Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

318 results about "Trusted Computing" patented technology

Trusted Computing (TC) is a technology developed and promoted by the Trusted Computing Group. The term is taken from the field of trusted systems and has a specialized meaning. With Trusted Computing, the computer will consistently behave in expected ways, and those behaviors will be enforced by computer hardware and software. Enforcing this behavior is achieved by loading the hardware with a unique encryption key inaccessible to the rest of the system.

Multi-source heterogeneous data intelligent fusion analysis system

The invention discloses an intelligent fusion analysis system for multi-source heterogeneous data, and the system comprises a dynamic data collection module which is used for carrying out the data collection, and carrying out the processing of a collected mixed data flow; the semantic alignment module is used for constructing a domain ontology knowledge graph according to a preset scene target and carrying out semantic alignment and coordinate alignment on the collected data; the self-adaptive fusion engine module is used for fusing the collected multi-source heterogeneous data; the trusted computing module integrates a secure multi-party computing protocol and a homomorphic encryption algorithm to realize that data is available and invisible; and the intelligent decision-making module constructs a state action reward model based on reinforcement learning according to a preset scene target, and performs analysis and decision-making by using historical data and data acquired in real time. According to the invention, the capability and effect of data processing and decision support are improved.
Owner:THE 28TH RES INST OF CHINA ELECTRONICS TECH GROUP CORP

Method and system for constructing TPCM trusted root based on multi-core BMC

The invention belongs to the technical field of computer trusted computing, and particularly relates to a method and system for constructing a TPCM trusted root based on a multi-core BMC, and the method comprises the steps: selecting the multi-core BMC, configuring one core as a trusted core, and achieving the physical and logic isolation with other cores; tPCM related codes are integrated in the trusted core, and a TCM module is combined to provide a running environment for the TPCM; when the system is started, the TPCM performs measurement check on the BMC code and the BIOS code, and if the BMC code and the BIOS code are abnormal, a security policy is started In the system operation process, the TPCM monitors hardware, firmware and software of a calculation part in real time, and discovers abnormal behaviors to block and give an alarm; and meanwhile, the management interface is connected with a trusted management center, so that remote configuration and monitoring are realized. A multi-core BMC is used as a protection component, a server host side is used as a calculation component, and a trust chain model of a star-shaped trusted topological structure is constructed. According to the method, the TPCM trusted root is constructed by using the existing resources of the multi-core BMC, so that the hardware cost is reduced, the real-time performance of trusted measurement and the monitoring comprehensiveness are improved, and the running safety and credibility of the server are improved.
Owner:四川华鲲振宇智能科技有限责任公司

Block chain technology-based review data information security tamper-proofing method

The invention discloses a block chain technology-based review data information security tamper-proofing method, and relates to the technical field of information security, the tamper-proofing method comprises the following steps: a data encryption storage step, a data evidence storage step, a trusted computing step and a data verification step, when a computing request is received, the trusted computing step is executed, and the trusted computing step is executed; whether the identity of a requester conforms to the access control strategy is verified through the smart contract, after verification is passed, the smart contract generates a calculation task event, the oracle monitors and captures the event, then a calculation task is transmitted to the trusted execution environment, ciphertext data is obtained in the trusted execution environment and decrypted, and the calculation task is sent to the target server. The method has the advantages that the balance of data privacy protection and integrity verification is realized through a hierarchical architecture combining on-chain evidence storage and off-chain encrypted storage, sensitive review data is stored in an off-chain database in an encrypted form, the security of the review data is improved, the security of the review data is improved, and the security of the review data is improved. Only data fingerprints are recorded on the block chain, data privacy is protected, and data integrity can be verified through the block chain.
Owner:HEFEI FANKE NETWORK TECH CO LTD

Sandbox type trusted data space construction method and equipment based on trusted verification architecture

PendingCN121637484ADigital data protectionPlatform integrity maintainanceTrusted ComputingDeterministic finite automaton
The invention discloses a sandbox type trusted data space construction method and equipment based on a trusted verification architecture, belongs to the technical field of data security circulation and trusted computing, and aims to overcome the defects that a traditional sandbox behavior is unknowable and untrusted and a strategy is rigid. The method comprises the following steps of: starting a sandbox in a hardware trusted execution environment and generating a task unique context identifier; intercepting system call by a monitoring agent; generating a chained operation certificate containing preorder certificate hash; compiling an advanced security policy into a deterministic finite automaton executable policy set; and the auditing unit is used for generating a decision instruction in an illegal scale, storing the chain anchor point to the non-tampering system, forcibly executing decision and generating a Merkel tree evidence. The equipment correspondingly comprises a sandbox management module, a behavior monitoring module, a strategy compiling module, a verification judgment module and an auditing execution module. The full-flow transparent tracing of the operation in the sandbox is realized, the strategy dynamic adaptation is supported, and the problem that a traditional sandbox monitoring log is easy to counterfeit and difficult to verify is solved.
Owner:姚远

Server security authentication system based on block chain trusted computing

The invention relates to the field of network and information security, and discloses a server security authentication system based on block chain trusted computing. Comprising a block chain network, an intelligent contract module, an authentication service module, a verification node and a to-be-authenticated server. The intelligent contract module records a registration index, a certification public key, a policy version number, a baseline commitment value and a revocation state. The authentication service module generates a challenge parameter and a challenge value based on the block height and the block hash digest. The trusted agent module collects a measurement abstract and forms a certification packet, and the trusted root module derives a staging certification key in a protected environment and signs the certification packet. And the verification node reads the data on the chain to complete signature verification, challenge value re-calculation, window verification and compliance proof verification, and generates an authentication bill containing an effective height range for resource access judgment after passing the verification.
Owner:EASY POINT GEEK (BEIJING) TECHNOLOGY CO LTD

PLC behavior measurement method, device and equipment based on trusted 3.0 and national cryptographic algorithms

The invention discloses a PLC behavior measurement method, device and equipment based on trusted 3.0 and national cryptographic algorithms, and relates to the field of safety control in an industrial control system.The method comprises the steps that a hardware trust root module installed on a PLC in advance is used for conducting trusted verification on the PLC during starting, and the module is constructed based on the trusted computing 3.0 standard; after verification succeeds, a behavior feature vector of the PLC operation state is obtained based on trusted computing 3.0, wherein the vector comprises at least one of an integrity verification parameter, a resource consumption parameter, an operation parameter and an associated parameter; generating behavior measurement data based on trusted computing 3.0, and measuring a vector through an Euclidean distance algorithm in combination with behavior baseline data; comparing the measurement result with a preset Euclidean distance threshold value, encrypting the measurement result by adopting a domestic key algorithm, and transmitting a comparison result to a security management platform; according to the method, trusted computing 3.0 (TC3.0) and the national cryptographic algorithm are combined, accurate behavior measurement is carried out on the operation state, and the equipment safety and the attack resistance can be enhanced.
Owner:NINGBO HOLLYSHI INFORMATION SECURITY RES INST CO LTD

Emergency rescue integrated data security protection method and system based on block chain

The invention discloses an emergency rescue integrated data security protection method based on a block chain, and belongs to the technical field of data security protection, and the method comprises the following steps: constructing an end-side cloud cooperative trusted computing architecture, and establishing a trust chain transmission mechanism from a terminal to an edge node through a physical trusted root; a dynamic multi-dimensional credibility measurement model is adopted, the static credibility, the behavior credibility and the collaborative credibility of the equipment are comprehensively evaluated, and the real-time credibility of the equipment is generated in combination with environmental factors; implementing credibility verification based on the behavior measurement index; cross-domain data sharing auditing is realized by using a block chain smart contract, and the full-life-cycle security of data is ensured through a fragmented storage strategy and a self-destruction key design. According to the method, the problems of insufficient security authentication, dynamic trust evaluation and data cross-domain sharing auditing of the multi-source heterogeneous equipment in emergency rescue are solved.
Owner:INST OF URBAN SAFETY & ENVIRONMENTAL SCI BEIJING ACAD OF SCI & TECH

Trusted startup design method of server

The invention discloses a trusted startup design method of a server, and belongs to the technical field of information security and trusted computing, after the server is powered up, a trusted root CPU core is started preferentially, a trusted startup program is operated, and a security environment is initialized; integrity measurement and verification are conducted on the BIOS, and after verification is passed, other CPU cores are released, and the BIOS is operated; the service CPU core loads a bootstrap program GRUB and submits the bootstrap program GRUB to the trusted root CPU core for verification; then loading an operating system kernel image and executing hash measurement, and calculating a path entropy value in combination with control flow information in a kernel initialization stage; performing segmentation comparison on the memory image and the disk mirror image, and calculating a mapping consistency coefficient; if the verification is passed, continuing to start the operating system; according to the method, the tampered component in the system startup chain can be effectively prevented from being loaded and operated, and the startup safety and the overall credibility of the server are enhanced.
Owner:NANJING JIEAN INFORMATION TECH CO LTD

Supply chain data protection method fusing block chain and attribute-based proxy re-encryption

The invention discloses a supply chain data protection method fusing a block chain and attribute-based proxy re-encryption, and the method comprises the steps: building an industry-based attribute through credible initialization, and achieving the parameter distribution through a block chain smart contract; dynamic key management is adopted to generate an attribute binding key for each participant, and automatic revocation and update are supported; an access strategy is accessed through conditional proxy re-encryption, and it is ensured that data only decrypts a requester meeting service conditions; a hierarchical encryption storage mechanism is designed, key data are stored on a chain, and large-capacity production logs are efficiently processed outside the chain through IPFS; and meanwhile, a compliance penetration interface is provided for a supervision mechanism, and legal data access under an emergency event is supported. It is ensured that the parameter generation process meets the verifiability requirement of a trusted computing platform, compliance verification and security isolation of data access are achieved, and attribute-level dynamic authorization and cross-enterprise security sharing of supply chain data are ensured.
Owner:JIANGXI UNIV OF SCI & TECH

Industrial project cross-department collaborative approval and supervision system based on trusted computing

The invention provides an industrial project cross-department collaborative approval and supervision system based on trusted computing, and relates to the technical field of cross-department processing, and the system comprises an extraction module which is used for triggering an intelligent contract deployed on an alliance chain based on an on-chain evidence storage record, generating an approval event, and sending the approval event to a server; according to the data integrity, the process time sequence and the operation behavior characteristics in the approval process event, each behavior characteristic is quantified into a risk index corresponding to each dimension through a preset risk model, and a set of the risk indexes of each dimension forms a multi-dimensional vector; through on-chain credible evidence storage, multi-dimensional risk measurement, dynamic credit evaluation and closed-loop regulation and control, precision, credibility and dynamic optimization of industrial project cross-department collaborative approval and supervision are realized, approval efficiency and supervision efficiency are improved, and scientificity and safety of collaborative management and control are guaranteed.
Owner:FUZHOU PLANNING DESIGN & RES INST

Data management method and system for trusted data delivery platform

The invention discloses a data management method and system for a data credible delivery platform. Access is realized through symmetric encryption of source data, and credible right confirmation is realized by relying on identities of owners and users of alliance chain evidence storage, source data hash and authorization rules; adding a timestamp to the encrypted data stream verified by the certificate to form a traceability mark, and encrypting or desensitizing privacy data; the trusted computing is provided with three modes: a local mode executes an algorithm in an ownership party isolation environment and records a log on a chain, a third-party mode constructs a trusted sandbox based on TEE, executes computing and links log hash after remote certification, and an algorithm privacy mode realizes cooperative computing through a Shamir secret sharing splitting algorithm in combination with MPC, a confusion circuit and zero-knowledge certification; and the result delivery adopts public key encryption, a decryption key is issued after the receipt of the user is verified, and the result hash and the receipt are linked for evidence storage, so that the problems that the existing trusted platform cannot support the execution of various algorithms and is lack of effective supervision are solved.
Owner:GUIZHOU DIGITAL INNOVATION HLDG (GRP) CO LTD

Oil reservoir digital intelligence twin modeling system and method based on trusted computing

The invention discloses an oil reservoir digital intelligence twin modeling system based on trusted computing, which comprises a physical entity layer used for collecting oil reservoir field data in real time and a data processing layer responsible for processing the collected data, the intelligent twinborn layer is used for constructing a digital twinborn model of the oil reservoir and performing model prediction and optimization; the digital intelligent application layer is used for realizing data visualization; the trusted computing layer is used for realizing the safety of the whole data process; the trusted computing layer is connected with the physical entity layer, the data processing layer, the intelligent twinborn layer and the digital intelligent application layer. According to the system, the security and traceability of data can be enhanced, the security and integrity of the data in the acquisition, transmission and processing processes can be ensured, and more efficient real-time monitoring and decision support can be realized.
Owner:SHAANXI YANCHANG PETROLEUM GRP

Transaction processing method and device oriented to credential environment, equipment and storage medium

The invention relates to a transaction processing method and device oriented to a credential environment, equipment and a storage medium. The method comprises the steps of receiving a target transaction to be processed, splitting the target transaction into at least two atomic transactions according to a transaction processing flow of the target transaction, determining a transaction execution sequence between the atomic transactions, and according to the transaction execution sequence, performing transaction processing on the atomic transactions according to the transaction execution sequence, in the process of sequentially processing the atomic transactions, if it is detected that any atomic transaction fails to be processed, rollback processing is conducted on the target transaction according to the position of the failed atomic transaction in the transaction execution sequence and the standard compensation operation corresponding to the atomic transactions, and under the condition that the rollback processing succeeds, the target transaction is subjected to the target transaction processing according to the position of the failed atomic transaction in the transaction execution sequence and the standard compensation operation corresponding to the atomic transactions. And re-executing the operation of sequentially processing each atomic transaction according to the transaction execution sequence. By adopting the method, the transaction processing efficiency can be improved.
Owner:GUANGDONG ELECTRIC POWER COMM CO LTD

Safe starting system and method of baseboard management controller

The invention provides a safe starting system and method for a substrate management controller, and the system comprises a plurality of first storage modules which are used for storing the power-on starting firmware of the substrate management controller; the first logic switching module is provided with a plurality of first selection ends and two first connection ends, and the first storage modules are connected with different first selection ends; the credibility verification module is used for carrying out credibility verification on the firmware content input by the verification input end; the trusted computing module is used for carrying out trusted computing on firmware content input by the computing input end; the second logic switching module is provided with two second selection ends and two second connection ends; and the control module is used for selecting any first selection end of the first logic switching module to be valid, and selecting any second selection end of the second logic switching module to be valid or two second connection ends to be connected in a loopback manner. According to the application, the starting and running safety, reliability and stability of the baseboard management controller can be effectively improved.
Owner:HUNAN BOJIANG INFORMATION TECHNOLOGY CO LTD

Subscriber Identity Module (Sim) card feature-based Non-Fungible Token (NFT)

A Subscriber Identity Module (SIM) card feature-based Non-Fungible Token. SIM card features, such as communication features, software / hardware features, electrical features, SIM Card behavior features and / or the like are extracted from the SIM card of a user's mobile communication device and a SIM card feature-based NFT is generated and stored on a distributed trust computing network. The distributed trust computing network serves to verify the authenticity of the underlying SIM card features. The NFT is subsequently used as a means for authentication is resource exchange events and other events requiring user / mobile communication device verification.
Owner:BANK OF AMERICA CORP

Zero-trust architecture-based emergency rescue multi-source data fusion method and system

The invention discloses an emergency rescue multi-source data fusion method based on a zero-trust architecture, and belongs to the technical field of multi-source data fusion, and the method comprises the following steps: constructing an end-side cloud collaborative trusted computing environment; based on trusted computing environment dynamic trust evaluation, correcting a trust value through a sliding window algorithm according to response time, an abnormal index and a collaborative efficiency index which are acquired in real time; encrypting and transmitting multi-source data based on the real-time trust value; and multi-party data fusion is carried out under encryption and trust guarantee. According to the method, multi-source data security fusion of a zero-trust architecture can be realized in an emergency rescue scene, and meanwhile, the problems of trust splitting and high delay of a traditional method are avoided.
Owner:INST OF URBAN SAFETY & ENVIRONMENTAL SCI BEIJING ACAD OF SCI & TECH

End-side large model parameter protection method and system based on trusted execution environment

The invention provides an end-side large model parameter protection method and system based on a trusted execution environment, and the method comprises the steps: enabling a large model client application program to receive the input of a user, and transmitting the input of the user to a trusted application, namely, a large model security application; the REE OS kernel forwards the request of the user mode to the trusted application, proxy I / O and NPU of the trusted application and continuous memory allocation requests are achieved, and trusted application thread scheduling is achieved; the security monitor is used for forwarding a request of the REE OS kernel to the TEE OS kernel; the TEE OS kernel is responsible for carrying out security configuration related to the TrustZone with high privilege and realizing address space isolation between security applications; and the large model security application realizes pipeline recovery accelerated reasoning, dynamic memory capacity expansion and NPU device calling by an NPU driver to perform calculation acceleration. According to the method, the hardware acceleration capability of the reasoning task is guaranteed, meanwhile, the scale of a TEE trusted computing base (TCB) is controlled, and the overall safety and the performance expandability of the system are improved.
Owner:SHANGHAI JIAOTONG UNIV

Enabling large frames for secure virtual machines

The computer-implemented methods, computer program products, and computer systems include computer operations that include executing, in a trusted computing environment, a call from a host in an untrusted computing environment, where the call is to determine a status of a large page of memory for use by a secure guest, where the secure guest is managed by the host in the untrusted computing environment. The executing includes determining that all small pages comprising the large page and the large page meet pre-defined security requirements. The executing also includes, based on the determining, setting security properties of the large page and the small pages comprising the large page to enable translation for the large page for a given block of memory of the secure guest. The executing also includes storing in a computing element, a designation identifying the large page as belonging to the secure guest.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION +1

Large model security enhancement method and system based on trusted computing

The invention provides a large model security enhancement method and system based on trusted computing, and the method comprises the steps: controlling a module through a built-in trusted platform in a terminal device in a starting process of the terminal device; verifying the current software downloaded by the trusted platform control module, the input / output system, the boot loader, the operating system, the large model and the terminal equipment from the trusted management center based on the preset verification information, and determining whether the running state of the current software is abnormal or not based on the preset permission information in the running process of the terminal equipment; and performing a preset response operation when the running state of the current software is abnormal, and performing a data encryption and decryption operation and / or an identity authentication operation based on a true random number generated by the quantum random number generator and an encryption and decryption algorithm stored in the trusted cryptographic module, thereby running the large model in the trusted execution environment. By adopting the method, the security of deployment and operation of the large model can be improved, the security of encryption and decryption operation is enhanced, and the efficiency and fairness of an encryption and decryption algorithm are improved.
Owner:CEC CYBERSPACE GREAT WALL

Regional building group power transaction safety guarantee system

The invention relates to the technical field of electric power security, and discloses a regional building group electric power transaction security guarantee system, which comprises the following modules: a trusted computing environment authentication module, a transaction data encryption and commitment module, an under-chain privacy computing and verification module, and a computing process certification and settlement module. According to the method, the algorithm hash value recorded in the program registry contract is combined with the remote authentication mechanism of the trusted execution environment, so that the traceability and verifiability of the under-chain computing environment are constructed. The system digitally signs a report containing an algorithm code hash value by using a hardware built-in private key, and submits the report to an on-chain contract for comparison, and the mechanism ensures that any under-chain privacy computing task is executed in a specified algorithm environment which is approved by block chain consensus and is not tampered with codes, so that the privacy computing efficiency is improved. The security risk caused by the untrusted computing environment or the non-compliance of the algorithm logic is completely eradicated from the source, and the basic guarantee is provided for the correctness of the subsequent computing result.
Owner:ZHEJIANG PROVINCE ELECTRIC POWER FUEL CORP +1

Vehicle-mounted domain controller verification protection method and system, electronic equipment and storage medium

The invention discloses a vehicle-mounted domain controller verification protection method and system, electronic equipment and a storage medium, and relates to the field of vehicle machine safety control, and the method comprises the steps: electrifying an HSM, starting an HSM Boot process, and carrying out an initialization operation; checking and pulling up an HSM APP process and sending an HSM state to a control layer; the HOST is powered on, the HOST Boot process is started, a verification request is sent to the HSM APP through the control layer, and the integrity and legality of the HOST Boot and the HOST APP are verified; the control layer performs trust evaluation on the received HOST request and forwards the request to the HSM APP after the evaluation is passed, and the HSM APP feeds back a calling result and supports the HOST Boot to complete verification and pull up the HOST APP; and the control layer continuously monitors the operation state of the HOST, and performs dynamic access control on the request of calling the HSM APP interface by the HOST APP according to the real-time trust evaluation result. According to the method, by introducing a dynamic authorization and continuous verification mechanism, normal form conversion of the trusted computing system from static defense to dynamic verification is realized, and the safety of the vehicle-mounted domain controller is further improved.
Owner:CHINA FAW CO LTD +1

Traffic flow optimization model in trusted data space

The invention relates to the technical field of intelligent traffic and data trusted computing, and discloses a traffic flow optimization model based on a trusted data space. According to the model, multi-source traffic data including road monitoring equipment, Internet of Vehicles (V2X), unmanned aerial vehicle images and the like are utilized to construct a trusted data space, and data fusion and optimization calculation are realized. And the non-tampering property of the data is ensured through a block chain technology, and a federated learning algorithm is adopted to carry out data analysis to generate an optimal traffic flow scheduling scheme. The optimization strategy comprises intelligent signal lamp control, dynamic lane allocation and intelligent navigation adjustment so as to improve the road traffic efficiency, reduce traffic congestion and improve the intelligent level of traffic management. The method is suitable for intelligent urban traffic management, and can effectively improve the road operation efficiency and reduce the carbon emission.
Owner:SHANGHAI SECOND POLYTECHNIC UNIVERSITY

Cross-border accounting compliance processing system based on federated learning and trusted computing

The invention belongs to the technical field of financial data sharing, and particularly relates to a cross-border accounting compliance processing system based on federated learning and trusted computing, and the system comprises a federated learning module which is used for synchronously updating the learning models of all financial nodes through a federated average algorithm according to the locally trained model parameters of each financial node; the dynamic account book mapping module is used for acquiring exchange rate data of a country where each financial node is located in real time, and automatically adjusting currency amount in an account book through sliding window backtracking and recalculation; the trusted execution module is used for executing the cross-chain contract in the isolation container; the tax graph reasoning module is used for calculating association strength among nodes in a locally configured knowledge graph through an attention mechanism so as to generate probability distribution of a compliance path and identify an optimal tax processing scheme; and the report generation module is used for generating a report in a standard format according to the related data about the accounting criterion alignment and the related data about the exchange rate adjustment.
Owner:SHANGHAI GREAT WISDOM SHENJIU INFORMATION TECH CO LTD

Power distribution terminal key management method and system based on trusted computing

The invention provides a power distribution terminal key management method and system based on trusted computing, and relates to the field of power system management.The method comprises the following steps that key strength is determined according to risk indexes; encrypting the real-time data of the power distribution terminal by using the encryption key; transmitting to a key management center through a preset security access gateway; performing integrity verification on the encrypted real-time data, and associatively storing a verification result, a security risk index and a transmission timestamp to a block chain evidence storage node to form a tampering-free encryption key operation context record; and dynamically optimizing an encryption key updating strategy in combination with the historical change trend of the security risk index so as to realize closed-loop security management and control of the whole life cycle of the encryption key. According to the invention, the active immunity and the overall safety management and control level of the power distribution Internet of Things in a complex environment are significantly improved.
Owner:HEFEI ZHONGNENG POWER TECH

Secret transmission security management system for secret-related electronic files

The invention relates to the technical field of secret-related electronic file transmission and management, and discloses a secret-related electronic file secret transmission safety management system which comprises a safety management system. The security management system comprises a hardware security support layer, a distributed security storage layer, a file full life cycle security management layer, a user identity authentication and behavior auditing layer, a security auditing layer and an emergency response layer. The confidential electronic file secret transmission security management system integrates a trusted computing chip, security boot firmware, a physical unclonable function (PUF) and an optical isolation technology through a hardware security support layer, is different from a traditional system which only depends on software protection, constructs a trusted execution environment from a hardware bottom layer, guarantees the operation credibility by using the trusted computing chip, and improves the security of the confidential electronic file. The secure boot firmware blocks illegal program loading, the PUF endows the hardware with a unique uncounterfeited identity, and the optical isolation realizes physical level network isolation, so that threats such as hardware tampering and physical attacks are radically defended.
Owner:BEIJING AEROSPACE NETWORK TECHNOLOGY CO LTD

Cross-device rendering method, device and equipment for credential environment and storage medium

The invention relates to a credential environment-oriented cross-device rendering method and device, equipment and a storage medium. The method comprises the steps that after rendering requests sent by at least two terminal devices for the same rendering task in the credential environment are received, task processing resources are allocated for the rendering task according to a task description file of the rendering task and the resource idle condition of all computing nodes, and the task processing resources are allocated for the rendering task according to the task description file of the rendering task; dividing the rendering task to obtain at least two rendering sub-tasks, calling task processing resources in a target container associated with the cross-architecture component, rendering each rendering sub-task to obtain a rendering result corresponding to the rendering task, and feeding back the rendering result to the corresponding terminal equipment; wherein the cross-framework component is obtained by compiling the at least two candidate framework components based on a unified component interface specification. By adopting the method, the reliability of rendering processing can be improved.
Owner:GUANGDONG ELECTRIC POWER COMM CO LTD

Request redirection with connectivity preparation

At a security gateway residing within a trusted computer network, a service request is obtained from an external client and is authenticated. In response, one instance of a plurality of available application instances is identified. The instances are hosted on a plurality of hosts having a plurality of firewalls, and the firewalls and the hosts reside within the network. The firewalls have been initially defaulted to block external access to all instances. A corresponding one of the hosts, within the trusted computer network, and corresponding to the identified one of the plurality of available application instances, is instructed to open a corresponding one of the firewalls to a network address corresponding to the external client. The external client is advised of a destination identifier and port corresponding to the opening of the firewall, to facilitate the external client communicating with the corresponding one of the hosts.
Owner:CHARTER COMM OPERATING LLC

Transparent enablement of large frames for secure guests

Computer program products, computer-implemented method, and computer systems include a trusted element enabling host translation for a large page for a given block of memory of a secure guest. The enabling can include executing, in a trusted computing environment, a call from a host to import a page to a memory of the secure guest. The trusted element can determine that a page virtual address matches a page corresponding absolute address and based on this determination can increase a counter associated with the large page; the counter indicates small pages comprising the large page imported to guest memories. When the counter indicates that all the small pages were imported and based on this determination, the trusted element determines if that all the small pages meet pre-defined security requirements and if they do, enables host translation for the large page for the given block of memory of the secure guest.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

High-concurrency trusted computing remote attestation method and system based on equipment type adaptation

PendingCN122001694AAvoid process redundancyReduce bandwidth consumptionPublic key for secure communicationUser identity/authority verificationDevice typeSoftware engineering
The invention discloses a high-concurrency trusted computing remote certification method and system based on equipment type adaptation, and relates to the technical scheme that the method comprises the following steps: receiving a registration request which is sent by a client and contains an equipment type identifier; creating a thread pool, packaging the received registration request into a registration processing task, scheduling the registration processing task, analyzing an equipment type field in the registration request, and storing a mapping relationship between a client identifier and an equipment type to a local configuration file; in the challenge certification stage, querying the equipment type of the client from the local configuration file, and selecting an adaptive remote certification protocol according to a preset mapping rule; and packaging response verification operation of the server to the client into a proof processing task, and submitting the proof processing task to a thread pool for high-concurrency scheduling. The method can adapt to multi-form client requests, and can efficiently process large-scale concurrent remote attestation requests at the same time.
Owner:TIANFU JIANGXI LAB