Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

926 results about "Whitelist" patented technology

Whitelisting is the practice of explicitly allowing some identified entities access to a particular privilege, service, mobility, access or recognition. It is the reverse of blacklisting.

Cloud desktop security access control method based on zero-trust architecture

The invention discloses a cloud desktop security access control method based on a zero-trust architecture, belongs to the technical field of network security, and is used for solving the problems of difficulty in hidden attack detection, cross-cloud attack chain breakage and conflict between security control and service continuity in a multi-cloud environment. Firstly, user identity attributes, session metadata and service call logs are aggregated, an identity-resource-behavior triple dynamic graph is constructed, cross-session association features are extracted, and a multi-dimensional behavior baseline is generated. And quantifying the access deviation degree based on the behavior baseline, triggering sensitive operation traceability analysis, constructing a time sequence risk propagation model, identifying latent attack features, predicting a penetration path and outputting a risk propagation coefficient. And finally, dynamically generating a process-level micro-isolation strategy according to a risk result, gradually adjusting the authority through a nonlinear authority attenuation function, inserting a secondary authentication node when unexpected resource jump is detected, reconstructing a communication white list, and realizing collaborative optimization of security protection and service continuity.
Owner:SHENZHEN HUITUO INFORMATION TECH CO LTD

Government affair cloud cross-department data security sharing method and device

The invention provides a government affair cloud cross-department data security sharing method and device, and relates to the technical field of data security. The method comprises the following steps: a main chain of a block chain performs first-level verification on a requester based on a VerifyCredate contract and an access policy white list set by a department to which government affair data belongs; the access strategy is a dynamic attribute base access strategy generated by a department to which the government affair data belongs based on a dynamic attribute encryption technology; under the condition that the first-level verification is passed, generating an access credential, synchronizing the access credential to a side chain of the block chain, generating a zero-knowledge proof by the side chain according to the operation log, and initiating a zero-knowledge proof verification request to the main chain to perform second-level verification; and under the condition that the main chain passes the second-level verification, determining a cross-domain trust score between the government affair data requesting department and the department to which the government affair data belongs based on the digital certificate submitted by the requester by adopting a federal model, and performing third-level verification according to the cross-domain trust score. According to the invention, the data sharing security can be improved.
Owner:CICC DATA (WUHAN) SUPERCOMPUTING TECH CO LTD

Vehicle-mounted data grading processing method, system, equipment and medium

The invention provides a vehicle-mounted data grading processing method, system, device and medium, the method is cooperatively realized by a cloud end and a terminal device, and the method specifically comprises the following steps: the cloud end generates a structured configuration file containing an acquisition signal, a data type, a transmission condition, a priority and a compression rule based on a service scene, a first processor of the terminal equipment analyzes a received structured configuration file to generate an acquisition white list, a second controller filters controller messages according to the white list, executes double verification of cyclic redundancy check and counter tamper-proofing, and transmits valid data passing the verification in a hierarchical manner according to priorities, and a cloud terminal performs hierarchical decompression analysis on the received data and sends the analyzed data to a server. A historical data supplement mechanism is triggered when the data is abnormal, and the terminal equipment responds to the request to upload data in a specified time period and performs compensation analysis; according to the method, the collection flexibility is realized through dynamic configuration, and the problems of high computing power pressure of terminal equipment, non-uniform network transmission distribution and low cloud computing power utilization rate are solved.
Owner:CHONGQING WUTONG CAR LINK TECH CO LTD

File uploading attack interception method based on semantic entropy enhancement

The invention provides a file uploading attack interception method based on semantic entropy enhancement, and aims at overcoming the defects of an existing file uploading security protection technology in the face of complex attacks. The method specifically comprises the steps that S1, file format analysis and content extraction are conducted, hidden scripts are mined through nested content recognition, and intermediate representation is generated through grammar cleaning and coding specifications; s2, constructing an abstract syntax tree and semantic entropy calculation, tracking a pollution chain, analyzing a high-risk function, identifying a high-entropy character string, modeling and controlling flow complexity, and generating a semantic entropy vector; s3, dynamic scoring and decision making are carried out, and accurate judgment is carried out in combination with white list perception, feature comparison, multi-modal model scoring, adaptive threshold and sandbox observation; and S4, carrying out real-time interception and feature synchronization, blocking malicious file landing, generating an attack log and synchronizing an attack fingerprint. The method takes the semantic entropy vector as a core, breaks through the limitation of static features, remarkably improves the recognition rate of complex attacks, reduces missed judgment, and guarantees the safety of Web applications.
Owner:CHINA LIFE INSURANCE CO LTD

Network attack active defense strategy optimization method based on deep reinforcement learning

The invention discloses a network attack active defense strategy optimization method based on deep reinforcement learning, and the method comprises the following steps: collecting multi-source data of a network environment, and carrying out the feature clipping and white list feature reservation; performing normalization and coding processing to generate a security situation vector; constructing a multi-index reward function, and generating an instant reward value and an event-level reward value; executing a double-closed-loop mechanism through an improved PPO model, and respectively outputting an instant strategy instruction and a long-term strategy parameter; performing multi-source evidence commissioning on the instant strategy instruction and the security situation vector, and judging a key evidence loss condition to obtain an execution token; inputting a risk budget pool to carry out resource quota checking, and executing anti-jitter and cooling control; and optimizing parameters of the multi-index reward function through a causal account book. According to the method, rapid response and continuous optimization of various attack behaviors can be realized, the defense effect and the resource utilization rate are considered, the false report and missing report rate is reduced, and the self-adaptability and stability of a network defense system are improved.
Owner:QIAN XINGCHENG NETWORK SECURITY TECH (HUNAN) CO LTD

Data security protection method for power transaction

The invention relates to the field of power transaction security, in particular to a data security protection method for power transaction. Comprising the following steps: a registration authentication stage: completing identity registration through triple authentication of a physical token, biological feature recognition and a dynamic password and GPS positioning white list verification; in the key initialization stage, an SM2 asymmetric key pair and an SM4 symmetric communication key are dynamically generated according to a transaction time window and main body attributes, and are issued through a point-to-point encryption channel and updated in time; in the data encryption and binding stage, a transaction instruction is encrypted, signed and subjected to double-layer integrity verification; a matching and on-chain registration stage: executing matching after verifying the signature, encrypting a result, writing the result into the block chain, and generating a zero-knowledge proof; and in the settlement and supervision stage, settlement or alarm responsibility investigation is started after decryption verification. According to the invention, the problems of single identity authentication, static key, easy data tampering and the like in the prior art are solved, full-flow security protection of power transaction is realized, and data confidentiality, integrity and traceability are improved.
Owner:SHANDONG ENERGY POWER SALES CO LTD

Mutually cooperative door lock complementary acquisition method and system

The invention discloses a mutual cooperative door lock complementary acquisition method and system, and the method comprises the steps: extracting the structural feature data of a target person according to an event that a self door lock recognizes a non-white list person, generating an assistance request containing a target ID and the feature data, and transmitting the assistance request to an adjacent door lock; according to the assistance request received by the adjacent door lock, target feature matching is carried out, and after matching succeeds, a target video stream is collected and selectively coded; according to the time points when the target appears and disappears, generating an association starting pointer and an association ending pointer, and synchronously storing the pointers between the door locks; and analyzing the association pointer according to the playback request, and automatically starting stream playing of the association video streams of the plurality of door locks to realize multi-view synchronous display. By utilizing the embodiment of the invention, continuous automatic tracking and multi-view synchronous playback of cross-equipment target activities can be realized through active cooperation and data association between door locks, and the continuity and efficiency of security monitoring are improved.
Owner:DESSMANN CHINA MACHINERY & ELECTRONICS

Distributed network access method and system

The invention is suitable for the technical field of gateway connection, and provides a distributed network access method and system, and the method comprises the steps: obtaining the network topology pre-configuration information of a gateway; the method comprises the following steps: periodically broadcasting own node state information through a plurality of edge access gateways, acquiring terminal state change, acquiring broadcast signals of the plurality of gateways in real time when the terminal state change occurs, and scoring each edge access gateway through a scoring function; the edge access gateway corresponding to the highest score is used as a target access node, an access request is initiated to the gateway, and after the edge access gateway receives the request, the request is decrypted and verified, and white list information is compared at the same time; the monitoring result is compared with the early warning threshold value, after the controller receives the early warning signal, an access migration strategy is generated by comprehensively evaluating the real-time state, the geographic position and the access load condition of the adjacent gateway, and the access migration method has the advantages that it is ensured that no perception is given to the terminal in the migration process, data are not lost, and communication is not interrupted.
Owner:BEIJING SUANLI TECH CO LTD +1

System and method for verifying authenticity of inbound emails within an organization

One variation of a method includes: intercepting an inbound email received from a sender at an inbound email address and addressed to a recipient within an organization; accessing a keyword list including a set of keywords associated with inauthentic email attempts; and, in response to identifying a first word, in a set of words contained in the inbound email, in the set of keywords, scanning the first inbound email for presence of external content linked to the first inbound email. In response to detecting a link to an external document within the first inbound email, the method further includes: accessing a whitelist including a set of verified email addresses associated with authentic email attempts within the organization; and, in response to the set of verified email addresses omitting the inbound email address, withholding transmission of the inbound email to the target recipient and flagging the inbound email for authentication.
Owner:PAUBOX INC

Endogenous-security network method and architecture, medium, and device

PCT designated stageWO2025180269A1Securing communicationData streamAuthorization Mode
The present application provides an endogenous-security network method and architecture, a medium, and a device. The method comprises: extracting forwarding characteristic information of normal service data flows; delivering the forwarding characteristic information of the normal service data flows to a transport network element, so as to form a forwarding table entry, a flow table, and a forwarding white list, wherein forwarding modes in a method for binding service data flow forwarding characteristics to forwarding table entries of transport network elements comprises: an authentication and authorization mode and an automatic learning mode; the transport network element performing packet forwarding according to the forwarding characteristic information of the normal service data flows; and discarding packets of abnormal service data flows, wherein packet identification is performed for forwarding operations on the basis of a whitelist automatically generated from configuration files of switches and routers. The present application solves the technical issue of an IP network having low inherent security protection capabilities due to the openness thereof and thus requiring the deployment of a large number of external security protection facilities. The issue results in poor effectiveness, high costs, and difficulty in establishing low-cost security protection capabilities, and ultimately makes the IP network easy to attack but difficult to defend.
Owner:BEIJING BLUE OCEAN INTELLIGENT VICTORY TECHNOLOGY CO LTD

White list state synchronous processing method and system combined with database transaction control

The invention discloses a white list state synchronous processing method and system combined with database transaction control, and relates to the technical field of database transaction control and data synchronous processing. The method comprises the following steps: recording a white list state change event based on a pre-writing mechanism of a database transaction log; change events in a transaction log are classified and aggregated according to a white list and then are asynchronously written into a specified buffer area, when a transaction is submitted, the sequence of data in the buffer area is controlled through a lightweight lock mechanism to be refreshed to a physical disk, and the priority of a disk IO queue is dynamically adjusted according to the transaction isolation level to reduce concurrent conflicts; according to the white list state synchronization processing method and system combined with database transaction control, the transaction concurrent processing performance and the database response efficiency are remarkably improved, and the expansion capability and stability of the white list synchronization system in a complex business environment are also improved.
Owner:北京中睿天下信息技术有限公司

Non-screen POS machine data acquisition method and system based on NFC and WeChat applet, POS machine and storage medium

The invention discloses a non-screen POS machine data acquisition method and system based on NFC and a WeChat applet. A POS machine simulates an NFC Type 4 label through a non-contact chip, performs SM2 signature and encryption on equipment data containing a timestamp and a random number by using a private key instantaneously reconstructed by a PUF, and performs Base64URL-CRC packaging, segmented NDEF writing and 30s TTL setting; the mobile terminal automatically pulls up the WeChat applet after triple verification of radio frequency field stability detection, URL white list and integrity fingerprint; the small program uploads parameters through an AES-128-GCM secondary encryption and a Reed-Solomon fragment tunnel; the background adopts a Redis idempotent lock, an HSM private key decryption, an SGX enclave one-time token display mechanism and other mechanisms to complete signature verification and decryption, and it is ensured that the device data are only briefly visible in the WeChat security sandbox. According to the invention, the problems of difficult operation and maintenance data acquisition, high cost and poor security of the non-screen POS machine are solved, and cross-platform, anti-replay and man-in-the-middle-resistant high-security data acquisition can be completed within 10 seconds.
Owner:AITIWEIER ELECTRONICS TECH BEIJING

Fund routing system, method and device based on multi-dimensional rule engine

The invention discloses a fund routing system, method and device based on a multi-dimensional rule engine, and belongs to the technical field of internet finance. The system comprises an access layer, a rule engine layer, a distribution decision layer, a data service layer and a monitoring and optimizing layer. The access layer uniformly manages API docking; the rule engine layer comprises a front screen, a white list strategy engine and a dynamic weight calculator; the distribution decision-making layer supports a plurality of distribution modes; the data service layer comprises a machine learning model library; and the monitoring and optimization layer automatically adjusts and optimizes rules through reinforcement learning. The method comprises the steps of multi-dimensional verification, white list auditing, weight calculation, distribution mode selection and the like. The device comprises a hardware layer, a software layer and an interaction layer. According to the invention, the rule flexibility, the distribution efficiency and the risk control capability are improved, and the distribution time is shortened.
Owner:HAIER CONSUMER FINANCE CO LTD

Transformer area edge safety linkage method based on electricity utilization information acquisition terminal

The invention discloses a zone area edge security linkage method based on an electricity utilization information acquisition terminal, and relates to the technical field of power distribution terminal security, and the method comprises the steps: only reading an object, an action and a time window to generate an intention fingerprint, building an edge security access partition, and allowing a certificate and a one-time token to enter and carrying out retention audit; generating an exclusive session window, and implementing selective communication between virtual segments and a switch array, carrier communication session key rolling (secret exchange), four and eight exclusive sessions and white list current limiting; a shadow integrity label and a sequence commitment are calculated in the end, abnormity is judged in combination with physical fingerprints, grading processing is carried out according to the minimum influence range, and bypass mirror images and equivalent migration mapping are recorded; performing dual authorization and time limit and range checking on the related control, solidifying an evidence chain, and completing rotation and upgrading of a key certificate; on the premise of not changing the meter, the reading and control reliability, traceability and compliance verifiability are improved, the port layer contention is reduced, and the influence radius is reduced.
Owner:LIYANG HUAPENG ELECTRIC POWER METER

System and Method for Automated Whitelisting Prior to Installation

A whitelist generator authenticates an installation file (e.g., an installation release package), parses the installation file and then for each element of the installation file, if the element is a program, the whitelist generator adds an entry in a whitelist such that after the whitelist is distributed to a target system and that program is installed on the target system, that program will be able to run on the target system.
Owner:PC MATIC INC

Open source system framework layer custom interface authentication method, equipment and medium

The invention discloses an open source system framework layer custom interface authentication method comprising the following steps: creating a custom service in an open source system framework layer, the custom service providing at least one custom interface; establishing an encrypted and stored authentication white list file, wherein the encrypted and stored authentication white list file comprises a package name and signature fingerprint information of an application needing to be authorized; integrating an authentication trigger mechanism in the custom interface, and executing a hierarchical authentication process when an external application calls the custom interface; the hierarchical authentication process comprises the following steps: acquiring a package name of a calling party application and checking whether the package name exists in an authentication white list file or not; if yes, signature fingerprint information of the calling party application is further obtained and compared with fingerprints recorded in the authentication white list file; and if the fingerprints are consistent, the authentication is successful, and the function logic of the user-defined interface is executed. According to the method provided by the invention, the custom interface is ensured to be only open to the authorized application through a dual verification mechanism of the package name and the signature fingerprint information, and the full choice and stability of the system are ensured.
Owner:WUHAN GUIDE SENSMART TECH CO LTD

Vehicle-mounted wireless charging control method and device based on NFC and vehicle

The invention relates to a vehicle-mounted wireless charging control method and device based on NFC and a vehicle, and the method comprises the steps: obtaining the equipment identification information of terminal equipment disposed on a wireless charging panel based on NFC; determining whether the equipment identification information exists in a charging safety white list or not; if the equipment identification information exists in the security white list, generating a dynamic key according to the identification information of the vehicle and the hardware random number; encrypting the dynamic secret key and transmitting the encrypted dynamic secret key to terminal equipment through NFC; after feedback information returned by the terminal equipment is received, verifying whether the feedback information is correct or not; and if the feedback information is correct, controlling to charge the terminal equipment through the wireless charging panel. The method is used for effectively avoiding leakage of private data, so that the effect of improving the safety of vehicle-mounted wireless charging is achieved.
Owner:CHONGQING CHANGAN AUTOMOBILE CO LTD

Unmanned aerial vehicle parameter consistency configuration method based on template management

The invention relates to the technical field of unmanned aerial vehicle control and management, in particular to an unmanned aerial vehicle parameter consistency configuration method based on template management, which adopts a structured parameter configuration template in a JSON format, comprises four blocks of metadata, parameter definition, constraint rules and digital signatures, establishes an MAVLink communication link with an unmanned aerial vehicle flight controller through a template management terminal, and provides an unmanned aerial vehicle parameter consistency configuration method. And executing an automatic configuration process based on a finite-state machine, and ensuring parameter logic consistency by using a difference comparison and constraint verification mechanism. According to the method, temporary storage, batch writing and atomic submission of parameter changes are achieved through the atomization transaction submission protocol, the integrity of the configuration process is guaranteed, the digital signature auditing log containing the timestamp, the device identifier, the template hash and the change details is generated after configuration is completed, whole-process tracing is supported, and the method is high in practicability and easy to popularize. Headless mode operation, parameter white list control and hardware abstraction layer adaptation are supported, and high automation, standardization and safety of unmanned aerial vehicle parameter configuration can be achieved.
Owner:JIANGXI LIANCHUANG (WANNIAN) ELECTRONICS CO LTD

Dynamic audio buffer management method and system and medium

The invention relates to the technical field of software, and discloses a dynamic audio buffer management method and system and a medium. The method comprises the following steps: presetting a white list library of a plurality of application scenes, and matching a package name of a current foreground running application with the white list library to determine a current application scene; acquiring system performance state parameters in real time, wherein the parameters comprise at least one of a CPU occupancy rate, a memory occupancy rate and a temperature control and frequency limiting state; generating a buffer adjustment variable according to a statistical result of the audio lagging times; inputting the current application scene, the system performance state parameter and the buffer area adjustment variable into a preset strategy model, and outputting a buffer area gear value; and dynamically adjusting the size of a buffer area of an audio driving layer according to the gear value so as to adapt to the performance change of the system. According to the invention, the problem of lagging or delay caused by a fixed buffer area can be solved.
Owner:SHANGHAI LONGCHEER TECH CO LTD

Office system and method for digital security

The invention discloses a digital security-oriented office system and method, and relates to the technical field of information security and office automation, the digital security-oriented office system comprises a sensing module, a decision module, an execution module, a tracking module and a closed loop module, the sensing module collects login information, performs multi-factor verification, generates security sensing data, and sends the security sensing data to the decision module; the decision-making module compares security perception data with historical login information, divides risk levels and generates an access control decision, the execution module constructs a virtual security sandbox or verifies an access request based on a zero trust principle and generates an authority white list and cooperation timeliness, and the tracking module records an operation behavior and a security log through a block chain. The closed-loop module monitors an office scene in real time and drives data updating and sandbox destroying. According to the method, the whole-process security control of the office scene is realized, the risk is accurately identified, the protection strategy is dynamically adjusted, the high security requirement of cross-organization and internal office is met, and a powerful guarantee is provided for the security of digital office data.
Owner:SICHUAN YOUJIA TRACEABILITY TECH CO LTD

IoT (Internet of Things) access control system with active safety capability

The invention relates to the field of Internet of Things security, and discloses an IoT access control system with an active security capability, and the system comprises an Internet of Things security gateway, a network infrastructure and an external IoT service system: a port authentication module of the gateway executes the binding verification of an MAC white list and a dynamic IP-MAC; the traffic monitoring module loads a protocol feature sequence template based on a service type, and verifies a device traffic behavior in a time window; the equipment verification interface module is linked with the service system to verify the equipment registration state; and the active defense module triggers precise blocking and network repairing operation according to the verification result. According to the application, organic fusion of equipment identity credibility verification, service behavior compliance detection and attack instant disposal is realized, attacks such as MAC counterfeiting, protocol tampering and service layer counterfeiting are effectively defended, and meanwhile, through adaptive flow modeling and elastic strategy adaptation, the method is compatible with multiple service scenes such as intelligent buildings and industrial Internet of Things, and the service security is improved. And the active defense capability of the IoT network is remarkably improved.
Owner:LINGBO TECH (BEIJING) CO LTD

Robot, operation method thereof, operation device, storage medium, and program product

The embodiment of the invention provides a robot and an operation method and device thereof, a storage medium and a program product. The method comprises the steps that natural language instruction information and multiple robot sensing data are received; performing spatial feature extraction processing based on at least part of the robot sensing data to obtain spatial feature information of the corresponding robot sensing data; performing time sequence feature fusion based on the spatial feature information of the perception data of the at least two robots to generate space-time semantic implicit representation information; performing cross-modal interaction based on the natural language instruction information and the space-time semantic implicit representation information to generate space target representation information; and path planning and / or action control are / is carried out based on the spatial target representation information, so that the robot is controlled to execute operation corresponding to the natural language instruction information. Therefore, high information integrity can be kept under the condition of low computing power, serious information loss caused by white list detection is reduced, and the universality of robot operation control is remarkably improved.
Owner:AGIBOT INNOVATION (SHANGHAI) TECHNOLOGY CO LTD

Honeypot interaction response generation method based on large language model

A honeypot interaction response generation method based on a large language model comprises the steps that an attacker initiates a malicious request, a firewall carries out screening based on a white list, and traffic matched with the white list is forwarded to an actual application server through a honeypot system; for the traffic not in the white list, redirecting the traffic to a honeypot system; a honeypot interaction response system is deployed in the honeypot system and comprises an embedding module, a coding module and a response decoding module, so that induction response is automatically generated and sent to an attacker, and meanwhile alarm information is generated and sent to safety analysts. The method comprises the following steps: firstly, converting input data into a vector form by using an embedding module, extracting overall characteristics of a request by using a coding module, and finally, generating an induced response by using a response decoding module. According to the method, the advantages of a large language model in the aspects of semantic comprehension, context modeling and generation capability are fully utilized, and accurate perception of attack behaviors and automatic generation of response contents are realized.
Owner:NANJING COLLEGE OF INFORMATION TECH

Campus intelligent alarm linkage method and system based on face recognition

The invention discloses a campus intelligent alarm linkage method and system based on face recognition, and the method comprises the steps: collecting a video stream in real time, and extracting a face image in a video frame through a face detection algorithm; comparing the face image with a white list database pre-stored in a campus in real time, and generating an identity recognition result and a confidence score of the face; calculating the threat level of the current behavior scene through a dynamic early warning judgment model and generating a graded early warning signal based on the identity recognition result and the confidence score in combination with the real-time analysis of the personnel behavior scene; automatically triggering a corresponding equipment linkage instruction according to the graded early warning signal; and on the basis of the execution state of the equipment linkage instruction and a subsequent video analysis result, generating a complete security event disposal report containing an incident position, an incident-related personnel image and a disposal suggestion. According to the embodiment of the invention, the active early warning capability and the emergency response efficiency of the campus security system can be improved.
Owner:ZHEJIANG TONGJI VOCATIONAL COLLEGE OF SCI & TECH +1

Fraud-related application detection method and device based on flow behavior analysis, medium and program product

The invention provides a fraud-related application detection method and device based on flow behavior analysis, a medium and a program product, and the method comprises the steps: carrying out the deep packet detection analysis of the current network downloading flow, comparing an application sample obtained through analysis with a preset white list and a black list, and screening out a missed to-be-detected sample; running a to-be-tested sample in a sandbox environment, collecting an interface image, extracting text features, and inputting a fraud-related classification model to judge whether the application program is a fraud-related application program or not; the method comprises the following steps: performing deep packet detection analysis on current network use traffic, extracting multi-dimensional behavior characteristics such as a terminal identifier, an application use frequency and an active time period, performing coding and scaling processing to form a fraud-related feature vector, and inputting a random forest detection model to judge whether a terminal has a fraud-related application use behavior or not. According to the method, through complementary fusion of content feature and behavior feature detection links, full-process identification of fraud-related applications in downloading and using stages is realized, and the coverage rate, the accuracy rate and the real-time performance of fraud-related detection are improved.
Owner:SINO TELECOM TECHNOLOGY CO INC

Slave device address acquisition method and system

The invention discloses a slave device address acquisition method and system, and the method comprises the steps: generating a search downlink message according to a search parameter, and carrying out the broadcasting of the search downlink message; if the search uplink message is received, generating and broadcasting a search confirmation message; repeatedly executing the search process until a search stop condition is met, and completing a round of search; modifying the search address range, and executing the next round of search based on the modified search parameters until the union set of the search address ranges of all the search rounds covers the preset address range; and confirming a slave device address list accessed to the master device based on all the search uplink messages. The master device sends the information to enable the slave device to respond to the slave device address of the slave device, the operation of manually recording the slave device address is replaced, the error risk and cost of manual operation are reduced, network signal blocking can be reduced through round-by-round search, a reliable basis is provided for configuring a white list and starting networking for a subsequent cloud platform, and the service life of the cloud platform is prolonged. And the access efficiency of the slave device is improved.
Owner:SUZHOU HEGUANG TONGYAO INTELLIGENT TECH CO LTD

Vehicle-mounted system safety detection and risk assessment system

The invention discloses a vehicle-mounted system safety detection and risk assessment system, which belongs to the technical field of vehicle-mounted network safety, and comprises a vehicle-mounted terminal environment sensing module used for collecting multi-level environment information of a vehicle-mounted system, including system layer information, network layer information and safety layer information; the vehicle-mounted configuration file and communication white list detection module is connected to the vehicle-mounted terminal environment sensing module and is used for establishing and maintaining a safety white list library according to the collected system information, comparing the current configuration file, the dynamic library, the port and the certificate state of the system with the safety white list library through periodic scanning, and sending the comparison result to the vehicle-mounted terminal environment sensing module; detecting configuration abnormity and file tampering events; a vehicle-mounted process and control task analysis module; a communication abnormity detection and code identification module; and a safety evaluation and risk feedback module. According to the invention, all-around monitoring and intelligent analysis of vehicle-mounted system configuration, process behaviors and network communication can be realized, and hidden backdoors, abnormal processes and malicious communication can be effectively identified.
Owner:HUBEI UNIV

Telecommunication network fraud case multi-dimensional graph series-parallel and visualization method based on graph database

The invention discloses a multi-dimensional graph series-parallel and visualization method for telecommunication network fraud cases based on a graph database. According to the method, intelligent series-parallel analysis across time-space cases is realized by constructing a knowledge graph containing various entities such as cases, personnel, accounts and equipment and deeply fusing a hard association matching algorithm and a soft similarity graph algorithm. The system has the functions of white list filtering, time sequence behavior analysis, NLP information extraction and the like, and can effectively identify criminal gangs, track fund flow directions and mine crime modes. And finally, dynamic visual display is carried out through a plurality of interactive views such as a force-oriented graph, a time axis and a mulberry-based graph, and clue intelligent pushing and report automatic generation are supported. According to the method, the case association mining depth, the serial-parallel analysis efficiency and the interpretability of a complex network are remarkably improved, and an efficient technical support is provided for the public security organization to fight against telecommunication network fraud.
Owner:ZHUHAI XINDEHUI INFORMATION TECH

Internet of Things equipment access authentication method and system based on edge computing

The invention discloses an Internet of Things equipment access authentication method and system based on edge computing. The method comprises the following steps: equipment sends an access request, and an edge node analyzes a protocol to generate a feature fingerprint; the cloud executes first-level protocol white list verification and second-level certificate and feature fingerprint verification, matches an authentication strategy according to environmental parameters and issues a token; the edge node executes localized authentication, monitors the state in real time and dynamically adjusts the strategy; and after the authentication is passed, synchronizing information to the cloud to complete registration. The system comprises an equipment access layer, an edge computing layer, an authentication management layer and an interactive interface layer, the edge layer analyzes protocols such as DALI and BACnet, and the management layer constructs a three-dimensional strategy mapping table and supports graphical configuration and machine learning optimization strategy libraries. According to the Internet of Things equipment access authentication method and system based on edge computing, low-delay and high-flexibility access of multi-protocol equipment is achieved, the real-time performance, expansibility and safety are improved, and the method and system are suitable for intelligent buildings, industrial Internet of Things and other scenes.
Owner:ZHONGWANGDAO TECH GRP CO LTD

USB multi-port device access encryption authentication method and system

The invention relates to the technical field of data encryption, in particular to a USB multi-port equipment access encryption authentication method and system. Comprising a power supply module 100, a master control MCU unit 200, an analog signal switching unit 300, a USB expansion unit 400, a plugging detection unit 500 and a host interface unit 600, and the master control MCU unit 200 is connected with the analog signal switching unit 300, the USB expansion unit 400, the plugging detection unit 500 and the host interface unit 600 and used for achieving signal control and state management; the method does not depend on operating system permission or user behaviors, software installation is not needed, identification, authentication and control operations are completed completely through hardware, and non-bypassing performance is achieved. The problems that a traditional white list strategy is easy to bypass, needs to depend on authorization of an operating system and lacks physical isolation are effectively solved. The system supports upgrade authentication algorithms such as RSA, ECC and the like, supports a log recording function and a remote communication management module, can realize strategy adjustment through a firmware upgrade mechanism, and meets access management and control requirements of different scenes.
Owner:SUQIAN POWER SUPPLY COMPANY OF JIANGSU PROVINCE POWER +1