Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

193 results about "Trust score" patented technology

A Trust Score™ is presented as a numerical value calculated and assigned to all users whether buying or selling. Points are awarded for completing tasks related to providing us with identifiable information. Each task is weighed in terms of it’s value as set by our algorithm.

Virtual power plant terminal access control system based on dynamic authority

The embodiment of the invention provides a virtual power plant terminal access control system based on dynamic permission, and the system comprises an identity authentication module which is configured to collect hardware invariant features and firmware signature information of terminal equipment and generate an encryption certificate; the trust evaluation module is in communication connection with the identity authentication module and is configured to continuously monitor communication behavior characteristics and service instruction characteristics of the terminal and output a dynamic trust score; the dynamic authority management module is in data connection with the trust evaluation module and is configured to adjust the access authority level in real time according to the mapping relation of the dynamic trust score in a preset authority level interval; the strategy engine module is configured to generate an access control instruction when abnormal behavior characteristics are detected; and the behavior monitoring module interacts with the strategy engine module and the dynamic authority management module and is configured to execute blocking operation and feed back an execution result to the log auditing module. And the hardware invariant features and the dynamic behavior features are subjected to fusion evaluation, so that the terminal credibility quantification precision is improved.
Owner:HUANENG SHANXI ENERGY SALES CO LTD +1

Large model dynamic protection method and system based on zero-trust architecture

The invention provides a large model dynamic protection method and system based on a zero-trust architecture. The method comprises the steps that a security proxy gateway receives an access request; authenticating an initiating main body of the access request, collecting context information and transmitting the context information to a strategy decision point; the strategy decision point calculates a trust score in real time based on a dynamic trust evaluation model and performs real-time evaluation in combination with an access control strategy to generate a dynamic authorization judgment result; if the access is allowed, forwarding the access request to a large language model server, and performing input security filtering; the large language model server generates response content and performs output security filtering; and returning the final response subjected to the output security filtering to the initiating main body through the security proxy gateway. According to the method, a multi-layer protection framework is constructed, a dynamic trust evaluation model is introduced, and a content filtering layer is deployed, so that continuous permission verification, risk adaptive control and full-link content security protection are realized, and the service security of a large model is effectively guaranteed.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

Dynamic access control method, device and equipment of baseboard management controller, and storage medium

The invention discloses a dynamic access control method and device of a baseboard management controller, equipment and a storage medium, and relates to the technical field of server hardware security management.The method comprises the steps that when an access request is detected in a trusted operation environment, multi-dimensional context attributes associated with the access request are collected; performing dynamic trust evaluation based on the multi-dimensional context attribute, and generating a dynamic trust score corresponding to the access request; and executing an access control decision corresponding to the access request according to the dynamic trust score. Compared with a traditional static trust model, the dynamic trust evaluation is carried out based on the multi-dimensional context attribute under the trusted operation environment of starting verification of the baseboard management controller, and the differentiated access control decision is executed according to the dynamic trust score, so that the access risk is accurately identified, and the reliability of the system is improved. The security vulnerability of'permanent trust in one-time authentication 'in the prior art is avoided, and the access security of the substrate management controller is improved.
Owner:中电长城科技有限公司

Zero-trust cybersecurity access control system using continuous identity verification

A system for zero-trust cybersecurity access control using continuous identity verification (100), comprising: a Policy Decision and Enforcement Orchestrator (1) configured to receive an access request from a user device and enforce a session with minimal privileges; an engine for continuous identity verification (2) configured to generate a time-dependent identity trust score by continuously verifying the user identity during an active session; a device state and telemetry collector (3) configured to acquire device state parameters, runtime signals and network telemetry and to generate a state value; a module for detecting behavioral risks and anomalies (4) that is configured to create behavioral profiles and detect anomalies based on user activity patterns, contextual signals and the history of resource access; a cryptographic authentication and secure token module (5) configured to issue and update a short-lived, bound access token associated with at least the identity trust value and the state value; and an adaptive response and microsegmentation module (6) configured to dynamically adjust access permissions, network segmentation and session privileges in real time, based on an aggregated risk assessment derived from modules (2) to (4), where the system (100) continuously reassesses trustworthiness during the session and selectively allows, restricts, requires enhanced authentication or terminates the session based on the aggregated risk assessment.
Owner:SIVASHANMUGAM SATHESH PADMANABAN GLENDALE

Traditional Chinese medicinal material full-link traceability anomaly detection method based on graph propagation and trust score

The invention relates to the technical field of data processing and traceability, and discloses a traditional Chinese medicinal material full-link traceability anomaly detection method based on graph propagation and trust scoring, which comprises the following steps of: obtaining multi-source heterogeneous data of a traditional Chinese medicinal material full link, and constructing a traceability graph containing a traditional Chinese medicinal material circulation entity node and an associated edge relationship; performing parallel detection on the to-be-detected nodes in the traceability map by using a sub-model library to obtain original abnormal scores of multiple dimensions; and calculating an adaptive fusion weight according to the feature adaptation degree of the sub-model and the to-be-detected node. The adaptive fusion weight is introduced in the local anomaly refining step, so that the system can automatically improve the weight of the sub-model sensitive to the high-risk feature, and the system can dynamically recognize and preferentially acquire the optimal model for the current data feature; the problem that the traditional static fusion method is insufficient in robustness when facing diversified abnormal modes is avoided.
Owner:GUANGDONG PAOHE CHINESE HERB ELECTRONIC COMMERCE CO LTD

Dynamic password access management method, system and equipment based on zero trust and medium

The invention discloses a zero-trust-based dynamic password access management method, system and device and a medium, and the method specifically comprises the steps: collecting the context information of an access request, and dynamically adjusting the intensity of multi-factor authentication based on the context information to verify the identity of a user; after the identity verification is passed, combining user attributes, resource attributes and environment attributes which are obtained in real time, inputting the user attributes, the resource attributes and the environment attributes into a user behavior portrait model to carry out real-time risk assessment and authorization calculation, generating and granting a minimum necessary permission set to the user, and obtaining an authorization decision result; dynamically generating a temporary access key according to the user role and the resource sensitivity in the authorization decision result; and continuously monitoring user access behaviors, and inputting the user access behaviors into the deep behavior analysis model for real-time trust score calculation. According to the invention, a dynamic password access management system based on zero trust is constructed, the access security and management flexibility are comprehensively improved, and various security threats are effectively resisted.
Owner:广州三七极耀网络科技有限公司

Data transmission security protection system for edge computing server

The invention discloses a data transmission security protection system for an edge computing server, which relates to the technical field of edge computing and network security, is deployed in an edge computing environment comprising a plurality of edge computing nodes, and comprises five modules: a behavior fingerprint construction module, a data processing module and a security protection module, dynamically updated behavior fingerprints are generated through a lightweight convolution auto-encoder; the dynamic trust chain management module constructs a dynamic trust chain network and generates a comprehensive trust score based on node historical interaction data; the collusion attack detection module identifies a collusion attack in combination with trust chain topology and node behavior consistency analysis; the self-adaptive isolation and recovery module isolates malicious nodes and migrates tasks to guarantee service continuity; according to the edge computing security protection method, protection is converted into active immunity from passive feature matching, collusion attacks are effectively defended, data transmission security is guaranteed, and the edge computing security protection method is suitable for edge computing security protection.
Owner:SHENZHEN XINHAOBO TECHNOLOGY CO LTD

Privacy calculation arrangement method, system and equipment based on dynamic trust and medium

The invention discloses a privacy computing arrangement method, system and device based on dynamic trust and a medium, and relates to the technical field of data security. The method comprises the following steps: receiving a data processing request, and collecting context data including user trust, environmental risk and data sensitivity; calculating a dynamic trust score based on the context data, and dynamically selecting a target privacy calculation technology according to the score; scheduling tasks based on the selected technology and deploying a guard agent in the computing container; running state data is periodically collected through a guard agent to serve as heartbeat for verification, and if verification fails, key interruption and memory erasing and fusing tasks are triggered; after calculation is completed, packaging a result and an access control strategy into a security capsule; and in response to the capsule opening request, decrypting the rendering result in the memory after verifying that the terminal environment conforms to the strategy. According to the method, full-life-cycle dynamic control from calculation request to result use is realized, and the problem that authorization is out of control is solved.
Owner:厦门农芯数字科技有限公司

Drug inventory dynamic monitoring method and system based on edge calculation

The invention provides a drug inventory dynamic monitoring method and system based on edge calculation. The drug inventory dynamic monitoring method comprises the steps that drug parameters and environment data of all intelligent drug cabinets and warehouse areas and biological characteristics of operators are collected; determining a behavior log of the operator according to the operation action and the medicine change data, and generating a digital signature of the operator through the biological characteristics; constructing lightweight block chain nodes of the intelligent medicine cabinets and the warehouse areas, and packaging and chaining behavior logs and digital signatures through inter-node consensus of all the block chain nodes to generate an operation voucher; according to the average compliance rate and the operation voucher, carrying out trust evaluation on the compliance condition during operation to obtain a trust score; and comparing the trust score with a trust threshold, and if the trust score is lower than the trust threshold, locking the high-risk drug operation authority of the operator. By adopting the scheme of the invention, real-time credible evidence storage and dynamic evaluation can be carried out through behaviors of an operator, so that timely interception and early warning of high-risk medicine operation are realized.
Owner:THE UNIVERSITY-TOWN HOSPITAL AFFILIATED TO CHONGQING MEDICAL UNIVERSITY

Task processing method and device based on multiple agents and storage medium

The invention discloses a task processing method and device based on multiple agents and a storage medium. The method comprises the following steps: acquiring performance index data corresponding to a plurality of agents; based on the performance index data corresponding to the multiple agents, real-time trust scores corresponding to the multiple agents are determined, and the trust scores are used for indicating the reliability degree of the corresponding agents; constructing an optimization function based on the real-time trust scores, the capability matching degrees, the real-time workloads and the task security risk coefficients corresponding to the multiple agents; determining a target agent from a plurality of agents by taking the maximum function value of the optimization function as a target; and distributing the to-be-executed task to the target agent. According to the method and the device, the technical problems of low task allocation and execution accuracy and poor safety in a multi-agent system are solved.
Owner:STATE GRID BEIJING ELECTRIC POWER CO +1

Network access control method and device, equipment and storage medium

The invention discloses a network access control method and device, equipment and a storage medium, and relates to the technical field of network security, and the method comprises the steps: receiving a network resource access request sent by a client, and determining a trust evaluation factor used for carrying out the trust evaluation of the client, and a current trust score; estimating a variation coefficient of a trust evaluation factor based on the number of accesses of the current access request and the current trust score; estimating a conflict coefficient of each trust evaluation factor based on the access frequency and the trust score, and determining an objective weight of each evaluation factor based on the conflict coefficient and the variable coefficient; fusing the subjective weight and the objective weight to obtain a comprehensive weight; and calculating the sum of the products of all the comprehensive weights and the current trust score to obtain a total trust score, if the total trust score exceeds a preset threshold, allowing access, and if the total trust score does not exceed the preset threshold, forbidding access. According to the method, the trust evaluation result can be more accurate, so that accurate network access control is realized.
Owner:CHINA SOUTH-TO-NORTH WATER DIVERSION GROUP WATER NETWORK SMART TECHNOLOGY CO LTD

Multi-tier stance clarity verification system with deterministic trust computation and independent governance

A computer-implemented system that reduces and resists computationally generated fraudulent reviews by enforcing aspect-level decomposition with evidence requirements, multi-tier cryptographic verification, and deterministic trust scoring. Reviewer tiers (public, independent reviewer, independent professional reviewer) use verifiable credentials, zero-knowledge purchase proofs, and device or platform attestation. Evidence gates apply fixed, monotonic transformations; mandatory-evidence aspects yield zero contribution absent a required artifact. A finite-state dialog protocol with immutable timer fields enforces typed, aspect-bound objections. A Consumer Trust Board employing threshold signatures issues binding decisions affecting Consumer Trust Score computation with bounded retro-adjustment. A certification registry maintains credentials and sanctions that calibrate weighting. Non-instrumented submissions are badge-ineligible and weight-capped. Uniqueness keys prevent double counting. Dialog records are version-chained and batch-anchored via collision-resistant commitments. All computations use parameters from a versioned configuration to ensure deterministic reproducibility.
Owner:LEVENTOGLU ÖNDER

Micro-service security isolation method and system for multi-tenant SaaS platform

The invention provides a micro-service security isolation method and system for a multi-tenant SaaS platform, and the method comprises the steps: collecting tenant identity information, equipment terminal data and access environment parameters for the multi-tenant SaaS platform, and generating tenant credible baseline data; based on a zero-trust architecture, performing dynamic comparison and risk assessment on the tenant trusted baseline data and the real-time access request data, generating a tenant real-time trust score, and distributing a tenant minimum necessary permission set according to the tenant real-time trust score; and transparent encryption and isolation are carried out on the micro-service interaction flow among the tenants, a verification rule corresponding to the minimum necessary permission set of the tenants is configured for the API gateway, identity verification and flow limiting processing are carried out on real-time access requests of the tenants, and full-link security management and control are formed. According to the method and the device, the defect that the end-to-end security control from the access entry to the service interaction is difficult to realize due to insufficient isolation precision among micro-services of the current multi-tenant SaaS platform is overcome.
Owner:BEIJING NORTH LATITUDE 30 DEGREE NETWORK TECH CO LTD

Adaptive authentication based on real-time risk evaluation

A computer system and method for managing device trust during digital interactions. The method comprises capturing device data, including static and dynamic parameters, from a device upon user login to a digital platform. Static parameters are analyzed during the initial login to establish a static trust score, while dynamic parameters are analyzed across sessions to establish a dynamic trust score, which is incrementally updated based on subsequent data. The static and dynamic trust scores are combined to generate a combined trust score, and the device is assigned to one of multiple risk clusters. Based on the assigned cluster, adaptive security protocols are triggered. Assignment to a moderate-risk cluster initiates a step-up authentication process, and failure of the process results in assignment to a high-risk cluster, restricting access to the platform.
Owner:WELLS FARGO BANK NA

Safety management and control method, system and equipment combined with biological characteristics and medium

The invention discloses a safety management and control method, system and equipment combined with biological characteristics and a medium, and the method comprises the steps: verifying the identity of a user in a manner of combining living body detection and behavior characteristic detection, and obtaining an identity verification result; calculating a trust score of the user in combination with a preset trust scoring model according to the identity verification result; dividing the users into N trust levels according to the trust scores, and configuring corresponding access permissions and security measures for each trust level; continuously monitoring physiological state change and operation behavior abnormity of the user in a user access process, and updating the trust score according to a monitoring result; and adjusting the trust level of the user through the updated trust score and a risk assessment algorithm. By constructing a zero-trust architecture based on multi-modal biological verification, the technical problems that a traditional power grid access control system is single in identity authentication and rigid in authority management are effectively solved.
Owner:GUIZHOU POWER GRID CO LTD

Large factory 5G private network communication method and system based on zero trust

The invention relates to the technical field of industrial internet communication, and discloses a zero-trust-based large-scale factory 5G private network communication method and system, and the method comprises the steps: constructing a hardware fingerprint; the firmware is subjected to Hash verification by using the national cipher SM4; an equipment activity area is delimited through GPS and UWB fusion positioning, and trust deduction is triggered when equipment crosses a boundary; constructing an equipment behavior baseline based on a Markov chain and historical data, and judging that the equipment behavior is abnormal when the equipment behavior baseline deviates from a threshold value; establishing a dynamic trust evaluation model, and calculating a trust value; the minimum bandwidth of the 5G slice is reduced to 10 Mbps, and the SDN controller completes scheduling within 100 ms; using an LSTM model to predict idle resources; slice isolation is realized through the NFV, the VLAN and the VXLAN; the equipment is accessed by an X.509 certificate and a work order ID, and the unrecorded equipment triggers a stealth strategy; performing session re-authentication and dynamically adjusting the authority; constructing a threat perception engine by using an IDS and a sandbox; and implementing three-level response on the equipment with the trust score less than 40. The network security and the resource utilization rate can be improved.
Owner:AEROSPACE XINTONG TECH CO LTD

Dynamic cross-domain access authority management method and system based on zero-trust architecture

The invention discloses a dynamic cross-domain access authority management method and system based on a zero-trust architecture, and the method comprises the steps: continuously obtaining user behavior data and terminal equipment information of a terminal, carrying out the multi-identity authentication processing of a user access behavior, generating an access trusted identity, and building a three-dimensional association network of a user, equipment and an environment. The method comprises the steps of generating an access permission rule matched with a current risk through context connection of user access behaviors and calculation of a dynamic trust score, mapping the access permission rule to an equivalent permission of a target domain corresponding to the user access behaviors, executing and tracking cross-domain access of the user access behaviors to generate a cross-domain access link of the user access behaviors, and sending the cross-domain access link to the user access behaviors. And performing access context re-verification processing on the user access behavior according to a preset period, and calculating the deviation degree of the re-verified cross-domain access link so as to dynamically adjust the user access authority. The method has the advantages that a unified access mechanism is established, safety control is achieved, and the dual requirements of equal-guarantee compliance and business innovation are met.
Owner:ELECTRIC POWER RES INST OF GUANGXI POWER GRID CO LTD

Cooperative scheduling method, system and device for computing power network security resources and medium

The invention relates to a computing power network security resource cooperative scheduling method, system and device and a medium. The method comprises the following steps: acquiring resource state information and security state information of a plurality of computing power nodes; according to the resource state information and the security state information, carrying out credibility evaluation on the plurality of computing power nodes to obtain credibility scores of the plurality of computing power nodes; obtaining a service request, and analyzing the service request to obtain resource demand index information of the service request; the resource demand index information comprises a computing power demand, a network resource demand and a security resource demand; according to the credible score and the resource demand index information, performing resource matching processing on the plurality of computing power nodes and the service request to obtain a resource scheduling strategy; and generating a scheduling instruction according to the resource scheduling strategy. By adopting the method, the comprehensive requirements of the service on the computing power, the network and the security can be accurately matched, and the resource utilization rate, the service execution reliability and the security protection capability of the computing power network are improved.
Owner:STATE GRID INFORMATION & TELECOMM BRANCH +1

Dynamic network access control system under zero-trust architecture

The invention discloses a dynamic network access control system under a zero-trust architecture, which relates to the technical field of network security, and comprises a multi-dimensional trust evaluation module, a self-adaptive micro-segmentation engine, a strategy decision execution module and a risk perception feedback module, the multi-dimensional trust evaluation module calculates a comprehensive trust score based on five-dimensional features of identity, equipment, network, application and data; the self-adaptive micro-segmentation engine dynamically generates network micro-segments based on a graph diffusion algorithm; the strategy decision execution module adopts deep reinforcement learning to generate an access decision; the risk perception feedback module identifies abnormity based on the LSTM network and adjusts trust parameters through closed-loop feedback, the four modules are deeply coupled and cooperated, refined dynamic access control is realized, the occurrence rate of security events is reduced by more than 85%, and an innovative solution is provided for enterprise network security.
Owner:INFORMATION CENT OF YELLOW RIVER WATER RESOURCES COMMISSION

A probabilistic verifiable computation framework and a verification strategy generation method and system thereof

The present application relates to a kind of probabilistic verifiable computing framework and its verification strategy generation method and system, comprising: the characteristic parameter of acquisition computing node, and the preprocessed characteristic parameter is constructed as data set;Trust evaluation model is built, and optimization is carried out using particle swarm optimization algorithm;Optimal parameter combination is used to train trust evaluation model, and the local trust score of trained trust evaluation model is output;Local trust score is corrected using prior knowledge, global trust score is calculated, and consistency verification is carried out on global trust score by consensus synchronization;Final verification probability is calculated;According to final verification probability and global trust score, select appropriate verification mode;Computing node real-time query verification mode, when triggering update condition, recalculate final verification probability, update verification mode;According to the selected verification mode, the verification of computing task is carried out, and abnormal handling is carried out according to verification failure.
Owner:QUAN CHENG LABORATORY

Detecting data and / or model poisoning attacks in fl

A method includes: obtaining a first inference result based on test data and a first local FL model received from an FL client; obtaining a second reasoning result based on the test data and the reference FL model; checking whether the deviation between the first reasoning result and the second reasoning result is greater than a predefined threshold value or not; and in response to checking that a deviation between the first reasoning result and the second reasoning result is greater than a threshold, at least one of:-removing the FL client from the FL training process, or-reducing a trust score of the FL client; wherein the first local FL model and the reference FL model are obtained in an FL training process; the reference FL model is a second local FL model or a global FL model obtained from an aggregated local FL model during the FL training process.
Owner:NOKIA TECHNOLOGIES OY

Systems and methods for providing system security using a trust score manager

Described herein are systems and methods for monitoring suspicious activity by a trust score manager (TSM). The TSM identifies a transaction initiated by a master to access a region of the memory. The TSM also performs a scoring mechanism including mapping an identification of the master to a register. The TSM can ensure that only a master with dedicate access can access a region of the memory.
Owner:AXIADO CORP

Method for secure transmission of time critical data within a communication system, communication system and adapter for a terminal device

The invention relates to the secure transmission of time-critical data within a communication system, the communication system comprising a plurality of local area networks (100), each of which comprises at least one switch (101) and a plurality of terminal devices (102-105), the communication system comprising a control unit (202), which controls the functions of the plurality of switches and terminal devices, and a control network (200), which is assigned to the control unit and is separate from the local area networks. Communication within a local area network is implicitly authorized on the basis of the allocation of the respective terminal device to the same local area network. Each terminal device is assigned a zero trust adapter (121, 131, 141, 151), which acquires status information about the terminal device, forwards the status information to the control unit via the control network for evaluation, and authenticates the terminal device to the control unit and / or a communication partner. The control unit determines a trust score for the terminal device on the basis of the status information and uses rules depending on the trust score for the configuration or permitted communication relationships of the terminal device, respectively.
Owner:SIEMENS AG

Privacy calculation method and system based on state driving and storage medium thereof

The invention discloses a privacy computing method and system based on state driving and a storage medium thereof, and relates to the technical field of information security and privacy computing. The method comprises the steps of obtaining execution state information of a current calculation task; dynamically generating a temporary key set based on the state information and configuring access authority; state information and interaction behaviors are continuously monitored in the task execution process; if the abnormal event is detected, key access response operation is executed, including revoking the current key access authority, updating a key set and authorization information thereof, and continuing task execution; and the updated state information and authorization information are fed back to the state evaluation module to realize closed-loop adaptive optimization of the control strategy. According to the method, the state credibility score and path deviation degree double-index feedback model is constructed, so that the exception recognition capability and the key management precision of the system in a complex environment are effectively improved, the flexibility of state perception and access control is enhanced, and the method is suitable for security sensitive scenes such as multi-party computing and federated learning.
Owner:YANGZHOU NATURE NETWORK INFORMATION

Data security dynamic assessment system and protection methods

This invention discloses a dynamic data security assessment system and protection method, belonging to the field of information security technology, and is used to solve the problem of dynamic collaborative protection of terminal device access control and behavioral risks. It generates fingerprints based on terminal device characteristics and verifies authorization. Authorized terminal devices input access feature slices into a time-series model. A trust score is generated based on the cosine similarity between the behavioral sequence and the predicted sequence. A Markov model is then constructed to dynamically select the authentication method. A risk index is calculated by combining network and geographic information and assigned to the real or virtual environment. Unauthorized terminal devices are assigned to a virtual environment after registration. Differential monitoring is implemented: a time-series database is established for virtual environments, and a suspicious score is generated through sequence matching; for real environments, a state deviation is calculated using a Hidden Markov Model and multi-dimensional features are fused to generate a risk score. Based on result-based access control, suspicious terminal devices have their permissions restricted, compliant terminal devices undergo authentication migration, and access is controlled according to the principle of least privilege and a time window mechanism.
Owner:TIBET YANRUI INFORMATION SECURITY TECHNOLOGY CO LTD

Artificial intelligence-based network security data analysis system and method

The application discloses an artificial intelligence-based network security data analysis system and method, relates to the technical field of network security, and constructs a structured triple, is mapped into a graph node and an edge, and is stored into a graph database; graph data is extracted from the graph database, a node feature matrix, an adjacency matrix and an edge feature matrix are generated; a node representation vector is trained by using a graph attention mechanism, and a semantic propagation matrix is constructed; a predicted attack path model is obtained; a candidate attack path set is generated; a trusted scoring model is constructed and optimized, high-trust paths with scores exceeding a threshold value are screened; a multilayer perception machine model is constructed, an attack source prediction model is obtained; real-time graph data is acquired, nodes exceeding the threshold value are marked as risk nodes, and are uploaded to a protection system to trigger an alarm and an inspection, and the automation and real-time performance of attack source identification are improved.
Owner:江苏中维智慧工业有限公司

Decentralized trust root generation method suitable for block chain oracle machine

The invention discloses a decentralized trust root generation method suitable for a block chain oracle machine, solves the problems of insufficient security and decentration degree and weak node trust mechanism in a traditional block chain oracle machine system in the prior art, and realizes the security, expandability and stability of the block chain oracle machine system. The method comprises the following steps: generating a root key through a PUF (Physical Unclonable Function) and deriving an AIK certificate to finish initialization; generating an authentication report by using the TPM, submitting the authentication report to the block chain, completing identity registration and continuous verification of a runtime state, and forming a trusted node pool; when a data request is received, nodes are selected from the pool to form an oracle machine committee, and a leader node is appointed; the committee processes out-of-chain data, and the leader node aggregates signature responses and submits the signature responses to the block chain; and finally, based on node trust score weighted distribution service cost, realizing excitation and trusted closed loop.
Owner:XIDIAN UNIV

Interface attack detection method and device, electronic equipment and storage medium

The present disclosure provides a method and device for detecting interface attacks, electronic equipment and storage medium, which relates to the technical fields of information flow, network security, artificial intelligence and machine learning. The specific implementation scheme is: obtaining an access request of an interface; obtaining a plurality of access triplets based on the access request; each access triplet includes user agent information, key information of a header, and value information corresponding to the key information; obtaining access feature information of each access triplet; based on the access feature information of each access triplet of the access request and a pre-trained trust score model, detecting whether the access request is an attack. The technology of the present disclosure can effectively improve the efficiency of interface attack detection.
Owner:BEIJING BAIDU NETCOM SCI & TECH CO LTD

Systems and methods for determining trust across mobility platforms

Systems and methods for determining trust across mobility platforms are provided. In one embodiment, a method includes receiving first mobility data for a first automation experience of a user with a first mobility platform. The method also includes receiving a swap indication for a second automation experience of the user with a second mobility platform after the first automation experience. The method further includes selectively assigning the first mobility platform to a first mobility category and the second mobility platform to a second mobility category different than the first mobility category. The method yet further includes calculating an estimated trust score for the second automation experience by applying a trust model based on the first mobility category, the second mobility category, and a sequence of the first automation experience and the second automation experience. The method includes modifying operation of the second mobility platform based on the estimated trust score.
Owner:HONDA MOTOR CO LTD

Encryption technology-based maintenance data storage method

PendingCN121984745AAchieve trusted traceabilityAccurately locate tampering linksKey distribution for secure communicationUser identity/authority verificationData packData integrity
The invention provides a maintenance data storage method based on an encryption technology, and relates to the technical field of industrial equipment maintenance data security. The method comprises the following steps that: terminal equipment acquires maintenance data, constructs an original data packet, and calculates an initial trust score of each transmission node; encrypting the original data packet and generating a digital signature, and constructing a security data unit; the transmission node performs verification and encrypted transmission in sequence to form an encrypted data link; the server calculates a dynamic trust score after receiving the data, verifies data integrity and updates a node trust score; generating a unique full-link traceability label for the verified data, and storing the unique full-link traceability label to the block chain; if verification fails, triggering an alarm and generating a responsibility definition report; and the authorized user can query full-link data through the traceability label. According to the method, the full-link credible traceability and tamper-proof protection of the maintenance data from generation to storage are realized, and the problem that the tamper link cannot be positioned and the responsibility cannot be defined by a traditional afterward verification mechanism is effectively solved.
Owner:CHINA YANGTZE POWER