Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

850 results about "Source address" patented technology

Door lock and card cooperative processing method and system

The invention discloses a door lock and card cooperative processing method and system, and the method comprises the steps: triggering a robot calling process according to preset times of doorbell button operation detected by a first door lock and read neighbor RFID card information, verifying a matching result of an RFID card and a resident registration form, and generating an authority verification passing signal; calculating a target multicast address based on the ID number of the RFID card, and converting the ID number of the RFID card into a false source IP address to obtain a communication parameter set; sending an IGMPv3 report message to the router according to the communication parameter set; according to the triggering operation of the same RFID card detected by the assisted second door lock, an assistance multicast request message is generated, the (S, G) forwarding table item is matched through the router and forwarded to the first door lock, the first door lock sends an assistance confirmation message to the second door lock, and robot calling authorization is completed. By utilizing the embodiment of the invention, efficient, safe and low-delay cross-door-lock cooperative operation can be realized.
Owner:HANGZHOU DIANZI UNIV +1

Government affair information management method based on cloud

The invention relates to the technical field of government affair information management, in particular to a cloud-based government affair information management method, which comprises the following steps of: S1, adding a sensitivity label for each piece of government affair data in a cloud storage layer; s2, extracting data from the government affair database and generating a dynamic data view with an authority mark; s3, establishing a mapping relation table between routing keys and data source addresses; s4, acquiring a requester department function code, a business scene code and a target data identifier; s5, matching a target data source, and based on the authority mark in the dynamic data view, executing a desensitization operation on the sensitive field; and S6, if the genetic marker bit of the original data is true, superposing the data security classification in the original tag and the current security classification to form a new tag. According to the method, by constructing the sensitivity label and the dynamic authority control mechanism, safe inheritance and accurate access of government affair data in cross-department circulation are achieved, and the safety and compliance of data management are remarkably improved.
Owner:DEEP THINKING COMPUTER (QINGDAO) CO LTD

Hardware accelerator and data handling method

The invention relates to the technical field of chips, and discloses a hardware accelerator and a data handling method, the hardware accelerator comprises a doorbell processing module, a descriptor cache module and at least one DMA engine module; wherein a target engine module in the at least one DMA engine module is configured to read a target descriptor from effective descriptors in the descriptor cache module and analyze the target descriptor to obtain a source address field, a source address space identifier, a destination address field and a destination address space identifier, and carrying the target data block in the first user space to the second user space based on the source address field, the source address space identifier, the destination address field and the destination address space identifier, wherein the effective descriptor is read from a descriptor ring in the first user space through the doorbell processing module and is written into the descriptor cache module. Therefore, through cooperative work of all the modules, full-hardware acceleration of user mode data carrying is completed, and therefore the data carrying efficiency is remarkably improved.
Owner:PHYTIUM TECH CO LTD

Apparatus and method for trusted access to expansion memory by multiple potentially heterogeneous compute nodes

Multiple roots of trust are described under a super Root of trust (SROT). One embodiment includes: cores of a host processor; a host processor memory subsystem to provide access to a host processor memory; a home agent to provide access by the cores to the host processor memory subsystem and an expansion memory subsystem, a source address decoder to decode memory requests generated from the plurality of cores to determine whether the memory requests are to be directed to the host processor memory subsystem or the expansion memory subsystem. Host-based security circuitry encrypts and decrypts memory requests directed to the expansion memory subsystem, the host-based security circuitry to perform the encryption and decryption based on a second key stored in a cache maintained by the host-based security circuitry.
Owner:INTEL CORP

Data replication method and device based on DMA, equipment and storage medium

The invention relates to a data replication method and device based on DMA, equipment and a storage medium. The method comprises the following steps: receiving a data copying instruction, wherein the data copying instruction comprises an initial source address, an initial destination address and a copying data length; determining an alignment difference between the initial source address and the initial destination address; an association ID table is determined according to the data copying instruction and the alignment difference, and in the association ID table, the association ID of one write request corresponds to the association ID of one or two read requests; and for one write request, obtaining a corresponding read request according to the associated ID table and the alignment difference, and writing a target result corresponding to the read request into a target storage medium according to the address of the write request. By adopting the method, the problem that the initial address is not aligned during data copying can be effectively solved.
Owner:沐曦集成电路(南京)有限公司

Kernel indirect control flow transfer dynamic verification method based on eBPF

According to the kernel indirect control flow transfer dynamic verification method based on the eBPF, an eBPF attachment point of an indirect call instruction is positioned, a verification program is dynamically attached, a source address and a target address are captured to generate a compound key, and the legality of a control flow is verified in a pre-constructed BPF hash table; and meanwhile, three indirect addressing modes of a differential strategy adaptive register, an immediate operand and a memory are adopted. Based on an eBPF technology, an EV program can be dynamically loaded into a running kernel as required during running, and the characteristic of dynamic expansion of a modern kernel can be perfectly adapted; all the capabilities are constructed on a universal software mechanism of a Linux kernel and do not depend on any hardware extension; while powerful security defense is provided, extremely low overhead during operation is realized. Benefited from an innovative hybrid verification strategy and an efficient CFG storage scheme, control flow hijacking attacks in the real world can be effectively defended with extremely low performance loss.
Owner:CHANGSHU INSTITUTE OF TECHNOLOGY

Data processing method and electronic device using scatter gather DMA

A data processing method using a scatter gather direct memory access (SG DMA), the method comprising: obtaining information for a rule table for specific subtasks of a SG DMA from a host, deriving the rule table for the specific subtasks based on the information, deriving source addresses, destination addresses and data sizes for the specific subtasks based on the rule table, and performing a SG DMA operation to transfer data of the data sizes located at the source addresses of a first memory to data spaces of the data sizes located at the destination addresses of a second memory.
Owner:REBELLIONS INC

Block chain-based trusted IoT (Internet of Things) access method and equipment

The embodiment of the invention provides a trusted IoT (Internet of Things) access method and equipment based on a block chain. The method is applied to the technical field of communication, and comprises the following steps: firstly, generating a key for the Internet of Things in a TEE environment of an intelligent gateway, encrypting a resource address of an Internet of Things device, preventing the key from being acquired by malicious software, preventing the key from being counterfeited, and ensuring the security of the Internet of Things device accessing a block chain network, and a block chain stores a key index instead of the key, so that the security of the Internet of Things device accessing a block chain network is ensured. The risk of key leakage is further reduced; by setting a device management contract and a policy authority contract, the authority of a user for accessing the Internet of Things device is inquired and managed, fine control of the access authority is realized, and only the user having the authority can obtain a corresponding secret key from an intelligent gateway to decrypt an encrypted resource address provided in a block chain. According to the arrangement, leakage of the resource address is effectively prevented, and sensitive information is prevented from being leaked.
Owner:NINGBO TELIAN INFORMATION TECH CO LTD

Enterprise application management and migration on a web proxy

A computer-implemented method for management of an application on an enterprise network which accesses external networks via a web proxy. The method comprises obtaining enriched metadata concerning an application executed on the enterprise network, the enriched metadata including at least source code information and ownership information, identifying application traffic on the enterprise network based on proxy log data, source IP and destination URL, generating an access control list (ACL) based on the enriched metadata and identified application traffic, the ACL including a source address of the application and a list of allowed destination addresses, converting the ACL into a proxy policy that can be processed by a web proxy to permit access by the application to the destination addresses in the ACL, and establishing data communication between the application and an external network based on the proxy policy.
Owner:MORGAN STANLEY SERVICES GROUP INC

Public opinion home address standardization method and system

The invention discloses a public opinion home address standardization method and system, and the method comprises the following steps: S1, obtaining and processing multi-source address original data to obtain an address data block, processing the data block based on a pre-trained text embedding model to obtain a corresponding semantic vector, and storing the address data block and the corresponding semantic vector, establishing a multi-source address knowledge base; s2, processing public opinion text data through the text embedding model to obtain a query vector of the public opinion text data; s3, querying the multi-source address knowledge base based on the query vector to obtain a plurality of address data blocks related to the query vector; and S4, constructing a cue word template based on the public opinion text data and the address data blocks, and inputting the cue word template into a large language model to perform public opinion attribution address standardization analysis.
Owner:XIAMEN MEIYABAIKE INFORMATION SECURITY RES INST CO LTD

Industrial AI model security management and control system

The invention discloses an industrial AI model security management and control system, and the system comprises a permission granularity control module which is used for declaring a required minimum permission set when an AI model is registered, and generating a dynamic access token containing a permission list for the model; wherein the identifier is a resource operation authority identifier; the permission mapping table module is used for maintaining a mapping relation from the resource operation permission identifier to the actual resource address; the access verification module is used for verifying the validity and the permission range of the dynamic access token when the model requests the system resources, and refusing the non-permission access; and the dynamic permission recovery module is used for removing the target permission identifier in the authorized permission set of the model in real time to update the permission set, marking that the old token is invalid, and generating a new token containing a timestamp based on the new permission set. According to the method, the industrial AI model can be effectively prevented from abusing the authority, and the system security is improved.
Owner:QKM TECH (DONG GUAN) CO LTD

Intelligent computing center path distribution method, data transmission method and network system

The invention provides an intelligent computing center path distribution method, a data transmission method and a network system. According to the technical scheme, based on the time sequence characteristics of the AI training data flow and the characteristic that each set communication library only selects one communication algorithm to drive data flow transmission in the same communication period, the data flow identification capable of identifying the data flow and the communication algorithm corresponding to the data flow identification are obtained, and path planning is carried out based on the communication algorithm. In this way, during actual communication, data streams driven by different communication algorithms on the same path cannot be transmitted at the same time, the link congestion risk is reduced, and idle links are reserved for subsequent data streams of the same communication algorithm; different links are allocated to data flow identifiers with the same source IP address or the same destination IP address corresponding to the same communication algorithm in the same set communication domain, multi-path load sharing is carried out, data flow dispersed transmission based on the same communication algorithm drive is ensured, the congestion risk of a single link is further reduced, and the transmission efficiency is improved. The communication efficiency of an intelligent computing center network is expected to be improved.
Owner:NEW H3C TECH CO LTD

Communication method and device and computer readable storage medium

The invention provides a communication method and device and a computer readable storage medium, and the method comprises the steps that a third network element receives a first message from a first network element, and the source IP address of the first message is the first IP address of the first network element; and when it is determined that the first message satisfies the first filtering condition, a first request is sent to a fourth network element, the first request is used for requesting establishment of a voice dedicated bearer, the first request comprises first PCC rule information corresponding to the first filtering condition, and a source IP address of the first filtering condition comprises a first IP address of the first network element. According to the embodiment of the invention, interaction can be carried out through network elements such as SBC, UPF / PGW-U, SMF / PGW-C and the like in allusion to the PCF / PCRF fault condition, the establishment of the special voice bearer is realized, and the reliability of the voice service can be improved.
Owner:HUAWEI TECH CO LTD

Data processing method and device, electronic equipment and storage medium

Embodiments of the invention provide a data processing method and apparatus, an electronic device and a storage medium. The method comprises the steps of obtaining a unit vector operation width supported by hardware; obtaining a source address to be aligned and the number of object data to be operated; in response to the fact that the width of the object data is larger than or equal to a first threshold value, the remainder obtained after the to-be-aligned source address is aligned with the unit vector operation width is calculated so as to obtain the data width of which the addresses are not aligned in the object data, and the width of the object data is equal to the product of the unit data width of the object data and the number of the object data; the width of the address misalignment data is equal to the difference value between the unit vector operation width and the remainder; determining the number of the address misalignment data according to the unit data width of the object data and the width of the address misalignment data, and determining first mask information based on the number of the address misalignment data and the unit vector operation width; and according to the first mask information, loading and processing the data of which the addresses are not aligned, and the method improves the data processing performance.
Owner:HYGON INFORMATION TECH CO LTD

Data loading method and device, storage medium and equipment

The invention relates to a data loading method and device, a storage medium and equipment, the method is used in an intelligent calculation data processing system comprising a host, a CSD and a SmartNIC, and a PCIe P2P data path is established between the CSD and the SmartNIC; the method comprises the steps that a host generates collaborative descriptors and respectively issues the collaborative descriptors to a CSD and a SmartNIC; the CSD reads source data from a storage medium according to source address information in the collaborative descriptor, executes a processing operation corresponding to the first operator identifier to obtain intermediate data, and directly transmits the intermediate data to a storage area of the SmartNIC through a PCIe P2P data path; and the SmartNIC executes a processing operation corresponding to the second operator identifier on the intermediate data to obtain target data, and transmits the target data to the computing device according to the target address information in the collaborative descriptor.
Owner:GUANGDONG UCAP INTERNET INFORMATION TECH

Software bill of material generation method and device

The invention relates to a software bill of material generation method and device, and belongs to the technical field of computers.The method comprises the steps that a software source address is obtained, and a software source type is recognized according to the software source address; positioning and downloading a warehouse metadata file according to a software source type; calling a corresponding parser to parse the warehouse metadata file according to the software source type to obtain software package metadata; and according to the software package metadata, extracting an original field required by the generation of the software bill of material, and converting the original field required by the generation of the software bill of material into a standard field of the software bill of material, thereby generating the software bill of material conforming to the specification of the software bill of material. According to the software bill of material generation method and device provided by the invention, the self-adaptive generation of software bills of material of different software source types can be realized, the universal adaptation capability for multi-source and multi-architecture in the software bill of material generation is improved, and the preposition, lightweight and efficient generation of the software bill of material is realized.
Owner:BEIJING LINX SOFTWARE CORP

Intelligent network card data forwarding method and system based on FPGA

The invention relates to the technical field of network communication, in particular to an intelligent network card data forwarding method and system based on an FPGA, and the method comprises the steps: after the FPGA receives a data stream, firstly extracting a time interval standard deviation of N data packets as a time feature, executing parallel hash operation on a source IP address and a destination IP address, and mapping the source IP address and the destination IP address into three-dimensional coordinates; splicing the time features and the space coordinates into a two-dimensional matrix; a time vector T and a space vector S are separated from the two-dimensional matrix, the time feature similarity is calculated through cosine similarity, the space similarity is calculated through an Euclidean distance normalization algorithm, and affinity is obtained after weighted fusion; the condition that the affinity exceeds a first preset threshold value is used as a triggering condition for micro-flow slice splitting, and a data label is added to the slice; the FPGA intelligent network card implements heterogeneous channel binding based on slice affinity, and the global crossbar switch realizes non-blocking channel switching according to priority. And the slice splitting is triggered according to the affinity threshold, so that the high-speed transmission efficiency is improved.
Owner:芯超越信息技术(杭州)有限公司

Mimicry camouflage defense method and system and electronic equipment

The invention discloses a mimicry camouflage defense method, a mimicry camouflage defense system and electronic equipment. The method comprises the steps that a TCP connection request at a mimicry port is monitored, the TCP connection request carries quintuple information, and the mimicry port is a port used for simulating a real service behavior; in response to the TCP connection request, obtaining a network source address parameter and an attack behavior parameter corresponding to an attacker according to the quintuple information; sending the preset port fingerprint information to an attacker according to the network source address parameter; and executing a defense strategy corresponding to the attacker to defend the attack behavior of the attacker, the defense strategy being determined according to the network source address parameter and the attack behavior parameter. According to the method and the device, the technical problem of low reliability of the made mimicry defense strategy during mimicry defense in related technologies is solved.
Owner:PURPLE MOUNTAIN LAB

DDoS attack source detection method and network server system

The invention discloses a DDoS attack source detection method, which comprises the following steps: judging whether a communication network is subjected to DDoS attack, if not, extracting a source IP address and a TTL value, calculating a TTL confidence interval according to the source IP address, and storing the source IP address and the TTL confidence interval to a global TTL mapping database; if yes, an attack source IP address and a TTL value are extracted, and whether the attack source IP address exists in a global TTL mapping database or not is inquired; if yes, whether a TTL value corresponding to the attack source IP address exceeds an attack source TTL confidence interval or not is judged, if yes, 1 is added to the abnormal count of the attack source IP address, when the abnormal count of the attack source IP address is larger than or equal to a preset threshold value, the attack source IP address is intercepted, and if not, the abnormal count is reset; if not, C-section layered active scanning detection is executed, and if a detection response is returned, a scanning detection IP address and a corresponding TTL value are extracted, a corresponding TTL confidence interval is calculated according to the scanning detection IP address, and the scanning detection IP address and the corresponding TTL confidence interval are stored in a global TTL mapping database.
Owner:BEIJING AODUAN SOFTWARE CO LTD

Data transmission method and device, medium, electronic equipment and program product

The invention belongs to the technical field of computers, and particularly relates to a data transmission method, a data transmission device, a computer readable medium, electronic equipment and a computer program product. The method comprises the steps that path information used for transmitting data on one or more computing nodes is obtained, each computing node comprises a plurality of computing modules, the path information comprises a source address and a destination address, the source address is the address of the computing module sending the data, and the destination address is the address of the computing module receiving the data; if the source address and the destination address are located at the same computing node, storing the path information to a specified memory space; and when a preset triggering condition is met, transmitting data among the plurality of computing modules in the same computing node according to the path information stored in the memory space. The data transmission efficiency can be improved.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

Methods and apparatus for an identifier server, communication device, server, authorization server, external invoker device, and application programming interface provider server

An identifier server (22) is deployed in a communication network (10). The identifier server (22) receives a request (26) for an identifier (12-ID) that is to identify a communication device (12) to an external invoker device (18) of an application programming interface, API, (16) exposed by the communication network (10). The identifier server (22) determines, based on a payload (26P) of the request (26) and / or a source address (26A) of the request (26), internal identifying information (12-INT) that identifies the communication device (12) internally to the communication network (10). The identifier server (22) generates an identifier (12-ID) that is bound to the internal identifying information (12-INT). The identifier server (22) transmits a response (28) that includes the generated identifier (12-ID).
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL) +1

Computationally efficient transfer processing and auditing apparatuses, methods and systems

The Computationally Efficient Transfer Processing, Auditing, and Search Apparatuses, Methods and Systems (“SOCOACT”) transforms smart contract request, crypto currency deposit request, crypto collateral deposit request, crypto currency transfer request, crypto collateral transfer request inputs via SOCOACT components into transaction confirmation outputs. Also, SOCOACT transforms transaction record inputs via SOCOACT components into matrix and list tuple outputs for computationally efficient auditing. A blockchain transaction data auditing apparatus comprises a blockchain recordation component, a matrix Conversion component, and a bloom filter component. The blockchain recordation component receives a plurality of transaction records for each of a plurality of transactions, each transaction record comprising a source address, a destination address, a transaction amount and a timestamp of a transaction; the source address comprising a source wallet address corresponding to a source digital wallet, and the destination address comprising a destination wallet address corresponding to a destination virtual currency wallet; verifies that the transaction amount is available in the source virtual currency wallet; and when the transaction amount is available, cryptographically records the transaction in a blockchain comprising a plurality of hashes of transaction records. The Bloom Filter component receives the source address and the destination address, hashes the source address using a Bloom Filter to generate a source wallet address, and hashes the destination address using the Bloom Filter to generate a destination wallet address. The Matrix Conversion component adds the source wallet address as a first row and a column entry to a stored distance matrix representing the plurality of transactions, adds the destination wallet address as a second row and column entry to the stored distance matrix representing the plurality of transactions, adds the transaction amount and the timestamp as an entry to the row corresponding to the source wallet address and the column corresponding to the destination wallet address; and generate a list representation of the matrix, where each entry in the list comprises a tuple having the source wallet address, the destination wallet address, the transaction amount and the timestamp.
Owner:FMR CORP

Processor, tensor processing method, and device

The present application relates to the technical field of data processing, and is used for realizing universal and efficient processing of a multi-dimensional tensor. Provided are a processor, a tensor processing method, and a device. A tensor processing unit in the processor comprises: a preprocessing circuit, which is used for adjusting first dimension information of a multi-dimensional tensor, so as to obtain second dimension information, wherein the product of the size of any dimension in the second dimension information and the capacity of a unit access storage space is smaller than or equal to the capacity of a data cache; an address generation circuit, which is used for generating, on the basis of the second dimension information, a plurality of source addresses corresponding to a plurality of pieces of data in the multi-dimensional tensor; an access control circuit, which is used for determining a plurality of pieces of cache mapping information corresponding to the plurality of source addresses, and sending a plurality of access requests on the basis of the plurality of source addresses, and is used for acquiring from a first memory the plurality of pieces of data of the multi-dimensional tensor; and the data cache, which is used for caching the plurality of pieces of data on the basis of the plurality of pieces of cache mapping information.
Owner:HUAWEI TECH CO LTD

Devices and methods for privacy-preserving communication in a WLAN

A WLAN station (110; 120) for communicating with a further WLAN station (120; 110) is disclosed. The WLAN station (110; 120) is configured to encrypt a MAC Service Data Unit, MSDU, payload, wherein the MSDU payload comprises a MSDU, an aggregate MSDU, A-MSDU, or a MAC Management Protocol Data Unit, MMPDU, wherein the MSDU, the A-MSDU, or the MMPDU comprises one or more source address values, SAs, and one or more destination address values, DAs. Moreover, the WLAN station (110; 120) is configured to generate a MAC Protocol Data Unit, MPDU, or an aggregate MPDU, A-MPDU, based on the encrypted MSDU payload, and to transmit the MPDU or A-MPDU to the further WLAN station (120; 110).
Owner:HUAWEI TECH CO LTD

Multi-node keep-alive communication system and method for cellular Internet of Things

The invention relates to the technical field of Internet of Things communication, in particular to a cellular Internet of Things multi-node keep-alive communication system and method, and the system comprises a first module which is used for intercepting and copying uplink and downlink data streams of a plurality of nodes forwarded by gateway equipment in a bypass mode to obtain a data packet, and extracting a specified message from the data packet; the second module is used for receiving a specified message, matching the specified message with a pre-stored sequence, and updating a corresponding sequence field and determining a sequence state if matching succeeds; updating a sequence state and a period based on a matching result; feature vectors are extracted according to the matched specified messages and sequence periods, and all sequences are clustered and grouped; according to a clustering result, a periodic keep-alive channel is established between the gateway equipment and the target servers, a cellular IP address obtained by the gateway is used as a source address, and a keep-alive detection request is sent to each target server according to a set time slot; after the response is received, the sequence keep-alive state is updated and fed back to the corresponding node.
Owner:SHANGHAI LIANGXUN IOT TECH CO LTD

Information encryption management method and system

The invention belongs to the technical field of data security and passwords, and provides an information encryption management method and system. After the system receives the access request, calling user historical behaviors, and calculating behavior baseline stability; obtaining a time deviation degree based on the difference between the current access time and the historical time distribution, obtaining a geographic deviation degree based on the difference between the source address and the geographic attribution, combining the time deviation degree and the geographic deviation degree into a comprehensive deviation degree, and modulating according to the behavior baseline stability to obtain a context disturbance factor. Fusing the context disturbance factor with the static risk index of the target data to obtain a session risk calibration value; and mapping the key length to the step set according to the session risk calibration value to obtain a final key length, and performing encryption. According to the method, the encryption strength can be adaptively improved when abnormal access occurs, the performance is kept under normal access, and the method has real-time performance, context sensing and good generalization ability.
Owner:NINGBO NINGFAN INFORMATION TECH CO LTD +1

Abnormity detection method for factory station automation network data packet

The invention relates to the technical field of anomaly detection, in particular to an anomaly detection method for plant station automation network data packets, which comprises the following steps of: extracting a source MAC address, a destination MAC address, a protocol type, a communication frequency and an average packet length of each data packet based on the plant station automation network data packets captured in real time; according to the method, the source MAC address, the destination MAC address, the protocol type, the communication frequency and the average packet length of a plant station automation network data packet are extracted in real time, a weighted directed communication map is established according to the relation between intelligent electronic equipment and a gateway, and further, a network steady-state behavior baseline is formed through quantification from the communication behavior characteristic value of a node, so that the network steady-state behavior is realized. And a sliding time window mechanism is adopted to continuously calculate a behavior deviation metric value, and a topology behavior fluctuation index is generated by comprehensively analyzing communication frequency change, protocol type change and centrality change of an SV message, so that the time and the position of network abnormity can be determined.
Owner:ELECTRIC POWER SCI RES INST OF STATE GRID XINJIANG ELECTRIC POWER CO LTD

Low-latency redundant communication protocol based on improved prp

PCT designated stageWO2026020674A1Error preventionFrame sequenceIp address
Provided in the present invention is a low-latency redundant communication protocol based on an improved PRP, which protocol is compatible with the PRP standard of IEC 62439-3-2016 and operates at a link layer. Two redundant ports are connected to an upper-layer protocol by means of a link redundancy entity, and are transparent to the upper-layer protocol; a network-end node has two or three redundant network ports, which are respectively connected to networks that are independent of each other and have the same topological structure, and the networks operate in parallel; and network ports belonging to PRP-supporting end nodes are configured with the same IP address and MAC address. The improvements in the present invention are as follows: a redundancy discarding algorithm is modified to a mode of directly uploading a first-arriving communication frame to an application layer; {source IP address, source MAC address and frame sequence number} is used as a determination condition for a redundant frame; by means of file pre-configuration, the IP address of a single-network-port node in a network is written into a configuration file in advance in a node; and statistics for the number of network port link up / down events, out-of-receive-window statistics, statistics for non-sequential frame sequence numbers, and statistics for the number of out-of-sync redundant frames are added.
Owner:BEIJING AEROSPACE AUTOMATIC CONTROL RES INST

Trusted data sharing system based on identification analysis and data circulation method

The invention belongs to the technical field of data processing, and particularly relates to a trusted data sharing system based on identification analysis and a data circulation method, and the method comprises the steps: receiving an identification analysis request submitted by a data requester; dynamically analyzing the identifier into bound metadata through a distributed node network, analyzing an authority strategy, and generating an access control decision in combination with the dynamic attribute of a data requester; if the decision result is refusal, refusal response is returned to the requester, and block chain evidence storage is triggered; if the decision result is permission, the data request is routed to an external data source deployed by a data provider according to a data source address and a protocol type; returning the response of the data source to the data requester; recording an operation log; and displaying the data flow direction and the block chain evidence storage record through a visual auditing interface. Flexible access control based on dynamic attributes, efficient data routing and complete operation log records are realized, and the security and compliance of data sharing are guaranteed.
Owner:INSPUR YUNZHOU (SHANDONG) IND INTERNET CO LTD

Real-time isolation method and device based on AI traffic anomaly recognition

The invention discloses a real-time isolation method and device based on AI traffic anomaly recognition, and relates to the technical field of network security and artificial intelligence, and the method comprises the steps: collecting network traffic data based on a preset traffic path, fusing communication protocol data, timestamp data, source address data and target address data, and obtaining a fusion result; the method comprises the steps of generating a traffic behavior model, analyzing the traffic behavior model, determining abnormal features in traffic behaviors and a distribution mode of the abnormal features, and switching a current traffic processing task to an isolation task when the distribution mode of the abnormal features meets a preset isolation condition. And generating an isolation area and an isolation signal according to the distribution mode of the abnormal characteristics, and executing an isolation task based on the isolation area and the isolation signal. By means of the mode, the technical problem that in the prior art, the processing efficiency of abnormal flow recognition and isolation is low is solved.
Owner:SHENZHEN NOVA TECH DEV CO LTD