Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

23 results about "Trusted client" patented technology

In computing, a trusted client is a device or program controlled by the user of a service, but with restrictions designed to prevent its use in ways not authorized by the provider of the service. That is, the client is a device that vendors trust and then sell to the consumers, whom they do not trust. Examples include video games played over a computer network or the Content Scramble System (CSS) in DVDs.

Resource access method and device, zero-trust platform and storage medium

The invention provides a resource access method and device, a zero-trust platform and a storage medium, and the method comprises the steps: receiving an internal resource access request of a zero-trust client, the access request carrying an access address of a target resource, user information of the zero-trust client, and temporary authentication information; the access address comprises a zero-trust platform domain name and a target resource identifier, the zero-trust platform domain name points to a public network address of the zero-trust platform, and the target resource identifier is used for uniquely identifying a target resource; the temporary authentication information is used for authenticating that the zero-trust client has the qualification of initiating the access request; based on the user information and the temporary authentication information, verifying the user identity and the access authority of the zero-trust client; after the verification is successful, determining a real address of the target intranet server based on a pre-configured mapping relationship between the real address of the intranet server and the internal resource identifier; and forwarding the access request to the target intranet server according to the real address of the target intranet server.
Owner:HANGZHOU DPTECH TECH

Robustness federated learning method based on dynamic aggregation weight and prototype guidance

The invention relates to a robust federated learning method based on dynamic aggregation weight and prototype guidance, and belongs to the technical field of federated learning. The method comprises the following steps: classifying clients into credible clients and drifting clients based on mutual evaluation; extracting trainable vectors in the client, and constructing a positive prototype set and a negative prototype set; calculating the similarity and complementarity of each client, obtaining the dynamic weight of each client in global model aggregation, and combining to obtain a dynamic aggregation weight matrix; based on a preset merging threshold value, performing merging operation on the models in the trusted clients to obtain a trusted client aggregation model; and carrying out distillation training based on the trusted client aggregation model, the positive prototype set and the negative prototype set, issuing the trained model to each client for the next round of iteration, and realizing robust federated learning through multiple rounds of iteration. The objective of the invention is to solve the problem of global model performance reduction caused by dynamic change of client data distribution and malicious client interference in federated learning.
Owner:KUNMING UNIV OF SCI & TECH

Federal learning security aggregation method based on vector space secret sharing

The invention relates to the technical field of federated learning, in particular to a federated learning security aggregation method based on vector space secret sharing, which comprises the following steps that: a client divides a local model gradient into a plurality of secret shares and distributes the secret shares to a plurality of servers; the server carries out aggregation operation on the secret share through a security computing protocol, wherein the aggregation operation comprises addition and multiplication operation; calculating the similarity between the clients based on the secret state data, and screening out a credible client set; and executing security aggregation on the gradient share of the trusted client, reconstructing a global model gradient and issuing the global model gradient. According to the method, client poisoning attacks can be resisted, server reasoning attacks can also be resisted, a federal learning global model security aggregation method is designed based on vector space secret sharing, and threats caused by server offline are reduced.
Owner:GUIZHOU UNIV

A security asset risk prediction data encryption method and a risk prediction method

ActiveCN116522353BFinanceDigital data protectionCiphertextTrusted client
The application discloses a kind of securities asset risk prediction data encryption method and risk prediction method, including label semi-ordered tree construction step, the generation step of ciphertext-based random forest classification model, customer securities asset risk prediction step.First, in the trusted client, the securities asset information of historical customer is in clear text, the construction of LSOPE tree is completed and semi-ordered encryption is carried out to user data, and the yield-loss data as label is encrypted using deterministic symmetric encryption scheme, to hide the actual securities asset information of user, only the relative ordering relationship is retained.Then, the ciphertext is sent to the server, and a classification model is constructed using the random forest algorithm.Finally, the client encrypts the new securities asset information, the server performs risk prediction, and the prediction result is transmitted back to the client for decryption.The application can protect the privacy of customer data in all directions, while ensuring the calculation efficiency and accuracy of risk prediction.
Owner:NANJING UNIV

Distributed lock management method and device, electronic equipment and storage medium

The invention discloses a distributed lock management method and device, electronic equipment and a storage medium, and relates to the technical field of storage, the management method comprises the following steps: in response to lease overdue of a client, judging whether a server works normally or not; in response to normal work of the server, releasing a distributed lock held by the overdue client, and recording session information of the overdue client into a preset database to prohibit the overdue client from executing lock recovery; and in response to restarting of the server, notifying the metadata server to enter a delay period, determining a target client of which the lock state is not recovered after the delay period is ended, controlling the metadata server to clear lock information of a distributed lock held by the target client, and recording session information of the target client into a preset database, the technical problem that the unconditionally trusted client recovers the lock request after the server is restarted is solved, and the technical effect of guaranteeing the data consistency and reliability of the distributed file system in a fault scene is achieved.
Owner:JINAN INSPUR DATA TECH CO LTD

Verification methods, devices, electronic equipment, and storage media for remote vehicle login

This invention discloses a method, apparatus, electronic device, and storage medium for verifying remote login to a vehicle, relating to the field of vehicles. The method includes: after the vehicle's infotainment system starts up, detecting an access request command sent by a client; in response to detecting the access request command, performing initial verification on the client based on the access request command to obtain an initial verification result; if the initial verification result indicates that the client is a pre-trusted client, controlling the remote login port of the infotainment system to switch from a hidden state to an open state; and performing login verification on the pre-trusted client based on the remote login interface in the open state to obtain a target verification result, wherein the target verification result indicates whether the client is a trusted client. This invention solves the technical problem of low security protection for remote login to vehicles.
Owner:CHINA FAW CO LTD

Quantum watermarking of biometric identifiers

Disclosed are various approaches for distinguishing between genuine biometric identifiers and fabricated or fraudulent biometric identifiers created using generative artificial intelligence (GenAI). One or more watermarks and one or more encryption keys can be distributed to authorized client applications executing on trusted client devices of users. A watermark can be encrypted and then embedded into a biometric identifier using a quantum computing device. To verify the authenticity of the biometric identifier, a quantum computing device can be used to extract the watermark from the biometric identifier. The watermark can then be decrypted. If the decrypted watermark is successfully extracted and decrypted, then it can be determined that the biometric identifier is legitimate.
Owner:AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC

Root Trusted Client Memory Page Management

Root trusted client memory page management is described. The root trusted client is loaded and authenticated by the hardware platform. The root trusted client is configured to manage memory operations of different clients via special permissions that allow it to perform memory operations using clients' private memory pages. To this end, the client page table includes a novel "T bit" in each entry, indicating whether the root trusted client or a different client owns the associated memory page. Each entry in the root trusted client's client page table additionally includes a "C bit," indicating whether the corresponding memory page is a protected page. The combined C and T bit values ​​of the page table entry indicate whether the operation performed as part of processing a client's memory request is offloaded from the hardware platform to the root trusted client.
Owner:ADVANCED MICRO DEVICES INC

Methods, apparatuses, devices, systems, and media for defending against phishing attacks

Embodiments of the present application disclose a method, device, equipment, system and medium for defending against a network phishing attack to solve the problem of security loopholes in the prior art for defending against a network phishing attack. The system for defending against a network phishing attack comprises a zero-trust gateway configured to receive a service access request sent by a zero-trust client, redirect the service access request to a remote browser service device, receive a modified HTTP response returned by the remote browser service device, and forward the modified HTTP response to the zero-trust client; and the remote browser service device configured to start a remote browser container instance according to the service access request, send an HTTP request to a target website through the remote browser container instance, receive an HTTP response returned by the target website, insert a security defense interceptor code into an HTML document of the HTTP response, obtain a modified HTTP response, and send the modified HTTP response to the zero-trust gateway.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Federal recommendation system end-cloud collaborative defense method based on disturbance trajectory consistency

The invention discloses a federal recommendation system end cloud collaborative defense method based on disturbance trajectory consistency, which comprises the following steps: a client locally executes optimization of a personalized recommendation model, and introduces a structure perception disturbance control mechanism; the client introduces an embedded amplitude constraint term in local training; the client adds a user preference direction guide regular item in a local training stage; updating uploaded by the client side is transmitted to the server side through a communication channel, the server records uploading history of the client side in multiple rounds of training, and behavior characteristics of the client side are modeled and analyzed; according to the uploaded track information, the server calculates the credibility score of each client; and a credible client set is screened out according to an evaluation result, and global model parameters are updated. According to the method, complex poisoning attacks such as slow drift type and alignment type can be effectively identified and inhibited under the condition that an external verification set is not needed, and the method has good universality and privacy friendliness and is suitable for various federal recommendation application scenes such as e-commerce, social contact and music recommendation.
Owner:CHANGAN UNIV

An application access method and apparatus

This application provides an application access method and apparatus, relating to the field of communication technology. The method is applied to a gateway device in a zero-trust network. It receives a first service message sent by a terminal device through a zero-trust client for accessing a web application; obtains a virtual IP address corresponding to the user token in the first service message, wherein the virtual IP address is allocated and issued to the gateway device by the controller in the zero-trust network after the terminal device successfully goes online; replaces the source IP address in the first service message with the virtual IP address to obtain a second service message; and forwards the second service message to the resource server of the web application.
Owner:NEW H3C SECURITY TECH CO LTD

Method, device and product for protecting intellectual property based on DBUS

The invention discloses a method, a device and a product for protecting intellectual property based on a DBUS. Comprising a server and a client. The server comprises a component registration module, an event monitoring module, an authentication module, a data decryption module and a request callback module; and the client comprises a ciphertext loading module, a data encryption module and a communication control module. The authentication module analyzes a token field of a JSON data structure of the communication request to extract encrypted authentication information, and if a piece of decrypted data of which the MAC address is matched with the MAC address of the current service equipment is extracted, it is proved that the communication request comes from a credit granted client, and data decryption operation continues; if the data are not matched, the authentication is not passed, error information is returned, and the communication request is interrupted. According to the invention, the DBUS is used as a service providing carrier, so that the service is safer and more stable.
Owner:GUANGXI PUBLIC INFORMATION IND CO LTD

Quantum zero trust client graphical user interface for electronic devices

1. Name of the product in this design: Quantum Zero Trust Client Graphical User Interface for Electronic Devices. 2. Purpose of this design: An electronic device. 3. The key design features of this product are its graphical user interface. 4. The picture or photo that best illustrates the key design points: Design 1 front view. 5. Design 1 is designated as the basic design. 6. Purpose of the graphical user interface: Used to set up and display the Quantum Zero Trust client software. 7. Human-computer interaction method of graphical user interface: Click "Connect" in the main view of Design 1 to enter the interface change state diagram 1 of Design 1; in the interface change state diagram 1 of Design 1, enter the username and password and click "Login" to enter the interface change state diagram 2 of Design 1; in the interface change state diagram 2 of Design 1, obtain and fill in the SMS verification code, click "Recharge Shield" to enter the interface change state diagram 3 of Design 1. Click "Connect" in the main view of Design 2 to enter the Design 2 interface change state diagram 1; in the Design 2 interface change state diagram 1, click "Username SMS" to enter the Design 2 interface change state diagram 2; in the Design 2 interface change state diagram 2, enter the username, obtain and fill in the SMS verification code, and click "Login" to enter the Design 2 interface change state diagram 3; in the Design 2 interface change state diagram 3, obtain and fill in the SMS verification code, and click "Recharge Shield" to enter the Design 2 interface change state diagram 4.
Owner:QUANTUMCTEK CO LTD

Client-server model with trusted client application

A method in a client-server system involves providing a trusted client application (TCA; 310) solely executing within a secure virtual machine (320) that is embedded within a client application (340). The secure virtual machine has a virtualized operating system (330) and provides an isolated runtime for the trusted client application (TCA; 310) to securely handle client resources (112; client data) for the client application (340). The client resources (112; client data) comprises executable client logic (client_logic), client assets data (client_assets), and optionally one or more of a client digital certificate (client_certificate) and client subscription data (client_subscription). The trusted client application (TCA; 310) receives (144) an execution request (142) from the client application (340) and validates (146) one or more of the client assets data (client_assets), client digital certificate (client_certificate) and client subscription data (client_subscription). Upon successful validation (148), the trusted client application (TCA; 310) executes at least some of the client logic (client_logic) and updates the client assets data (client_assets).
Owner:CRUNCHFISH

A blockchain federated learning secure aggregation framework based on hierarchical index screening

The application discloses a kind of based on hierarchical index screening's blockchain federated learning security aggregation framework, it is related to federated learning technical field, including pre-training stage, formal training stage and aggregation stage, wherein: pre-training stage, training client participates in pre-training and uploads the loss value calculated to blockchain;Official training stage, trusted client trains model and provides scoring standard, training client trains and uploads local model parameter, trusted client scores local model and calculates its weight, uploads model trust score and weight;Aggregation stage, model aggregation is carried out according to model trust score and weight, obtains the global model of this round and is chained.The application aggregates the trust score of uploaded local model by FLTrust algorithm, excludes malicious client, to some extent, counteracts byzantine attack, guarantees the accuracy of finally obtained global model, accelerates aggregation speed by loss prediction and aggregation weight, obtains better global model with less convergence round.
Owner:SHANGHAI JIAOTONG UNIV

Terminal equipment access control method, communication system and zero-trust security management platform

The invention provides a terminal equipment access control method, a communication system and a zero-trust security management platform, and relates to the technical field of communication. The terminal equipment access control method comprises the following steps: receiving terminal feature information sent by a zero-trust client deployed on terminal equipment; acquiring access control information of the terminal equipment according to the terminal feature information; and sending a subscription data modification request for the terminal equipment to a network equipment function NEF network element according to the access control information, so that the NEF network element modifies subscription data of the terminal equipment in a unified data management UDM network element according to the subscription data modification request, and triggers PDU session modification of the terminal equipment. Generating access control information of the terminal device based on the terminal feature information collected by the zero-trust client; therefore, the state of the terminal equipment accessing the target core network can be subjected to safety management based on the access control information, and potential safety hazards are avoided.
Owner:SHENZHEN AI LINK CO LTD

A federated backdoor attack detection method and system supporting adaptive parameter layering

PendingCN122634587AAttackTrusted client
The application relates to the field of backdoor detection of federated learning, and discloses a federated backdoor attack detection method and system supporting adaptive parameter layering, which comprises the following steps: receiving model update parameters uploaded by each client in the current round of training, dividing the model update parameters into a high-layer parameter set and a low-layer parameter set according to a calculated parameter division ratio; performing direction consistency detection on the model update parameters in the high-layer parameter set and performing sign consistency detection on the model update parameters in the low-layer parameter set; calculating the historical distribution difference between the current round of training and historical rounds, filtering out abnormal clients according to the direction consistency, the sign consistency and the historical distribution difference, and aggregating the model update parameters of the filtered trusted clients to obtain a global model update result. The application has the advantages that the model update parameters of abnormal clients can be accurately identified and filtered, and the accuracy and stability of backdoor attack detection are ensured.
Owner:泉州职业技术大学

Privacy and robust federated learning method and system based on dimension screening

PendingCN120979693ADigital data protectionMachine learningAttackTrusted client
The invention provides a privacy and robust federated learning method and system based on dimension screening, and belongs to the technical field of federated learning, and the method comprises the steps: extracting a gradient corresponding to a current model parameter from a client participating in federated learning; performing cutting and noise adding processing on the gradient to obtain a noise-added gradient; updating model parameters by using the gradient added with the noise and acquiring an accumulated gradient; carrying out dimension screening on the accumulated gradients and uploading the screened gradients to a central server; calculating the similarity between the uploaded gradient distribution and standard normal distribution; screening out credible clients according to the similarity; aggregating the model parameters of the trusted client to obtain global model parameters; and updating the global model by using the global model parameters until global model training is completed. According to the method, the attack of a malicious client is effectively resisted by adopting a dimension screening and robust aggregation algorithm, and the accuracy of a global model is ensured.
Owner:BEIJING INST OF TECH

Label noise robust federated learning method based on self-paced learning and adjacency matrix

The application relates to a label noise robust federated learning method based on self-step learning and an adjacency matrix, a horizontal federated learning framework based on a client-server mode, and distributed training, and comprises the following steps: step S1, selecting a trusted client; step S2, calculating the near neighbor relationship of all client samples according to the trusted client; performing federated learning according to the trusted client obtained in step S1 to obtain a global federated model, and using the global federated model to calculate the near neighbor relationship of all client samples; step S3, self-step updating of sample near neighbor relationship and label evaluation and correction; and step S4, out-of-cluster sample processing. The application provides a safe and reliable label noise robust federated learning method based on self-step learning and an adjacency matrix, can effectively reduce the interference of noise data on a model, and improves the model convergence speed.
Owner:NANJING UNIV OF POSTS & TELECOMM

Secure access methods, devices, media, electronic equipment, and software products for resources

A resource access method, apparatus, readable medium, electronic device, and program product are disclosed. This relates to the field of information security technology. A client sends a resource access request message for a target application to a gateway device. This resource access request message includes a first access token issued by the client based on the private key in a business key pair, and a session identifier generated by the server based on a login request message sent by the client. The gateway device then authenticates the client based on the first access token and the session identifier through a pre-established binding relationship on the server. Upon successful authentication, the gateway device requests business resources of the target application based on the resource access request message. The binding relationship represents the relationship between the session and a trusted client of the target application. Based on this binding relationship, it can be confirmed that the client sending the resource access request message is a trusted client, thereby preventing session theft and improving the security of business data.
Owner:BEIJING FEISHU TECH CO LTD

Data sharing system based on P2P technology

The application discloses a data sharing system based on P2P technology and relates to the technical field of data sharing.The client module acquires the data pre-shared by a user and shares the data into the rest trusted client modules.The device scoring unit scores the trusted client modules.The sharing analysis unit periodically analyzes the data capacity and click time of all the shared data and calculates the sharing capacity evaluation quantity in combination with the device score.The sharing management unit intercepts a plurality of trusted client modules according to the size of the sharing capacity evaluation quantity, obtains a sharing management table, and then selects the sharing client modules from the sharing management table when a certain client module pre-shares data, so that the sharing client modules replace the relay service unit to perform the sharing operation of the data.Through the method, the load pressure of the server on the shared data can be greatly reduced, and the sharing resources of the trusted client modules can be reasonably utilized as much as possible.
Owner:ZHONGSHUI SANLI DATA TECH CO LTD

Authorization login method and device, computer device, readable storage medium and program product

The application relates to an authorized login method and device, computer equipment, a computer readable storage medium and a computer program product. The method comprises the following steps: in response to an access request of an authorized page sent by a mobile terminal, feeding back the authorized page to the mobile terminal; the access request is sent by the mobile terminal in response to a graphic code displayed by a zero-trust client; the graphic code is generated based on parameter information in a management and control server; the parameter information at least contains an access address and a user identifier of the authorized page, and the authorized page is used for triggering a login authorization request; receiving a login authorization request sent by the mobile terminal, the login authorization request carrying an authorization code provided by a third-party platform and the user identifier; obtaining identity information corresponding to the user identifier from the third-party platform based on the authorization code, and completing the authorized login processing. The method can realize offline login authorization of the zero-trust client.
Owner:HANGZHOU YIGE CLOUD TECH CO LTD

A method of single package authentication and related apparatus

Embodiments of the present application provide a single package authentication method and related device, which are used to improve the convenience of obtaining a zero trust client and an SPA knocking key. The method of the embodiments of the present application comprises: receiving an access address of a zero trust server input by a user through a browser; displaying a download installation page of the zero trust client to the user according to a pointing address of the access address of the zero trust server and download information of the zero trust client; if the user installs the zero trust client, receiving a knocking key obtaining request sent by the zero trust client, wherein the knocking key obtaining request carries a knocking key identifier encrypted by an irreversible algorithm; verifying the knocking key obtaining request; if the verification of the knocking key obtaining request is passed, forwarding the knocking key obtaining request to the zero trust server according to an IP address of the access address of the zero trust server, so that the zero trust server calls a message gateway to send the knocking key to the zero trust client.
Owner:SHENZHEN SHENXIN INFORMATION SECURITY CO LTD