Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

40 results about "Trusted Computing" patented technology

Trusted Computing (TC) is a technology developed and promoted by the Trusted Computing Group. The term is taken from the field of trusted systems and has a specialized meaning. With Trusted Computing, the computer will consistently behave in expected ways, and those behaviors will be enforced by computer hardware and software. Enforcing this behavior is achieved by loading the hardware with a unique encryption key inaccessible to the rest of the system.

Railway signal system based on trusted computing security computing protection technology

PendingCN122113178AAutomatic systemsUser identity/authority verificationTelecommunications linkTrusted Computing
The application discloses a kind of railway signal system security computing protection technology and system based on trusted computing.The application takes hardware trusted module as trust root, constructs the end-to-end trusted verification chain covering operation and maintenance terminal, communication link and destination device;Through the trusted management platform of center, the trust measurement and white list management of operation and maintenance tool are realized;Deeply integrate railway "window time" and standard operation process, construct device dynamic trusted benchmark model, and generate operation and maintenance personnel behavior trusted model based on historical behavior data;Deploy lightweight trusted agent to monitor operation and maintenance behavior in real time, and implement hierarchical response and authority control to behaviors deviating from the two models.The application realizes dynamic trusted protection in the whole operation and maintenance process, effectively improves the active defense capability against internal and external threats, balances safety strength and operation and maintenance efficiency, and provides business-aware security protection for railway signal system and key infrastructure.
Owner:CHINA STATE RAILWAY GRP CO LTD +1

A power industrial control security protection system and method based on microkernel active defense

PendingCN122179216ASecuring communicationScheduling (computing)Trusted computing base
The application discloses a power industrial control safety protection system and method based on a microkernel active defense, wherein the system takes a microkernel isolation base as a minimum trusted computing base, allocates revocable communication endpoints and controlled mapping permissions to each protection domain, and provides base support for the isolation domain boundary and permission recovery in the active defense; in the method, the system is uniformly formatted by an input module to process field data and service requests and generate a request identifier, a request distribution service distributes the same request to an odd number of online executors for parallel processing, a single decision output available externally is generated, an executor scheduling service selects a candidate executor from a candidate protection domain pool and reconstructs an online user mode service cluster according to a feedback index by adopting a periodic rotation and event triggering strategy, and if the request distribution service, the consistency arbitration service or the executor scheduling service fails, a minimum bottom-up cleaning is performed by an active defense kernel state support module and a reestablishable state is entered.
Owner:NARI INFORMATION & COMM TECH

Router online upgrading system based on credibility measurement

The application provides a router online upgrading system based on credibility measurement, which is composed of a network management device and a plurality of routers, the network management device is used for providing a required credible software package and remote issuing instruction of the router, and is internally provided with a credible module; each router comprises a main control board and a plurality of single boards, and is provided with an independent credible module and a storage device, the main control board is provided with a device software management module, downloads the credible software package and performs software package verification; the software upgrading instruction is issued to each single board, and upgrading results of the single boards are collected and reported; each single board is provided with a single board software management module, and credible software updating and activation of the single board are realized; the credible module is used for credible calculation and verification; and the storage device is divided into two partitions, a main area in which current software runs and a standby area. The application guarantees high safety and high reliability requirements of online upgrading of the whole network router, and is suitable for evolution and maintenance demand scene of an endogenous security communication network.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

Managing namespace mapping, trusted computing group ranges, and encryptions in a memory sub-system

PendingUS20260203229A1Computer hardwareTrusted Computing
A system includes a memory device and a processing device, operatively coupled with the memory device, to perform operations including: receiving a request to modify one or more regions of the memory device; identifying one or more mapping structures associated with each region of the one or more regions of the memory device; determining that a counter satisfies a threshold criterion, wherein the counter indicates a number of memory access commands at the one or more regions; creating a copy of each mapping structure associated with each region; and modifying the copy of each mapping structure according to the request to modify the one or more regions of the memory device.
Owner:MICRON TECHNOLOGY INC

A method and system for verifying the trusted state of a virtual machine based on TIPU

PendingCN122365514AMemory addressTerm memory
This invention relates to the intersection of cloud computing security, trusted computing, and hardware acceleration technologies, and discloses a virtual machine trusted state verification method and system based on TIPU. The method includes: configuring a measurement task on the host side of the TIPU, the measurement task containing the memory address information of the target virtual machine and its corresponding expected hash value; the TIPU directly reading the memory data of the target virtual machine via DMA based on the memory address information to generate an actual hash value; the TIPU comparing the actual hash value with the expected hash value to determine whether the target virtual machine is in a trusted state; when the virtual machine is determined to be in an untrusted state, the TIPU calls a built-in root of trust to sign the verification result and generate a remote proof report. This invention obtains the mapping table from the client's physical address to the host's physical address through the virtualization platform interface via a host agent and pre-configures it to the TIPU. The TIPU only accesses the target virtual machine's memory, achieving virtual machine context awareness and effectively avoiding cross-virtual machine information leakage.
Owner:TIANFU JIANGXI LAB

MULTIPLE PHYSICAL REQUIREMENT INTERFACES FOR SAFETY PROCESSORS

A procedure that includes the following: Communicating a first tenant from a plurality of tenants with a security processor (160) of a computer platform (100) via a first physical request interface (822) of the security processor (160) to acquire ownership of a first instruction execution machine (826) of the security processor (160) connected to the first physical request interface (822); Communicating a second tenant from the plurality of tenants with the security processor (160) via a second physical request interface (824) of the security processor (160) to acquire ownership of a second instruction execution machine (828) of the security processor (160) connected to the second physical request interface (824); Receiving with the security processor (160) a first request (808) from the first tenant in the first physical request interface (822); Receiving with the security processor (160) a second request (816) from the second tenant in the second physical request interface (824); and Processing the first request (808) with the first instruction execution engine (826) and processing the second request (816) with the second instruction execution engine (826) to perform appropriate trusted computational operations.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Graphics processor, computer system, resource allocation method and related apparatus

Embodiments of the present application provide a graphics processor, a computer system, a resource allocation method and related devices. The graphics processor comprises: a trusted computing block; and a security management module configured to, when determining that a current processing computing task is a confidential computing task, determine a matching resource usage according to a task requirement of the confidential computing task, at least re-allocate a corresponding allocated trusted virtual shared memory of the trusted computing block to obtain an adjusted trusted virtual shared memory, and determine a corresponding mapped physical shared memory, configure the determined physical shared memory as a security state, so that the physical shared memory in the security state is the adjusted trusted physical shared memory for processing the confidential computing task, and virtual shared memory that is not re-allocated as the trusted virtual shared memory is non-trusted virtual shared memory for processing a non-confidential computing task. The technical solution provided by the embodiments of the present application can improve the flexibility of resource allocation.
Owner:HYGON INFORMATION TECH CO LTD

A ciphertext conversion method and system for an internet of things scenario

PendingCN122457296AKey (cryptography)Ciphertext
The application belongs to the technical field of cryptography and data security, and discloses a ciphertext conversion method and system for an Internet of Things scene, which comprises the following steps: a key management end is initialized to generate series parameters; a client encrypts original plaintext data by using a homomorphically friendly symmetric encryption algorithm; a server constructs a homomorphic key stream; the server converts symmetric ciphertext into homomorphic ciphertext; and the server performs subsequent homomorphic calculation. According to the application, direct calculation of encrypted data can be realized without plaintext decryption of data on the server side, so that the risk of data leakage is reduced; meanwhile, the introduction of symmetric encryption reduces the communication overhead of the client, improves the overall efficiency of the system, and is suitable for a multi-party collaborative trusted calculation scene in the Internet of Things scene.
Owner:ANHUI ZHIJI TECHNOLOGY CO LTD

An e-commerce product spot check evidence storage system and method thereof

PendingCN122390754ATrusted ComputingE-commerce
The application discloses an e-commerce product spot-check storage evidence system and method, and relates to the technical field of e-commerce product quality supervision and credible calculation, and comprises the following steps: based on quantum random numbers, unpredictably sampling instructions are dynamically generated on the spot, and physical sampling operations are performed according to the instructions, and first process data containing instruction generation and execution processes are synchronously collected; the sampled samples are placed in intelligent storage containers embedded with environment and state sensors, second process data are continuously collected through the containers and their associated fog calculation node networks during the whole process of sample circulation to detection institutions, and real-time hash sequences are generated at the network edges; through hardware quantum random number injection sampling links, the possibility of artificially manipulating samples is eliminated from the source, laying the foundation for the fairness of the whole process.

A multi-modal anti-counterfeiting verification method and terminal based on microstructure cross-spectrum scattering stability and trusted computing

PendingCN122336449ANormalized mutual informationData stream
This invention discloses a multimodal anti-counterfeiting verification method and terminal based on microstructure transspectral scattering stability and reliable computation. The method includes: establishing a physical bus access mechanism for direct sensor access through a secure execution environment; extracting dark current fixed-mode noise for hardware fingerprint verification; acquiring visible light images and lidar point clouds and performing spatial mapping and alignment; extracting the visible light texture gradient field and infrared reflectivity distribution field, and calculating local normalized mutual information as a transspectral scattering invariant; inferring the main light source direction based on the point cloud surface normal and a lightweight feature extraction network, and calculating the macroscopic illumination residual; combining the above hardware fingerprint, transspectral microscopic and macroscopic illumination features, and using an adaptive compensation function to generate a comprehensive judgment result. This invention solves the problem of difficulty in defending against low-level data stream hijacking and generative forged images, significantly improving the physical interpretability and reliability of anti-counterfeiting verification.
Owner:深圳市元明科技股份有限公司

A trusted computing method and system based on double general-purpose computers

PendingCN122339800APERQGeneral purpose computer
This invention belongs to the field of trusted computing and network security technology, specifically a trusted computing method and system based on a dual general-purpose computer. The host system comprises a trusted environment (Enclave) and an untrusted environment (Normal World). The Enclave implements evidence verification, trusted state detection, and control policy selection. The Normal World is responsible for network communication, message encapsulation, and calling the Enclave, enabling secure input and output of data from the slave to the host's TEE environment. The slave includes a measurement agent (Slave Agent) that collects data from kernel modules, executable files, and IMA lists, and submits the collected data to the host. After the host issues a control policy, the Slave Agent receives and executes control operations. This invention achieves dynamic measurement and proactive control, possessing excellent security, portability, low latency, and low power consumption characteristics.
Owner:TAIYUAN UNIVERSITY OF TECHNOLOGY

C4i computing power network trusted access and computing method, device and computer equipment

The application belongs to the field of computing power network and information security, and relates to a C4I computing power network trusted access and computing method, device and computer equipment.The method comprises the following steps: fusing a C4I command link and a trusted computing power network, constructing a task scene driven hierarchical access and collaborative scheduling system, and outputting a task priority quantitative value; using a trusted execution environment, a national secret algorithm and a quantum key distribution full-stack trusted mode to construct a hardware level security base; constructing a dynamic trust evaluation model, calculating a real-time trust value and realizing adaptive iteration of a security strategy; realizing safe and elastic scheduling of computing power resources; using a Double DQN reinforcement learning algorithm for global collaborative optimization, dynamically adjusting a security strategy, a scheduling strategy and an elastic scheduling strategy; according to the strategy execution effect, constructing a multi-scene quantitative adaptation model to realize adaptation of different infrastructure scenes and cross-scene collaboration. The application realizes trusted access and collaborative computing of a high-security, high-real-time and high-collaborative computing power network.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

A script program trust measurement method and system for an interpreted language

The application provides a script program credibility measurement method and system for an interpretive language, and is used in the technical field of network security. The method comprises the following steps: scanning and traversing script program files in a credibility measurement terminal to obtain a list of expected measurement values; in the process of normal operation of the credibility measurement terminal, for two execution modes of command line parameter execution and runtime dynamic loading, the dynamic hook technology is used to intercept before the execution of the script program, the content of the script program is obtained, and the current measurement value is calculated; the current measurement value is compared with the expected measurement value, and the execution of the script program is blocked or allowed according to the comparison result, so that the credibility measurement of the script program is realized without modifying system files and compiler program files. The application can solve the problem that malicious script programs are difficult to be detected and intercepted, and improve the security of the trusted computing environment.
Owner:CHINESE PEOPLES LIBERATION ARMY UNIT 96901

Method and device for measuring credibility of display data, electronic device and program product

PendingCN122333552AComputer hardwareGraphics
This invention discloses a trusted measurement method, apparatus, electronic device, and program product for GPU memory data, relating to the fields of artificial intelligence system security and trusted computing technology. The trusted measurement method includes: determining the data object to be measured and obtaining the target measurement strategy and target baseline measurement value corresponding to the data object from a root of trust; generating a measurement instruction based on the target measurement strategy and encrypting the measurement instruction to obtain an encrypted measurement instruction; sending the encrypted measurement instruction to the measurement engine in the graphics processor through a secure measurement channel; receiving the encrypted hash value sent by the measurement engine through a trusted measurement proxy, decrypting the encrypted hash value, and comparing the decrypted hash value with the target baseline measurement value to obtain a trusted measurement result. This invention solves the technical problem in related technologies where real-time trusted measurement of data blocks in specific areas of GPU memory is impossible, reducing data security.
Owner:BEIJING CREDIBLE HUATAI TECHNICAL SERVICE CO LTD +1

An industrial-grade trusted business orchestration method and system based on multi-role separation

PendingCN122363661ATrusted ComputingOrchestration (computing)
The application discloses an industrial-grade trusted business arrangement method and system based on multi-duty separation, and belongs to the technical field of industrial automation, trusted computing and workflow arrangement. Business data and configuration parameters are respectively written into a configuration layer, a running layer and a definition layer according to duties; task requests are divided into deterministic tasks or non-deterministic tasks according to task metadata or static analysis, the deterministic tasks are routed to an execution instance layer to load a solidified code unit and are protected to be executed, the non-deterministic tasks are routed to an arrangement generation layer to generate and execute a dynamic plan in real time after light verification; and the execution records of the two types are uniformly written into the running layer to form a complete audit trace chain covering input, state and result.

A method for cross-domain data security interaction protection integrating trusted computing

PendingCN122093131AGuaranteed not to leakRealize all-round protectionMultiple keys/algorithms usageUser identity/authority verificationSecure communicationTrusted Computing
This invention discloses a cross-domain data security interaction protection method integrating trusted computing, belonging to the field of data security technology. The method includes: S1, each node participating in cross-domain data interaction deploys a trusted execution environment (TEA). When the initiating node requests data interaction from the target node, the TEA of the initiating node generates an authentication request. After receiving the authentication request, the target node verifies its validity through its TEA; S2, a secure communication link is constructed through the TEA. For transmitted data, a hybrid encryption strategy is used to encrypt it in the TEA before data interaction; S3, during data usage, data access and operation behaviors are monitored in real time, and an audit log system is established. The audit logs are analyzed periodically to assess the security of cross-domain data interaction. The cross-domain data security interaction protection method integrating trusted computing provided by this invention can better meet the needs of cross-domain data security interaction.
Owner:SHANGHAI SHIYUE COMPUTER TECH CO LTD

An evolvable game-based optimization trusted cloud level calculation system and method

ActiveCN121644230Bretain stabilityBe dynamically adaptablePairwise comparison matrixAlgorithm
The application relates to the technical field of computer system evaluation, and particularly discloses an evolvable and reliable cloud level calculation system and method based on game optimization; the method comprises the following steps: in the first stage, a pair comparison matrix is established based on the theory of trusted computing dependency tree and the analytic hierarchy process to generate a static weight vector; in the second stage, multi-source threat data is collected through an AI model, a double comparison matrix is constructed through double-dimension labeling classification, and a dynamic weight vector is output; through game theory, an antagonistic pair of core security mechanisms is identified, an antagonistic gradient and the dynamic weight vector are calculated, a weight convergence interval and a level promotion upper bound are predicted, and an optimal weight evolution path is generated; the system is used for realizing an evolvable and reliable cloud level calculation method based on game optimization; and the application is favorable for improving the adaptability and predictability of cloud security evaluation and providing a decision basis for cloud service security optimization.
Owner:WUHAN TRUSTED CLOUD TECH CO LTD

A trustzone-based trusted dual architecture implementation method

PendingCN122310540AProcess memoryAttack
This invention discloses a trusted dual-system architecture implementation method based on Trustzone, relating to the fields of information security and trusted computing technology. This architecture deploys a computing subsystem and a protection agent in the REE (Reliable Execution Environment), and a simplified protection system in the TEE (Trusted Execution Environment), achieving secure separation of the two execution environments through hardware isolation mechanisms. During application startup and runtime, the protection agent performs static and dynamic measurements on target files and process memory, and sends the measurement results to the TEE for integrity determination via security monitoring calls. The determination module in the TEE generates determination results based on a pre-stored trusted benchmark library and feeds them back to the protection agent, thereby controlling application execution by allowing, suspending, or terminating it. Simultaneously, the kernel monitor in the TEE periodically verifies the integrity of the REE kernel and the protection agent through a secure timer to prevent high-privilege attacks from bypassing the protection mechanism. This invention achieves decoupling of computing and protection functions without increasing hardware costs, exhibiting good security and versatility.
Owner:BEIJING UNIV OF TECH

System security starting method and intelligent computing all-in-one machine system

PendingCN122451921AOperational systemTrusted Computing
The application discloses a system security starting method and a wisdom calculation integrated machine system, relates to the technical field of trusted computing and data security, and forms a starting trust chain from an undefined state, a trust root establishment state, a firmware trusted state, a system trusted state, a trusted execution state and a component trusted state to a space identity state through six stages of hardware root of trust initialization, firmware trustworthiness measurement and verification, operating system trusted loading, TEE trusted execution environment construction, space component trustworthiness measurement and trusted data space identity anchoring based on 24 PCR registers of TPM. The application adopts six-stage chain progressive security starting, extends traditional four-stage starting measurement (BIOS-Boot-Kernel-Driver) to two brand-new stages of TEE trusted execution environment construction and trusted data space identity anchoring, fully utilizes 24 PCR registers of TPM, realizes one-time through of a complete trust chain from hardware power-on to trusted data space identity binding, and eliminates the trust gap after starting completion.
Owner:STATE GRID INFO TELECOM GREAT POWER SCI & TECH

A terminal access identity authentication method and system based on trusted computing

PendingCN122179188AUser identity/authority verificationKey exchangeAttack
This invention relates to the field of trusted computing technology and discloses a terminal access authentication method and system based on trusted computing. The method includes: performing a step-by-step extension measurement on the hardware root of trust to obtain an initial trusted chain construction result; performing time-series dependency analysis on the construction result to obtain a runtime timing benchmark; using the time interval between the client key exchange parameters and the micro-timestamp of the digital certificate in the protocol handshake message as a behavioral pattern signal to evaluate the perturbation factorization of the system event sequence to obtain an endogenous temporal perturbation factor; performing an overlap test on the behavioral pattern signal and the endogenous temporal perturbation factor to obtain an identity state linkage indicator; determining the dynamic trust risk level of identity authentication based on the identity state linkage indicator, and making an authentication decision on the identity authentication process based on the dynamic trust risk level to obtain an identity authentication result. This invention can improve the accuracy of identity authentication decisions and the efficiency of adaptive response in complex attack scenarios.
Owner:SHANDONG ZHENGXIN BIG DATA TECH CO LTD

Signature verification method, key acquisition method, and related device

PendingCN122457263AAlgorithmTrusted Computing
Embodiments of the present application provide a signature verification method, a key acquisition method and related equipment, which can be used in the field of trusted computing. The method comprises: a first node acquiring a first aggregated signature, the first aggregated signature being obtained by aggregating n first signatures, the n first signatures comprising a first signature of each of n second nodes, the first signature of each second node being obtained by signing with a private key of each second node, and n being an integer greater than 1; and verifying the first aggregated signature based on a public key of each of the n second nodes. If the first aggregated signature is verified successfully, it means that the n first signatures are all verified successfully, and if the first aggregated signature is verified unsuccessfully, it means that the n first signatures are all verified unsuccessfully. The first node can complete the verification of the signatures of the n second nodes at one time, and an efficient verification scheme is provided.
Owner:HUAWEI TECH CO LTD

A blockchain-enhanced trusted system

ActiveCN122048361BTrusted ComputingSmart contract
The application discloses a kind of based on blockchain enhanced trusted system, which includes bottom hardware layer, middleware layer and blockchain layer.Bottom hardware layer executes trusted start and measurement by the trusted intelligent interconnection board card of integrated trusted cryptographic module, generates and signs measurement voucher;The middleware layer receives, verifies and assembles voucher into blockchain transaction;Blockchain layer uses alliance chain network, realizes the distributed management of device identity, the non-tamperable storage of measurement record and the dynamic execution of verification strategy by three smart contracts of registration contract, verification contract and strategy contract.The application effectively solves the problems in traditional trusted computing, such as the measurement result being easily tampered with, the dependence on centralized verification service, and the difficulty in policy synchronization, and realizes high-trusted, auditable and decentralized automated remote attestation.
Owner:TIANFU JIANGXI LAB

A method and system for building a virtual machine monitor secure execution environment

The application discloses a virtual machine monitor security execution environment construction method and system. The method is as follows: removing the host OS and virtual machine monitor runtime code from the trusted computing base TCB, and constructing a simple security monitor on the CPU privilege level of the host; removing the privilege permission of the host OS to obtain a reduced-privilege host OS; using the simple security monitor to instantiate a Bid-Enclave instance for each virtual machine on the host to carry the virtual machine monitor runtime; and executing a bidirectional isolation strategy between the reduced-privilege host OS and the instance and between different instances; dividing I / O processing into a control plane and a data plane; using the reduced-privilege host OS to process the control plane and auditing by the simple security monitor; and under the supervision of the simple security monitor, establishing a protected direct memory access channel between the instance and a PCIe SR-IOV virtual function or an analog device queue to access the data plane.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

Intelligent agent management and control method and device based on trusted computing technology and intelligent agent terminal

PendingCN122346843ATrusted ComputingEmbedded system
The application discloses an agent management and control method and device based on a trusted computing technology and an agent terminal. The method comprises the following steps: receiving a first operation request of a first agent, wherein the operation request is used for requesting to perform a first key sensitive operation, and the first agent runs in a computing component of the agent terminal; and performing the first key sensitive operation in a first execution running environment of a protection component of the agent terminal, wherein the protection component is based on a hardware trusted root and is used for providing an isolated execution running environment for key sensitive operations of the agent, a secure isolation mechanism is adopted between the computing component and the protection component, and the computing component and the protection component interact through a special access channel. The application solves the technical problem that the agent terminal has a security risk in the related art.
Owner:BEIJING CREDIBLE HUATAI TECHNICAL SERVICE CO LTD +1

A data sovereignty sharing method and system based on a trusted gateway for a zero-carbon park

PendingCN122293424ABusiness enterpriseTrusted Computing
This invention discloses a data sovereignty sharing method and system based on a trusted gateway for zero-carbon industrial parks. Belonging to the interdisciplinary fields of data security and green computing, it aims to address the pain points of data trust conflicts between enterprises and parks in zero-carbon industrial parks, and the inability of existing technologies to simultaneously address enterprise data sovereignty protection and the park's carbon accounting needs. This invention constructs a four-in-one collaborative architecture comprising an enterprise-side data sovereignty connector, a park-side trusted computing gateway, a policy and contract center, and an audit and evidence storage system. Through data hierarchical management and policy binding, digital carbon contract control, trusted aggregation computing within the TEE, end-to-end full-hash evidence storage, and sovereignty traceability, it achieves "usable but invisible" carbon data. This invention can meet the park's carbon accounting and dual-carbon management needs without disclosing the enterprise's original sensitive data, effectively protecting enterprise data sovereignty, and is applicable to various zero-carbon industrial park construction scenarios.
Owner:NORTHEASTERN UNIV CHINA

Method and system for protecting instructions of a large model based on four-layer cooperative closed loop

The application discloses a kind of big model instruction security protection method, system and storage medium based on four-layer cooperative closed-loop protection mechanism, belong to artificial intelligence security and trusted computing field.The application is deployed non-intrusive independent protection layer between user input layer and big model inference execution layer, through instruction weight dynamic control, context integrity check, multi-modal public power subject credible verification, four big links cooperative linkage of security rule priority rigid locking, combined with shared semantic label library, dynamic threshold value synchronization mechanism and cross-layer abnormal feedback channel constructs whole-link closed-loop protection system.The application realizes high semantic weight content attenuation by instruction weight system, resists split bypass attack by context governance, guarantees public power identity credible by multi-modal double verification, realizes permission control and algorithm transparent by rule priority rigid locking, built-in global multi-jurisdiction compliance rule library, adapt to global regulatory requirements and have anti-black-box auditable characteristics.The application does not need to modify model bottom code, supports hardware-level isolation and national encryption algorithm acceleration, can be widely applied to government, finance, military industry and other high-end security scene, provides non-intrusive, global, high-security compliance protection solution for big model.
Owner:高鹏

Key management method and device, computer readable medium and electronic device

ActiveCN115203710BComputer networkTrusted Computing
The application belongs to the technical field of computers, and particularly relates to a key management method, a key management device, a computer readable medium and an electronic device. The method comprises the following steps: performing decryption processing on a sealed data file in a secure area of a memory to obtain user-hosted key data, the key data comprising a key identifier and a user key associated with the key identifier, and the secure area being a trusted area created in the memory based on trusted computing; in response to a received key management request, traversing the key data to determine whether there is a target key identifier matching the key management request; and generating response data for the key management request according to the traversal result of the key data, and returning the response data to the sender of the key management request. The method can improve the reliability of key management and reduce the cost of key management.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

A trusted boot method and system based on a trusted dual architecture

The application discloses a trusted boot method and system based on a trusted dual architecture, relates to the technical field of industrial control safety, and comprises the following steps: obtaining a hardware layer, an operating system layer and an application layer of a PLC system, encapsulating an image file, designing a key of the image file, and burning the key and the image file into a storage position corresponding to the PLC system; after the PLC system is powered on, an operating system kernel calls an on-chip Boot Loader and a reference value in ROM data in a trusted CPU, integrity verification is sequentially performed on each system boot component, integrity verification of an application program is performed by the system boot component, and based on the integrity verification, it is judged whether the trusted boot of the PLC system is completed or an alarm prompt is sent. Through the trusted dual architecture CPU, the application overcomes the defect that a trusted computing module in a previous architecture is subordinate to a traditional computing module, improves the trustworthiness and security of core components in a starting stage, and enhances the robustness and trusted starting performance of the system.
Owner:NANJING ZHILIHUI INFORMATION TECHNOLOGY CO LTD

Financing lease verification method, device and equipment based on off-chain trusted computing

ActiveCN115114642BTrusted ComputingReliability engineering
The embodiment of the specification discloses a financing lease verification method based on off-chain trusted computing, a device and equipment, which is applied to a privacy computing node arranged in a block chain. The scheme comprises the following steps: receiving encrypted privacy data sent by a financing lease platform, the encrypted privacy data being generated by a financing party after encrypting private operation data thereof; performing privacy calculation on the encrypted privacy data by running a verification contract published in the block chain to generate a corresponding verification result; returning the verification result to the financing lease platform, so that the financing lease platform interacts with an investment party according to the verification result to decide whether the investment party invests in and purchases specified resources and leases the specified resources to the financing party for operation; and in the case that the verification result indicates that the verification is passed, the encrypted privacy data or the private operation data is uploaded to the block chain to enable an authorized party to access.
Owner:ANT BLOCKCHAIN TECHNOLOGY (SHANGHAI) CO LTD