Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

265 results about "Trust score" patented technology

A Trust Score™ is presented as a numerical value calculated and assigned to all users whether buying or selling. Points are awarded for completing tasks related to providing us with identifiable information. Each task is weighed in terms of it’s value as set by our algorithm.

Data security dynamic evaluation system and protection method

The invention discloses a data security dynamic evaluation system and a protection method, belongs to the technical field of information security, and is used for solving the problem of terminal equipment access control and behavior risk dynamic collaborative protection. The method comprises the following steps: generating fingerprints through terminal equipment features, verifying authorization, inputting access feature slices into a time sequence model by authorized terminal equipment, generating a trust score based on cosine similarity of a behavior sequence and a prediction sequence, and constructing a Markov model to dynamically select an authentication mode according to the trust score; calculating a risk index by combining network and geographic information, and distributing the risk index to a real or virtual environment; and the unauthorized terminal equipment distributes the virtual environment after registration. Differentiated monitoring is carried out, a time sequence library is established in the virtual environment, and doubt scores are generated through sequence matching; the state deviation of the real environment is calculated through a hidden Markov model, and the risk score is generated by fusing the multi-dimensional features. And based on the result management authority, the suspicion terminal equipment isolates and shrinks the authority, the compliance terminal equipment authenticates and migrates, and the access is regulated and controlled according to the minimum privilege principle and the time window mechanism.
Owner:TIBET YANRUI INFORMATION SECURITY TECHNOLOGY CO LTD

Security authentication method, device and system of test platform, and storage medium

The embodiment of the invention provides a security authentication method, device and system for a test platform, and a storage medium, and relates to the technical field of network security. The method comprises the following steps: performing fingerprint acquisition on virtual and real equipment to generate a unique identifier, dynamically slicing based on a software defined network to form an isolated test environment, and injecting a zero-trust access strategy associated with the fingerprint; and based on the zero-trust access policy and the device fingerprint, allocating a minimum permission through an attribute-based access control model, continuously evaluating device behaviors to calculate a dynamic trust score, and adaptively updating the permission according to the trust score. By constructing a full-process security certification system and through multi-dimensional mechanism cooperation, dynamic risk perception and timely strategy adjustment, fine-grained control of virtual and real equipment access in an industrial control scene is realized, the dynamic adaptability and risk resistance of a test platform in a complex network environment are improved, and the test efficiency is improved. Equipment access safety, authority distribution minimization and behavior monitoring continuity are ensured, and the safety risk of the industrial control system is reduced.
Owner:STATE GRID SHANDONG ELECTRIC POWER CO +2

Intelligent warehousing system based on supply chain management

The invention discloses an intelligent warehousing system based on supply chain management, and particularly relates to the technical field of warehousing identification and supply chain information processing, and the system comprises an information collection module, a trigger judgment module, a data verification module, a risk assessment module and a state grading module. Collecting target carrier identification data through a multi-source device, performing credibility scoring according to stability, consistency and a historical confidence level, and judging whether to enter a verification process or not; in the verification stage, an identification consistency index and a supply chain synchronization credibility index are generated, and a risk score is output by the model; implementing credible marking, image checking or multi-source reconstruction according to the scoring level, and realizing identification result hierarchical control and operation closed loop; according to the method, the identification vector is constructed through multi-source acquisition, so that the state of the target carrier is accurately acquired; the identification processing efficiency is improved by adopting a hierarchical judgment mechanism; a differential response strategy is executed based on the risk score, a recognition credibility closed loop is constructed, and the recognition accuracy and operation safety of the system are effectively improved.
Owner:JIANGXI LINCHUANG CATERING CULTURE CO LTD

Block chain dynamic trust evaluation system and method based on artificial intelligence

The invention provides a block chain dynamic trust evaluation system and method based on artificial intelligence, and the method comprises the steps: carrying out the time sequence modeling of the transaction data of a block chain node and the consensus historical record of the node participation consensus, obtaining the behavior credibility of the block chain node, calculating the resource contribution degree of each transaction node, and carrying out the calculation of the resource contribution degree. Fusing the behavior credibility and each resource contribution degree to obtain a consensus score of each transaction node; constructing a node graph neural network of the block chain based on the transaction topological relation and the interaction frequency between the transaction nodes, detecting a plurality of malicious nodes in the block chain by using the node graph neural network, and further evaluating a consensus influence coefficient of the current malicious node aggregation on the block chain node consensus; and performing punitive correction on the consensus score of each malicious node through the consensus influence coefficient to obtain a final trust score of each transaction node in the block chain. Based on the above scheme, punishment correction of malicious node aggregation in blockchain node trust evaluation can be realized.
Owner:NINGBO DAHONGYING UNIV

Virtual power plant terminal access control system based on dynamic authority

The embodiment of the invention provides a virtual power plant terminal access control system based on dynamic permission, and the system comprises an identity authentication module which is configured to collect hardware invariant features and firmware signature information of terminal equipment and generate an encryption certificate; the trust evaluation module is in communication connection with the identity authentication module and is configured to continuously monitor communication behavior characteristics and service instruction characteristics of the terminal and output a dynamic trust score; the dynamic authority management module is in data connection with the trust evaluation module and is configured to adjust the access authority level in real time according to the mapping relation of the dynamic trust score in a preset authority level interval; the strategy engine module is configured to generate an access control instruction when abnormal behavior characteristics are detected; and the behavior monitoring module interacts with the strategy engine module and the dynamic authority management module and is configured to execute blocking operation and feed back an execution result to the log auditing module. And the hardware invariant features and the dynamic behavior features are subjected to fusion evaluation, so that the terminal credibility quantification precision is improved.
Owner:HUANENG SHANXI ENERGY SALES CO LTD +1

Large model dynamic protection method and system based on zero-trust architecture

The invention provides a large model dynamic protection method and system based on a zero-trust architecture. The method comprises the steps that a security proxy gateway receives an access request; authenticating an initiating main body of the access request, collecting context information and transmitting the context information to a strategy decision point; the strategy decision point calculates a trust score in real time based on a dynamic trust evaluation model and performs real-time evaluation in combination with an access control strategy to generate a dynamic authorization judgment result; if the access is allowed, forwarding the access request to a large language model server, and performing input security filtering; the large language model server generates response content and performs output security filtering; and returning the final response subjected to the output security filtering to the initiating main body through the security proxy gateway. According to the method, a multi-layer protection framework is constructed, a dynamic trust evaluation model is introduced, and a content filtering layer is deployed, so that continuous permission verification, risk adaptive control and full-link content security protection are realized, and the service security of a large model is effectively guaranteed.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

Access request security assessment method and device, resource server, storage medium and program product

The embodiment of the invention provides an access request security assessment method and device, a resource server, a storage medium and a program product, and relates to the technical field of cloud native security. According to the method, entity attributes, access context, behavior features and environment features in an access request are obtained after identity verification is passed, and the features are input into a pre-trained long-short memory network model to dynamically generate trust scores; therefore, the trust evaluation of the access request is changed from the traditional static rule judgment to an intelligent scoring mechanism based on the multi-dimensional dynamic characteristics. After the trust score exceeds the score threshold and the target policy rule matched with the access request is found in the policy rule base, the access request is processed based on the target policy rule, and refined and dynamic security management of the access request is realized through combination of a multi-dimensional intelligent scoring mechanism and a policy rule matching mechanism; therefore, the security and the intelligent level of access control in the cloud native environment are improved.
Owner:GUIYANG SHIJIHENGTONG TECH

Satellite internet endogenous security grading identity authentication method based on dynamic trust evaluation

The invention provides a satellite internet endogenous security grading identity authentication method based on dynamic trust evaluation, which comprises the following steps: a user registration stage: collecting and storing all identity information of a satellite internet user and information of entity equipment used for login; in a user login stage, performing identity authentication on the user according to a security level identity authentication process corresponding to the user login authentication identity, and allowing the user to log in after successful authentication; and determining an initial trust value based on the user identity information, obtaining a dynamic trust score based on the dynamic behavior and the initial trust value, and judging that the identity is abnormal when the dynamic trust score is lower than a set security threshold.
Owner:ZHENGZHOU UNIV

Dynamic access control method, device and equipment of baseboard management controller, and storage medium

The invention discloses a dynamic access control method and device of a baseboard management controller, equipment and a storage medium, and relates to the technical field of server hardware security management.The method comprises the steps that when an access request is detected in a trusted operation environment, multi-dimensional context attributes associated with the access request are collected; performing dynamic trust evaluation based on the multi-dimensional context attribute, and generating a dynamic trust score corresponding to the access request; and executing an access control decision corresponding to the access request according to the dynamic trust score. Compared with a traditional static trust model, the dynamic trust evaluation is carried out based on the multi-dimensional context attribute under the trusted operation environment of starting verification of the baseboard management controller, and the differentiated access control decision is executed according to the dynamic trust score, so that the access risk is accurately identified, and the reliability of the system is improved. The security vulnerability of'permanent trust in one-time authentication 'in the prior art is avoided, and the access security of the substrate management controller is improved.
Owner:中电长城科技有限公司

Systems and methods for calculating a trust score

Systems, devices, and methods are described herein for calculating a trust score. The trust score may be calculated between entities including, but not limited to, human users, groups of users, organizations, or businesses / corporations. A system trust score may be calculated for an entity by combining a variety of factors, including verification data, a network connectivity score, publicly available information, and / or ratings data. A peer trust score targeted from a first entity to a second entity may also be calculated based on the above factors. In some embodiments, the peer trust score may be derived from the system trust score for the target entity and may take into account additional factors, including social network connections, group / demographic info, and location data. Finally, a contextual trust score may be calculated between the first and second entities based on a type of transaction or activity to be performed between the two entities.
Owner:WWW TRUSTSCI COM INC

Methods and systems for improved data trust scores

Described herein are methods and systems for evaluating datasets through a multi-faceted scoring approach that assesses data quality across multiple dimensions. A trust score for a dataset may be generated by a scoring engine and displayed on a user interface, providing a comprehensive assessment of the dataset's readiness for use in artificial intelligence applications. The trust score incorporates multiple dimensions including diversity, timeliness, accuracy, security, discoverability, and LLM-readiness, offering users quantitative insights into dataset quality. This scoring system enables organizations to identify high-quality datasets suitable for AI model training, reducing the risk of poor model performance due to inadequate data. The visualization of trust scores through intuitive interfaces allows data scientists, analysts, and other stakeholders to quickly assess and compare datasets, facilitating more informed decision-making in AI development processes.
Owner:QLIK TECH INTERNATIONAL AB

Zero-trust cybersecurity access control system using continuous identity verification

A system for zero-trust cybersecurity access control using continuous identity verification (100), comprising: a Policy Decision and Enforcement Orchestrator (1) configured to receive an access request from a user device and enforce a session with minimal privileges; an engine for continuous identity verification (2) configured to generate a time-dependent identity trust score by continuously verifying the user identity during an active session; a device state and telemetry collector (3) configured to acquire device state parameters, runtime signals and network telemetry and to generate a state value; a module for detecting behavioral risks and anomalies (4) that is configured to create behavioral profiles and detect anomalies based on user activity patterns, contextual signals and the history of resource access; a cryptographic authentication and secure token module (5) configured to issue and update a short-lived, bound access token associated with at least the identity trust value and the state value; and an adaptive response and microsegmentation module (6) configured to dynamically adjust access permissions, network segmentation and session privileges in real time, based on an aggregated risk assessment derived from modules (2) to (4), where the system (100) continuously reassesses trustworthiness during the session and selectively allows, restricts, requires enhanced authentication or terminates the session based on the aggregated risk assessment.
Owner:SIVASHANMUGAM SATHESH PADMANABAN GLENDALE

Traditional Chinese medicinal material full-link traceability anomaly detection method based on graph propagation and trust score

The invention relates to the technical field of data processing and traceability, and discloses a traditional Chinese medicinal material full-link traceability anomaly detection method based on graph propagation and trust scoring, which comprises the following steps of: obtaining multi-source heterogeneous data of a traditional Chinese medicinal material full link, and constructing a traceability graph containing a traditional Chinese medicinal material circulation entity node and an associated edge relationship; performing parallel detection on the to-be-detected nodes in the traceability map by using a sub-model library to obtain original abnormal scores of multiple dimensions; and calculating an adaptive fusion weight according to the feature adaptation degree of the sub-model and the to-be-detected node. The adaptive fusion weight is introduced in the local anomaly refining step, so that the system can automatically improve the weight of the sub-model sensitive to the high-risk feature, and the system can dynamically recognize and preferentially acquire the optimal model for the current data feature; the problem that the traditional static fusion method is insufficient in robustness when facing diversified abnormal modes is avoided.
Owner:GUANGDONG PAOHE CHINESE HERB ELECTRONIC COMMERCE CO LTD

Dynamic password access management method, system and equipment based on zero trust and medium

The invention discloses a zero-trust-based dynamic password access management method, system and device and a medium, and the method specifically comprises the steps: collecting the context information of an access request, and dynamically adjusting the intensity of multi-factor authentication based on the context information to verify the identity of a user; after the identity verification is passed, combining user attributes, resource attributes and environment attributes which are obtained in real time, inputting the user attributes, the resource attributes and the environment attributes into a user behavior portrait model to carry out real-time risk assessment and authorization calculation, generating and granting a minimum necessary permission set to the user, and obtaining an authorization decision result; dynamically generating a temporary access key according to the user role and the resource sensitivity in the authorization decision result; and continuously monitoring user access behaviors, and inputting the user access behaviors into the deep behavior analysis model for real-time trust score calculation. According to the invention, a dynamic password access management system based on zero trust is constructed, the access security and management flexibility are comprehensively improved, and various security threats are effectively resisted.
Owner:广州三七极耀网络科技有限公司

Data transmission security protection system for edge computing server

The invention discloses a data transmission security protection system for an edge computing server, which relates to the technical field of edge computing and network security, is deployed in an edge computing environment comprising a plurality of edge computing nodes, and comprises five modules: a behavior fingerprint construction module, a data processing module and a security protection module, dynamically updated behavior fingerprints are generated through a lightweight convolution auto-encoder; the dynamic trust chain management module constructs a dynamic trust chain network and generates a comprehensive trust score based on node historical interaction data; the collusion attack detection module identifies a collusion attack in combination with trust chain topology and node behavior consistency analysis; the self-adaptive isolation and recovery module isolates malicious nodes and migrates tasks to guarantee service continuity; according to the edge computing security protection method, protection is converted into active immunity from passive feature matching, collusion attacks are effectively defended, data transmission security is guaranteed, and the edge computing security protection method is suitable for edge computing security protection.
Owner:SHENZHEN XINHAOBO TECHNOLOGY CO LTD

Privacy calculation arrangement method, system and equipment based on dynamic trust and medium

The invention discloses a privacy computing arrangement method, system and device based on dynamic trust and a medium, and relates to the technical field of data security. The method comprises the following steps: receiving a data processing request, and collecting context data including user trust, environmental risk and data sensitivity; calculating a dynamic trust score based on the context data, and dynamically selecting a target privacy calculation technology according to the score; scheduling tasks based on the selected technology and deploying a guard agent in the computing container; running state data is periodically collected through a guard agent to serve as heartbeat for verification, and if verification fails, key interruption and memory erasing and fusing tasks are triggered; after calculation is completed, packaging a result and an access control strategy into a security capsule; and in response to the capsule opening request, decrypting the rendering result in the memory after verifying that the terminal environment conforms to the strategy. According to the method, full-life-cycle dynamic control from calculation request to result use is realized, and the problem that authorization is out of control is solved.
Owner:厦门农芯数字科技有限公司

Drug inventory dynamic monitoring method and system based on edge calculation

The invention provides a drug inventory dynamic monitoring method and system based on edge calculation. The drug inventory dynamic monitoring method comprises the steps that drug parameters and environment data of all intelligent drug cabinets and warehouse areas and biological characteristics of operators are collected; determining a behavior log of the operator according to the operation action and the medicine change data, and generating a digital signature of the operator through the biological characteristics; constructing lightweight block chain nodes of the intelligent medicine cabinets and the warehouse areas, and packaging and chaining behavior logs and digital signatures through inter-node consensus of all the block chain nodes to generate an operation voucher; according to the average compliance rate and the operation voucher, carrying out trust evaluation on the compliance condition during operation to obtain a trust score; and comparing the trust score with a trust threshold, and if the trust score is lower than the trust threshold, locking the high-risk drug operation authority of the operator. By adopting the scheme of the invention, real-time credible evidence storage and dynamic evaluation can be carried out through behaviors of an operator, so that timely interception and early warning of high-risk medicine operation are realized.
Owner:THE UNIVERSITY-TOWN HOSPITAL AFFILIATED TO CHONGQING MEDICAL UNIVERSITY

Task processing method and device based on multiple agents and storage medium

The invention discloses a task processing method and device based on multiple agents and a storage medium. The method comprises the following steps: acquiring performance index data corresponding to a plurality of agents; based on the performance index data corresponding to the multiple agents, real-time trust scores corresponding to the multiple agents are determined, and the trust scores are used for indicating the reliability degree of the corresponding agents; constructing an optimization function based on the real-time trust scores, the capability matching degrees, the real-time workloads and the task security risk coefficients corresponding to the multiple agents; determining a target agent from a plurality of agents by taking the maximum function value of the optimization function as a target; and distributing the to-be-executed task to the target agent. According to the method and the device, the technical problems of low task allocation and execution accuracy and poor safety in a multi-agent system are solved.
Owner:STATE GRID BEIJING ELECTRIC POWER CO +1

Network access control method and device, equipment and storage medium

The invention discloses a network access control method and device, equipment and a storage medium, and relates to the technical field of network security, and the method comprises the steps: receiving a network resource access request sent by a client, and determining a trust evaluation factor used for carrying out the trust evaluation of the client, and a current trust score; estimating a variation coefficient of a trust evaluation factor based on the number of accesses of the current access request and the current trust score; estimating a conflict coefficient of each trust evaluation factor based on the access frequency and the trust score, and determining an objective weight of each evaluation factor based on the conflict coefficient and the variable coefficient; fusing the subjective weight and the objective weight to obtain a comprehensive weight; and calculating the sum of the products of all the comprehensive weights and the current trust score to obtain a total trust score, if the total trust score exceeds a preset threshold, allowing access, and if the total trust score does not exceed the preset threshold, forbidding access. According to the method, the trust evaluation result can be more accurate, so that accurate network access control is realized.
Owner:CHINA SOUTH-TO-NORTH WATER DIVERSION GROUP WATER NETWORK SMART TECHNOLOGY CO LTD

Explosive material multi-modal generation method based on deep targeted penetration

The invention discloses an explosive material multi-modal generation method based on deep targeted penetration, and particularly relates to the technical field of material multi-modal generation, and the method comprises the steps: carrying out the unified mapping, alignment, complementation and tagging processing of multi-source data, and reducing the accumulation risk of feedback distortion from the source; through sensitivity mapping and strategic conversion of distortion diagnosis features, the influence of delay and pollution is directly constrained as grade distribution, exploration proportion and sample screening rules in a material generation and delivery strategy, so that a generation link forms dynamic balance between quality control and diversity exploration, and meanwhile, the generation efficiency is improved. The materials are written into a candidate library after cross-modal consistency verification and trust scoring, strategy meta-information is bound, the content credibility and the execution traceability of a generated result are guaranteed, and in a delivery link, a tracking identifier and a return event link are additionally designed.
Owner:HUNAN TRYINE TECH CO LTD

Network security defense decision-making method

The invention discloses a network security defense decision-making method, and particularly relates to the technical field of network security. The method comprises the following steps: acquiring user account access behavior data in a network environment and intrusion observation data output by an intrusion detector, and performing data cleaning and feature extraction to obtain historical trust evidence sequence data; performing time sequence feature analysis by using a recurrent neural network, and identifying an abnormal behavior mode of the account; trust evaluation is carried out based on an actor-commentator reinforcement learning algorithm, and account real-time trust score data is generated; performing association analysis by combining the behavior abnormal mode feature data and the real-time trust score data to obtain potential threat feature data of the user account; evaluating the effectiveness of the defense strategy by adopting a strategy evaluation network, and generating defense strategy evaluation data; and generating an optimal network defense decision according to the potential threat feature data of the user account and the defense strategy evaluation data. According to the method, the detection accuracy of potential network intrusion and the effectiveness of defense measures are improved.
Owner:UNIV OF SCI & TECH BEIJING

Dynamic data filtering based on trust score within service mesh

A computer-implemented method performs dynamic filtering within a service mesh. While transferring data from one microservice to another microservice, each microservice evaluates a level of trust with each upstream and downstream microservice based on the level of trust score. Each microservice evaluates which data should be filtered while transferring data to downstream microservice and which data should be filtered while receiving data from upstream microservice.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Multi-tier stance clarity verification system with deterministic trust computation and independent governance

A computer-implemented system that reduces and resists computationally generated fraudulent reviews by enforcing aspect-level decomposition with evidence requirements, multi-tier cryptographic verification, and deterministic trust scoring. Reviewer tiers (public, independent reviewer, independent professional reviewer) use verifiable credentials, zero-knowledge purchase proofs, and device or platform attestation. Evidence gates apply fixed, monotonic transformations; mandatory-evidence aspects yield zero contribution absent a required artifact. A finite-state dialog protocol with immutable timer fields enforces typed, aspect-bound objections. A Consumer Trust Board employing threshold signatures issues binding decisions affecting Consumer Trust Score computation with bounded retro-adjustment. A certification registry maintains credentials and sanctions that calibrate weighting. Non-instrumented submissions are badge-ineligible and weight-capped. Uniqueness keys prevent double counting. Dialog records are version-chained and batch-anchored via collision-resistant commitments. All computations use parameters from a versioned configuration to ensure deterministic reproducibility.
Owner:LEVENTOGLU ÖNDER

Micro-service security isolation method and system for multi-tenant SaaS platform

The invention provides a micro-service security isolation method and system for a multi-tenant SaaS platform, and the method comprises the steps: collecting tenant identity information, equipment terminal data and access environment parameters for the multi-tenant SaaS platform, and generating tenant credible baseline data; based on a zero-trust architecture, performing dynamic comparison and risk assessment on the tenant trusted baseline data and the real-time access request data, generating a tenant real-time trust score, and distributing a tenant minimum necessary permission set according to the tenant real-time trust score; and transparent encryption and isolation are carried out on the micro-service interaction flow among the tenants, a verification rule corresponding to the minimum necessary permission set of the tenants is configured for the API gateway, identity verification and flow limiting processing are carried out on real-time access requests of the tenants, and full-link security management and control are formed. According to the method and the device, the defect that the end-to-end security control from the access entry to the service interaction is difficult to realize due to insufficient isolation precision among micro-services of the current multi-tenant SaaS platform is overcome.
Owner:BEIJING NORTH LATITUDE 30 DEGREE NETWORK TECH CO LTD

Adaptive authentication based on real-time risk evaluation

A computer system and method for managing device trust during digital interactions. The method comprises capturing device data, including static and dynamic parameters, from a device upon user login to a digital platform. Static parameters are analyzed during the initial login to establish a static trust score, while dynamic parameters are analyzed across sessions to establish a dynamic trust score, which is incrementally updated based on subsequent data. The static and dynamic trust scores are combined to generate a combined trust score, and the device is assigned to one of multiple risk clusters. Based on the assigned cluster, adaptive security protocols are triggered. Assignment to a moderate-risk cluster initiates a step-up authentication process, and failure of the process results in assignment to a high-risk cluster, restricting access to the platform.
Owner:WELLS FARGO BANK NA

Safety management and control method, system and equipment combined with biological characteristics and medium

The invention discloses a safety management and control method, system and equipment combined with biological characteristics and a medium, and the method comprises the steps: verifying the identity of a user in a manner of combining living body detection and behavior characteristic detection, and obtaining an identity verification result; calculating a trust score of the user in combination with a preset trust scoring model according to the identity verification result; dividing the users into N trust levels according to the trust scores, and configuring corresponding access permissions and security measures for each trust level; continuously monitoring physiological state change and operation behavior abnormity of the user in a user access process, and updating the trust score according to a monitoring result; and adjusting the trust level of the user through the updated trust score and a risk assessment algorithm. By constructing a zero-trust architecture based on multi-modal biological verification, the technical problems that a traditional power grid access control system is single in identity authentication and rigid in authority management are effectively solved.
Owner:GUIZHOU POWER GRID CO LTD

Charger supply chain data traceability management method based on block chain

The invention discloses a charger supply chain data traceability management method based on a block chain, and relates to the technical field of supply chain data management, the method is constructed on a hybrid architecture of on-chain anchoring and under-chain execution, and an encryption trust anchor point is generated according to a supplier trust score and a data importance level; then, in combination with a dynamically evolved supplier trust score and a block chain network load factor, a verification depth and an anchoring frequency are decided in real time through an elastic verification trigger function; further, a total utility function of the system is solved periodically to obtain an optimal parameter combination, and the optimal parameter combination is used for calibrating a decision function to realize combination of strategic optimization and tactical response; and finally, chain storage evidence is carried out on the trust anchor point through the oracle machine, and off-chain asynchronous verification is triggered. According to the invention, the storage and consensus overhead of the block chain is significantly reduced, the expandability of the system is improved, the security, efficiency and cost can be adaptively balanced, and low-cost, high-efficiency, safe and reliable supply chain data traceability management is realized.
Owner:QIDONG XUNENG ELECTRONIC TECH CO LTD

Large factory 5G private network communication method and system based on zero trust

The invention relates to the technical field of industrial internet communication, and discloses a zero-trust-based large-scale factory 5G private network communication method and system, and the method comprises the steps: constructing a hardware fingerprint; the firmware is subjected to Hash verification by using the national cipher SM4; an equipment activity area is delimited through GPS and UWB fusion positioning, and trust deduction is triggered when equipment crosses a boundary; constructing an equipment behavior baseline based on a Markov chain and historical data, and judging that the equipment behavior is abnormal when the equipment behavior baseline deviates from a threshold value; establishing a dynamic trust evaluation model, and calculating a trust value; the minimum bandwidth of the 5G slice is reduced to 10 Mbps, and the SDN controller completes scheduling within 100 ms; using an LSTM model to predict idle resources; slice isolation is realized through the NFV, the VLAN and the VXLAN; the equipment is accessed by an X.509 certificate and a work order ID, and the unrecorded equipment triggers a stealth strategy; performing session re-authentication and dynamically adjusting the authority; constructing a threat perception engine by using an IDS and a sandbox; and implementing three-level response on the equipment with the trust score less than 40. The network security and the resource utilization rate can be improved.
Owner:AEROSPACE XINTONG TECH CO LTD

Block chain-driven data exchange full-process monitoring system and method

The invention relates to the technical field of data exchange, and particularly discloses a blockchain-driven data exchange full-process monitoring system and method, and the system comprises the steps that a trusted data collection end collects business data, synchronously generates an environment fingerprint, carries out the digital signature of the combination of the business data and the environment fingerprint, and generates a trusted data package; the edge verification gateway end receives the trusted data packet and verifies the validity of the TEE signature, and when the validity verification of the TEE signature is passed, environment fingerprints are extracted and compared with corresponding equipment behavior baselines, and a real-time trust score is calculated; when the trust score is higher than a trust score threshold value, the hierarchical and fragmented storage end stores the trusted data packet to a corresponding storage layer in a fragmented manner according to the storage attribute to obtain a storage result; the elastic consensus selection end determines a current network load based on a storage result, and dynamically selects a consensus algorithm based on the current network load to generate a cross-chain verifiable evidence for the trusted data packet; and smooth proceeding of the whole data exchange process and reliable circulation of data are ensured.
Owner:GUANGZHOU YITUO SOFTWARE DEV CO LTD

Dynamic cross-domain access authority management method and system based on zero-trust architecture

The invention discloses a dynamic cross-domain access authority management method and system based on a zero-trust architecture, and the method comprises the steps: continuously obtaining user behavior data and terminal equipment information of a terminal, carrying out the multi-identity authentication processing of a user access behavior, generating an access trusted identity, and building a three-dimensional association network of a user, equipment and an environment. The method comprises the steps of generating an access permission rule matched with a current risk through context connection of user access behaviors and calculation of a dynamic trust score, mapping the access permission rule to an equivalent permission of a target domain corresponding to the user access behaviors, executing and tracking cross-domain access of the user access behaviors to generate a cross-domain access link of the user access behaviors, and sending the cross-domain access link to the user access behaviors. And performing access context re-verification processing on the user access behavior according to a preset period, and calculating the deviation degree of the re-verified cross-domain access link so as to dynamically adjust the user access authority. The method has the advantages that a unified access mechanism is established, safety control is achieved, and the dual requirements of equal-guarantee compliance and business innovation are met.
Owner:ELECTRIC POWER RES INST OF GUANGXI POWER GRID CO LTD