI BRANCH

A cryptographic processing method and system based on SM2 and SM4 algorithms

PendingCN122457240ABatch processingAlgorithm
The application discloses a kind of based on SM2 algorithm and SM4 algorithm's password processing method and system, belong to computer information security technical field, comprising: the enhanced task control block including service index number and data amount is constructed;Based on historical performance data calculation processing coefficient, utilize double threshold hysteresis comparator decision serial or parallel mode, avoid mode frequent switching;Parallel mode is through load balancing weight function for subtask allocation IP core;Hardware synchronization control unit maintains three index tables being processing, blocking and having been processed, realizes the automatic blocking and wake-up of associated job package, and with service index number as address accesses key and intermediate state;Adopt interrupt aggregation and double buffering batch processing result;Based on sliding window adaptive calibration double threshold and dynamically adjusting weight coefficient.The application effectively reduces interrupt overhead, eliminates scheduling ping-pong effect, realizes hardware level job synchronization, improves load balancing and image encryption structure fidelity.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

Blockchain-based methods for protecting medical data privacy and authorizing sharing

This invention discloses a blockchain-based method for medical data privacy protection and authorized sharing, relating to the field of medical data technology. This invention achieves medical data privacy protection and compliant sharing through a four-step closed-loop process. The first step is data splitting and encryption: the original data from the target hospital is split into cell units according to the smallest clinical semantic unit, independently encrypted using the SM4 algorithm, and then differentiated enhancement processing is implemented according to sensitivity to build a strong privacy defense. The second step is storage and evidence preservation: the encrypted units are distributed and stored in fragments, and the fragment hash value, semantic tag, and storage index are uploaded to the shared chain for evidence preservation, simultaneously building a cross-chain gateway and protocol to break down sharing barriers. The third step is authorization and verification: a four-dimensional intelligent authorization model is built to verify requests and generate a temporary key bound to this authorization, achieving precise authorization. The fourth step is usage control: the user decrypts and reassembles the data in a TEE adapted to the cryptographic algorithm, with real-time monitoring of the entire operation and synchronization to both chains, ensuring end-to-end security, controllability, and traceability.
Owner:ANQING VOCATIONAL & TECHN COLLEGE

Data management and control method and system based on identification analysis middleware oriented to mine safety production

The invention provides a data management and control method and system based on mine safety production-oriented identification analysis middleware, and relates to the technical field of data management and control. Mine safety production identification analysis middleware is constructed, and underground multi-type terminal original identification data is received to obtain a to-be-processed packet; then coding and error correction are carried out on the to-be-processed packet to obtain a tundish; analyzing the tundish through a lightweight deep learning model, packaging the tundish into a standardized data object, and checking security information by using a national cryptographic SM4 algorithm in combination with an encrypted dynamic mapping library, and binding to obtain an enhanced object; the method comprises the following steps: acquiring mine identification data, performing electronic fence processing to obtain an early warning result, performing verification and display at a cloud to obtain a work order, and performing dynamic authentication to strengthen management and control, thereby realizing whole process processing from acquisition, analysis and early warning of the mine identification data to cloud management and control, and further ensuring safe and efficient management and control of the data.
Owner:BEIJING CHANGTU TECH CO LTD

Vehicle administration office business active handling method and system based on AI capability, and storage medium

The invention provides a vehicle administration office business active handling method and system based on AI capability, and a storage medium. The method comprises the following steps: dynamically scanning a traffic management business database to identify a business expiration record; generating a personalized reminding verbal skill and starting an AI voice outbound call; extracting key information of the material by using an OCR technology; verifying the format and logic of the key information through a rule engine; encrypting the key information by using an SM4 algorithm, and securely transmitting the encrypted material to the internal network all-in-one machine; calling an API (Application Program Interface) to complete automatic business handling; and closed-loop management is realized through multi-channel feedback of handling results. According to the invention, the problems of untimely service handling, tedious process, unsmooth information transmission and poor interactivity in the prior art can be effectively solved, and active reminding of service expiration, full-process automatic handling, data security encryption transmission, efficient interaction of internal and external networks and user experience optimization are realized.
Owner:CHONGQING AOXIONG INFORMATION TECH

High-frequency sampling signal processing method based on high-density array pressure sensor

The invention relates to the technical field of sensor signal processing, discloses a high-frequency sampling signal processing method based on a high-density array pressure sensor, and aims to solve the problems of insufficient accuracy, safety and real-time performance of a system under high-density nodes and high sampling frequency, and the method comprises the following steps: S1, carrying out row-column cross addressing scanning and activating a preset pressure threshold node; s2, the independent analog-to-digital converters are assembled in a partition mode, and crosstalk is eliminated through time interleaving sampling; s3, the signal is enhanced through a three-stage link of pre-amplification, noise suppression and filtering, and the noise is reduced; s4, the voltage-controlled temperature-compensated crystal oscillator is matched with the phase-locked loop and the digital delay line to realize clock synchronization; s5, encrypting transmission data through a national cryptographic SM4 algorithm; s6, three-level verification is carried out to guarantee data validity; and S7, performing moving average updating on the null drift baseline and performing compensation output. According to the invention, stable sampling of 10000Hz-50000Hz is realized, the signal-to-noise ratio is greater than or equal to 90dB, the bit error rate is less than or equal to 10 <-10 >, the effective data retention rate is greater than or equal to 99.5%, and the comprehensive performance of the system is improved.
Owner:CHINA AUTOMOTIVE ENG RES INST

Personal information management method for company management

The invention relates to the technical field of information management, and discloses a personal information management method for company management, which comprises the following steps of: realizing security management through three core processes: firstly, classifying employee information according to security levels, encrypting and storing the employee information by adopting a national cipher SM4 algorithm, and particularly deleting original data after generating an irreversible digital template for biological characteristics; secondly, when the service system accesses the sensitive information, initiating real-time authorization of employees through multi-channel authentication of the same equipment, and generating a dynamic token with timeliness and permission constraint; and finally, operating the whole life cycle of the information to generate a log containing cryptographic evidence, ensuring that tampering cannot be performed through an auditing chain and a block chain, and supporting intelligent risk analysis alarm at the same time. According to the invention, controllable authorization, encrypted storage and whole-course tracing of employee information are realized, the method is suitable for sensitive information management of personnel, finance and other scenes of various enterprises, and the information leakage risk is significantly reduced.
Owner:ZHENGZHOU UNIVERSITY OF AERONAUTICS

Industrial encryption communication method and system fusing national secret algorithm and dynamic key mechanism

The invention relates to the technical field of secure network communication, and discloses an industrial encryption communication method and system fusing a national cryptographic algorithm and a dynamic key mechanism, and the method comprises the steps: a transmitting end obtains a network layer data packet, analyzes a specific field of an IP head of the network layer data packet, and obtains a current timestamp; based on the specific field and the timestamp, a dynamic key sequence number is calculated through a preset key sequence number generation algorithm; extracting a corresponding encryption key and an initialization vector from a pre-stored key library which is the same as the receiving end according to the serial number; and encrypting the data load by using the CTR working mode of the SM4 algorithm, adding a timestamp to the head of the encrypted load, and sending the encrypted load. And the receiving end extracts the timestamp to perform timeliness verification, and calculates the same key sequence number based on the same field and the timestamp to complete decryption. The method realizes a one-time pad dynamic key mechanism, has the advantages of high encryption strength, good compatibility and the like, and is particularly suitable for an industrial control communication environment with high requirements on real-time performance and reliability.
Owner:DONGFANG ELECTRIC (CHENGDU) INNOVATION RES CO LTD +1

A data security transmission method based on digital archive multi-protection

The application discloses a data security transmission method based on digital file multiple protection, and relates to the field of data security transmission, which comprises the following steps: generating a random seed in real time based on a quantum state, combining a Logistic chaotic mapping to iteratively block the quantum seed, outputting a variable-length key fragment, using a lightweight SM4 algorithm to symmetrically encrypt file data to obtain encrypted data of the fragment; calculating a behavior anomaly probability through a hidden Markov model, calculating a risk score through a safety interval, and triggering a hierarchical response when the score value exceeds a safety threshold; using n nodes to generate a key fragment, and at least k fragments to reconstruct a signature to monitor the state of a blockchain node, and automatically switching to a three-layer architecture when the node anomaly rate exceeds a node threshold. The application has the advantages that: through quantum dynamic key, risk-driven hierarchical response and blockchain disaster recovery switching, an active multiple protection system is constructed to realize quantum attack resistance and dynamically adaptive network risk transmission.
Owner:ANHUI LEADER TECHNOLOGY INNOVATION DEVELOPMENT CO LTD

Over-the-air (OTA) upgrading system and method for domain controller of commercial vehicle

The invention relates to a domain controller OTA upgrading system and method for a commercial vehicle, and belongs to the technical field of data security, and the system comprises a cloud TSP platform which is used for generating a digital signature of an upgrade package based on an SM2 algorithm, and generating a seed value based on a vehicle VIN code and a current UTC timestamp by using an SM3 algorithm; the OTA platform is used for performing primary verification based on the digital signature and the seed value, and generating an independent key of each upgrade session in the upgrade package based on an SM4 algorithm; the domain controller is used for acquiring hardware identifiers of a plurality of to-be-upgraded ECUs before upgrading to construct an equipment fingerprint database, and performing secondary verification based on the equipment fingerprint database and an independent key; and the plurality of to-be-upgraded ECUs are used for performing three-level verification based on the firmware compatibility between the to-be-upgraded ECUs and the upgrade package. According to the method and the device, the security of the OTA upgrading process is effectively improved.
Owner:DONGFENG COMML VEHICLE CO LTD

Wireless secure forwarding device and method based on national cryptographic algorithm

The invention discloses a wireless secure forwarding device and method based on a national cryptographic algorithm. The method comprises the steps of registering a device identifier based on an SM9 algorithm and generating an identifier file; safe distribution of identification files is realized through a 5G network and a super SIM card; the wireless security forwarding device and the authentication server complete bidirectional authentication and key negotiation based on an SM9 + SM4 algorithm; simultaneously accessing an AP (Access Point) and an STA (Station) mode terminal through a multi-channel Wi-Fi module, and receiving multi-source streaming media data; performing protocol analysis and transcoding processing on the data, and uniformly packaging the data into an RTMP format; encryption and integrity verification are carried out on the data based on an SM4 algorithm, a safe data frame is generated, and reliable forwarding of the encrypted data is realized through a 5G and WAN double-link backup mechanism. According to the invention, equipment identity security authentication, multi-mode terminal compatible access, heterogeneous streaming media unified processing and encrypted data stable transmission are realized, and the security and service adaptability in a special wireless communication scene are effectively improved.
Owner:THE FIRST RES INST OF MIN OF PUBLIC SECURITY

Data security exchange method and system based on national cryptographic algorithm encapsulation

The invention relates to a data security exchange method and system based on national cryptographic algorithm packaging. The method comprises the steps that a server cluster generates a unique file abstract for each file through a national cryptographic SM3 algorithm; the sending end program extracts an entity file of the to-be-ferried file through a dynamic token generated by a national secret SM2 algorithm according to the file abstract, judges whether the entity file is encrypted or not, encrypts the entity file by adopting an SM4 algorithm if the entity file is not encrypted, and packages and places the file abstract, the entity file and other file meta-information to a specified network position; the gatekeeper ferries to a receiving end network; and the receiving end network decrypts the received file through the SM4 symmetric algorithm, verifies the abstract of the original file, and encrypts and stores the file in the distributed storage node again through the SM4 symmetric algorithm. According to the invention, on the premise of ensuring security auditing, internal and external network files can be synchronized stably and quickly at a quasi-real-time (second-level) speed.
Owner:CHINA NAT SOFTWARE & SERVICE

Method and device for constructing VPN (Virtual Private Network) based on SM4, electronic equipment and storage medium

The invention belongs to the field of information security, and relates to a method and device for constructing a VPN based on SM4, electronic equipment and a storage medium, and the method comprises the steps: carrying out SM4 algorithm acceleration based on a pre-calculation and memory search mode, and providing a bottom layer encryption engine for a VPN system; an optimized communication protocol based on Base91 and partial encryption is designed, transmission control information is added to the encrypted data block, and a security policy combination adopted by the data block is identified, so that a receiving end can correctly analyze and process; a message confusion mechanism is set, and a confusion encryption layer is provided for data needing higher-level confidentiality protection; performing dynamic one-time pad key management based on a key derivation function and a timestamp; integrating a time window, and carrying out comprehensive security verification on the HMAC; and updating the dynamic relationship library supporting distributed computing, and expanding the VPN service architecture. The calculation efficiency is improved; the encryption and decryption speed is obviously improved, and resource occupation is optimized; and the safety is effectively guaranteed.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Power distributed terminal secure communication method and system based on post-quantum cryptography

PendingCN122293324AKey sizeKey (cryptography)
This invention discloses a secure communication method and system for power distributed terminals based on post-quantum cryptography. With the development of quantum computing technology, traditional secure communication mechanisms based on elliptic curve cryptography face potential vulnerabilities. In existing secure communication systems for power distributed terminals, the terminal device and the secure access gateway typically use the SM2 elliptic curve cryptography algorithm for session key negotiation, which poses security risks in a quantum computing environment. This invention replaces the SM2 algorithm with a lattice-based post-quantum cryptography algorithm for session key negotiation and doubles the key length of the SM4 algorithm used for symmetric encryption services. While maintaining the original power communication system architecture and business processes, this invention achieves a quantum security upgrade for the power distributed terminal communication system, improving the system's long-term security in future quantum computing environments.
Owner:STATE GRID JIANGSU ELECTRIC POWER CO LTD RESEARCH INSTITUTE +1

Searchable encryption method and device based on sm4 algorithm

The invention discloses a searchable encryption method and device based on an sm4 algorithm, and the method comprises the following steps: a secret key generation step: a data owner generates two secret keys s1 and s2 corresponding to the SM4 algorithm based on preset security parameters, s1 and s2 belong to {0, 1} k, k is the length of the secret key, and s1 and s2 serve as encryption operation basic secret keys of the SM4 algorithm; through innovative fusion of the SM4 algorithm and the searchable encryption technology, the technical breakthrough of efficient retrieval, low resource consumption and strong adaptability is realized on the premise of ensuring the security and privacy of cloud data, the core contradiction that security and efficiency are difficult to consider in the prior art is solved, and the security and privacy of the cloud data are ensured. The method can be widely applied to scenes with high requirements on data security and retrieval efficiency, such as personal cloud storage, enterprise-level document management, medical data sharing and the like, and has extremely high commercial value and application prospect.
Owner:DIGITAL LUZHOU IND INVESTMENT GRP CO LTD

Solid state disk data encryption method and solid state disk

ActiveCN121327867BDigital dataData stream
The application relates to the technical field of electric digital data processing security, and discloses a solid state disk data encryption method and a solid state disk. The method realizes transparent encryption of written data and transparent decryption of read-out data by serially arranging a national secret algorithm hardware encryption and decryption coprocessing module on a data bus between a main control chip and a flash memory particle array; the module is based on an SM4 algorithm and an XTS advanced encryption standard mode, combines a logical address as an adjustment value to perform encryption and decryption, and injects a root key through an out-of-band interface to derive a data key. The system comprises a main control chip, a flash memory array and the coprocessing module, the latter integrates a hardware encryption and decryption engine, a key management unit and data flow control logic. The application realizes high-performance, high-compatibility, high-security national secret hardware-level full-disk encryption without changing a general main control chip.
Owner:深圳市彦胜科技有限公司

Searchable encryption method and system based on sm4 algorithm

The invention relates to the technical field of information security, in particular to a searchable encryption method and system based on an sm4 algorithm, and the method comprises the steps: key generation: generating a first key and a second key; index construction: constructing an inverted index dictionary based on the data set; key word encryption: carrying out encryption replacement on key words in the reverse index by using the first key; node encryption and filling: encrypting the nodes in the inverted record tables by using the second key, and filling all the inverted record tables to be equal in length; trap door generation: respectively executing first key encryption and second key encryption on the query keyword to generate a search trap door; and searching and matching: carrying out matching retrieval in the encrypted inverted index by utilizing the search trap door, and outputting a corresponding encrypted document identifier. According to the method, through collaborative design of SM4 double-key encryption, pseudo-random permutation, equal-length filling and a trap door retrieval mechanism, high-security storage of cloud data and efficient retrieval under the ciphertext condition are achieved.
Owner:YUNNAN TOP TECH CO LTD +1

Three-layer cooperative secure transmission method and system for remote control of engineering machinery

The invention discloses a three-layer cooperative secure transmission method and system for remote control of engineering machinery. The three-layer cooperative secure transmission system is composed of a terminal sensing layer, an edge transmission layer and a cloud application layer, wherein the terminal layer realizes equipment identity bidirectional authentication and data grading marking; the edge layer designs a working condition self-adaptive encryption mechanism based on an SM4 algorithm, and improves the transmission reliability in a complex environment in combination with a multi-channel scheduling strategy of 4G / 5G and Beidou short messages; the cloud supports fine-grained authority control and operation auditing by adopting M-tree key management and alliance chain evidence storage; and the dynamic key updating protocol triggers local key reconstruction according to conditions such as equipment movement and session duration. An operation behavior learning model based on LSTM is introduced, abnormal operation is detected, a key freezing mechanism is linked, and illegal operation risks of legal users are prevented; while low-delay transmission of a P0-level control instruction is guaranteed, the overall security and anti-attack ability of the system are effectively improved, and the method is suitable for engineering machinery remote control scenes under high-dynamic and heterogeneous networks.
Owner:DAOJIANYOUXING (CHONGQING) TECH CO LTD +2

Duplicate removal and compliance verification method and system for secret evaluation evidence picture

The invention provides a duplicate removal and compliance verification method and system for a secret evaluation evidence picture. The method comprises the steps of S1, secret evaluation evidence picture obtaining and preprocessing, S2, double-fingerprint duplicate removal processing, S3, multi-dimensional compliance verification processing, S4, compliance problem grading processing and S5, national secret SM4 encryption storage processing. By establishing a double-fingerprint duplicate removal mechanism combining perceptual hash and national secret SM3, accurate identification and accurate verification of similar graphs are realized, and national secret encryption compliance requirements are met; linkage is formed by constructing an automatic compliance verification processing flow and a duplicate removal flow, and full-flow automatic processing of the secret evaluation evidence picture is achieved; and storage compression is realized by reserving an original image and combining reference information replacement, and encryption and packaging are performed by adopting a national cryptographic SM4 algorithm, so that the security and effectiveness of cryptographic evaluation data are guaranteed. The method has the advantages of high duplicate removal precision, compliance verification meeting the secret evaluation requirement, high secret evaluation processing efficiency, high security and secret evaluation compliance, low storage cost and clear data association.
Owner:JINGYUAN ANQUAN

Camera security and secrecy reinforcing module and method

The invention provides a camera security and confidentiality reinforcing module and method, and relates to the technical field of video monitoring security. The camera security confidentiality reinforcing module integrates a physical trusted root unit, a dynamic multi-dimensional watermark engine and a self-adaptive encryption array, and adopts a triple protection framework of hardware root trust, dynamic watermark binding and hierarchical encryption adaptation. The technical problems that in the prior art, identity authentication is single, tampering tracing is difficult, and encryption and transmission rate are not matched are solved. The module is realized through hardware acceleration of a national cryptographic SM4 algorithm, and is combined with an active physical watermark embedding mechanism based on a roller shutter door effect, so that the tampering frame detection accuracy is greater than or equal to 99.2% and the equipment identity authentication anti-counterfeiting success rate is 100% while the encryption rate of an SM4 OFB mode is ensured to reach 85Mbps. The module supports transparent deployment, does not need to change an original camera hardware structure and network topology, adapts to 1080P / 4K and other multi-resolution video streams, and can be widely applied to video security protection of public security, finance, government affairs and other confidential scenes.
Owner:TOEC (GRP) CO LTD +1

A method for backing up electronic files of geological data

This invention relates to a method for backing up electronic geological data files, belonging to the field of data backup. The method includes: a dynamic backup strategy determination step, which classifies and grades data according to its confidentiality, size, and intended backup medium, matching differentiated strategies and executing backups using a pipelined scheduling approach; a content-based redundancy deduplication step, which uses MD5+SM3+CRC32 calculations to build a global index to eliminate redundant data; a file segmentation and reassembly step, which automatically segments large files exceeding 50GB into 10GB sub-files and records the segmentation metadata; a file storage and security step, which randomly selects 2-3 data blocks based on the size of the electronic geological data file for encrypted replacement, encrypts metadata using the SM4 algorithm, and ensures data security through role-based access control, integrity verification, and audit logs; and a backup check and recovery step, which performs automatic verification, annual sampling checks, and heterogeneous recovery. The method improves storage efficiency through intelligent deduplication and tiered strategies, and enhances data security through encryption and integrity verification.
Owner:DEV RES CENT OF CHINA GEOLOGICAL SURVEY

Firmware security online upgrading method and system based on national cryptographic algorithm

The invention discloses a firmware security online upgrading method and system based on a national cryptographic algorithm. The method comprises the following steps: encrypting an upgrading file by using a national cryptographic SM4 algorithm; identity authentication and signature verification are carried out by using a national cipher SM2 algorithm, the firmware upgrade server signs the upgrade file by using a private key, and the firmware device verifies the signature by using a public key of the server; secret key management and protection: performing safe generation, storage and transmission on a secret key used in a firmware upgrading process by adopting a secret key management mechanism provided by a national secret algorithm; the firmware is updated in a secondary verification mode; the system comprises an encryption module, a verification module, a management and protection module and an updating module. The method has high security and reliability, equipment can be effectively protected from being threatened by hostile attacks and data leakage, the firmware online upgrading process is safer and more reliable, and the requirement of national cryptographic algorithm management is met.
Owner:NARI INFORMATION & COMM TECH