Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

97results about "Data taking prevention" patented technology

In-vehicle device, program, and information processing method

This vehicle-mounted device is connected to a vehicle-mounted network mounted on a vehicle, and is provided with a processing unit that performs a process relating to a determination of whether or not data flowing through the vehicle-mounted network is normal, receives periodic data periodically transmitted through the vehicle-mounted network, and transmits the periodic data to the vehicle-mounted network. When event data of the same type as the periodic data is received between the reception time points of two pieces of continuously received periodic data, a determination is made as to whether or not the event data is normal on the basis of the value of the payload of the event data and the value of the payload of at least one of the two pieces of periodic data.
Owner:AUTONETWORKS TECH LTD +2

Route selection system, route selection method and program

PendingJPWO2024180603A5Data taking prevention
A route selection system (10) according to one embodiment of the present disclosure comprises: an acquisition means (11) that acquires access information that at least includes information regarding access purposes, security information that indicates communication route security regarding a usable communication route from an access source to an access destination, and route characteristic information that at least includes performance information indicating the performance of a communication route; and a selection means (12) that selects, using the access information and route characteristic information, one or more communication routes that are used for communication between the access source and the access destination.

Communication control system, communication method and program

To provide a communication control system for easily setting a RADIUS client and provide a method.SOLUTION: A communication control system 1 contains: an access point 10 that includes a function as a RADIUS server for determining whether or not a network communication of a terminal is identified or a first RADIUS client corresponded to the RADIUS server, and stores identification information and a secret key for identifying the RADIUS server; and a layer 2(L2) switch 20 directly connected in a network segment similar to the access point. The access point 10 contains a transmission part that transmits the stored identification information and the secret key to the L2 switch in a first time period. The layer L2 switch contains: a reception part that receives the identification information and the secret key transmitted from the access point; and a setting part that performs a setting so that the L2 switch is operated as a second RADIUS client corresponded to the RADIUS server on the basis of the received identification information and the secret key.SELECTED DRAWING: Figure 1
Owner:YAMAHA CORP

Integrated wireless platform

A system is provided. The system includes a plurality of wireless access points (WAPs) corresponding to a plurality of wireless communication protocols. The system includes a wireless local network server coupled to the plurality of WAPs via a communication bus. The wireless local network server is configured to convert data under the plurality of wireless communication protocols to data under a local protocol. The system includes a data diode communicatively coupled to the communication bus. The system includes a processor configured to control the data diode to exchange the data under the local protocol between the plurality of WAPs. Also provided is a method and an apparatus.
Owner:SAUDI ARABIAN OIL CO +1

Communication analysis system, analysis method, and program

A communication analysis system includes: an information obtainer (2501) that obtains past communication information indicating communication performed by a monitoring target (10); a prediction target link extractor (2502) that extracts, based on the past communication information obtained, an unestablished communication link of communication that has not been established in the past communication information, the unestablished communication link being at least one communication link that is a prediction target; a link confidence level calculator (2504) that calculates a confidence level indicating the likelihood that the unestablished communication link extracted will be established as a normal communication link in the future; and a NW graph creator (2506) that creates a NW graph, in which the unestablished communication link and information regarding the unestablished communication link are mapped, as graph information for determining whether to add the communication link to a whitelist (22), using the unestablished communication link extracted, the confidence level calculated, and the past communication information obtained.
Owner:PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA

Communication analysis system, analysis method, and recording medium

A communication analysis system includes: an information obtainer that obtains past communication information indicating communication performed by a monitoring target; a prediction target link extractor that extracts, based on the past communication information obtained, an unestablished communication link of communication that has not been established in the past communication information, the unestablished communication link being at least one communication link that is a prediction target; a link confidence level calculator that calculates a confidence level indicating the likelihood that the unestablished communication link extracted will be established as a normal communication link in the future; and a NW graph creator that creates a NW graph, in which the unestablished communication link and information regarding the unestablished communication link are mapped, as graph information for determining whether to add the communication link to a whitelist, using the unestablished communication link extracted, the confidence level calculated, and the past communication information obtained.
Owner:PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA

Vehicle communication system and vehicle communication methods

Vehicle communication system, comprehensive: an on-board device (130); and one or more vehicle controllers (120) connected to a vehicle network (NW1, NW2) wherein the on-board device (130) is configured to perform the following steps: Transmitting an encrypted message (MS), encrypted outside of a vehicle, to one or more vehicle controllers (120) connected to the vehicle network (NW1, NW2); and if the encrypted message (MS) is an individual message to one of the vehicle controllers (120), transmission of the encrypted message (MS) to one of the vehicle controllers (120) via the vehicle network (NW1, NW2); and if the encrypted message (MS) is a common message to the one or more vehicle controllers (120), decrypt the encrypted message (MS) using an encryption key (K2, K5) belonging to the on-board device (130), and then transmit the decrypted message to the one or more vehicle controllers (120) via the vehicle network (NW1, NW2).
Owner:TOYOTA JIDOSHA KK

System and method to communicate using a secure obfuscated network

A dual-mode communication device adapted for communication over a public network, wherein the dual-mode communication device is adapted to be operated in a normal mode and in an obfuscated mode. The dual-mode communication device includes a processor and a network interface device. The processor develops a frame from a payload received by the dual-communication device and, if the dual-mode communication device is operating in the obfuscated mode, an obfuscated frame from the frame. The frame and the obfuscated frame comprise a preamble that conforms with protocols associated with the public network and the processor. A network interface transmits one of the frame or the obfuscated frame using the public network. The payload may be extracted from the frame by any receiving device operating in the normal mode in the public network and the payload may be extracted from the obfuscated frame only by another communication device also operating in the obfuscated mode in the public network.
Owner:NORTHROP GRUMMAN SYSTEMS CORP

Communication device, communication method, and program

To prevent normal data frames from being discarded when a communication device establishes a connection via multiple frequency channels.SOLUTION: In a state in which a communication device 102 and a communication device 103 have established a connection via a first frequency channel on a first link 104, it is determined whether the communication device 103 has established a connection via a second frequency channel on a second link 105, and if it is determined that the communication device 103 has established a connection via the second frequency channel, a cryptographic key common to communication via the first frequency channel and communication via the second frequency channel is set.SELECTED DRAWING: Figure 1
Owner:CANON KK

Communication device

To provide a communication device capable of determining that an unauthorized device is connected by the communication device as a single unit.SOLUTION: A communication device includes a transceiver 10 and a controller 20. The controller outputs a transmission signal including identification information as a communication signal to be transmitted through a communication wire, and receives a reception signal including the identification information as a communication signal received through the communication wire. The transceiver is connected to the communication wire, transmits the transmission signal inputted from the controller from the communication wire, and outputs the reception signal received from the communication wire to the controller. The transceiver includes a storage part 132 for storing the identification information included in the transmission signal, and a processing part 131 for determining that an unauthorized device is connected to the communication wire in the case that the same identification information as the identification information included in the reception signal is stored in the storage part.SELECTED DRAWING: Figure 2
Owner:DENSO CORP

Security policy analysis

A security policy analysis is disclosed. Configuration information containing at least one policy is received. A model is built using the received configuration information, which includes normalizing the policy. A policy analysis is performed using the policy, which includes performing a pre-change analysis associated with the proposed policy change. The results of the policy analysis are provided as output.
Owner:PALO ALTO NETWORKS INC

Information management system having firewall with transparency setting function

The information management system includes a firewall connected to a network camera (i.e., a device) having an image capturing function and a sound collecting function and a management server performing an authentication process for authenticating a user using the user terminal between the management server and the user terminal and allowing the user terminal to connect to the network camera via the firewall. The information management system is configured to acquire, via the firewall, media data including an image captured by the network camera and an audio collected by the network camera from the network camera to which the user terminal is allowed to connect based on a connection permission condition defined in the management server.
Owner:PZP CO

Information processing system and program

To suppress an increase in a load required for the determination compared to when an electronic certificate is used to determine whether to permit access, and to prevent unnecessary prohibition of access to the system to be accessed compared to when the permission of access is determined only on the basis of information indicating the destination.SOLUTION: In a case in which a user specifies a system to be accessed and an operation to be performed on that system, when the information indicating the destination of the system specified by a user and the information indicating the operation specified by the user are not linked and stored in memory, a processor requests the system to perform name resolution based on the information indicating the destination of the system specified by the user, and accesses the system according to the address obtained in response to the request.SELECTED DRAWING: Figure 1
Owner:FUJIFILM BUSINESS INNOVATION CORP

Unauthorized signal detection device, vehicle, and unauthorized signal detection method

To provide a fraudulent signal detection device and a fraudulent signal detection method for detecting that a fraudulent signal is input to a communication network where signals are expected to be input at a predetermined period.SOLUTION: In a vehicle, a fraudulent signal detection device (ECU 110) includes a measurement unit that measures a time interval between a plurality of consecutive signals input to a communication network in chronological order, and a determination unit that determines that a conflict has occurred when a second signal is transmitted, and determines that the second signal is a mediated normal signal if a time interval between a first signal and the second signal that should be transmitted at the time interval is longer than the time interval, and a signal interval between the second signal and a signal input immediately before is equal to or less than a predetermined interval.SELECTED DRAWING: Figure 2
Owner:HONDA MOTOR CO LTD

Information processing device, information processing method, and information processing program

The information processing apparatus (100) includes: an acquirer (121) configured to acquire a security log including information regarding unauthorized communication stored in the upper NW device being a device constituting an overlay network, an authentication log stored in the cloud server, and a communication log stored in the lower NW device being a device constituting an underlay network; a specifier (123) configured to specify information such that, when the authentication log includes a connection source IP address that does not exist in the communication log acquired by the acquirer (121) and the security log includes information regarding an access not permitted to be used from the connection source IP address, the specifier (123) specifies the information regarding the access as unauthorized communication; and a blocking instructor (124) configured to give an instruction for blocking of the unauthorized communication specified by the specifier (123).
Owner:NTT DOCOMO BUSINESS INC

Information processing device, information processing program, and information processing method

This makes it easy to analyze the settings of firewall policies. [Solution] The information processing device according to the present invention comprises: a configuration file that describes a firewall policy that controls packet transmission based on a pre-configured policy; a policy format that shows a policy description pattern; an extraction unit that identifies an authorization record from the configuration file that corresponds to a policy containing authorization information that allows the firewall to transmit packets; and extracts source information and destination information from the authorization record; and a generation unit that generates first communication pattern information relating to a communication pattern permitted between the source and the destination based on the source information and destination information.
Owner:SOFTBANK CORPORATION

Information processing system, information processing method, and information processing program

The information processing system (1) is an information processing system including: an upper NW device (100) being a device constituting an overlay network; and a lower NW device (200) being a device constituting an underlay network. In this system, the upper NW device (100) detects unauthorized communication, specifies at least one of a communication destination and a communication source of the unauthorized communication using information regarding the unauthorized communication detected, notifies the lower NW device (200) of at least one of the communication destination and the communication source of the specified unauthorized communication. The lower NW device (200) acquires information related to communication of a terminal connected to the lower NW device (200), and blocks unauthorized communication based on the information regarding the unauthorized communication notification of which is provided.
Owner:NTT DOCOMO BUSINESS INC

Information processing device and botnet analysis method

To accurately identify a conning-tower server in a botnet and perform detailed analysis, such as classifying the botnet.SOLUTION: An information processing device 10 detects bots that constitute a botnet by analyzing packets observed on a dark net. Based on the packets transmitted from the detected bots, the information processing device 10 classifies the bots according to their types and identifies the common communication destination of the classified bots as a conning-tower server for the bots.SELECTED DRAWING: Figure 2
Owner:NIPPON TELEGRAPH & TELEPHONE CORP

Threshold calculation device, abnormality detection device, threshold calculation method, and abnormality detection method

A threshold value calculation device according to the present invention calculates a threshold value used in an abnormality detection device for detecting abnormal communication in a first device in a facility in which a home network (11) is installed. A second device different from the first device is provided in the facility. The threshold value calculation device is provided with: a device state acquisition unit (110) for acquiring a device state of the first device in a first time period; a room occupancy situation determination unit (120) for determining a room occupancy situation of a person who is present in the facility in the first time period on the basis of information acquired from the second device; a communication log collection unit (130) for collecting a communication log generated by communication transmitted and received by the first device in the first time period; and a learning unit (140) for calculating a threshold value for communication in the first device in a second time period subsequent to the first time period on the basis of the device state, the room occupancy situation, and the communication log. The device state includes at least one state of the first device, the room occupancy situation includes at least one situation of the person, and the learning unit (140) calculates a threshold value for each combination of the at least one state and the at least one situation.
Owner:PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA

Automated web traffic anomaly detection

An anomaly detection system that includes a database and a server. The server is connected to the database. The server is configured to identify anomalous web traffic for a certain time period based on one or more client keys from the certain time period. The client key(s) includes at least two characteristics related to web traffic data. The server includes a processing unit and a memory. The server is configured to receive the web traffic data from the database, calculate a z-score metric for the client key, calculate a change rate metric for the client key, calculate a failure metric for the client key, determine an anomaly score based on the z-score metric, the change rate metric, and the failure metric, and determine that the certain time period is an anomalous time period based on the anomaly score.
Owner:MASTERCARD TECHNOLOGIES CANADA ULC

Method for managing a terminal connection

Terminal Connection Management Procedure The process for managing a connection from a terminal (T1) to a communication service, via at least one network (R), is implemented by a management device (DG) and comprises: - a step of receiving, from said terminal (T1), a first identifier contained in a signal of said connection, - in the absence of a match between the first identifier and a second identifier contained in at least one media stream of the communication service supported by the connection, a step of rejecting the connection of said terminal. Figure for the abbreviation: Figure 1
Owner:ORANGE SA

Vehicle-mounted relay device, vehicle-mounted relay method, and vehicle-mounted relay program

To improve security while suppressing communication delay in an on-vehicle network.SOLUTION: An on-vehicle relay device comprises: a reception section which receives a frame from an on-vehicle unit; a first IC (Integrated Circuit) which performs relay processing of the frame received by the reception section; and a second IC which is connected between the reception section and the first IC, outputs the frame received from the reception section to the first IC and outputs the frame received from the first IC to the outside of the on-vehicle relay device. The second IC monitors the frame and, in a case where it is determined that the frame is an unauthorized frame, stops outputting the frame.SELECTED DRAWING: Figure 3
Owner:AUTONETWORKS TECH LTD +2

In-vehicle network

To provide an ECU layout determination method with which it is possible to suppress the adverse effect of illegal access to an onboard network.SOLUTION: The layout of each ECU is determined on the basis of the cost attributable to the number of wire and the diameter of wire used in an onboard network (step ST4). The form of wire division for realizing the layout of each ECU is determined, and accordingly the position of a connector located at the divided position and the number of connectors are determined (step ST5). Determination is made as to whether or not there exists an ECU whose access difficulty is low (step ST7), and when a bus to which an ECU having security risk is connected is the one that has an ECU connected thereto whose security level is not high, the ECU having security risk is connected to anther bus by layout change and an onboard network to be established is determined (step ST10).SELECTED DRAWING: Figure 2
Owner:TOYOTA JIDOSHA KK