Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

1098 results about "Whitelist" patented technology

Whitelisting is the practice of explicitly allowing some identified entities access to a particular privilege, service, mobility, access or recognition. It is the reverse of blacklisting.

Cloud desktop security access control method based on zero-trust architecture

The invention discloses a cloud desktop security access control method based on a zero-trust architecture, belongs to the technical field of network security, and is used for solving the problems of difficulty in hidden attack detection, cross-cloud attack chain breakage and conflict between security control and service continuity in a multi-cloud environment. Firstly, user identity attributes, session metadata and service call logs are aggregated, an identity-resource-behavior triple dynamic graph is constructed, cross-session association features are extracted, and a multi-dimensional behavior baseline is generated. And quantifying the access deviation degree based on the behavior baseline, triggering sensitive operation traceability analysis, constructing a time sequence risk propagation model, identifying latent attack features, predicting a penetration path and outputting a risk propagation coefficient. And finally, dynamically generating a process-level micro-isolation strategy according to a risk result, gradually adjusting the authority through a nonlinear authority attenuation function, inserting a secondary authentication node when unexpected resource jump is detected, reconstructing a communication white list, and realizing collaborative optimization of security protection and service continuity.
Owner:SHENZHEN HUITUO INFORMATION TECH CO LTD

Personal data cross-border circulation method based on block chain

The invention discloses a personal data cross-border circulation method based on a block chain. The method comprises the steps of data acquisition and local storage, third-party neutral institution witness and data fingerprint chaining, data transmission and use authorization declaration, fingerprint verification and data verification on a receiver chain, and full-link tracing and dynamic auditing. Aiming at the problems that trust guarantee of personal data cross-border circulation depends on a single technical means such as centralized institution authentication or encrypted transmission or a static legal protocol, a trust transfer chain is lengthy, and cross-national legal mutual recognition is fragile, a data fingerprint anchoring system constructed based on a block chain is designed; aiming at the problems that traditional data cross-border authorization depends on a manual signing protocol or static strategy configuration, response lag exists, rule execution deviation exists, privacy protection and compliance auditing are difficult to consider and the like, a data use rule is dynamically constrained through an intelligent contract; a user defines a data use range, timeliness and an operation white list through a declarative intelligent contract, and contract codes are automatically executed after being subjected to consensus verification of nodes on a chain.
Owner:National Information Center (National E-Government Extranet Management Center)

Cross-region and cross-mechanism health medical data security sharing method based on block chain

The invention discloses a cross-regional cross-mechanism health medical data security sharing method based on a block chain, and relates to the technical field of data security, and the method comprises the steps: 1, carrying out the content balance fragmentation of an electronic health record, and obtaining a plurality of content fragments, encrypting each content fragment by using a random salt value generated by the head hash value of the previous height block to obtain a salt-added ciphertext fragment; 2, calculating a hash sequence for all salted ciphertext fragments of the same patient and generating a Merkel root; 3, when the external medical institution makes an access application, the chain smart contract compares the identity code set of the applied external medical institution with the patient agreement white list; and when an agreement threshold value set by the patient is met, generating and verifying an access authorization token by adopting a signature mechanism, and writing an authorization result into a block chain auditing side chain. According to the method, the problems of low data sharing efficiency, high trust dependence, difficulty in auditing and the like in a traditional mode are solved.
Owner:SHANDONG WOHUA HEALTH TECH CO LTD +1

Government affair cloud cross-department data security sharing method and device

The invention provides a government affair cloud cross-department data security sharing method and device, and relates to the technical field of data security. The method comprises the following steps: a main chain of a block chain performs first-level verification on a requester based on a VerifyCredate contract and an access policy white list set by a department to which government affair data belongs; the access strategy is a dynamic attribute base access strategy generated by a department to which the government affair data belongs based on a dynamic attribute encryption technology; under the condition that the first-level verification is passed, generating an access credential, synchronizing the access credential to a side chain of the block chain, generating a zero-knowledge proof by the side chain according to the operation log, and initiating a zero-knowledge proof verification request to the main chain to perform second-level verification; and under the condition that the main chain passes the second-level verification, determining a cross-domain trust score between the government affair data requesting department and the department to which the government affair data belongs based on the digital certificate submitted by the requester by adopting a federal model, and performing third-level verification according to the cross-domain trust score. According to the invention, the data sharing security can be improved.
Owner:CICC DATA (WUHAN) SUPERCOMPUTING TECH CO LTD

Vehicle-mounted data grading processing method, system, equipment and medium

The invention provides a vehicle-mounted data grading processing method, system, device and medium, the method is cooperatively realized by a cloud end and a terminal device, and the method specifically comprises the following steps: the cloud end generates a structured configuration file containing an acquisition signal, a data type, a transmission condition, a priority and a compression rule based on a service scene, a first processor of the terminal equipment analyzes a received structured configuration file to generate an acquisition white list, a second controller filters controller messages according to the white list, executes double verification of cyclic redundancy check and counter tamper-proofing, and transmits valid data passing the verification in a hierarchical manner according to priorities, and a cloud terminal performs hierarchical decompression analysis on the received data and sends the analyzed data to a server. A historical data supplement mechanism is triggered when the data is abnormal, and the terminal equipment responds to the request to upload data in a specified time period and performs compensation analysis; according to the method, the collection flexibility is realized through dynamic configuration, and the problems of high computing power pressure of terminal equipment, non-uniform network transmission distribution and low cloud computing power utilization rate are solved.
Owner:CHONGQING WUTONG CAR LINK TECH CO LTD

Industrial database protection method based on multi-mode authentication and encryption

The invention discloses an industrial database protection method based on multi-modal authentication and encryption, which belongs to the technical field of data processing and comprises the following steps: acquiring input data to be input into an industrial database; a multi-mode authentication gateway is adopted to verify user identity information, and a biological feature, a dynamic device fingerprint and a quantum random number token are fused to generate a third-level identity verification identifier; after the three-level identity verification is passed, determining an encryption algorithm according to the sensitive level of the industrial data transmitted in real time and the system load state, and encrypting the industrial data through the encryption algorithm; and for the encrypted industrial data, analyzing the function code of the Modbus message of the industrial data transmitted in real time, establishing a white list instruction set, and intercepting the industrial data of the function code which is not in the white list instruction set. According to the industrial database protection method based on multi-modal authentication and encryption, the problem of how to improve the real-time response capability of a system on the premise of ensuring the security of industrial data is solved.
Owner:KINGWAY FOSHAN ELECTRONICS TECH CO LTD

File uploading attack interception method based on semantic entropy enhancement

The invention provides a file uploading attack interception method based on semantic entropy enhancement, and aims at overcoming the defects of an existing file uploading security protection technology in the face of complex attacks. The method specifically comprises the steps that S1, file format analysis and content extraction are conducted, hidden scripts are mined through nested content recognition, and intermediate representation is generated through grammar cleaning and coding specifications; s2, constructing an abstract syntax tree and semantic entropy calculation, tracking a pollution chain, analyzing a high-risk function, identifying a high-entropy character string, modeling and controlling flow complexity, and generating a semantic entropy vector; s3, dynamic scoring and decision making are carried out, and accurate judgment is carried out in combination with white list perception, feature comparison, multi-modal model scoring, adaptive threshold and sandbox observation; and S4, carrying out real-time interception and feature synchronization, blocking malicious file landing, generating an attack log and synchronizing an attack fingerprint. The method takes the semantic entropy vector as a core, breaks through the limitation of static features, remarkably improves the recognition rate of complex attacks, reduces missed judgment, and guarantees the safety of Web applications.
Owner:CHINA LIFE INSURANCE CO LTD

Industrial host control method and system based on artificial intelligence

The invention provides an industrial host control method and system based on artificial intelligence. The method comprises the steps that a white list process is set, and when a process accesses the industrial host, the industrial host monitors whether the process accessing the industrial host is abnormal or not through application layer data before and during running of the process; then, real-time syscale flow data is collected through an eBPF behavior collector of an inner kernel layer of the industrial control host, and the syscale flow data is analyzed through an AI decision engine to judge whether the syscale flow data is abnormal or not; and acquiring a process behavior entropy value, smoothing the behavior entropy value by adopting a moving average method, and controlling triggering of a fusing instruction based on monitoring of an application layer and a kernel layer. Through the method and the corresponding system, the capability of detecting the abnormal process can be improved.
Owner:SHENZHEN INNOVATIVE CLOUD COMPUTER CO LTD

Network attack active defense strategy optimization method based on deep reinforcement learning

The invention discloses a network attack active defense strategy optimization method based on deep reinforcement learning, and the method comprises the following steps: collecting multi-source data of a network environment, and carrying out the feature clipping and white list feature reservation; performing normalization and coding processing to generate a security situation vector; constructing a multi-index reward function, and generating an instant reward value and an event-level reward value; executing a double-closed-loop mechanism through an improved PPO model, and respectively outputting an instant strategy instruction and a long-term strategy parameter; performing multi-source evidence commissioning on the instant strategy instruction and the security situation vector, and judging a key evidence loss condition to obtain an execution token; inputting a risk budget pool to carry out resource quota checking, and executing anti-jitter and cooling control; and optimizing parameters of the multi-index reward function through a causal account book. According to the method, rapid response and continuous optimization of various attack behaviors can be realized, the defense effect and the resource utilization rate are considered, the false report and missing report rate is reduced, and the self-adaptability and stability of a network defense system are improved.
Owner:QIAN XINGCHENG NETWORK SECURITY TECH (HUNAN) CO LTD

Data security protection method for power transaction

The invention relates to the field of power transaction security, in particular to a data security protection method for power transaction. Comprising the following steps: a registration authentication stage: completing identity registration through triple authentication of a physical token, biological feature recognition and a dynamic password and GPS positioning white list verification; in the key initialization stage, an SM2 asymmetric key pair and an SM4 symmetric communication key are dynamically generated according to a transaction time window and main body attributes, and are issued through a point-to-point encryption channel and updated in time; in the data encryption and binding stage, a transaction instruction is encrypted, signed and subjected to double-layer integrity verification; a matching and on-chain registration stage: executing matching after verifying the signature, encrypting a result, writing the result into the block chain, and generating a zero-knowledge proof; and in the settlement and supervision stage, settlement or alarm responsibility investigation is started after decryption verification. According to the invention, the problems of single identity authentication, static key, easy data tampering and the like in the prior art are solved, full-flow security protection of power transaction is realized, and data confidentiality, integrity and traceability are improved.
Owner:SHANDONG ENERGY POWER SALES CO LTD

Train-mounted network security protection method and device and electronic equipment

The invention discloses a train on-board network security protection method and device and electronic equipment, and relates to the field of train on-board network security protection. Comprising the following steps: determining a firmware information hash value by using a national cryptographic algorithm, and verifying by using a firmware reference value; measuring a mirror image of an operating system by using a cryptographic algorithm and a dynamic measurement engine, and executing TRDP protocol information deep filtering based on a white list on vehicle-mounted communication data by using a vehicle-mounted firewall; encrypting the filtered communication data by using a national cryptographic algorithm; detecting the filtered communication data by using bypass mirror image monitoring equipment; updating a blocking strategy of the vehicle-mounted firewall to obtain a dynamic defense result; based on the system operation data and the dynamic defense result, using an event restoration record in a security database to verify the defense effectiveness, and obtaining a verification result; and updating the dynamic measurement engine according to the verification result. According to the invention, the trusted environment of the vehicle-mounted network can be perfected, the security level of the vehicle-mounted network is improved, and the defense capability and efficiency of the vehicle-mounted network to unknown threats are enhanced.
Owner:NINGBO HOLLYSHI INFORMATION SECURITY RES INST CO LTD

Mutually cooperative door lock complementary acquisition method and system

The invention discloses a mutual cooperative door lock complementary acquisition method and system, and the method comprises the steps: extracting the structural feature data of a target person according to an event that a self door lock recognizes a non-white list person, generating an assistance request containing a target ID and the feature data, and transmitting the assistance request to an adjacent door lock; according to the assistance request received by the adjacent door lock, target feature matching is carried out, and after matching succeeds, a target video stream is collected and selectively coded; according to the time points when the target appears and disappears, generating an association starting pointer and an association ending pointer, and synchronously storing the pointers between the door locks; and analyzing the association pointer according to the playback request, and automatically starting stream playing of the association video streams of the plurality of door locks to realize multi-view synchronous display. By utilizing the embodiment of the invention, continuous automatic tracking and multi-view synchronous playback of cross-equipment target activities can be realized through active cooperation and data association between door locks, and the continuity and efficiency of security monitoring are improved.
Owner:DESSMANN CHINA MACHINERY & ELECTRONICS

Distributed network access method and system

The invention is suitable for the technical field of gateway connection, and provides a distributed network access method and system, and the method comprises the steps: obtaining the network topology pre-configuration information of a gateway; the method comprises the following steps: periodically broadcasting own node state information through a plurality of edge access gateways, acquiring terminal state change, acquiring broadcast signals of the plurality of gateways in real time when the terminal state change occurs, and scoring each edge access gateway through a scoring function; the edge access gateway corresponding to the highest score is used as a target access node, an access request is initiated to the gateway, and after the edge access gateway receives the request, the request is decrypted and verified, and white list information is compared at the same time; the monitoring result is compared with the early warning threshold value, after the controller receives the early warning signal, an access migration strategy is generated by comprehensively evaluating the real-time state, the geographic position and the access load condition of the adjacent gateway, and the access migration method has the advantages that it is ensured that no perception is given to the terminal in the migration process, data are not lost, and communication is not interrupted.
Owner:BEIJING SUANLI TECH CO LTD +1

System and method for verifying authenticity of inbound emails within an organization

One variation of a method includes: intercepting an inbound email received from a sender at an inbound email address and addressed to a recipient within an organization; accessing a keyword list including a set of keywords associated with inauthentic email attempts; and, in response to identifying a first word, in a set of words contained in the inbound email, in the set of keywords, scanning the first inbound email for presence of external content linked to the first inbound email. In response to detecting a link to an external document within the first inbound email, the method further includes: accessing a whitelist including a set of verified email addresses associated with authentic email attempts within the organization; and, in response to the set of verified email addresses omitting the inbound email address, withholding transmission of the inbound email to the target recipient and flagging the inbound email for authentication.
Owner:PAUBOX INC

Sidelink enhancements resource allocation assistance information

The exchange of resource allocation assistance information between a requester User Equipment (UE) and an assistant UE allows the requester to make better resource allocation decisions. The assistance information may include a blacklist, a whitelist, resource allocation information, a candidate resource set, and measurement information, for example. Both UEs may have an assistance configuration to assist in the exchange of resource allocation assistance information, that may be obtained from a third apparatus, such as a base station. The configuration may include information related to when to trigger assistance, identities of UEs, and types of assistance information, for example. The requester may, based on the assistance information received, modify a candidate resource set at a Medium Access Control (MAC) layer. The requester may, at the MAC layer, determine a configured sidelink grant for a selected destination using assistance information targeting this destination.
Owner:INTERDIGITAL PATENT HOLDINGS INC

Endogenous-security network method and architecture, medium, and device

PCT designated stageWO2025180269A1Securing communicationData streamAuthorization Mode
The present application provides an endogenous-security network method and architecture, a medium, and a device. The method comprises: extracting forwarding characteristic information of normal service data flows; delivering the forwarding characteristic information of the normal service data flows to a transport network element, so as to form a forwarding table entry, a flow table, and a forwarding white list, wherein forwarding modes in a method for binding service data flow forwarding characteristics to forwarding table entries of transport network elements comprises: an authentication and authorization mode and an automatic learning mode; the transport network element performing packet forwarding according to the forwarding characteristic information of the normal service data flows; and discarding packets of abnormal service data flows, wherein packet identification is performed for forwarding operations on the basis of a whitelist automatically generated from configuration files of switches and routers. The present application solves the technical issue of an IP network having low inherent security protection capabilities due to the openness thereof and thus requiring the deployment of a large number of external security protection facilities. The issue results in poor effectiveness, high costs, and difficulty in establishing low-cost security protection capabilities, and ultimately makes the IP network easy to attack but difficult to defend.
Owner:BEIJING BLUE OCEAN INTELLIGENT VICTORY TECHNOLOGY CO LTD

White list state synchronous processing method and system combined with database transaction control

The invention discloses a white list state synchronous processing method and system combined with database transaction control, and relates to the technical field of database transaction control and data synchronous processing. The method comprises the following steps: recording a white list state change event based on a pre-writing mechanism of a database transaction log; change events in a transaction log are classified and aggregated according to a white list and then are asynchronously written into a specified buffer area, when a transaction is submitted, the sequence of data in the buffer area is controlled through a lightweight lock mechanism to be refreshed to a physical disk, and the priority of a disk IO queue is dynamically adjusted according to the transaction isolation level to reduce concurrent conflicts; according to the white list state synchronization processing method and system combined with database transaction control, the transaction concurrent processing performance and the database response efficiency are remarkably improved, and the expansion capability and stability of the white list synchronization system in a complex business environment are also improved.
Owner:北京中睿天下信息技术有限公司

Multi-security protection level service container system call control method and system

The invention provides a call control method and system for a service container system with multiple safety protection levels, and belongs to the field of computer containers, and the call control method comprises the following steps: S1, defining corresponding Seccomp configuration baselines for containers with different safety protection levels; s2, according to the safety protection level of the container and a Seccomp configuration baseline, collecting and learning behaviors called by a container system, and further dynamically generating a specific Seccomp strategy configuration file of the container; s3, the Seccomp strategy configuration file is adjusted and optimized, and an optimized Seccomp strategy configuration file and a system calling white list are obtained; and S4, on the basis of the optimized Seccomp strategy configuration file, performing real-time protection on system calling of the container, and intercepting abnormal system calling which is not in the system calling white list. According to the method disclosed by the invention, a self-learning function is realized, and Seccomp strategy configuration files meeting different safety protection requirements are dynamically generated.
Owner:AVICIT CO LTD

Non-screen POS machine data acquisition method and system based on NFC and WeChat applet, POS machine and storage medium

The invention discloses a non-screen POS machine data acquisition method and system based on NFC and a WeChat applet. A POS machine simulates an NFC Type 4 label through a non-contact chip, performs SM2 signature and encryption on equipment data containing a timestamp and a random number by using a private key instantaneously reconstructed by a PUF, and performs Base64URL-CRC packaging, segmented NDEF writing and 30s TTL setting; the mobile terminal automatically pulls up the WeChat applet after triple verification of radio frequency field stability detection, URL white list and integrity fingerprint; the small program uploads parameters through an AES-128-GCM secondary encryption and a Reed-Solomon fragment tunnel; the background adopts a Redis idempotent lock, an HSM private key decryption, an SGX enclave one-time token display mechanism and other mechanisms to complete signature verification and decryption, and it is ensured that the device data are only briefly visible in the WeChat security sandbox. According to the invention, the problems of difficult operation and maintenance data acquisition, high cost and poor security of the non-screen POS machine are solved, and cross-platform, anti-replay and man-in-the-middle-resistant high-security data acquisition can be completed within 10 seconds.
Owner:AITIWEIER ELECTRONICS TECH BEIJING

Depth review material authenticity automatic verification method, system and platform based on deep network search and large model

The invention discloses a title review material authenticity automatic verification method, system and platform based on deep network search and a large model. The method comprises the following steps: respectively generating and acquiring first data and second data corresponding to a to-be-processed material, and generating corresponding third data; creating a first model corresponding to the natural language, and generating fourth data corresponding to the search engine on the basis of the first model and in combination with the third data; based on the fourth data and in combination with a white list data source, performing search processing to generate fifth data corresponding to the to-be-processed material; constructing an auditing prompt word corresponding to the first data, and generating sixth data corresponding to the to-be-processed material according to the auditing prompt word in combination with a first model; wherein the sixth data are authenticity verification result data and reasoning basis data, and the system and the platform corresponding to the method can solve the problems of low manual auditing efficiency, insufficient retrieval automation degree, poor verification accuracy caused by semantic model closure and the like.
Owner:GUANGZHOU ZHONGKE YIDE TECH CO LTD

Fund routing system, method and device based on multi-dimensional rule engine

The invention discloses a fund routing system, method and device based on a multi-dimensional rule engine, and belongs to the technical field of internet finance. The system comprises an access layer, a rule engine layer, a distribution decision layer, a data service layer and a monitoring and optimizing layer. The access layer uniformly manages API docking; the rule engine layer comprises a front screen, a white list strategy engine and a dynamic weight calculator; the distribution decision-making layer supports a plurality of distribution modes; the data service layer comprises a machine learning model library; and the monitoring and optimization layer automatically adjusts and optimizes rules through reinforcement learning. The method comprises the steps of multi-dimensional verification, white list auditing, weight calculation, distribution mode selection and the like. The device comprises a hardware layer, a software layer and an interaction layer. According to the invention, the rule flexibility, the distribution efficiency and the risk control capability are improved, and the distribution time is shortened.
Owner:HAIER CONSUMER FINANCE CO LTD

Transformer area edge safety linkage method based on electricity utilization information acquisition terminal

The invention discloses a zone area edge security linkage method based on an electricity utilization information acquisition terminal, and relates to the technical field of power distribution terminal security, and the method comprises the steps: only reading an object, an action and a time window to generate an intention fingerprint, building an edge security access partition, and allowing a certificate and a one-time token to enter and carrying out retention audit; generating an exclusive session window, and implementing selective communication between virtual segments and a switch array, carrier communication session key rolling (secret exchange), four and eight exclusive sessions and white list current limiting; a shadow integrity label and a sequence commitment are calculated in the end, abnormity is judged in combination with physical fingerprints, grading processing is carried out according to the minimum influence range, and bypass mirror images and equivalent migration mapping are recorded; performing dual authorization and time limit and range checking on the related control, solidifying an evidence chain, and completing rotation and upgrading of a key certificate; on the premise of not changing the meter, the reading and control reliability, traceability and compliance verifiability are improved, the port layer contention is reduced, and the influence radius is reduced.
Owner:LIYANG HUAPENG ELECTRIC POWER METER

System and Method for Automated Whitelisting Prior to Installation

A whitelist generator authenticates an installation file (e.g., an installation release package), parses the installation file and then for each element of the installation file, if the element is a program, the whitelist generator adds an entry in a whitelist such that after the whitelist is distributed to a target system and that program is installed on the target system, that program will be able to run on the target system.
Owner:PC MATIC INC

Open source system framework layer custom interface authentication method, equipment and medium

The invention discloses an open source system framework layer custom interface authentication method comprising the following steps: creating a custom service in an open source system framework layer, the custom service providing at least one custom interface; establishing an encrypted and stored authentication white list file, wherein the encrypted and stored authentication white list file comprises a package name and signature fingerprint information of an application needing to be authorized; integrating an authentication trigger mechanism in the custom interface, and executing a hierarchical authentication process when an external application calls the custom interface; the hierarchical authentication process comprises the following steps: acquiring a package name of a calling party application and checking whether the package name exists in an authentication white list file or not; if yes, signature fingerprint information of the calling party application is further obtained and compared with fingerprints recorded in the authentication white list file; and if the fingerprints are consistent, the authentication is successful, and the function logic of the user-defined interface is executed. According to the method provided by the invention, the custom interface is ensured to be only open to the authorized application through a dual verification mechanism of the package name and the signature fingerprint information, and the full choice and stability of the system are ensured.
Owner:WUHAN GUIDE SENSMART TECH CO LTD

Vehicle-mounted wireless charging control method and device based on NFC and vehicle

The invention relates to a vehicle-mounted wireless charging control method and device based on NFC and a vehicle, and the method comprises the steps: obtaining the equipment identification information of terminal equipment disposed on a wireless charging panel based on NFC; determining whether the equipment identification information exists in a charging safety white list or not; if the equipment identification information exists in the security white list, generating a dynamic key according to the identification information of the vehicle and the hardware random number; encrypting the dynamic secret key and transmitting the encrypted dynamic secret key to terminal equipment through NFC; after feedback information returned by the terminal equipment is received, verifying whether the feedback information is correct or not; and if the feedback information is correct, controlling to charge the terminal equipment through the wireless charging panel. The method is used for effectively avoiding leakage of private data, so that the effect of improving the safety of vehicle-mounted wireless charging is achieved.
Owner:CHONGQING CHANGAN AUTOMOBILE CO LTD

Unmanned aerial vehicle parameter consistency configuration method based on template management

The invention relates to the technical field of unmanned aerial vehicle control and management, in particular to an unmanned aerial vehicle parameter consistency configuration method based on template management, which adopts a structured parameter configuration template in a JSON format, comprises four blocks of metadata, parameter definition, constraint rules and digital signatures, establishes an MAVLink communication link with an unmanned aerial vehicle flight controller through a template management terminal, and provides an unmanned aerial vehicle parameter consistency configuration method. And executing an automatic configuration process based on a finite-state machine, and ensuring parameter logic consistency by using a difference comparison and constraint verification mechanism. According to the method, temporary storage, batch writing and atomic submission of parameter changes are achieved through the atomization transaction submission protocol, the integrity of the configuration process is guaranteed, the digital signature auditing log containing the timestamp, the device identifier, the template hash and the change details is generated after configuration is completed, whole-process tracing is supported, and the method is high in practicability and easy to popularize. Headless mode operation, parameter white list control and hardware abstraction layer adaptation are supported, and high automation, standardization and safety of unmanned aerial vehicle parameter configuration can be achieved.
Owner:JIANGXI LIANCHUANG (WANNIAN) ELECTRONICS CO LTD

Ransomware double-layer defense method combining bait file monitoring and letter verification

The invention discloses a ransomware double-layer defense method combining bait file monitoring and letter verification, and belongs to the field of network security. Firstly, a ransomware double-layer defense mechanism in which a user mode module and a kernel mode module cooperatively work is constructed, and the user mode module generates a bait file and a letter white list and transmits the bait file and the letter white list to the kernel mode module. Then, the bait file monitoring module judges whether the target file of the ransomware is a bait file or not, and if the target file of the ransomware is the bait file, the bait file monitoring module directly blocks malicious behaviors and feeds back the malicious behaviors to the user mode module; and if the ransomware tries to directly encrypt the real user file, the bait file monitoring module transmits the operation request to the dynamic letter verification module for deep verification, and feeds back the processing result to the user mode module. And finally, the malicious process processing module executes a termination and isolation strategy on the malicious process. According to the method, various behaviors of ransomware are comprehensively covered, the false alarm rate is reduced, and the defense real-time performance and effectiveness are improved.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Dynamic audio buffer management method and system and medium

The invention relates to the technical field of software, and discloses a dynamic audio buffer management method and system and a medium. The method comprises the following steps: presetting a white list library of a plurality of application scenes, and matching a package name of a current foreground running application with the white list library to determine a current application scene; acquiring system performance state parameters in real time, wherein the parameters comprise at least one of a CPU occupancy rate, a memory occupancy rate and a temperature control and frequency limiting state; generating a buffer adjustment variable according to a statistical result of the audio lagging times; inputting the current application scene, the system performance state parameter and the buffer area adjustment variable into a preset strategy model, and outputting a buffer area gear value; and dynamically adjusting the size of a buffer area of an audio driving layer according to the gear value so as to adapt to the performance change of the system. According to the invention, the problem of lagging or delay caused by a fixed buffer area can be solved.
Owner:SHANGHAI LONGCHEER TECH CO LTD

Office system and method for digital security

The invention discloses a digital security-oriented office system and method, and relates to the technical field of information security and office automation, the digital security-oriented office system comprises a sensing module, a decision module, an execution module, a tracking module and a closed loop module, the sensing module collects login information, performs multi-factor verification, generates security sensing data, and sends the security sensing data to the decision module; the decision-making module compares security perception data with historical login information, divides risk levels and generates an access control decision, the execution module constructs a virtual security sandbox or verifies an access request based on a zero trust principle and generates an authority white list and cooperation timeliness, and the tracking module records an operation behavior and a security log through a block chain. The closed-loop module monitors an office scene in real time and drives data updating and sandbox destroying. According to the method, the whole-process security control of the office scene is realized, the risk is accurately identified, the protection strategy is dynamically adjusted, the high security requirement of cross-organization and internal office is met, and a powerful guarantee is provided for the security of digital office data.
Owner:SICHUAN YOUJIA TRACEABILITY TECH CO LTD

IoT (Internet of Things) access control system with active safety capability

The invention relates to the field of Internet of Things security, and discloses an IoT access control system with an active security capability, and the system comprises an Internet of Things security gateway, a network infrastructure and an external IoT service system: a port authentication module of the gateway executes the binding verification of an MAC white list and a dynamic IP-MAC; the traffic monitoring module loads a protocol feature sequence template based on a service type, and verifies a device traffic behavior in a time window; the equipment verification interface module is linked with the service system to verify the equipment registration state; and the active defense module triggers precise blocking and network repairing operation according to the verification result. According to the application, organic fusion of equipment identity credibility verification, service behavior compliance detection and attack instant disposal is realized, attacks such as MAC counterfeiting, protocol tampering and service layer counterfeiting are effectively defended, and meanwhile, through adaptive flow modeling and elastic strategy adaptation, the method is compatible with multiple service scenes such as intelligent buildings and industrial Internet of Things, and the service security is improved. And the active defense capability of the IoT network is remarkably improved.
Owner:LINGBO TECH (BEIJING) CO LTD