IP Library › Granted Patent US 12,267,303
Granted Patent B2
US 12,267,303 · App. 17/789,082 · Granted Apr 1, 2025

Input/output system applied to network security defense system

Inventors: Lei He (Zhengzhou, CN); Jiangxing Wu (Zhengzhou, CN); Qinrang Liu (Zhengzhou, CN); Ke Song (Zhengzhou, CN); Shuai Wei (Zhengzhou, CN); Jianliang Shen (Zhengzhou, CN); Libo Tan (Zhengzhou, CN); Yu Li (Zhengzhou, CN); Quan Ren (Zhengzhou, CN); Jun Zhou (Zhengzhou, CN); Min Fu (Zhengzhou, CN); Weili Zhang (Zhengzhou, CN); Ruihao Ding (Zhengzhou, CN); Yiwei Guo (Zhuhai, CN)
Assignees: CHINA NATIONAL DIGITAL SWITCHING SYSTEM ENGINEERING & TECHNOLOGICAL R&D CENTER; PURPLE MOUNTAIN LABORATORIES
H04L63/0281H04L1/0061
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,267,303
App. No.
17/789,082
Granted
Apr 1, 2025
Kind
B2
Abstract

A structural encoding unit and an error correction decoding unit are divided. The structure encoding unit is divided into input branch processor and an input proxy processor; and the error correction decoding unit is divided into an output routing processor, an output proxy processor, an adjudication branch processor, an adjudication proxy processor and a voting processor. The input branch processor is used for duplicating and distributing messages, the arbitration branch processor is used for duplicating and distributing data, the voting processor is used for performing voting, and the output routing processor is used for selecting an output result from processing results of the output proxy processor according to a voting result of the voting processor.

Claims (54)

1. An input-output system applicable in a network security defense system, the input-output system comprising a structural encoding unit and an error correction decoding unit, wherein:

the structural encoding unit comprises an input branching processor and an input proxy processor, wherein the input branching processor is configured for message replication and distribution, the input branching processor is verified as having no backdoor, and is configured for erasing a memory of generalized disturbance;

the error correction decoding unit comprises an output selecting processor, an output proxy processor, an arbitration branching processor, an arbitration proxy processor and a voting processor, wherein:

the arbitration branching processor is configured to replicate and distribute data,

the voting processor is configured to vote,

the output selecting processor is configured to select, based on a voting result of the voting processor, an output result from processing results of the output proxy processor,

the output selecting processor, the arbitration branching processor and the voting processor are verified as having no backdoor and have the memory erasure function, and

at least the output proxy processor and the arbitration proxy processor are set up with a dynamically heterogeneous redundancy mechanism,

wherein any one of the input branching processor, the output selecting processor, the arbitration branching processor, and the voting processor serves as a target processor,

the target processor is configured with a non-random disturbance memory erasure mechanism,

wherein the target processor is further configured with a redundancy and replacement mechanism, wherein

the redundancy and replacement mechanism enable the target processor to erase a memory of random disturbance; and

the non-random disturbance memory erasure mechanism comprises at least one of program curing, program tamper resistance, data initialization, and data tamper resistance.

2. The system according to claim 1 , wherein

the program curing comprises curing a program running in the target processor to prohibit changing a logic of the program, or curing, for a user, a program running in the target processor, to prohibit the user from changing a logic of the program; and

the program tamper resistance comprises at least one of the following:

comparing a program with a backup thereof, and replacing the program with the backup in response to logic difference between the program and the backup;

restoring, periodically or non-periodically, the program through a preset restoration method in the program;

verifying, in real time or non-real time, the program through a preset verification method; and

correcting, in real time or non-real time, the program based on a preset code for encryption or error correction.

3. The system according to claim 1 , wherein

the data initialization comprises initializing a storage space for data, or cleaning the storage space for the data; and

the data tamper resistance comprises at least one of the following:

comparing the data with a backup thereof, and replacing the data with the backup in response to difference between the data and the backup; and

verifying or correcting the data based on a code for verification, encryption, or error correction preset in the data, and initializing the data in response to a verification result indicating a data change.

4. The system according to claim 1 , wherein

the input branching processor is configured to replicate a received user request message into a plurality of copies, and distribute the plurality of copies of the user request message to the input proxy processor; and

the input proxy processor is set up with the dynamically heterogeneous redundancy mechanism.

5. The system according to claim 1 , wherein

the input proxy processor is configured to receive a user request message, and transmit the user request message to the input branching processor; and

the input branching processor is configured to replicate the user request message into a plurality of copies, and distribute the plurality of copies of the user request message to service executors.

6. An input-output system applicable in a network security defense system, the input-output system comprising a structural encoding unit and an error correction decoding unit, wherein:

the structural encoding unit comprises an input branching processor and an input proxy processor, wherein the input branching processor is configured for message replication and distribution, the input branching processor is verified as having no backdoor, and is configured for erasing a memory of generalized disturbance; and

the error correction decoding unit comprises a voting processor, an output selecting processor and an output proxy processor, wherein

the voting processor is configured to vote,

the output selecting processor is configured to select, based on a voting result of the voting processor, an output result from processing results of the output proxy processor, and

the output selecting processor and the voting processor are verified as having no backdoor and have the memory erasure function,

wherein any one of the input branching processor, the output selecting processor, and the voting processor serves as a target processor,

the target processor is configured with a non-random disturbance memory erasure mechanism,

the target processor is further configured with a redundancy and replacement mechanism, wherein

the redundancy and replacement mechanism enable the target processor to erase a memory of random disturbance; and

the non-random disturbance memory erasure mechanism comprises at least one of program curing, program tamper resistance, data initialization, and data tamper resistance.

7. The system according to claim 6 , wherein

the program curing comprises curing a program running in the target processor to prohibit changing a logic of the program, or curing, for a user, a program running in the target processor, to prohibit the user from changing a logic of the program; and

the program tamper resistance comprises at least one of the following:

comparing a program with a backup thereof, and replacing the program with the backup in response to logic difference between the program and the backup;

restoring, periodically or non-periodically, the program through a preset restoration method in the program;

verifying, in real time or non-real time, the program through a preset verification method; and

correcting, in real time or non-real time, the program based on a preset code for encryption or error correction.

8. The system according to claim 6 , wherein

the data initialization comprises initializing a storage space for data, or cleaning the storage space for the data; and

the data tamper resistance comprises at least one of the following:

comparing the data with a backup thereof, and replacing the data with the backup in response to difference between the data and the backup; and

verifying or correcting the data based on a code for verification, encryption, or error correction preset in the data, and initializing the data in response to a verification result indicating a data change.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 24, 2022
From: HE, LEI; WU, JIANGXING; LIU, QINRANG; SONG, KE; WEI, SHUAI; SHEN, JIANLIANG; TAN, LIBO; LI, YU; REN, QUAN; ZHOU, JUN; FU, MIN; ZHANG, WEILI; DING, RUIHAO; GUO, YIWEI
To: CHINA NATIONAL DIGITAL SWITCHING SYSTEM ENGINEERING & TECHNOLOGICAL R&D CENTER; PURPLE MOUNTAIN LABORATORIES
Reel/Frame 060310/0523 →
Priority Claims (1)
CN 202010519102.X · Jun 9, 2020 · national
Continuity (1)
Related Publication 20230039521A1 · Feb 9, 2023
References Cited (27)
US 20100040272A1 · Zheng · 2010 [cited by examiner]
US 20120124393A1 · Sethumadhavan · 2012 [cited by examiner]
US 20140287685A1 · Griffin · 2014 [cited by examiner]
US 20150131396A1 · Sosogi · 2015 [cited by examiner]
US 20170102943A1 · Voellmy · 2017 [cited by applicant]
US 20180234585A1 · Yano · 2018 [cited by examiner]
US 20190081639A1 · Hanham · 2019 [cited by examiner]
US 20200026965A1 · Guo · 2020 [cited by examiner]
US 20210342420A1 · Doré · 2021 [cited by examiner]
CN 107346272A · 2017 [cited by examiner]
CN 108134740A · 2018 [cited by applicant]
CN 109525594A · 2019 [cited by applicant]
CN 110177084A · 2019 [cited by applicant]
CN 110381008A · 2019 [cited by applicant]
CN 106790085B · 2020 [cited by examiner]
CN 112217604A · 2021 [cited by applicant]
EP 1059578A2 · 2000 [cited by applicant]
English translation of CN-107346272-A, Clarivate Analytics, 2017, pp. 1-20 (Year: 2017). [cited by examiner]
English translation of CN-106790085-B, Clarivate Analytics, 2020, pp. 1-16 (Year: 2020). [cited by examiner]
Saberi et al., State Estimation via Worst-Case Erasure and Symmetric Channels with Memory, 2019 IEEE International Symposium on Information Theory (ISIT), pp. 3072-3076 (Jul. 2019) (Year: 2019). [cited by examiner]
Wu, et al., “A Mimic Arbitration Optimization Method Based on Heterogeneous Degree of Executors” Computer Engineering, 2020, vol. 46, No. 5; pp. 12-18. [cited by applicant]
Ma Hailong et al., “Dynamic Heterogeneous Redundancy Based Router Architecture with Mimic Defenses” Journal of Cyber Security Jan. 2017, vol. 2, No. 1; 14 pages. [cited by applicant]
International Search Report and Written Opinion for PCT/CN2021/098596, dated Aug. 24, 2021; 9 pages, including English Translation of Search Report. [cited by applicant]
Song, et al. “An Equivalent Scheduling Strategy for Cyberspace Mimicry Defense Based on Security Priority” Procedings of the 2018 International Conference on Advanced Mechatronic Systems, Zhengzhou, China, Aug. 30-Sep. … [cited by applicant]
Kingming, et al., “Markov game modeling of mimic defense and defense strategy determination” Journal on Communications, vol. 39, No. 10; Oct. 2018; 12 pages. [cited by applicant]
Yurjia, et al., “Mimic Security Defense Strategy Based on Software Diversity” Computer Science, vol. 45, No. 2, Feb. 2018; 7 pages. [cited by applicant]
The State Intellectual Property Office of People's Republic of China: First Office Action issued in CN Application No. 202010519102.X dated May 20, 2022; 11 pages including English translation. [cited by applicant]