Systems and methods for creating situational networks

The system efficiently identifies and interconnects devices in a geographic area affected by a situation, establishing multiple communication channels to facilitate timely information exchange during emergencies, addressing the limitations of existing systems.

JP2026504848APending Publication Date: 2026-02-10シットネット エルエルシー
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025540756
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-01-11
Filing Date
2024-01-11
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

Existing emergency communication systems lack the ability to quickly and efficiently identify and interconnect devices of participants needed for a situation network, often leading to overloaded systems and limited communication capabilities during emergencies or large-scale events, and fail to provide information to users not directly affected by the situation.

Method used

A system that identifies devices in a geographic area affected by a situation, shares protected data, and establishes multiple group communication channels using various communication modes, such as SMS and WhatsApp, to facilitate efficient communication among affected users and allocate resources effectively.

Benefits of technology

Enables efficient communication among affected users without system overload, allows users to receive situation-related information, and quickly forms communication channels across different platforms, ensuring timely information exchange during emergencies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026504848000001_ABST
    Figure 2026504848000001_ABST
Patent Text Reader

Abstract

A system and method are provided for establishing multiple group communication channels for multiple subsets of a plurality of devices. A situation system identifies a geographic area affected by a situation and multiple devices associated with multiple users in the identified geographic area. The situation system causes the multiple devices to enter a situation mode. The situation system retrieves protected data from each of the multiple devices. The situation system generates a data structure identifying connections between users of the multiple users and available communication modes for each connection. The situation system establishes multiple group communication channels for the multiple subsets of the plurality of devices.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] (CROSS-REFERENCE TO RELATED APPLICATIONS) This application claims the benefit of U.S. Provisional Patent Application No. 63 / 438,395, filed January 11, 2023, which is incorporated herein by reference in its entirety. This application also claims the benefit of U.S. Provisional Patent Application No. 63 / 438,392, filed January 11, 2023, which is incorporated herein by reference in its entirety.

[0002] The present disclosure relates to systems and methods for causing multiple devices to enter a situational mode in which multiple group communication channels are established for multiple subsets of the multiple devices. Summary of the Invention [Means for solving the problem]

[0003] Many situations affect large groups of people simultaneously. Some examples of such situations include emergencies (e.g., natural disasters, terrorist attacks, active shooter events, etc.) and social gatherings (e.g., concerts, conferences, parties, etc.). In these situations, it is often beneficial for a system to provide information relevant to the situation to those involved. For example, it is beneficial for people affected by an earthquake to receive updates about the earthquake, such as assistance information and the safety status of loved ones. Systems often lack the ability to quickly and efficiently identify the devices of participants needed for a situation network for a particular situation and interconnect them via one or more platforms (e.g., platforms that do not remember relationships between participants).

[0004] In one approach, emergency alert systems, such as those used by police and fire departments (e.g., emergency 911 systems, as augmented by systems such as FirstNet and Emergency Call Works), provide a channel for users to report emergency situations to local authorities and emergency services via telephone calls. In another approach, emergency alert systems (e.g., Emergency Alert System, Wireless Emergency Alerts, etc.) provide a foundation for emergency communications via SMS messages, television broadcasts, public radio, wireless cable, and satellite services. In another approach, social networks may provide the ability to identify potential participants for a situation network based on stored relationships between parties, geographic locations, their relationships to nodes representing the situation, qualifications, posts, behaviors, interests, and other attributes associated with their profiles and history on the social network. However, social networks are not always the primary means of communication between individuals, many of whom will rely on linear networks such as cellular calls, short messaging service (SMS, also known as "text messaging"), WhatsApp, Slack, Microsoft Teams, or even email to communicate with each other.

[0005] While such emergency communication systems may identify devices of users affected by an emergency situation, many drawbacks are apparent. One drawback is that existing emergency communication systems are one-way communication channels, thus lacking the ability for affected users to communicate with other affected users via a specific communication channel. Another drawback of existing emergency communication systems is that users not directly affected by the situation do not receive information about the situation. For example, parents of a child attending school in another state or country would want to receive information about emergency situations in their child's area. Another drawback is that the above systems are used only for emergency situations and still lack on-the-fly communication channels with relevant users for non-emergency situations, such as social events. While situations may be easily identifiable on social networks (and relevant participants identified), it may be beneficial or even necessary to interconnect parties through other networks and thus form a situation network on a platform that does not inherently remember relationships or that remembers only limited relationships, such as an association between an individual and an employer (e.g., a member is part of a company).

[0006] Another drawback is that the system can become overloaded with the number of incoming calls or network messages at one time, such as in the case of a large-scale emergency. When the same communication mode is used by many geographically close devices (e.g., when all phones are trying to send SMS or WhatsApp messages), the system's capacity to handle all the traffic can be degraded, resulting in slow service or even some messages being dropped. For example, a WhatsApp server or a Wi-Fi network can become locally overloaded. Such an outcome is undesirable, especially in an emergency situation when each message can be critical.

[0007] What is needed is a system that quickly identifies the necessary participants arising from a particular situation and interconnects them over one or more platforms and / or networks, including platforms that may not remember the participants or the relationships between the nodes that identify them as participants. Once identified, participants can be connected and resources (e.g., communication channels and associated bandwidth, memory and access to stored databases and documents) allocated so that they can communicate effectively about the situation. In addition, parties should have the ability to choose to participate or not participate in a situation network to which they are invited or added.

[0008] To help address these issues, in some embodiments, the situation system identifies a geographic area affected by a situation. For example, the situation system identifies that an earthquake occurred in the Bay Area of ​​California. In some embodiments, the situation system identifies multiple devices associated with multiple users in the identified geographic area. For example, the situation system identifies smartphones belonging to users in the Bay Area. In some embodiments, the situation system identifies the geographic area by obtaining motion data from motion sensors on multiple devices that is indicative of an emergency situation. For example, during an earthquake in the Bay Area, the situation system receives shaking motion data from smartphones in the Bay Area. In some embodiments, the situation system identifies the geographic area by identifying multiple calls to emergency services from multiple devices. For example, the situation identifies that many smartphones in the Bay Area are calling 911.

[0009] In some embodiments, the context system causes multiple devices to enter a context mode, and the devices in the context mode are configured to share protected data. In some embodiments, the context system makes a particular device available over the network for access to at least one of (a) data stored on the particular device that is inaccessible over the network when the particular device is not in context mode, or (b) a sensor data stream from at least one sensor of the particular device that is inaccessible over the network when the particular device is not in context mode. For example, while a smartphone is in context mode, the context system may have access to messaging application usage data.

[0010] In some embodiments, the context system obtains secured data from each of the plurality of devices, the secured data comprising contact list information from a plurality of communication modes available on each of the plurality of devices. For example, smartphones in the Bay Area provide user relationship data, contact information, and communication preference information to the context system after the context system identifies the occurrence of an earthquake. In some embodiments, the context system generates a data structure that identifies connections between users of the plurality of users and identifies available communication modes for each connection based on the contact list information for each of the plurality of devices. For example, the context system generates a graph of relationships between user device nodes and various available forms of communication used between the user device nodes.

[0011] In some embodiments, the available communication modes comprise one or more of: (a) messaging applications installed on the multiple devices; (b) physical network interfaces present on the multiple devices; or (c) a combination of messaging applications and physical network interfaces. For example, different group communication channels may use different combinations of messaging applications and physical network interfaces, e.g., one channel using WhatsApp over Wi-Fi and another using Microsoft Teams over AT&T cell service. In some embodiments, multiple cell services, e.g., AT&T and Verizon, are utilized by the situation system. In some embodiments, the situation system generates a graph in which each user of a multiple number of users is represented by a node, and generates edges for the graph, each edge connecting two nodes of the graph and identifying available communication modes for communication between user devices associated with the two nodes. For example, the situation system generates a graph with two connected nodes indicating that the represented users can communicate through WhatsApp.

[0012] In some embodiments, the situation system establishes multiple group communication channels for multiple subsets of the multiple devices based on the data structure, with each group communication channel of the multiple group communication channels enabling communication via one of the available communication modes. For example, a situation network can be established over an optimal communication mode (e.g., SMS, WhatsApp, etc.) to interconnect users affected by a crisis or event, allowing them to ensure their safety and communicate among themselves. In some embodiments, the situation system transmits situation-related information to each of the multiple devices via the established multiple group communication channels. For example, the situation system sends relevant update messages to each smartphone in a group of smartphones designated to use WhatsApp during an earthquake.

[0013] In some embodiments, the context system receives sensor data from a plurality of devices in a context mode. The context system constructs a 3D representation of the identified geographic area based on the sensor data and generates the 3D representation on an extended reality (XR) display for display. In some embodiments, the context system transmits at least a portion of the 3D representation to each of the plurality of devices via the established plurality of group communication channels.

[0014] In some embodiments, for each device of the plurality of devices, the context system determines a subset of the plurality of subsets to which the individual device belongs. The context system identifies communication modes for individual group communication channels of the determined subset and disables or throttles communication modes other than the identified communication modes on the individual device. For example, a group of devices that use SMS messaging may have throttled Wi-Fi connectivity, leaving resources for another group of devices that use WhatsApp over Wi-Fi.

[0015] Such aspects allow devices associated with a user in an emergency situation to communicate with each other efficiently and quickly, without delays from an overloaded system. Because communication between multiple geographically nearby devices is spread via many communication modes, such as WhatsApp and SMS, the system is not overloaded by the number of incoming alerts or network messages at once, such as in the case of a large-scale emergency, and messages are not dropped. Such aspects also allow devices associated with a user to receive news of a situation without having to have a previous communication channel with other affected users. For example, a user may not have the phone numbers of their neighbors, but if the situation system forms a WhatsApp group message during an earthquake, the user can communicate with their neighbors and exchange useful information. Such aspects also allow users to be in a position to quickly contact each other without having to manually form group or individual chats. This is particularly beneficial in emergency situations, where fast communication is often important.

[0016] The advent of virtual reality (VR) systems now allows users to participate in either virtual or physical events, allowing participants from around the world to witness or, in some instances, participate in the event. Because the number of participants can be significantly large, methods and systems identify users who should be connected to the event and for whom resources (e.g., bandwidth) should be allocated. For some events, such as crises or medical emergencies, it becomes important to interconnect required personnel. When a virtual event is established to respond to a physical crisis or medical emergency, users can participate virtually and potentially contribute information or skills, but they need to be identified and properly connected.

[0017] Some networks store significant information about users and their associations. Social networks such as Facebook and LinkedIn store vast amounts of information about users and their associations (e.g., locations and interests, skills and qualifications, friends, employment). The number of monthly users (and therefore nodes representing those users) exceeds a billion for some social networks, and therefore the number of stored associations is orders of magnitude larger. It would be desirable to be able to monitor the relationships and presence of specific nodes within a social network and create a situation network that transcends the social network and interconnects parties that appear on linear networks such as SMS and WhatsApp, as well as on virtual networks (e.g., the metaverse). Given the number of nodes and associations on social network platforms, methods and systems are needed that can efficiently extract relevant relationships and nodes from the social network, create a situation network, and extend it to linear networks such as SMS and WhatsApp. The advent of "big data," which includes the amount of data stored within social networks, plus information about individuals and their status (e.g., physical parameters such as location, pulse rate, communication records, browsing habits, etc.) and detailed information about objects (e.g., vehicles, including information about location, speed and direction, acceleration, engine parameters, etc.), only exacerbates the situation in terms of determining who and what should be interconnected in a particular situation. While big data, combined with artificial intelligence ("AI") data mining techniques, offers the ability to gain enormous insights into individuals, their habits, and their desires, the sheer volume of data makes it computationally difficult to identify the relevant individual in any given situation.

[0018] What is needed is a system and method in which affected parties can be identified through both social networks and linear networks (e.g., SMS networks), where users maintain contact and communicate only with a defined number of individuals or departments with whom they have a recent or regular contact history. Additionally, it is desirable to establish a cross-platform (e.g., from social networks to personal networks) situational network so that communication between participants is not limited to one platform. For applications incorporating a metaverse, the ability to identify and interconnect appropriate individuals from anywhere in the world is essential. As described above, resources such as bandwidth and access to memory need to be appropriately allocated to support interconnections and not allow system resources to be inappropriately used by parties not relevant to the situation.

[0019] The required system should be able to identify relevant participants in a situation network within a very short time period based on their relationships, their relationship to other parties identified as relevant to the situation, their degree of separation from the selected user / node, their geographic location when relevant (both relative to the situation and to other parties involved in the situation itself), their history within the social network, their qualifications, their behavior, and other parameters that indicate their suitability or need to be part of the situation network. The system should also be able to allocate resources (e.g., establish links) for communication between participants as required on either the social network in which they are identified or on an auxiliary network. This must all occur within a short time period, ensuring the usefulness of the situation network.

[0020] Methods and systems are presented in which a server projects a situational network from a social network, graph, or other database, and connections between parties are established over the social network, an associated or unassociated one-dimensional network, a metaverse, or a combination thereof. The networks can be operated by a single service provider or independent service providers and may operate using the same or different protocols. An example would be a social network (e.g., a first network) running on a first set of servers and relying primarily on Internet protocols (e.g., TCP / IP (Transmission Control Protocol / Internet Protocol), UDP / IP (User Datagram Protocol / Internet Protocol), HTTP (Hypertext Transfer Protocol), and FTP (File Transfer Protocol)) for communications, and a second network operating over SMS, radio frequency voice communications (e.g., a 911 emergency network), or other protocols distinct from those over which the social network operates.

[0021] The server creates projections from social networks or graph databases based on a set of defined criteria to identify desired participants for the situation network, and upon request, creates an intermediate database that links desired participants within the situation network across platforms using a combination of user identifiers, including, but not limited to, social network handles and names, phone numbers, device IDs, MAC addresses, IP addresses, and email addresses, or any combination of the above. The server creates the intermediate database, which can reside on the creating server, another server, or in the cloud. The intermediate database is accessed by a second network, which can operate on the same or a different protocol as the first network. An example of a second network would be a short messaging service (SMS) network, in which communication occurs using a telecommunications network with telephone number-based addressing and communication via a telecommunications infrastructure, including Signaling System 7 (SS7). The creation of the intermediate database by the server and access of that database by servers supporting the second network allows the situation network to be operated on platforms beyond the one on which it is deployed.

[0022] A server, network interface device, or other computing platform may [ka] By applying operators such as [ka] or a combination of both, by applying operators such as [ka] By applying

[0000] (

[0000] ), participants for the situation network are projected from the social network. The resulting network is the situation projection S(G). Users in the situation projection S(G) can connect with each other via the social network or through one-dimensional networks such as SMS or WhatsApp by finding corresponding users and creating appropriate groups (e.g., text or chat groups).

[0023] In some embodiments, a node may represent a situation (e.g., a weather event, a public safety threat, a disaster) associated with a particular geographic location. In this instance, the social network includes user location information as part of the user node or in a separate node. A projection operator, performed by a server or other computing device, finds users registered in the social network that are geographically proximate to the weather event and marks them as affected parties. To enable communication across the social network, affected parties (projected from the social network) can connect with each other via SMS or other one-dimensional networks by creating appropriate groups and adding or inviting affected parties to the groups. In some embodiments, an intermediate database ID[S(G)) stores the identities (e.g., usernames, phone numbers, user IDs) of desired participants (identified as S(G)) and is used to create a specific situation network for one or more platforms. Thus, the intermediate database captures the identified requested or desired participants in the social network and establishes the required connections for the situation network on the second platform.

[0024] In the aforementioned situations, a situation network is projected or projected from a network (e.g., a social graph or social network) containing the required association and event node information. The projection sorts through the relationships and events quickly established and stored in the social network and determines important participants based on the situation. The system, operating on one or more servers and consisting of a first network having social graph characteristics from which participants for the desired situation network are projected, then allocates resources to establish the desired interconnections between the parties and allocate other system resources, including, but not limited to, resources (e.g., bandwidth) associated with their interconnections and access to information stored therein. In some embodiments, resources can be deallocated to specific users / nodes either because the situation requires limiting their access or because resources are required by other participants in the situation network.

[0025] In some embodiments, the system prioritizes certain communication modes (e.g., SMS or WhatsApp) over other communication modes (e.g., Facebook, Instagram) because the user preferentially uses those modes. In some embodiments, certain apps or communication modes are deprioritized or turned off so that the user's attention is directed to the communication mode through which messages related to the situation and situation network are transmitted.

[0026] To efficiently identify and incorporate appropriate nodes into the situation network, one or more "seed" techniques can be used to project candidate participants. For example, a degree of separation can be used such that parties known to have been affected by the situation serve as seeds, and nodes connected by n degrees of separation are considered to determine whether they should be included in the projection. The search can be based on projection criteria that are independent of the degree of separation or that vary based on the degree of separation. In some embodiments, geographic location is used to seed the projection, and the initial projection is based on nodes identified to be within a specified radius r of a location, with r gradually increased to result in additional nodes. This allows for rapid identification, where nodes closest to the situation are identified and incorporated into the situation network.

[0027] In some embodiments, the seeds are based on specific associations, which are stored as links. Associations, including but not limited to employment, interests, attendance, behavior, activity, data patterns, or other parameters associated with a user / node, are used alone or in conjunction with node parameters (e.g., identity, title, location) to initiate a projection. Other nodes or association parameters can then be added to the projection to increase the number of nodes identified in the projection. By limiting the number of nodes in the initial projection, the system can identify a first set of participants for the situational network and then expand the projection to identify and include other participants.

[0028] In some embodiments, the system performs projection based on a synchronous search, in which the search begins on one or more nodes and their associated nodes based on a seed or other criteria, and proceeds to other nodes, sequentially projecting and extracting nodes in the process. This has the advantage of providing an immediate response and immediately identifying nodes to be incorporated into the context network based on seed parameters (e.g., degree of separation, location). In some embodiments, the system initiates an asynchronous search across the database, adding nodes to the projection as they are identified in the independent and non-blocking search. In some embodiments, a combination of synchronous and asynchronous searches is used.

[0029] One or more nodes can serve as active nodes in the projection process and be used as nuclei for projection. In some embodiments, a node is designated as an active node or a situation node, and projection is based on that node. A node can serve as the basis for synchronous projection for the identification of related nodes to be incorporated into the situation network. Such a node can also serve as a situation authority, having the authority and basis for incorporating other nodes into the situation network or networks. [Brief explanation of the drawings]

[0030] The present disclosure, in accordance with one or more various embodiments, will be described in detail with reference to the following figures. The drawings are provided for illustrative purposes only and merely depict typical or exemplary embodiments. These drawings are provided to facilitate understanding of the concepts disclosed herein and should not be considered limiting of the scope, scope, or applicability of these concepts. It should be noted that for clarity and ease of illustration, these drawings are not necessarily made to scale.

[0031] [Figure 1]FIG. 1 shows an illustrative example of a representative social network, depicted as a social graph, according to some embodiments of the present disclosure.

[0032] [Figure 2] FIG. 2 shows illustrative examples of undirected and directed social graphs according to some embodiments of the present disclosure.

[0033] [Figure 3] FIG. 3 shows an illustrative example of a linear contact list for two users, according to some embodiments of the present disclosure.

[0034] [Figure 4] FIG. 4 shows an illustrative example of a representative Simple Messaging Service (SMS) network, according to some embodiments of the present disclosure.

[0035] [Figure 5] FIG. 5 shows an illustrative example of an architecture for a network such as WhatsApp, according to some embodiments of the present disclosure.

[0036] [Figure 6A] FIG. 6A illustrates a link and node operator diagram for creating a situation projection S(G) according to some embodiments of the present disclosure. [ka] An illustrative example of the use of

[0037] [Figure 6B] FIG. 6B shows an illustrative example of a hierarchical graph database that stores communication modes as associations between nodes, representing users, in accordance with some embodiments of the present disclosure.

[0038] [Figure 7]FIG. 7 shows an illustrative example of a representative communication for a situational network formed over a text or chat application, according to some embodiments of the present disclosure.

[0039] [Figure 8] FIG. 8 shows an illustrative example of the use of multiple projections (e.g., S1(G), S2(G), and S3(G)) to create three situational networks for different types of access based on the parties, in accordance with some embodiments of the present disclosure.

[0040] [Figure 9A] FIG. 9A shows an illustrative example of participants and infrastructure in a multi-network situation network for a cybersecurity use case, according to some embodiments of the present disclosure.

[0041] [Figure 9B] FIG. 9B shows an illustrative example of the formation of a physical context network corresponding to an example association network for a cybersecurity use case, according to some embodiments of the present disclosure.

[0042] [Figure 9C] FIG. 9C shows an illustrative example of formed and combined situation networks for an exemplary cybersecurity use case, according to some embodiments of the present disclosure.

[0043] [Figure 9D] FIG. 9D shows an illustrative example of a permission table for a combined context network for an exemplary cybersecurity use case, in accordance with some embodiments of the present disclosure.

[0044] [Figure 9E]FIG. 9E shows an illustrative example of a representative terminal display for different participants in a combined situation network for an exemplary cybersecurity use case, according to some embodiments of the present disclosure.

[0045] [Figure 10] FIG. 10 shows an illustrative example of a representative implementation of a system for creating a cross-platform situational network according to some embodiments of the present disclosure.

[0046] [Figure 11] FIG. 11 is a flowchart of an illustrative process for a VR use case, according to some embodiments of the present disclosure.

[0047] [Figure 12A] FIG. 12A shows an illustrative example of participants and infrastructure in a multi-network situation network for an example 911 use case, according to some embodiments of the present disclosure.

[0048] [Figure 12B] FIG. 12B shows an illustrative example of the formation of a physical situation network corresponding to 911, social, and healthcare networks for an exemplary 911 use case, according to some embodiments of the present disclosure.

[0049] [Figure 12C] FIG. 12C shows an illustrative example of formed and combined situation networks for an example 911 use case, according to some embodiments of the present disclosure.

[0050] [Figure 12D] FIG. 12D shows an illustrative example of a permission table for a combined situation network for an example 911 use case, according to some embodiments of the present disclosure.

[0051] [Figure 12E] FIG. 12E shows an illustrative example of representative terminal displays for different participants in a combined situation network for an exemplary 911 use case, according to some embodiments of the present disclosure.

[0052] [Figure 13] FIG. 13 shows an illustrative example of an exemplary computing device according to some embodiments of the present disclosure.

[0053] [Figure 14] FIG. 14 is an exemplary computing system according to some embodiments of the present disclosure.

[0054] [Figure 15] FIG. 15 illustrates a flowchart for creating a situation network according to some embodiments of the present disclosure.

[0055] [Figure 16] FIG. 16 illustrates an exemplary architecture for aspects of the present invention as applied in a virtual reality (VR) environment, according to some embodiments of the present disclosure.

[0056] [Figure 17] FIG. 17 shows an illustrative example of how a smartphone and a smart or fitness watch may be utilized in creating a situational network to assist in a crisis or emergency situation, according to some embodiments of the present disclosure.

[0057] [Figure 18] FIG. 18 is a flowchart of an illustrative process used to determine whether an individual emergency contact should be alerted via a situation network for an emergency situation, according to some embodiments of the present disclosure.

[0058] [Figure 19]FIG. 19 is a flowchart of an illustrative process used to determine the locality and potential scope of an emergency event that initiates the formation of a situation network, according to some embodiments of the present disclosure.

[0059] [Figure 20] FIG. 20 shows an illustrative example of projecting matching candidates in a social graph using a facial recognition template, according to some embodiments of the present disclosure.

[0060] [Figure 21] FIG. 21 shows an illustrative example of a representative architecture of a system for creating a context network using genetic information, according to some embodiments of the present disclosure.

[0061] [Figure 22A] FIG. 22A shows an illustrative example of participants and infrastructure in a multi-network situation network for an example virtual reality use case, according to some embodiments of the present disclosure.

[0062] [Figure 22B] FIG. 22B shows an illustrative example of a graph representing nodes and associations for an example virtual reality use case, according to some embodiments of the present disclosure.

[0063] [Figure 22C] FIG. 22C shows an illustrative example of formed and combined context networks for an example virtual reality use case, according to some embodiments of the present disclosure.

[0064] [Figure 22D] FIG. 22D shows an illustrative example of a permission table for a combined situation network for an example virtual reality use case, according to some embodiments of the present disclosure.

[0065] [Figure 22E]FIG. 22E shows an illustrative example of a representative in-vehicle terminal display for emergency responders in a situational network, according to some embodiments of the present disclosure.

[0066] [Figure 22F] FIG. 22F shows an illustrative example of a representative "SitNet Situation Room" in a VR environment, according to some embodiments of the present disclosure.

[0067] [Figure 22G] FIG. 22G shows an illustrative example of a representative "SitNet Control Room" within a VR environment, according to some embodiments of the present disclosure.

[0068] [Figure 23A] FIG. 23A shows an illustrative example of a representative triple store database for a 911 use case, according to some embodiments of the present disclosure.

[0069] [Figure 23B] FIG. 23B shows an illustrative example of a representative set of projection operators for a 911 use case, according to some embodiments of the present disclosure.

[0070] [Figure 23C] FIG. 23C shows an illustrative example of a representative set of resource allocation parameters for a 911 use case, according to some embodiments of the present disclosure.

[0071] [Figure 23D] FIG. 23D shows an illustrative example of a representative triple store database for a 911 / virtual reality use case, according to some embodiments of the present disclosure.

[0072] [Figure 23E] FIG. 23E shows an illustrative example of a representative set of projection operators for a 911 / virtual reality use case, according to some embodiments of the present disclosure.

[0073] [Figure 23F] FIG. 23F shows an illustrative example of a representative set of resource allocation parameters for a 911 / virtual reality use case, according to some embodiments of the present disclosure.

[0074] [Figure 23G] FIG. 23G shows an illustrative example of a representative triple store database for a network security use case, according to some embodiments of the present disclosure.

[0075] [Figure 23H] FIG. 23H shows an illustrative example of a representative set of projection operators for a network security use case, according to some embodiments of the present disclosure.

[0076] [Figure 23I] FIG. 23I shows an illustrative example of a representative set of resource allocation parameters for a network security use case, according to some embodiments of the present disclosure.

[0077] [Figure 23J] FIG. 23J shows an illustrative example of a representative triple store database for an enterprise communications use case, according to some embodiments of the present disclosure.

[0078] [Figure 23K] FIG. 23K shows an illustrative example of a representative set of projection operators for an enterprise communications use case, according to some embodiments of the present disclosure.

[0079] [Figure 23L] FIG. 23L shows an illustrative example of a representative set of resource allocation parameters for an enterprise communications use case, in accordance with some embodiments of the present disclosure.

[0080] [Figure 24A]FIG. 24A shows an illustrative example of a representative implementation of a situational network for a representative cybersecurity use case, as applied to resource allocation, in accordance with some embodiments of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0081] Detailed Description In some embodiments, the situational application runs a situational system, for example, on one or more devices, e.g., devices 5500, 5510, 6002, 6004. In some embodiments, the situational application runs on a user equipment device, such as a server, a laptop, a smartphone, a tablet, a television, or any other suitable device, or any combination thereof.

[0082] A social network, such as that illustrated in FIG. 1, can be modeled and constructed as a graph network on a server using one or more databases, where nodes represent entities such as users, posts, comments, or locations, and edges represent relationships between the nodes. In the case of social networks such as Facebook or LinkedIn®, edges can represent friendships / connections, event attendance or interest, or behavioral interests (e.g., vehicle purchases). A variety of additional information can be stored as associations, ranging from qualifications, proximity and location data, health information, and, in the case of networks, network parameter information, including usage, party contacts, and types of established connections. In some embodiments, these are stored in a graph database. Nodes in the graph can represent users, events, including crises and informative events such as concerts, network security events, including breaches and attacks, organ donors, healthcare facilities, and other objects, people, events, and locations. In other embodiments, the nodes and associations are stored in a triple store database. Each entry, or "semantic triple," is stored in the database, consisting of a subject, a predicate, and an object. Together, these triples describe meaningful relationships between subjects (nodes) and store information about the subjects (nodes).

[0083] 1, a social network is represented as a directed graph, with nodes representing both users and events and edges representing associations and relationships. As can be seen, a first user (Bob) is represented by first user node 5100 and has a friendship relationship shown with a second user (Alice), represented by second user node 5110, with friend associations represented by Bob-Alice friend association 5102 and Alice-Bob friend association 5104. Similarly, a third user (Sue), represented by third user node 5120, has a Sue-Bob friendship association 5106 and a Bob-Sue friendship association 5108. A concert event is represented by concert node 5130, and user Alice, represented by second user node 5110, has an "interested" association 5112 and an "interested in" association 5114, with concert node 5130 indicating that she is interested in the event. A third user Sue, represented by third user node 5120, has a bidirectional attendance relationship with concert node 5130, as indicated by attendance associations 5122 and 5124. A server associated with the social network creates a post node 5150 when third user Sue, represented by third user node 5120, makes the comment "I can't wait!" The server stores the association between the poster (Sue) and the post by posted association 5126 and posted association 5128. Alice's response to the post (a "like") is captured by liked association 5116 and liked-by association 5118.

[0084] Various systems and architectures can utilize social networks / graphs for storage of information and subsequent development of a situation network for a particular use case. For example, a data breach event can be represented in a social network by a data breach node 5140. While a data breach event can be detected in several ways, a typical breach detection system searches for malicious software activity on the network. Malicious software activity can include, but is not limited to, attempts to access secure portions of the network or secure data, attempts to log on to an account, and the installation of malicious software or ransomware that would render the system unusable. Specific users affected by a data breach event can be represented by the situation system by associations such as affected association 5142 and affected association 5144. In fact, any event, whether beneficial (e.g., a music or performance event), a crisis, or otherwise, can be modeled as a node in a social network / graph. As will be discussed, corresponding virtual events can also be created to correspond to actual physical-world events.

[0085] Referring to FIG. 2, social networks implemented on servers (e.g., of a context system) and other computing platforms can be modeled as undirected ( FIG. 2(a)) and directed ( FIG. 2(b)) graphs with nodes N(G) and links (edges or associations) L(G). A link or edge can be shown as an ordered pair (i, j), representing a connection between node i (the initial node) and node j (the final node). If the direction of the link is immaterial, such that the existence of a link between node i and node j necessarily implies the existence of a link from j to i, the network can be considered an undirected graph. If the direction of the link is material and allows for a distinction between links from i to j and from j to i (as in FIG. 2(b)), the network is said to be a directed graph.

[0086] As one skilled in the art will appreciate, a social network may be represented by an undirected or directed graph, and the social network of Figure 1 may be represented by an undirected graph. The types of event nodes shown in Figure 1 are merely representative; a wide variety of events may be represented by event nodes, ranging from weather events, crisis situations, network attacks, and other emergency and non-emergency events. As used herein, the term "association," when used with respect to a social network or graph database, refers to a stored link or edge.

[0087] While social networks are widely used and useful for both social and business purposes, individuals frequently rely on linear networks, including contact databases (stored on phones, computers, cloud storage, or across all of their devices / platforms) that contain contact information for their direct (single-degree-of-separation) contacts. Figure 3 illustrates contact lists for two users (William and Alice) and shows the presence of one duplicate contact. Because contact databases are one-dimensional (linear) in the sense that they store users as contacts along with various contact parameters, regardless of connections between them or between users and other entities not within the contact fields (e.g., credentials, location information, history), information about the fact that both William and Alice know John (and thus are second-degree-of-separation contacts) is not stored; neither William nor Alice knows each other based on their contacts. Thus, a social network utilized by William, Alice, and John may have stored information (e.g., a stored association) between the parties, including the fact that Alice and John are connected by two degrees of separation (e.g., through John), whereas a linear network may not store this association.

[0088] In some embodiments, a situation network is formed from a social network by the situation system by having a server or other computing device, either part of the social network or residing on a server with access to the social network, project parties (nodes) from the social network or on an alternative social network platform that are affected or required for assistance (in the case of a crisis event), or potentially of interest (in the case of an event). In the case of a crisis involving a specific geographic location, the location of individuals relative to the crisis can be used to identify affected parties via geographic location projection. In the case of an event, interest parameters can be used to project interested parties / nodes from the network and create a situation network. Interest or service parameters can be combined with geographic location to identify parties both potentially interested and in proximity to the event and connect them via the situation network. Additionally, relationships between users, such as degrees of separation, associations with users with particular interests / likes, and history on the social platform can be used in developing the projections.

[0089] An illustration of the use of projection is shown in FIG. 6A , where social graph 5600 represents nodes and interconnections typical within a social network. A server or other computing device utilizes projection operator 5602 to project relevant participants into the situation network. To create appropriate groups or lists for the formation of a situation-related network on a platform that does not include the nodes and associations of the social graph, intermediate database 5620 contains compiled user data regarding suggested participants in the situation network that operates on a platform other than the social network from which the situation network was projected. In some embodiments, messaging system database 5610 finds contact data regarding the projected participants, and intermediate database 5620 is accessed to retrieve the information required to contact users outside the social network platform and include them in the situation network.

[0090] In some embodiments, an intermediate database (ID) can be used to store information corresponding to addresses (e.g., emails, phone numbers, or other unique identifiers) that can be used to connect to users on networks other than the social network / graph on which the projection operates. As illustrated in FIG. 6A , the intermediate database (ID) 5620 tabulates relevant information, creates contextual groups, and enables interconnections within the appropriate linear network. In some embodiments, the ID 5620 is created by one or more servers that form part of the social network from which the projection occurs. In some embodiments, the ID 5620 is created by a server that is not directly associated with the social network but has access to it. The ID 5620 can be stored on the server that created it or may reside on one or more other servers that are not part of the social network. In some embodiments, the ID 5620 is stored locally on the user device.

[0091] The server creating ID 5620 populates a database with sufficient information to interconnect affected parties on either the social network from which the projection was made or a secondary network. For example, ID 5620 may include the names and phone numbers of the relevant parties identified in the projection. The user information can be used, for example, to establish SMS group messages or chat groups with group members. In some embodiments, the server hosting ID 5620 communicates with messaging system database 5610 to determine appropriate contact information or user IDs for that particular platform. For example, projection operator 5602 may create a list of relevant parties using usernames and IDs for social networks, which provides the basis for group creation (via projection). Messaging system database 5610 can be accessed to determine appropriate user IDs for individual platforms. For example, if the projection is made from a social networking platform such as Facebook, the server hosting ID 5620 may contact an SMS database (via SS7) to verify phone numbers for the proposed participants and contact a WhatsApp server to determine contact information for the participants on that platform.

[0092] FIG. 6B represents an alternative to ID 5620, which is a "hierarchical graph" database in which relationships between users and potentially other information are stored in a directed or undirected graph database. In some embodiments, users are shown as nodes, which in FIG. 6B is user (principal) 5601. Individuals with whom a user is associated, typically recorded as contact data, frequently stored on a user device such as a smartphone, are stored as nodes. For example, user (principal) has contacts Bob Jones 5603, Susan Wilkerson 5605, and BillyBop 5607, which are represented as nodes in the hierarchical graph, and their contact information is stored as associations between users, with the nodes representing their contacts. The user's contact information for other individuals (e.g., Instagram handles, SMS, or WhatsApp numbers) is also stored as associations between user (principal) 5601, with nodes associated with individual contacts. Although FIG. 6B illustrates a directed graph in which directionality indicates contact information for a party associated with user (principal) 5601, other embodiments based on undirected graphs are also possible.

[0093] In some embodiments, data about how users are typically contacted is recorded in the hierarchical graph as associations between users and nodes representing their contacts. For example, in addition to storing Bob Jones's 5603 contact information as associations (e.g., WhatsApp (561-327-5691), Instagram (@b Jones), and SMS (561-327-5961)), the frequency with which Bob Jones 5603 is contacted by User 1 (Principal) 5601 using each communication mechanism may also be stored (e.g., WhatsApp is used 72% of the time, Instagram 20% of the time, and SMS 8% of the time). In addition to usage rates, an individual's response time on a particular platform may also be stored so that projections can be made to identify the platform on which the individual will respond most quickly (e.g., the average SMS response time is 12.7 minutes, and the average Instagram response time is 2.3 minutes). This feature can be used to significantly improve the efficiency of the resulting situation network because it allows for optimization of the response times of the identified participants. Additional information can be derived through computer-based observation of network communications using artificial intelligence techniques, including data mining, that provide for learning of patterns used by participants, who in the example described above are individuals who communicate with Bob Jones 5603 via various platforms.

[0094] In some embodiments, additional nodes representing parties potentially not known to user (principal) 5601 are also stored in the hierarchical graph. For example, Bob Jones may know, be related to, or be associated with (through a relationship such as work, or through a communication or social media platform) an individual named Cindy Jones. Thus, Cindy Jones may be represented as a node in the hierarchical graph (Cindy Jones 5609). Relationships may also be recorded in the hierarchical graph, as shown in FIG. 6B as the Instagram address @Cindyj, which would indicate that Bob Jones 5603 follows Cindy Jones 5609 on Instagram via @Cindyj. This information may be derived from existing social networks and may be present in the hierarchical graph, associated with the user, even if it is not consciously known to the user or stored in their contact information.

[0095] In some embodiments, the information stored in the hierarchical graph may not be limited to contact information, but may also include associations such as where an individual works, events they have attended, interests, "likes," and other information typically stored in a social network. As illustrated in Figure 6B, the "works" association between Susan Wilkerson 5605 and Ford Motor Corporation 5611 can be stored in the hierarchical graph.

[0096] The hierarchical graph can be derived through multiple mechanisms and stored in one or more locations. In some embodiments, a user device, such as a smartphone, mines the user's contact information and creates a hierarchical graph, which is stored locally and backed up in the cloud. In this embodiment, an application that provides hierarchical graph creation may be provided as part of the smartphone. In an alternative embodiment, third-party software is utilized as an application that runs either on the user's device (e.g., smartphone) or on a remote server. The third-party application can mine not only the user's contact information but also external social networks (e.g., Facebook, Instagram, LinkedIn®) to determine not only first-degree contacts and associated information (e.g., addresses, screen names, work locations, events attended, "likes"), but also second-degree through N-degree contacts and associations between their contacts, represented as edges on the hierarchical graph.

[0097] In some embodiments, existing social network providers (e.g., Facebook, Instagram, LinkedIn®) offer "hierarchical graph" services in which they aggregate information across their platforms or across several platforms, including platforms outside the social networks on which they operate. Access to the hierarchical graph is provided to users, allowing them to perform projections onto the hierarchical graph and create cross-platform situational networks.

[0098] As will be appreciated by those skilled in the art, hierarchical graph databases enable the fast and efficient creation of cross-platform situation networks in which parties can be identified and invited or added to the situation network despite the fact that they may not all be on the same platform. The ability to automatically connect parties from one platform (e.g., 911 services or SMS messaging) to social networks such as Facebook and Instagram and communication platforms such as WhatsApp allows individuals who need to communicate important information related to a situation to look up their contact information and communicate that information to the appropriate parties without requesting a connection. Additionally, situation networks that arise on social networks such as Facebook, Instagram, or LinkedIn® can be easily extended to linear networks such as SMS messaging platforms or WhatsApp through the use of hierarchical graphs, projecting related individuals (nodes) and automatically connecting them.

[0099] The hierarchical graph can be used as or in conjunction with the intermediate database. In some embodiments, the hierarchical graph serves as the intermediate database itself and is used to establish the basis for cross-network connections. In alternative embodiments, the hierarchical graph is used as the basis for the intermediate database, and the available or most appropriate (e.g., based on response time) communication means for a particular user are derived from the hierarchical graph and used to populate the intermediate database.

[0100] As an example of how node and link operators can be used to predict recommended membership for a situation network, a situation such as a power outage can be noted and an appropriate event node can be created within the social network. In some embodiments, node projection and link projection [ka] A weighted combination of the weights can be used by identifying users within the geographic proximity of the outage as well as users with a defined relationship to those users within the geographic proximity of the outage. For example, service providers (e.g., suppliers of food, generators, medical care, and other essential services) that may supply users (determined by geographic proximity) affected by the outage may be identified via the link portion of the projection. Similarly, associates of users affected by the outage may also be projected from their social networks (as represented by a social graph) via the projection operator.

[0101] Because users frequently rely on a combination of databases, such as social networks and linear or flat databases that simply include a list of contacts with their contact information (which may be contact information including email addresses, phone numbers, and social media handles), it may be important to be able to create a multi-network situation network that allows users to add to the situation network across platforms such as social media platforms (e.g., Facebook) and linear networks such as SMS networks or WhatsApp. As will be discussed, several techniques can be used to create a multi-network situation network.

[0102] FIG. 7 illustrates exemplary SMS / chat communications for parties placed in a situation network. In some embodiments, a server hosting ID 5620 communicates (through either a proprietary interface, an open interface, or a defined API) with a server associated with an SMS / chat communication system to create a group chat on the SMS / chat communication platform. In some embodiments, ID 5620 resides directly on the server associated with the SMS / chat communication system, and the group chat is created directly on the SMS / chat communication system. A notification message 5700 indicates to the user that they have been placed in a group chat based on a decision (projection) and provides the user with the ability to opt out by responding "No" or "N." In some embodiments, the user is provided with full contact information for the parties in the situation network, as shown by situation roster 5710. In an alternative embodiment, members of the situation network remain anonymous through the blocking of their contact data in the group message / chat. Thus, parties can join a situation network without revealing details such as their name and contact data (eg, phone number, email, social network name).

[0103] In some embodiments, the creation of a context network, whether created across one platform or expanded across platforms, requires the allocation of resources within the network. Resources can include computational resources such as processing power (e.g., CPU or GPU processing power), storage resources such as disk space or cloud storage, memory resources such as RAM allocation, network resources such as bandwidth and access to network segments, software resources such as licenses or API access, data resources such as databases or data sets, energy resources such as power allocation, and user-specific resources such as access to user accounts and profile customizations, security resources such as encryption / decryption keys, access to firewalls and security settings, and access to cloud computing resources such as virtual machines and container instances.

[0104] In some embodiments, as part of forming a situation network, in addition to inviting or adding potential participants to the situation network, as outlined in the flowcharts of FIGS. 11 and 15, resources need to be allocated. These resources can be Internet-based, such as establishing a TCP / IP channel or connection, or may involve the allocation of bandwidth over a cellular, satellite, fiber optic, or other network. In addition, control of certain parameters, such as bandwidth, video camera pan and zoom, volume level, or other control parameters, may be given to particular participants in the situation network. This allows important information to be properly managed and distributed. In some embodiments, resources, such as access to files, are granted to situation network participants, while in other cases, access can be restricted.

[0105] FIG. 8 illustrates the creation of multiple hierarchies or layers of a situation network. This can be accomplished through the use of different projection operators when the projection is made, or by filtering, querying, or other database techniques when applied to the projected list of participants. As will be understood by those skilled in the art, the server creating the projection can utilize different dimensions formed by the nodes and associations of the social network when creating the projection. For example, parties identified as first responders (e.g., police, fire, and paramedics) can be represented as a specific dimension within the social network. This dimension, combined with geographic proximity, availability, response time, and other attributes, can be used by the server when creating the projection. Considering the case of a school shooting, a first responder situation network can be created by a server associated with or having access to the social network and can result in first responder IDs 5800, which include contact information for appropriate first responders. Similarly, a first hierarchy of parties affected by the shooting can be created, representing parties under threat, such as teachers and students. This information is represented in ID 5810. Finally, the parties involved in the shooting, including the parents of students in the school, can be identified and their contact information maintained in involved party ID 5820.

[0106] As will be appreciated by those skilled in the art, different communication networks can be used in a hierarchical hierarchy in a situation network, as illustrated in FIG. 8 . For example, first responders may communicate with each other using secure police / fire / EMS communication networks, including FirstNet Authority and other closed networks. Projection enables rapid organization of a first responder situation network via First Responder ID 5800. Affected parties, including students and teachers likely within the school, can be identified via projection, and their information is stored in Affected Party ID 5810. These parties may be contacted immediately so they can receive instructions, be confirmed safe, or provide important information regarding the situation. Finally, relevant parties identified via projection are tabulated in Random Shooting Related Party ID 5820. These individuals will desire information regarding the situation, but are not necessarily involved in emergency management themselves. Establishing a hierarchy within a situation allows for different priority situation networks, potentially operating on different platforms.

[0107] Although described in the context of linear networks such as SMS and chat applications such as WhatsApp, the methods and systems described herein can be used in conjunction with web-based systems and email, as well as radio and satellite-based systems, including police and emergency bands, amateur radio bands, and satellite radio and telecommunications networks. The use of web-based systems would support the use of graphical user interfaces, support advanced security / roll call procedures, and provide the ability to provide news portals and advanced communication capabilities.

[0108] FIG. 15 shows an illustrative flowchart for creating a situation network. In step 6510 of identifying a situation or event, a situation or event is identified. In some embodiments, processing circuitry identifies the situation or event. Events can range from crises such as fires, random shootings, hurricanes, earthquakes, etc.; network security events, including detected or activated data breaches, compromised servers, phishing, denial-of-service attacks, malware, or ransomware; emergency requests for organs or notifications of organ availability; informative events, such as concerts, conferences, meetings, special forums, social gatherings, book clubs, market events (e.g., trade shows, craft fairs, hamfests), or any other situation or event in which one or more participants are either present at or affected by the event. A situation or event may be identified and subsequently reported by human observation, or can be detected in an automated manner from cameras, facial recognition or artificial intelligence mechanisms combined with image analysis, monitoring social networks for posts, or other human or automated detection mechanisms.

[0109] In some embodiments, once a situation or event is detected, an event / situation node is created on a server (e.g., one or more servers within the social network or on a network external to the social network) to establish the event / situation node (step 6520). In step 6530 of projecting and extracting next potential participants, the potential participants are projected via processing circuitry using node projections and link projections. [ka] As will be appreciated by those skilled in the art, the projection operator will be determined by the details of the situation or event.

[0110] In step 6540 of creating an initial network, a test is performed to determine whether a situation network can be established on the social network from which the participant has been identified. Criteria for determining whether a situation network should be established on a social network may include the degree of connectivity and responsiveness compared to other networks. As an example, participants using a social network such as Facebook may have a longer response time than participants on an SMS / chat platform. For critical applications such as crises (e.g., fires, random shooters), it may be necessary to create a situation network on a network other than a social network. In some embodiments, situations / events are categorized for automated determination of the need to create a situation network on a different platform. In other cases, computer-based analysis is performed via processing circuitry to consider communication characteristics required for the situation / event and determine whether the situation network should reside solely on the social network or should be established on one or more alternative networks. Upon completion of the initial network creation test 6540, the process flow creates an intermediate database (step 6550) if it is determined that a situational network should be created on another network or intersecting between the social network and another network. In some embodiments, a hierarchical graph mechanism such as that shown in Figure 6A can be used to determine the best mechanism for contacting an individual or object and serve as the intermediate database.

[0111] If the computing platform (e.g., server or servers) determines that a situation network can be created on the social network formed therefrom, the process proceeds to an invite candidate participants step 6570, discussed below.

[0112] In some embodiments, transmitting to second network step 6560 results in transmitting an intermediate database (such as that shown in FIG. 6A) to the second network or using a hierarchical graph database (such as that shown in FIG. 6B) to communicate inter-network information. Once transmitted, inviting candidate participants step 6570 invites the selected participants to the situation network, including people outside the platform (e.g., social network) that may have been used for the initial identification of the participants.

[0113] In some embodiments, allocating resources to participants step 6575 allocates appropriate resources to individuals as they join the situation network. As described above, these resources can include various computing, network, or other resources that are in limited supply. For example, individuals who join the situation network may be granted a certain amount of bandwidth to enable them to reliably communicate or transmit / receive video. In instances of live video transmitted over the situation network, dedicated bandwidth may be allocated to situation network participants to ensure video quality. Other mechanisms, such as traffic shaping to prioritize video traffic over less time-sensitive traffic, may also be used to maintain video stream quality. Quality of Service (QoS) parameters can be set to give higher priority to video and audio packets. Network security settings, including firewall configurations and the use of virtual private networks (VPNs), can be used to provide robust and secure connections, which can also be used for video. Server resources include the use of dedicated servers for certain types of communication (e.g., video) and load balancing to ensure proper resource availability. Backup communication paths and redundant servers can be established to ensure reliable communication. Similarly, network monitoring and resource utilization tracking can also be used to monitor.

[0114] In some embodiments, in a step 6580 of establishing a network connection between approving parties, the parties accepting the invitation are connected to the situation network that is being formed. Once added to the situation network, they can utilize the resources allocated to them, within the constraints of any permissions / restrictions they are granted, to communicate with other members of the situation network, to participate in the situation network, and generally have access to information and resources that are deemed necessary for the operation of the situation network.

[0115] In some embodiments, an exemplary Short Message Service (SMS) system is shown in Figure 4, in which a first user 5400 and a second user 5410 operate telephones 5402 and 5412, respectively. These telephones act as Short Messaging Entities (SMEs), which transmit a first SMS message 5404 and a second SMS message 5414, which are received by operator A's Short Message Service Center (SMS-C 5406) ​​and operator B's SMS-C 5416, respectively. The operators' SMS-C units utilize aspects of Signaling System 7 (SS7) 5408 to interoperate and route the SMS messages to the appropriate end receiving device (e.g., a phone or computer).

[0116] As will be appreciated by those skilled in the art, physical entities within a telecommunications network, including Service Switching Points (SSPs), Signal Transfer Points (STPs), and Service Control Points (SCPs), cooperate with physical entities within a cellular network, including, but not limited to, Base Transceiver Stations (BTSs), Base Station Controller Stations (BTSs), and Mobile Switching Centers (MSCs), to properly route SMS messages. Databases within the SS7 system, including the Home Location Registry (HLR) and Visitor Location Registry (VLR), maintain subscriber service profiles and maintain information about the subscriber's current location. However, the databases do not maintain information about events or associations and cannot directly support the creation of situational networks.

[0117] FIG. 5 illustrates the basic architecture of a chat system (e.g., WhatsApp) in which a first mobile device 5500 and a second mobile device 5510 are connected to a message server 5504. In some embodiments, the Extensible Messaging and Presence Protocol (XMPP) is used to send files and messages. In some embodiments, messages are sent to the message server 5504, which stores the messages in a temporary database 5506 where they are queued for delivery. The mobile devices 5500 and 5510 can use HTTP web sockets to send and retrieve multimedia data (e.g., images and videos) through a separate server (not shown), but may not keep the web socket open all the time (e.g., when offline). Upon opening the chat application and therefore reconnecting to the socket, messages stored in the temporary database 5506 can be routed to the appropriate user by the message server 5504, and the messages can be deleted from the temporary database.

[0118] 5, a first local database 5502 is connected to a first mobile device 5500, and a second local database 5512 is connected to a second mobile device 5510. These local databases are used to store contacts, messages, and associated files and form part of the chat system. A media data / profile / contacts database 5508 also exists to store relevant information about the system, but does not store associations or event nodes beyond what is necessary to maintain chat communication between users.

[0119] Referring to Figure 10, a representative example of an implementation architecture is shown. Social network 6000 consists of social network server 6010 operating via network 1 6020. In some embodiments, network 1 6020 is the Internet. User 1 6001 operates user device 6002, user 2 6003 operates user 2 device 6004, and user 3 6005 operates user 3 device 6006.

[0120] 10, a second network, in this case an SMS / chat network 6030, operates on a series of linear network servers 6040 connected to network 2 6042. Network 2 6042 can be the Internet or an alternative network such as a public telecommunications infrastructure. User 4 6007 operates user device 4 6008, and user 3 6005 operates user 3 device 6006.

[0121] In some embodiments, an event such as physical event (fire) 6070 occurs and is reported to or detected by social network 6000. Social network 6000 can determine that physical event (fire) 6070 has occurred through reporting by members of social network 6000, automated detection and verification of posts related to physical event (fire) 6070, connection to a public safety network, monitoring police and fire communications, or other methods of detection and verification. Once the existence of physical event (fire) 6070 is reported and confirmed, an event node corresponding to the event will be created in social network 6000. In some embodiments, servers associated with social network 6000 will determine which businesses or individuals are associated with the event (e.g., because they live at the fire's address), and the association between those parties and the event node will be recorded in one or more of the servers.

[0122] In some embodiments, once the event node is created, the social network 6000 utilizes one or more of the social network servers 6010 to create one or more projections of parties that should be part of the situation network as associated with the physical event (fire) 6070. As described above, several projection operators can be utilized based on proximity to the event, status as first responders, availability or response time, associations with parties (e.g., businesses or individuals) that have an association with the event node that has been created for the physical event (fire) 6070.

[0123] In some embodiments, based on the projection, an intermediate database (ID) 5620 is created by one of the social network servers 6010 and stored on one or more of those servers. In some embodiments, one of the social network servers 6010 uses the information in ID 5620 to create one or more SMS / chat group messages addressed to the situation network participants identified in the projection. An interconnection 6060 between Network 1 6020 and Network 2 6040 is used by the social network 1000 to either transmit messages directly over the SMS / chat network 1030 or request one of the linear network servers 6050 to generate SMS / chat group messages for the situation network participants. Alternatively, a hierarchical graph such as that illustrated in FIG. 6B can be used to determine the best communication mechanism for particular users, and those users can be added to the situation network based on the identified preferred, most reliable, or fastest response time communication means.

[0124] In some embodiments, the projection results and resulting ID 5620 are transmitted via interconnect 6060 along with a request to send a group message, which can then be created by one of the linear network servers 6050.

[0125] In some embodiments, a situation network can be created within the social network 6000 itself by identifying potential participants through projection and projection operators (which operate on a combination of nodes and association criteria), transmitting invitations to some or all of the participants, and connecting approving parties on the social network 6000.

[0126] In some embodiments, once projection is performed and a potential participant is identified, one of the social network servers 6010 may determine, while building the intermediate database 5620, that there is insufficient information to identify the potential participant on a second network, such as the SMS / chat network 6030. An example would be when an individual has an account on the social network 6000 but does not have a phone number associated with the account. Thus, the ID 5620 cannot include a phone number entry for the individual. In such a situation, the potential participant can be notified via the social network 6000 that they have been invited to a situation network on an alternative platform (for purposes disclosed) and will be required to provide a phone number (or network address / identifier for the alternative platform) if they wish to join. Alternatively, the potential participant can be provided with updates via the social network 6000 even if they have not fully joined the situation network established on the second network (e.g., the SMS / chat network 6030).

[0127] 10 illustrates social network 6000 connecting to a single secondary network (SMS / chat network 6030) via interconnection 6060, but multiple secondary networks, such as fire / police / EMS communication networks and other specialized closed networks, can be addressed. In some embodiments, multiple intermediate databases are generated by servers within social network 6000, and different hierarchies of the situation network are established, as described above. In some embodiments, a hierarchical graph database is used to establish the cross-platform situation network, and the associations in the hierarchical graph database contain information useful in identifying the best platforms to access and interconnect participants.

[0128] The system need not be limited to a particular number of social or linear (e.g., SMS) networks and can be extended across multiple platforms. In some embodiments, a situation network is initially formed on a social network such as Facebook, but participants with accounts on alternative platforms, including Instagram, WhatsApp, and text (SMS), are identified using an intermediate database (such as that shown in FIG. 6A) or a hierarchical graph such as that shown in FIG. 6B. Once identified, participants join or are invited to join the situation network. In some embodiments, the situation network is maintained by the social network from which participants are identified, and communications, including with those outside that social network, are also maintained by the social network. In alternative embodiments, the situation network is operated by a server / system independently of the social network from which it was created. In some embodiments, an independent server / system is used to identify the required participants (via projection), join or invite them, and establish cross-platform communications.

[0129] While the above is discussed with respect to SMS networks, advanced networks such as 5G can also be used in the creation and operation of a situation network. 5G's service-based architecture (SBA), in which modular network functions interact through a common framework, can also be utilized to support connections within the situation network. Features such as network slicing, in which a network can be divided into multiple virtual networks or "slices," with each slice optimized for a particular type of service or customer, can also be utilized during the formation of the situation network via a resource allocation step. In some embodiments, messaging within slices allocated to situation network participants can be tailored to meet specific requirements, such as low latency or high bandwidth. This can be utilized in various aspects of the situation network, including tiered applications, where certain tiers of the network (e.g., first responders) require low latency or high bandwidth connections. Similarly, 5G features such as enhanced Multi-Bandwidth Broadcasting (eMBB) and Multiple Multi-Connection Communications (mMTC) can also be utilized to guarantee performance characteristics for designated connections within the situation network.

[0130] In some embodiments, a cybersecurity use case can be used to further illustrate the creation and utilization of a situational network to protect assets and minimize the impact of security threats and breaches. Referring to Figure 9A, a first corporate device 5900 is infected with a virus, and the virus on the device is subsequently transferred over the internet to Jane user infected device 2, 5906. On infected device 2, an indication of the threat can be displayed on the user's monitor.

[0131] In the considered use case, there are also other users connected to the same network, represented by user device 3, 5908, and user device 4, 5910. The presence of a virus generates an incident report 5914 when a virus detection alert 5912 is generated through a virus being detected by a virus detection scan, a scheduled scan, or in another embodiment, by one of various protection software and processes known to those skilled in the art. The incident report arrives at the workstation of a security analyst 5916, who reviews the virus detection log and may also determine the nature of the threat. The security analyst 5916 reports the incident to an IT administrator 5918. If the incident meets a threshold, the report may continue escalating to a security operations center (SOC) 5920.

[0132] In some embodiments, cybersecurity event node 5907 is created in response to the presence of a virus and its intrusion into Acme Financial Software Corp network server 5904. Cybersecurity event node 5907 can be created automatically, for example, based on a threshold number of infected machines, or triggered from an electronic report or communication (e.g., email) indicating the presence of a virus on a corporate computer. In some embodiments, cybersecurity event node 5907 is created by a situational authority, such as security operations center 5920 or security analyst node 5916.

[0133] In some embodiments, depending on criteria related to the event or threat, a notification may be generated to the legal department 5922. For known or existing threats, the threat may also be reported to the incident response (IR) team 5926 as related to an existing event 5925. In the case of a new event, the legal department may deem a management notification required, in which case the management team 5924 would receive the notification. Together, the legal department 5922 and SOC 5920 may request the formation of a new incident response team 5926, which would be designed to handle the specific threat.

[0134] In some embodiments, depending on the nature of the threat or incident, notification may be required for the company's board of directors based on corporate governance policies, and at the appropriate time, management may also request that public relations 5928 make appropriate disclosures to the public. The dotted circle on the left side of FIG. 9A represents Acme Financial Software Corporation and their engagement network 5904. This network and corresponding participants may reside at a financial software provider whose clients are banks. They may provide third-party software to facilitate operations such as account management, brokerage accounts, and brokerage accounts. In this embodiment, Acme manages its own network security. In some embodiments, Acme engages a third-party Managed Detection and Response Provider (MDRP) 5934. Similarly, a company like Acme may alternatively engage a Secure Incident Event Manager (SIEM) 5936 to delegate event management and perform security operations center functions. Many enterprises of this nature also have an endpoint protection provider 5940, which acts as the first and last line of defense between all network devices and devices and resources outside the network, for example, through the Internet. These third parties, the endpoint protection provider 5940, the SIEM 5936, and the MDRP 5934, each generate their own reports, provide notifications, and can trigger events, including requests for the creation of situational networks, depending on the nature and size of the threat. External auditors 5944 are typically contracted to perform tests, such as penetration tests, that are conducted proactively and periodically to anticipate and prevent threats.

[0135] In some embodiments, a Common Vulnerabilities and Exposures (CVE) database is used to determine other victims or potential victims of a particular CVE threat, such as a particular virus or malware signature. These other victims of a particular CVE 5951 have previous experience with the current threat that is valuable to parties such as Acme Corp. as well as their networks of resource providers, MDR, SIEM, endpoint protection providers, or other related entities. Referring again to Figure 9A, cloud service provider 5946 may host application servers 5948 and databases 5950 to support operations for entities such as those represented in this use case.

[0136] Also depicted in Figure 9A are exemplary clients for Acmes financial software: National Bank 5962, National Bank of Scotland 5960, and First Online Bank 5958, which are connected to Acme Corporation and their end-user customers through network 5942, which in some embodiments is the Internet. On the right side of Figure 9A are three exemplary suppliers to Acme Corporation: Consolidated Interbank 5964, which assists with transaction and credit card processing; Everyday Staffing 5966, which provides Acme Corporation with team members as needed; and Global Shipping, which assists with shipping packages and packages to customers and Acme Corporation's suppliers. One or more social network servers 5954 link participants to various social networks, such as X (formerly known as Twitter), Facebook, WhatsApp, LinkedIn®, and other social networks. The top right of Figure 9A illustrates several regulatory agencies 5970, including, but not limited to, the Federal Deposit Insurance Corporation, the Office of the Comptroller of the Currency, and the Board of Governors of the Federal Reserve System. Each of these agencies has specific reporting thresholds and disclosure requirements. Other regulatory bodies may also be included, as will be understood by those skilled in the art.

[0137] FIG. 9B illustrates an example structure of situation networks created to support a cybersecurity use case. As shown at the bottom of FIG. 9B, these are a cybersecurity event situation network 5978, a cybersecurity industry situation network 5986, a social network physical situation network 5990, and a regulatory agency situation network 5996. These situation networks are formed from their respective social graphs and / or databases containing information about relevant parties. For example, the left side of FIG. 9A illustrates a cybersecurity event situation network 5978 created from Acme Software's specific social graph 5971, generated by Acme Software Server 5904, through the use of projection 5976. This projection involves relevant parties, such as direct management or affected clients. The second stack in FIG. 9A illustrates a cybersecurity industry situation network 5986 centered on the cybersecurity industry. Due to the eruptive nature of cybersecurity threats and the required short response times, the cybersecurity industry requires high interconnectivity and fast response times. Context networks can be formed to enable the sharing of industry-specific information in a private and secure forum. A social network server 5954 works in conjunction with the social network social graph 5956 and projections 5988 to create a social network context network 5990 based on the social network projections 5988 as applied to one or more social networks 5956. In the far right column, a regulatory physical context network is formed in the same manner, connecting disparate regulatory agencies on a combined context network.

[0138] FIG. 9C illustrates an example architecture for a combined context network that incorporates the context networks covered in FIG. 9B along with the network devices that connect them and multiple servers that help facilitate a multi-network context network. In some embodiments, each party in the combined context network has access to specific data, as dictated by their entry in the Inter-Network Permissions and Node Information table 5998, as shown in FIG. 9D, which illustrates an example permission table for a combined context network. Each participating party is listed in the table along with an indication of the type of data they are allowed to receive. For example, corporate management has the right to know all relevant cybersecurity information in order to effectively coordinate a response. Conversely, regulatory agencies may only have access to required regulatory notices sent to them and are not permitted to view internal corporate communications, such as IR plans. This allows all relevant parties to be connected on the same combined context network while still allowing for appropriate data privacy and information security.

[0139] In some embodiments, Acme Financial Corp. network server 5904 is used to create cyber threat projections 5976, cybersecurity industry network projections 5984, social network projections 5988, and regulatory agency network projections 5995. In this embodiment, Acme Financial Corp. is responsible for forming the cybersecurity event situation network 5978, cybersecurity industry situation network 5986, social network situation network 5990, and regulatory agency situation network 5996. In some embodiments, cybersecurity event node 5907 actively triggers the projections and resource allocations necessary to create the situation networks, either directly by invoking code to perform those operations, or in conjunction with requests to cybersecurity industry network 5982, social network 5956, and regulatory agency network 5994. These requests can be made via APIs for the individual networks, in which parameters related to projections, permissions, and resource allocations are passed to each network, which results in the formation of the individual situation networks.

[0140] In some embodiments, cybersecurity industry situation network 5986, social network physical situation network 5990, and regulatory agency situation network 5996 are created by their respective servers, network server 5980, social network server 5954, and various regulatory agency servers 5992. In this embodiment, projection operators, permissions, and resource allocations are predetermined and stored on each of the respective servers or transmitted from another node or server, such as cybersecurity events node 5907 residing on Acme Financial Corp. network server 5904.

[0141] In some embodiments, in the event of a report of suspicious activity or an actual breach, the multiple parties depicted in Figure 9A will exchange data and time-sensitive information regarding the indication of a potential threat or the resolution of an actual threat, assuming those deemed responsible, accountable, or needing to be consulted or notified. Given the dimensionality (variable number of parties, both internal and external to Acme, depending on the situation, their roles and permissions, and access requirements), only a representative few of the many monitors and their indications are provided below. As an example, in the event of evidence of a breach of personal information in the financial services industry, seven or more agencies and up to 50 U.S. states, as well as international agencies, require regulatory notification.

[0142] Referring to FIG. 9E, 5999a shows a malware-generated pop-up window that appears on the computer screen of Jane user-infected device #2. The pop-up may appear when Jane user attempts to boot up or wake up the machine from sleep mode, or may interrupt normal use of her workstation. Typically, these screen pop-ups are brightly colored and flashing, accompanied by threatening information about the nature of the breach, the threat actor's demands, and instructions for payment. While the notification can take one of many other forms (e.g., a shutdown and reboot accompanied by a blank screen but a text message), a pop-up window is typical. Alternatively, Jane user may not see the message, but may notice that her computer is booting up extremely slowly due to high CPU utilization when the threat notification and demand are presented to another party.

[0143] In some embodiments, the security analyst terminal 5999b illustrates several types of information required by that party to assess the situation, which may include reports or pop-up alerts about viruses detected by regular scans, suspicious activity reports or charts showing log file sizes or CPU utilization (or many other resources) above or below control limits or outside established boundaries, and help desk tickets from users experiencing attacks and their resolution. These are merely a few examples of the many potential alerts and visual signals.

[0144] In some embodiments, a security monitoring and response service (MDR) provider terminal 5999c illustrates several types of information required by that entity to assess and address a situation, which in the example of a response manager's workstation monitors may include notifications of threat or breach alerts from their various customers, along with related summary information and status updates and communications to key parties within the MDR company to resolve the threat.

[0145] In some embodiments, the system operations center (SOC) terminal 5999d displays several types of information as required by the organization. In a typical SOC (either in-house at Acme or at an external service provider), there may be virtually hundreds of monitors with messages, run charts of important resource statistics (e.g., CPU utilization, log file sizes, network and Internet traffic, etc.), status indicators, along with suspicious activity alerts, among many other things displayed. For example, firewall logs, pop-up alerts from security monitoring or virus detection software indicating a port scan may be displayed.

[0146] An exemplary process for creating a situation network for a cybersecurity use case involves identifying relevant parties / nodes via projection operators (nodes and associations) and allocating network resources to provide appropriate communication channels and allocating (granting access to) or de-allocating (e.g., denying access to) specific network resources, such as databases (e.g., databases containing personally identifiable information, also known as PII). The process is described herein with respect to databases as illustrated in Figure 23G, projection operators as illustrated in Figure 23H, and allocated resources as illustrated in Figure 23I. In addition to projection operators and resource allocations, permissions, such as those shown in Figure 9D, can also be incorporated into the formation of various situation networks.

[0147] Referring to FIG. 23G, an exemplary triple store database is shown for forming a situation network for a cybersecurity breach. This database holds user relationships within an enterprise (including equipment such as servers, websites, and other nodes) and associations relevant to a cybersecurity use case. For example, the database may store that user Jane's device has a virus and record that Jane's user ID accessed a database containing personally identifiable information (PII). These points, combined with appropriate projections, may also enable the identification of targets under threat. As will be explained, the database can also be used to assist in the projection of participants in the situation network. While described herein as a triple store database, data can also be maintained in other types of graph databases. Relational databases, which store information about both users / nodes and relationships or other auxiliary information about users / nodes, can also be used to store information relevant to a cybersecurity use case.

[0148] As described above, node and link (association) operators [ka] A weighted combination of can be used to project relevant participants from a database, which in this use case is the database illustrated in Figure 23G. An example projection operator is shown in Figure 23H.

[0149] In some embodiments, as cybersecurity events are uncovered, a cybersecurity event situation network 5978 can be established by applying operators such as those shown in Figure 23G to the cybersecurity events. The operators can be expressed in Boolean terms, and an example formula for the projection is: Cybersecurity Event [Date] Situation Network Projection S(G) = ((User Device AND Has Virus) OR (User Device AND Trouble Ticket Submitted)) OR (IT Personnel AND Executive). This projection would incorporate user Jane and any other users of the enterprise network infrastructure for whom the system has detected the presence of a virus on a device associated with their account or for whom they have reported a trouble ticket, and users (see FIGS. 9A and 9B) depicted as IT personnel, including but not limited to security analysts 5916, security operations center 5920, incident response team 5926, secure incident event manager 5936, and security monitoring and response service provider 5934. Executive management (e.g., CEO, CFO, CIO, COO, CTO) are also included within the exemplary projection shown above.

[0150] As illustrated in FIG. 23G, some projections can be projected from the database based on node information alone (e.g., nodes representing "IT personnel," "cyber insurance providers," "FDIC," or "Financial Crimes Enforcement Networks"), regardless of association. This can be considered a projection with zero weighting on the association component. To the extent association is required in addition to node information to identify the required participants, that projection information can be added to the table shown in FIG. 23G.

[0151] Referring to resource allocation for the cybersecurity use case as illustrated in FIG. 23H, resources can be allocated to create a cybersecurity event status network 5978. In some embodiments, a node is created to represent the cybersecurity event. Once the node representing the cybersecurity event is created, an association between the event and other users / devices can also be created and stored. For example, parties can be designated as "infected" or "notified" via their association with the node.

[0152] Other resource allocations include generating email notifications to participants identified for inclusion into the cybersecurity event status network 5978. In some embodiments, the node representing the cybersecurity event is used as the “from” party in the email, and a corresponding mailbox is created for the event. This has the advantage of establishing an event-specific mailbox for receipt of status information related to the event, which can be monitored by a human or artificial intelligence means. Users receiving messages about the event can respond to the event-specific mailbox. A communication channel to specifically address the cybersecurity event can be automatically created, and users identified in the projection are automatically added as part of the cybersecurity event status network 5978. The communication channel can be established using internal enterprise software and tools, such as, but not limited to, Slack, Discord, Microsoft Teams, Mattermost, Rocket.Chat, Ryver, Zoho Cliq, Glip, or Twist, or via an interface to an enterprise communication tool.

[0153] A typical command for allocation of these resources would be: CREATE(CybersecurityEvent[Date]Node,EmailBox) NOTIFY(cybersecurity event [date] situation network projection S(G), cybersecurity event [date], email) CREATE(Cybersecurity event [date] situation network projection S(G), Cybersecurity event [date], Message channel)

[0154] In addition to allocating resources, restricting access to resources can also be an aspect of creating a situation network. For example, in the context of a cybersecurity use case, users within an organization with a virus can be projected and their access to their database containing PII can be removed via the following representative projection and resource (de)allocation. Cybersecurity event [date] access projection S (G) removal = IF ((user device AND has virus) THEN DENY (PII database).

[0155] In some embodiments, it may be desirable to establish a specific, secure (e.g., via encryption), and authorized (e.g., privileged and confidential) channel within the cybersecurity event status network 5978 where security analysts 5916, legal department 5922 (which may include general counsel), and selected members of the executive team (e.g., CEO, COO, and CIO) can discuss the cybersecurity event, potential solutions, and legal / financial implications for the company. A typical projection and resource allocation command would be: Cybersecurity Event [Date] Authorized Channel Projection S (G) = (Security Analyst, General Advisor, CIO) CREATE(Cybersecurity event [date] authorized channel projection S(G), Cybersecurity event [date], Secure message channel)

[0156] As will be understood by those skilled in the art, the example projection illustrated in Figure 23H, in conjunction with the example resource allocation illustrated in Figure 231, can be used to establish communications and allocate / de-allocate resources for each of the situation networks of Figure 9B, including the cybersecurity event situation network 5978, the cybersecurity industry situation network 5986, the social network situation network 5990, and the regulatory agency situation network 5996. The allocated resources may result in automated email notifications (including event-specific email "reply to" addresses) to the cybersecurity industry situation network 5986, the generation of automated posts, the establishment of breach event nodes, and the establishment of message boards or channels on the social network situation network 5990, and email notifications to projected entities in the regulatory agency situation network 5996.

[0157] The described method and system for creating various situation networks and allocating or deallocating resources for cybersecurity event use cases has numerous advantages, including the automated and efficient use of computing and network resources in response to virus or malware 5902-infected devices on the Acme Financial Software Corp. network 5904 (FIG. 9A). Specifically, databases containing information such as that shown in FIG. 23G are constantly growing and changing as the situation evolves and other user devices become infected or updated with antivirus software. These constant changes complicate the generation of relevant queries to the database due to both the volume and time-varying nature of the data. The storage of projection operators such as those shown in FIG. 23H, in conjunction with resource allocation operators such as those shown in FIG. 23I, allows a simple and, in some instances, standardized set of rules to be applied to the dynamic and data-intensive environment related to a cybersecurity event, automatically projecting and extracting relevant parties, creating communication channels between them, and allocating or deallocating resources as required. As opposed to requiring human intervention to determine who should be included in each particular communication channel, the system projectively extracts relevant parties and automatically establishes appropriate communication channels.

[0158] Another advantage of the system and method is that the system can add / remove members from the appropriate situation network as the situation evolves. For example, a user with a device that was infected by a virus but whose computer has been cleaned or otherwise updated with antivirus software would no longer be considered to have an infected device (e.g., "JANE User Device," "Has," "Virus" in FIG. 23G) and would be automatically dropped from projections looking for users with infected devices. This would result in their removal from communication channels dealing with cybersecurity events. In some embodiments, this occurs by periodically triggering projections and resource allocations and updating the situation network (e.g., batch processing hourly, nightly, or at other predetermined intervals), while in other embodiments, projections and resource allocations are triggered based on external events, such as patch availability, a significant increase or decrease in the number of infected devices, or other metrics as needed for the event. The present system and method can thus automatically update the situation network despite rapidly changing situations, potentially involving large datasets. This allows for efficient use of available computing resources, dedicated bandwidth for communication channels, and protects valuable resources (e.g., databases containing PII) while minimizing impact on workflow. Additionally, human resource burden is also considered: individuals who need access to information about the situation are automatically connected to the appropriate channel regarding the event, while individuals who are either not affected by the event or do not need to know details about the event are kept away from unnecessary communications that would distract them from performing their required tasks.

[0159] In some embodiments, nodes created as a result of an event (e.g., through resource allocation CREATE(cybersecurity event [date] node, email box)) are responsible for the projections and resource allocations that form the various situation networks. The nodes can actively schedule projections and resource allocations and record associations or links that indicate infected or protected devices. In this embodiment, the event node actively connects to other nodes and records relationships. This has the advantage of centralizing activity for the event. As the event is addressed and ultimately resolved, the nodes associated with the node (and associations / links) and other data related to the event can be archived. Eventually, once all aspects of the situation have been addressed (e.g., infected devices are cleaned up, data breaches are addressed, regulatory agencies are notified), the situation network and associated channels and resource allocation / deallocation can be decommissioned. This has the distinct advantage of freeing up computing and network resources associated with the situation and addressing human resource limitations by removing situation-sensitive communications from users' feeds.

[0160] Because the number of affected users in cybersecurity use cases can reach very significant numbers (e.g., millions or even tens of millions of users), the aforementioned methods and systems can employ several techniques to efficiently establish a situation network. In some embodiments, once a cybersecurity event is identified (e.g., one or more infected devices), projection is initiated based on the infected users and users within defined degrees of separation, organizational parameters, or communication patterns (e.g., users connected within n degrees of separation, users in the same organizational department, users with a large amount of communication between them). The use of scaled projection allows for efficient and automatic identification of users that should be interconnected in a situation network. In some embodiments, while an initial set of affected users is projected and added to the appropriate situation network, the system asynchronously iterates through the database to identify other users / devices that should be connected to one or more of the situation networks associated with the event.

[0161] Artificial intelligence techniques can be employed in various aspects during the establishment of a situational network. In the context of cybersecurity use cases, techniques such as data analysis, predictive analysis, email screening, real-time analysis, and traffic analysis can be used to declare the existence of a cybersecurity event, trigger the establishment of an event node, and assist in launching projections and resource allocation for the establishment of a situational network. In some embodiments, projections to find users to be included in a particular situational network are based on user behavior analysis (UBA), baseline behavior models, signature and signature-less detection, automated analysis, vulnerability identification, and prioritization. In this embodiment, one or more of the aforementioned techniques are used to identify a subset of users, connect them to one or more situational network channels, and potentially allocate or deallocate network resources to them. Stored projection operators take into account the use of one or more of these techniques and can be identified by an indicator such as “user_high risk,” which indicates that the system has identified users who are at high risk of having infected devices, but whose devices are not currently known to be infected. Such users can be connected to channels within the situation network that address high-risk users and offer solutions that may be entirely different from users with devices known to be infected. For example, by identifying high-risk users and connecting them to a particular channel within the situation network, they can be directed to network resources, including software / patches that they can install to protect their devices. By identifying a subset of high-risk users and creating channels within the situation network, it is possible to focus computing and communication resources on those individuals, as opposed to broadcasting messages to all users, which is both inefficient and can lead to bottlenecks in installing the appropriate software / patches.In operation, a command to extract a projection for "user_high risk" results in the invocation of a subroutine or method that uses one or more of the techniques described above to identify those users and form a projection.

[0162] In essence, the cybersecurity use case illustrates the use of a situational network to automatically create communication channels and allocate / deallocate resources in response to a cybersecurity event. As discussed, appropriate parties are automatically interconnected to facilitate communication regarding various aspects of the event (containment, resolution, regulatory compliance) and to appropriately handle the event. Identification of appropriate parties can be done efficiently despite the fact that large amounts of data are involved and the situation is dynamic. Network resources, including computing and communication resources, are judiciously utilized through projection and the establishment of specific communication channels.

[0163] The advent of virtual reality systems and devices that support virtual reality (such as Meta Quest and Oculus virtual reality / VR products) now allows participants to virtually gather and participate in events. An event may be a physical event with a corresponding virtual event or an entirely virtual event. The use of VR products in their various forms allows participants to view live video from the event, video related to or generated in support of the event, and avatars representing either individuals within the real event or virtual participants. These virtual events can be created to resemble the physical event or can have fully independent representations. In some embodiments, such as a real surgical procedure, this has a corresponding virtual event, and the virtual participants may be given access to components or devices in the real event, such as a robotic device for performing the surgical procedure. In such a situation, a virtual participant (such as a virtual surgeon with specific required expertise) may be invited to participate in the surgical procedure and provided with access to the robotic device, allowing them to use their expertise and contribute to or even perform the surgical procedure. In other situations, a virtual event can be created to correspond to a physical event, and participants can be invited to participate in either the virtual or physical event.

[0164] Because virtual reality offers the ability to invite large numbers of individuals to an event, it becomes necessary to appropriately determine who should be available to attend the event and under what conditions. Furthermore, because an event may have a corresponding physical event, and because the event may be an emergency or crisis situation, it becomes important for individuals to join either the physical event communication channel or the virtual event so that they can offer assistance or expertise. To the extent that appropriate individuals can be identified and added to one or more situation networks associated with the event, network resources can be utilized efficiently.

[0165] FIG. 11 illustrates a flowchart for creating a representative situation network in the metaverse, which in this example has a corresponding physical event. In an identify situation or event step 6100, a situation or event is identified. In establishing a physical event node 6110, one or more servers establish a physical event node. In establishing a virtual event node step 6120, a virtual event is established by a server or other computing device. In projectively extracting candidate participants step 6130, candidates for the situation network are identified. In creating an intermediate VR database step 6140, the server creates an intermediate database containing participants for the situation network in the metaverse. In transmitting to metaverse step 6150, the intermediate VR database is transmitted to a server, which associates it with the metaverse. In inviting candidate metaverse participants step 6160, the identified candidates are notified and invited to join. In a step 6161 of allocating network resources, resources such as bandwidth, encryption / decryption keys, access to secure channels, guaranteed quality of service (QoS) parameters, or other network parameters are set based on the permissions granted to the candidates or based on initial pre-determined values. In a step 6170 of checking participants into the VR event, candidates who accept the invitation are admitted to join the event and thus join the situation network created in the metaverse.

[0166] 16 illustrates an exemplary architecture for utilizing a context network within a virtual environment. Social network 6000 consists of social network server 6010 operating via network 1 6020. In some embodiments, network 1 6020 is the Internet. User 1 6001 operates user device 6002, user 2 6003 operates user 2 device 6004, and user 3 6005 operates user 3 device 6006.

[0167] In some embodiments, metaverse 6600 can be created on metaverse server 6610 via network 2 6040, which is connected with metaverse user 1 6620 and metaverse user 2 6630, who connect and participate in the metaverse through the use of VR devices (such as those described above), which interconnect to network 2 6040. In some embodiments, social network 6000 and metaverse 6600 operate on the same platform using overlapping servers.

[0168] As an example of the creation of a metaverse event, a physical event 6070 (e.g., a fire) may occur, resulting in the establishment of an event node within the social network 6000. Participants may connect to the event node through the physical network 6020, which may be considered an initial network through which information about the physical event 6070 is exchanged. In some embodiments, a corresponding virtual event 6640 is created within the metaverse 6600. The creation of the corresponding virtual event 6640 may, in some embodiments, be automated, such that once the physical event 6070 is verified and a node is established corresponding to the created physical event 6070, the corresponding virtual event 6640 is established. Verification may take several forms, including, but not limited to, multiple reports of the physical event 6070 (e.g., multiple posts), correlation of multiple reports to verify similar photographic or video evidence, image recognition performed on photographic or video feeds, verified or trusted emergency reports (e.g., 911 calls), or other data indicating that the physical event 6070 actually occurred or is actually occurring.

[0169] Although described in the context of an emergency event, in some embodiments, physical event 6070 can be an informative or entertainment event such as a party, concert, rally, political event (e.g., a debate or protest), conference, surgery, examination, class, or any other event that can be of interest to either participants or witnesses.

[0170] In operation, a set of contextual network participants can be projected from social network 6000. Proposed participants are tabulated in intermediate database 5620, which is transmitted via interconnect 6060. Participants who accept the invitation are interconnected or allowed admission to virtual event 6640. In some embodiments, metaverse participants, such as metaverse user 1 6620 and metaverse user 2 6630, are connected via virtual network 6040, which is interconnected to physical network 6020 via interconnect 6060. In alternative embodiments, metaverse network 6040 and physical network 6020 are one and the same network. As will be discussed subsequently, permissions can be used to control the level of access and network resources available to different users, even when operating on the same network.

[0171] While the previous examples illustrate the creation of virtual event nodes for metaverse events corresponding to physical events, an alternative example of a 911 call (also referred to as a “911 / VR use case”) with a corresponding virtual event node is developed to further illustrate the system and method. Referring to FIG. 22A , a diagram illustrates the participants and participants in a situation network that exist concurrently in both physical space and virtual reality. The participants in FIG. 22A are centered around an emergency event 7200. In this exemplary use case, the emergency event 7200 is a house fire at the Owens family residence located at 1200 Evergreen Street. The residents listed at this address are Bob Owens 7204, his wife Sally Owens 7216, and their son Jamie Owens 7206. The fire event was witnessed by passerby Diana Newit 7210 and neighbor Thorton Bradley 7208, who responded to witnessing the fire by calling 911 and transmitting recorded video. Depending on the emergency, various emergency responders may be dispatched, and in FIG. 22A these emergency responders are represented as Fire Engine 16 7202, Princeton Hospital Ambulance 7212, and Police Officer Tim Nowak 7214.

[0172] In some embodiments, a virtual reality situation network is created utilizing the network 7222 to connect affected parties or related parties who are not in the same physical location as the emergency event 7200. In this use case, the connected parties consist of Bob's mother, Meredith Owens 7218, Charlie L. Ring 7232, one or more virtual witnesses (not shown), Channel 9 news reporter 7234, structural inspection engineer Paul Gutenberg 7236, 911 dispatcher James Lopez 7226, and therapist Susan Gray 7228. As will be appreciated by those skilled in the art, the virtual witnesses can be any number of different related parties, including, but not limited to, close friends, employers, family members, and news organizations, as well as personnel important to or influential in the situation, such as dispatcher James Lopez 7226.

[0173] 22B illustrates an exemplary context-specific social graph that can be used to create a situation network for a potential use case. Physical and virtual emergency events and the involved parties (and in some instances, equipment such as ambulances) are depicted as nodes, while relationships between these nodes are shown as associations, such as Damage 7257 for victims affected by a fire. Additionally, associations, such as Connection 7258, Dispatch 7259, Notification 7259, and Video Feed 7263, may also be stored to indicate that a party is connected to both physical and virtual events (e.g., Connection 7258), dispatched to a physical event (e.g., Dispatch 7259), notified of an important event (e.g., Notification 7259), or providing a video feed from a physical event (e.g., Video Feed 7263).

[0174] In some embodiments, graph databases, such as the one illustrated in FIG. 22B, have the advantage of being capable of storing large amounts of complex and interconnected data. While many types of graph databases can be used to store and manage the data used to create one or more context networks, exemplary databases include, but are not limited to, Noe4j, OrientDB, and ArangoDB. Other types of databases that are generally considered to be graph databases can also be used. For example, triple store databases (generally considered to be a type of graph database) can also be used to store data in a subject-predicate-object structure. Triple store databases offer the advantage of being able to store and easily query semantic web data, typically using the Resource Description Framework (RDF).

[0175] Although illustrated as a graph database in Figure 22B, other types of databases can also be used. These other database structures include relational databases (e.g., SQL-type databases such as MySQL, PostgreSQL, Oracle, etc.), NoSQL databases (e.g., MongoDB, Redis, Cassandra), NewSQL databases (e.g., Google Spanner, CockroachDB), time-series databases (e.g., InfluxDB, TimescaleDB), object-oriented databases, search engines, and data warehouses that may be used to store, access, and manage the data from which the situational network data is derived.

[0176] In some embodiments, a virtual event node 7250, automatically created in response to the establishment of a physical event node 7240, serves to represent the physical emergency event in virtual reality. This allows geographically distant parties to receive information and updates related to the physical emergency event while remaining part of a consistent virtual reality situation network. FIG. 22B also demonstrates example associations between participants that determine their invitation to the physical and virtual situation networks. Participants present at the physical event are directly associated with physical event nodes, including victims represented by Bob Owens node 7249, Jamie Owens node 7251, and Sally Owens node 7252, as well as first responder Fire Engine 16 node 7243, Princeton Ambulance node 7245, and Police Officer Nowak node 7247. As can be seen in FIG. 22B , some participants, such as Meredith Owens (represented by Meredith Owens node 7253) and Thornton Bradley (represented by Thornton Bradley node 7241), are associated with both a physical event node 7240 and a virtual event node 7250. This may indicate that those parties are near, contributing to, reporting from, or affected by the physical event (e.g., a fire) represented by physical event node 7240, and are participating in the virtual reality social network hosted by virtual event node 7250. Additional participants may also be brought onto the VR situation network, represented in FIG. 22B as Commander Lopez node 7246, Therapist Gray node 7248, Channel 9 News node 7246, Investigative Technician node 7244, and Charlie L. Ring node 7242. As will be understood by one skilled in the art, the identification of the participants in each situation will vary from situation network to situation network, depending on the participants projected. Each node represents an active participant in the network while they contribute to the situation.For example, Channel 9 News node 7246 represents a news reporter who witnesses an event and reports information about it.

[0177] As described above and illustrated in the exemplary process shown in the flowchart in FIG. 11 , one or more situation networks can be created based on the basic steps of, for example, using node and association operators to project participants from a database, check for permissions, allocate resources, and add participants to one or more of the situation networks being formed. In a VR use case, when a physical emergency is reported, a corresponding virtual event node is created. From here, situation network participants are selected and assigned to one of three groups depending on their associations and abilities to influence the situation. These roles, as will be discussed, may not be fixed or stationary, but rather may be adapted to the situation through mechanisms such as promotion placement.

[0178] In some embodiments, the first situation network primarily includes first responders, such as paramedics and firefighters, but can also include any parties actively contributing information or assistance related to the event. Referring to FIG. 22C, a first responder situation network 7268 can be formed for those parties needing access to the emergency network. As shown in FIG. 22C, the first responder situation network 7268 can include police officer Nowak 7214, Princeton ambulance service vehicle 7212, nearby resident Thornton Bradley 7208 (who is promoted to the first responder situation network 7268 based on the video feed he is providing), and virtually added therapist Susan Grey 7228.

[0179] In the current use case, Princeton Ambulance 7212 and Police Officer Nowak 7214 are projected as associated first responders and invited to the first responder network 7268. Therapist Susan Grey 7228 was not initially invited, but the invitation was extended when information became available that victim Jamie Owens, represented by Jamie Owens node 7251, had died during the event.

[0180] Similarly, an affected and interested party situation network 7276 can be formed, in this instance consisting of Meredith Owens 7218 participating virtually, Channel 9 news reporter 7234 participating virtually, and nearby resident Thornton Bradley 7208 participating physically and being promoted to the first responder situation network 7268 as will be discussed. A broadcast status network 7278 is also created to provide information about the physical event. In the example shown in FIG. 22C , the broadcast status network includes Channel 9 news reporter 7234 (subsequently promoted to the affected and interested party status network 7276), Charlie L. Ring 7232, and investigative technician Paul Guttenberg 7236. As will be discussed, network resources can be allocated such that the first responder status network 7268 and its participants are prioritized for resources such as bandwidth and are guaranteed low latency and stable connections, whereas witnesses in the broadcast status network 7278 may have limited two-way bandwidth, but they can still receive high-quality video via multicast or other video broadcast techniques.

[0181] In some embodiments, due to the interconnected nature of the combined situation networks, the location of participants within a particular situation network may change as new information is brought to the situation. For example, Bob Jones's neighbor Thornton Bradley 7208 was initially invited to the affected party situation network 7276 due to his physical proximity to the location. In response to learning of a fire, instead of joining the network in VR, Thornton elects to go outside and stream video of the fire. Due to the addition of potentially useful new information to the system, the invitation to the first responder network is extended, which is referred to as promotion placement 7280. In some embodiments, this promotion placement is generated automatically through review of one or more aspects of the video feed, including location, viewpoint, quality of the video feed, individuals identified in the video feed through facial recognition, or other parameters indicative of the video feed's usefulness to managing the situation. Similarly, Channel 9 news reporter 7234 is monitoring the event from the broadcast situation network 7278. If the severity of the situation increases, such as a rise in the number of deaths, the news reporter will automatically be promoted. This promotion requires increased permissions and / or resources for the promoted user, allowing the news reporter access to more detailed and up-to-date information, as well as increased or guaranteed bandwidth, for example. This approach allows for the delivery of multiple sources of real-time information, while still allowing sources to be invited and removed as needed, conserving bandwidth and facilitating communication. As will be understood by those skilled in the art, demotion may also occur, such as when a video feed is no longer relevant or a better (e.g., higher resolution or better positioned) video feed becomes available.

[0182] FIG. 22C also illustrates a combined situation network created from three distinct situation networks within the VR use case. The combined VR situation network 7270 is formed through the interconnection of the first responder situation network 7268, the affected and interested party situation network 7276, and the broadcast situation network 7278. These situation networks are in turn supported by their respective servers: the first responder network server 7262, the affected and interested party server 7264, and the broadcast network server 7266. In alternative embodiments, more or fewer servers can be used to host the situation networks. In some embodiments, a single server is used to host all situation networks while still maintaining the individual characteristics (and permitted participants) of each network.

[0183] As will be understood by those skilled in the art, not all participants within the same physical situation network need be shown the same information. Through utilization of the inter-network permissions and node information table 7274, permissions can be established on a per participant / device basis. In some embodiments, first responders on the first responder situation network 7268 have unlimited two-way communication access, while physically distant bystanders on the broadcast situation network 7278 receive one-way read-only information, similar to what may be found on TV.

[0184] Referring to Figure 22D, an exemplary permission table is shown for some of the participants (individuals and / or devices) shown in Figure 22A as they are brought into the relevant situation network. The information shown in Figure 22D can be used to populate the inter-network permission and node information table 7274 shown in Figure 22C. As can be seen, elevated deployment provides further access to information. Additionally, a participant such as investigation technician Paul Gutenberg 7236 may initially be granted access only to broadcast video and status, but the permissions for that individual may change, such as if it is determined that a fire has caused structural damage and investigation technician Paul Gutenberg 7236 needs the ability to make requests regarding the video feed, in which case he would be elevated and given access to both responder information and video feed control so he could make decisions regarding the status and safety of the structure. Permissions such as those shown in FIG. 22D and the type illustrated in FIG. 12D (including HIPAA permissions) can be incorporated into the Inter-Network Permissions and Node Information Table 7274 or an alternate table accessed by the servers and software involved in forming the contextual network and controlling access to information by those individuals.

[0185] 22E, in some embodiments, relevant information is displayed on a terminal located inside the responder vehicle, such as Princeton Ambulance Service vehicle terminal 7213. This terminal is connected to an appropriate situation network, in this case the first responder situation network 7268, which allows information to be updated in real time by situation authorities such as 911 dispatchers, other local authorities, or real or virtual authorities providing near-real-time information. Similarly, physicians may have terminals such as a physician terminal (not shown) that provide information about patients affected by the situation. The physician terminal may be included as part of a smartphone, tablet, or other mobile or fixed computing device with a display or providing audio prompts.

[0186] As shown in FIG. 22F, a situation room (physical, virtual, or a combination of both) can be configured with alerted parties and witnesses identified in the situation network formed about the physical event. This situation room is a location where alerted parties, such as family members or employers, can receive information and situation updates. In some embodiments, these updates are provided by a main monitor 7220a, which displays general information, as well as a personal monitor 7220b, which may privately display privileged information, such as information available to the parents of a minor victim but not their teacher. Additionally, auxiliary information can be made continuously available through monitor updates.

[0187] In some embodiments, participants can enter or exit the situation control room. In this use case, Sally Owens 7216 was not at home during the fire and subsequently joined the situation control room illustrated in FIG. 22F. Also present in the room are Meredith Owens 7218, Charlie L. Ring 7232, Channel 9 News Reporter 7234, and neighbor Thornton Bradley 7208. All participants present are represented by virtual reality avatars while in the VR situation network. Meredith and Charlie are in the same situation control room, but due to their different relationships with their families, they are not necessarily aware of each other's presence and receive different information. Sally Owens 7216, parent of minor Jamie Owens 7206, has the right to know that confidential information, while Thornton Bradley, who lives one door away, only sees relevant information about the probability of the fire spreading before promotion placement. Following promotion, Thornton Bradley (post-promotion) is granted access to first responder information as well as video control (responding to requests for changes in perspective, zoom, and other features related to video feed control) and message boards to contribute live video about the situation. Charlie L. Ring7232 is a witness and therefore only receives updates about the status of the house fire, which can be viewed on news or community apps such as Citizen. Due to the fact that he is not a member of the immediate family, he is not permitted to interact with them during the crisis.

[0188] Referring to FIG. 22G, a fully immersive VR environment associated with the situation network in this use case is shown. For emergency responders whose duties do not require their physical presence, including, but not limited to, 911 dispatchers, social workers, and off-site physicians such as victim specialists, the VR environment allows them to interact and contribute while they are not on-site. In some embodiments, multiple VR monitors 7220c present within the virtual environment display various information, likely including situation updates and a list of involved parties. Participants in the control room can "drop in" to individual situation network situation control rooms to perform their duties in the emergency situation. In this use case, Dispatcher James Lopez 7226 enters the VR environment to monitor the 1200 Evergreen Street fire, the bomb threat at Parker High School, and the domestic disturbance at 55 Main Street. When he receives the words "fire extinguished" from fire engine 16, he utilizes the "drop in" feature via the situation control room entry request button 7220d to join the 1200 Evergreen situation control room, as shown in FIG. 22F. From here, Lopez can notify those present that the fire has been extinguished and instruct them on how to proceed. Crisis therapist Susan Grey 7228 also utilizes the situation network control room to manage multiple emergency events in parallel. In this use case, Jamie Owens has been killed in a house fire, and Susan Grey has been notified. She utilizes the "drop in" feature to enter the 1200 Evergreen Street situation control room and immediately begin counseling the family.

[0189] Figures 23D, 23E, and 23F illustrate an example triple store database, example projection operators, and example resource allocation for the 911 / VR use case, and how these components are used in forming various situation networks, as illustrated in Figure 22C. Figure 23D is an exemplary triple store database. These stored relationships enable the identification of related individuals and / or events, and that information provides the basis for invitations to situational networks (via projection) and distinguishes participants tied to physical event nodes from participants on virtual networks. Individuals can be determined to be in proximity to an event (e.g., within a defined distance) using geolocation techniques, including GPS, and other techniques, including but not limited to self-reporting, check-ins, and other methods in which user devices transmit location. In some embodiments, the database maintains a grasp of family and friend relationships utilizing relationship information (e.g., family and separation degrees or friend relationships and separation degrees) such as that stored in social networks. For example, the database can thus store information indicating that Bob Owens and Jamie Owens are at the location of a fire, while Sally Owens is not there. Using these relationships, BOB and JAMIE are shown as potentially injured parties in the physical event node, while SALLY is not, but instead is extended an invitation to join the first responder situation network 7268 and participate through virtual reality. As can be appreciated by those skilled in the art, the relationships stored within this database can consist of interpersonal relationships as well as numerous other relevant associations such as resource availability, emergency responder location, and hospital occupancy rates.

[0190] In some embodiments, the information stored in a triple store database such as that illustrated in FIG. 23D need not be static but may evolve with the situation. For example, once Thornton Bradley reports a fire to a 911 call center, the database is updated and a record including personally identifiable information (e.g., name and phone number) is stored along with an association of the individual reporting the incident. This can be used in a subsequent projection that brings Thornton Bradley into the first responder situation network 7268 based on his report of the incident and that he may have additional information about the first responder team that may be important in saving lives. Similarly, although there may be many structural engineers who could assist, Paul Guttenberg may be identified and listed in the database through various mechanisms (e.g., previous experience, association with one or more first responders).

[0191] 23E shows an example projection operator for the formation of a 911 / VR situation network. A projection operator is represented as a node operator, which may have one or more paired association operators. A representative projection for a first responder situation network 7268 would be: First Responder [Incident] Situation Network S(G) = (IF event is ongoing THEN ((first responder AND nearby) OR (user AND 911 notified))) OR (IF victim is identified THEN (user AND victim's next of kin)).

[0192] In this example, conditional logic is used to check that the event is still ongoing and to project all nearby first responders. Additionally, if a victim in the event has been identified (e.g., through discovered ID or by facial recognition), household members are immediately included in the projection. The projection also includes user Thornton Bradley, as he was the individual who notified 911 and may have additional information about the situation / event, as described above. Similarly, a representative projection for the affected and interested party context network 7276 would be: Affected and Interested Parties [Incident] Situation Network S(G) = (IF Victim Identified THEN (User AND Friend or Non-Relative of Victim)) OR (User AND Has Live Video Feed) OR (User is Within 0.1 Miles) OR (Press Team AND Has Live Video Feed)

[0193] In some embodiments, this projection will bring non-relatives and friends (assuming the victim has been identified) who are potentially in danger because they are nearby (e.g., within a 0.1 mile radius of the event), or who may be potentially useful, along with the live video feed to the user or media. In the case of multiple video feeds, the system may select parties to be included in the situation network automatically (e.g., based on video quality or feed location / viewpoint) or through manual intervention.

[0194] A representative projection for the broadcast situation network 7278 would be: Broadcast [incident] situation network S(G) = (reporters AND have live video feeds) OR (users AND have live video feeds) OR (users AND have requested access to VR event nodes)

[0195] In some embodiments, this projection will bring in all live video feeds (press and users) and offer the potential to add users requesting access (attendance) to the virtual event. Regarding the allocation of resources, Figure 23F illustrates how resources can be allocated to various situation networks. A representative set of commands for allocation of resources for the first responder situation network 7276 would be: CREATE((First Responder, Dispatcher, Hospital), Secure Radio Channel AND Corresponding Secure Internet Channel) ALLOCATE (Promote allocated user, video feed command) ALLOCATE (close relatives, general status message board)

[0196] In some embodiments, the first CREATE command establishes a secure radio channel and the radio channel's corresponding Internet feed, allowing parties named first responders, dispatchers, and hospitals who form part of the projection to communicate about the situation. In some embodiments, an encrypted police and fire radio channel is used to establish the radio channel, and a corresponding Internet channel / stream exists over which authorized users can directly connect and communicate on the radio channel. This has the advantage of allowing parties to communicate on the same channel even without wireless devices or out of range. In some embodiments, one or more broadcast video feeds are provided on the secure Internet channel. In some embodiments, all members of the first responder [incident] situation network S(G) are included within the secure radio channel and the corresponding secure Internet channel.

[0197] In some embodiments, also included within the resource allocation are commands, illustrating that promoted users may be given access to video feed commands (e.g., requests) that may be generated by first responders. In the case of nearby resident Thornton Bradley 7208, who is promoted to the first responder status network 7268 via promotional deployment 7280, he may receive a request to alter the position or viewpoint of his video feed so that other members of the first responder team may assess the situation, monitor damage, or search for victims. Similarly, commands are illustrated to allow next of kin to view a general status message board or to allow them to monitor another general status communication channel.

[0198] In some embodiments, with respect to the affected and interested party status network 7276, an example resource allocation command may be in the form: CREATE (Affected and Interested Party [Incident] Status Network S(G) (Access to General Status Message Boards and Streaming)

[0199] This allows all members of the affected and interested party status network 7276 to have both access to a general status message board as well as access to all video streams transmitted from the physical event.

[0200] In some embodiments, for a broadcast situation network, the resource allocation command may be in the form: CREATE (Create a broadcast video node, multicast) ALLOCATE (requesting user joins multicast) ALLOCATE(requesting user, non-confidential status board)

[0201] These exemplary commands take one or more broadcast video streams, create a multicast transmission, and allow users to request access (e.g., via a website or VR portal) to gain access by joining the multicast. By using multicast, bandwidth is conserved. Users requesting access are also presented with a non-confidential status board or other messaging mechanism that communicates the general status of the situation.

[0202] In some embodiments, permissions can be granted via a projection and resource allocation mechanism, but permissions such as those illustrated in Figure 22D can also be used through separate access and enforcement, either prior to allocating resources, in conjunction with allocating resources, or subsequent to allocating resources. Although described herein with respect to the 911 / VR use case, the permission table can be used in other use cases as well.

[0203] The embodiments described in the context of the 911 / VR use case have the advantage of quickly and automatically establishing one or more situation networks, such as a first responder situation network 7268, an affected and interested party situation network 7276, a broadcast situation network 7278, and, as illustrated in FIG. 22C , a combined situation network 7270. By applying projection operators to the appropriate databases, required individuals, objects, and equipment can be easily identified and brought into the situation network along with the appropriate resources. Because projection operators can be predetermined and do not require knowledge of specific individuals (users) or objects / equipment, they can be automatically referenced and applied to find the set of individuals, objects, and equipment that needs to be brought into the network. This is not only efficient from a computational perspective, but also eliminates the need for human intervention to identify individuals who must first be placed into the network.

[0204] In some embodiments, the projection operator also provides the ability to distinguish tiers of access corresponding to different situational networks, as described above and identified in Figure 22C. By using the projection operator to create defined participants within each situational network, resources can subsequently be allocated, and valuable resources such as bandwidth can be preferentially reserved for higher tiers, such as the first responder situational network 7268. This eliminates the need for human intervention to conserve valuable resources.

[0205] The aforementioned 911 / VR use case also provides a combined situation network 7270, which in some instances can be used to provide messages to all parties. Examples of such messages include broadcasts from official parties regarding the event / situation, global updates to all parties, and other messages and communications that should be transmitted to all parties, including those virtually participating, regarding the event / situation.

[0206] Referring to FIG. 12A , a diagram illustrates the participants and participants in a multi-situation network environment resulting from a 911 call. In FIG. 12A , a person witnesses a potentially injured party 6200, who has a safety smart device 6204. The safety smart device 6204 can be a smartphone, smartwatch, or other similar device that not only supports communication but also monitors personal safety and, in some instances, may detect abnormalities such as falls or fluctuations in vital signs. The device may then, autonomously or through obtaining permission from the potentially injured party 6200, transmit a distress signal 6206, which may consist of a voice message or data indicating that help is requested. In some embodiments, the safety smart device 6204 also transmits a status signal 6224, which can be received by one or more networks. In some embodiments, the distress signal 6206 is received by a 911 dispatcher 6208, which includes a human or computer-based receiver that receives the distress signal 6206. The 911 dispatcher 6208 is connected to various devices through a 911 network 6212, which includes a connection to a 911 server 6210, and to police1 6218, police2 6220, EMS1 6216, and EMS2 6214. In some embodiments, the 911 network 6212 is a private wireless-based network, while in other embodiments, it is based on a wired private network or utilizes the Internet. The 911 network 6212 is typically connected to an external network, such as external network 6223, which can be the Internet. As will be understood by those skilled in the art, the 911 dispatcher 6208 can instruct police and EMS and assist the potentially injured party 6200, as will be discussed.

[0207] Refers to participants who are not part of the emergency network but may be interested in the status of the potentially injured party 6200, including family member 1 6226, family member 2 6228, friend 1 6230, friend 2 6232, and user 2 6236. These individuals may form part of a social network, which is recorded on a social network server 6222, in which the potentially injured party 6200 may also be a participant. In some embodiments, all of the aforementioned participants are part of a social network hosted on the social network server 6222, and each member has access to the social network via a computer or a smart device such as a smartphone or watch. 12A , doctor 1 6244, doctor 2 6250, nurse 1 6252, nurse 2 6254, social worker 1 6256, and social worker 2 6258 are connected to a healthcare network 6246, which is supported by a HIPAA compliant server 6242. In addition, a hospital 6240 is also connected to the healthcare network 6246 and has access to a HIPAA compliant server 6242, which allows it to maintain and access records related to individuals admitted or about to be admitted to the hospital 6240. Note that a HIPAA disclosure device 6248 also forms part of the healthcare network 6246 and, as will be discussed, allows information to be disclosed under appropriate conditions.

[0208] FIG. 12B illustrates the creation of physical situation networks corresponding to the 911 request situation network and healthcare situation network created in support of the 911 use case. As shown at the bottom of FIG. 12B, these networks are 911 physical situation network 6262B, social network physical situation network 6272B, and healthcare physical situation network 6274B. These situation networks are formed from separate social graphs and databases containing information about the involved parties. In the example of 911 physical situation network 6262B, it is generated by 911 server 6210 from 911 social graph 6260B through use of 911 projection 6261B. In particular, the nodes of 911 social graph 6260B can include potentially injured party node 6200, 911 dispatcher node 6208B, police node 6220B, EMS2 node 6214B, EMS1 node 6216B, and police1 node 6218B. As will be appreciated by those skilled in the art, other nodes can also be included in the 911 social graph 6260B, and relationships between those nodes are stored as associations 6263B. A projection operator that can be used to project relevant nodes is 911 projection 6261B, which in some embodiments includes, but is not limited to, the proximity of police and EMS nodes to the potentially injured party 6200, vital signs measured by smart safety devices 6205, equipment delivered by police or EMS personnel, and other parameters, such as violence parameters, that may indicate the need for police presence prior to EMS arrival, to find appropriate EMS and police staff to assist the potentially injured party 6200. Other projections and projection operators can also be utilized, with the goal of quickly and efficiently identifying the most relevant parties to interconnect for further communication related to the status of the potentially injured party 6200.Referring to social network server 6222, this is used in conjunction with social network 6270B, and social network projection 6271B projects and extracts appropriate parties for social network physical situation network 6272B. As will be discussed, these may include individuals who require information related to potential injured party 6200. Referring to HIPAA compliant server 6242, this is used in conjunction with healthcare network 6246 and healthcare network projection 6273B to create healthcare physical situation network 6274B.

[0209] 12C , resulting from having various interconnected situation networks is a combined situation network 6290 including a 911 physical situation network 6262B, a social network physical situation network 6272B, and a healthcare physical situation network 6274B. As will be appreciated by those skilled in the art, the networks can be interconnected through a variety of mechanisms, including traditional TCP / IP as well as a translation function-enabled network that converts messaging on a combined network or private network, such as a 911 network, into messages that can be received on a traditional internet-based network. The network is supported by separate servers, including a 911 server 6210, a social network server 6222, and a HIPAA-compliant server 6242. 12B , the identified relevant parties include a 911 dispatcher 6208, who, once receiving a call or data from the potentially injured party 6200, then responds to assist the potentially injured party 6200 with the formation of a 911 physical situation network 6262B interconnecting police2 6220 and EMS1 6216 to facilitate communication between the identified relevant parties. With reference to the social network physical situation network 6272B, the identified relevant parties through the projection include family member1 6226, family member2 6228, and friend2 6232. With respect to the healthcare physical situation network 6274B, the related interconnected parties include doctor1 6244, nurse2 6254, and social worker2 6258. Note that for any of these situation networks and healthcare physical situation network 6274B, the identified participants may change over time, such that Doctor 1 6244 may go out of practice and another doctor may take his place within healthcare physical situation network 6274B.In some embodiments, a combined situation network can be created by facilitating intercommunication between a 911 physical situation network 6262B, a social network physical situation network 6272B, and a healthcare physical situation network 6274B. An inter-network server 6280, in some embodiments, is used to access an inter-network permission and node information table 6282, which contains information that allows or prohibits information from being distributed.

[0210] As shown in FIG. 12D , each party is designated to receive certain information, including, but not limited to, 911 information, HIPAA-related information such as health records or health status, access to message boards, and status updates. As an example, 911 Dispatcher 6208 can have access to all 911 information, HIPAA information, message boards, and status updates. Police 2 6220, EMS 1 6216, Doctor 1 6244, and Nurse 2 6254 can do the same, while Social Worker 2 6258, while designated as part of Healthcare Physical Condition Network 6274B, only receives status updates and is not authorized to receive other types of information. Family members 1, 2, and Friend 2 do not receive any 911 information, but based on their HIPAA authorization, Family Member 1 can receive HIPAA information and access message boards and status updates, while Family Member 2 and Friend 2 only receive status updates.

[0211] Referring to FIG. 12E, the terminal displays seen by relevant participants in the combined situation network 6290 are illustrated. Thus, the 911 Dispatcher terminal 6208E will display messages generated by or related to the 911 Dispatcher party, and the Police2 terminal will display information relevant to that participant, including important information such as status, address, incident, and estimated time of arrival at the scene. Similarly, the EMS1 terminal 6216E displays similar information. Health care participants, including Doctor1, receive information on the Doctor1 terminal 6244E, which shows relevant information such as estimated time of arrival and status regarding vital signs or information related to vital signs, such as a "vitals awaiting" message. The Nurse2 terminal 6254E displays similar information, allowing individuals to prepare for the arrival of the potentially injured party 6200. The Social Worker2 terminal 6255E displays only the information the participant has authorized to see, which in this case is limited to status notifications. Referring to family members and friends, the family member 1 terminal 6226E shows information related to the status of the potentially injured party 6200, along with instructions on how they may obtain further information. The friend 2 terminal 6232E receives simple status information, which can be subsequently updated. As will be understood by those skilled in the art, each terminal or display device may appear different and the functionality of the message board or status updates may vary, but the display of information is conveyed in accordance with the inter-network permissions and node information table 6282. Additionally, as will be understood by those skilled in the art, parties may enter information or may be required to enter information to be included in the message board, while other parties may have limited access to the message board or are not authorized to enter information based on the inter-network permissions and node information table 6282.

[0212] In some embodiments, another application of the creation and use of situational networks is the monitoring of personal safety and the autonomous creation of situational networks or multi-network situational networks in emergency situations. As will be appreciated by those skilled in the art, a situational network that can be quickly created with the identification of appropriate emergency response personnel can be essential to saving an individual's life.

[0213] In some embodiments, a monitoring device carried by an individual is used as the starting point for a situation network or multi-network situation network. Referring to FIG. 17 , in a first monitoring step 6710, a device such as a smartphone, smartwatch, or other monitoring device typically monitors a situation for the individual. The monitoring in step 6710 may include monitoring parameters of the individual's health, including biometrics such as heart rate and respiratory rate; monitoring an accelerometer to detect falls; monitoring noises such as gunshots, car accidents, or other potential events; and monitoring for smoke, fire, or excessive temperature. In step 6720, an emergency at the local level may be determined due to the fact that a monitor associated with the individual indicates an out-of-range or dangerous parameter. In a subsequent testing step 6730, the user is prompted to call 911 or is prompted as to the nature of the emergency through a more detailed screen display and menu system. If the user responds indicating an emergency requesting emergency services such as those provided by calling 911, a subsequent step 6740 is performed in which a connection is established either through a call within the telephone network or other electronic connection to a 911 operator or other emergency service. In a subsequent step 6750, important information about the individual or local situation is transmitted, which may include, but is not limited to, biometric information, accelerometer information that may indicate a collision, fall, or other event leading to a sudden change in position or high speed acceleration and subsequent deceleration, excessive temperature, or other parameters related to the local emergency. In a subsequent step 6760, a public threat test is performed in which it is determined whether the local emergency is a threat to multiple individuals (in which case it would be considered a public threat and proceed to flowchart option B) or is not a public threat (leading to flowchart option A).Returning to test 6730, if the user either responds negatively to the prompts or does not respond to the prompts regarding the need for emergency service, the system proceeds to test 6770 to see if the user responds by sending additional prompts. If the user responds to these prompts and continues to indicate that they do not need emergency service, the system returns to monitoring step 6710. If the user does not respond, the system performs another test to determine if the biometrics are within range, and if they are, the system again returns to monitoring step 6710. If not, the system performs another user responsiveness test 6790, and if the user does not respond, the system automatically performs step 6740 to call or connect 911 services. If the user is determined to respond in 6790, the system returns to monitoring step 6710.

[0214] Referring to FIG. 18 , test 6810 is performed via the processing circuitry to determine whether it is necessary to notify the affected individual's emergency contacts. If it is determined that the emergency contacts should not be notified, the system stops in step 6820 and returns to monitoring via the processing circuitry, as shown in step 6710 of FIG. 17 . If it is determined that it is necessary to notify the emergency contacts, a second test is performed via the processing circuitry to determine the need to create a situation network (step 6830). This test is performed by considering the parameters that led to the notification of 911 service, including biometric parameters associated with the individual, other environmental parameters, or parameters such as acceleration and temperature, to determine whether creation of a situation network is necessary to either inform individuals of the status of the individual who requested 911 service or to inform those individuals regarding their own safety. If it is determined that situation network creation is not required, stop step 6840 is reached, and the system eventually returns to the monitoring 6710 state. If test 6830 determines that a situation network should be created, connections are made in step 6850 to the social graph, initiating creation of the situation network by the processing circuitry. In a subsequent step 6860, projection parameters are transmitted to the social network, which may include parameters required to identify individuals who should be part of the situation network. These parameters may include friendship relationships, separation analysis, geographic location, individual status, their past history within the social graph, and events they attended. In some embodiments, the projection parameters are developed based on a determined assessment of other individuals' risk to the local emergency. For example, if an individual calls 911 services indicating they are physically ill and may have ingested something toxic, in creating the situation network, the projection parameters may include restaurants where the individual has dined or recently checked in, and other individuals who have dined at those restaurants.Thus, the projection parameters can be determined based on the parameters used to notify emergency services. In step 6870, a situation network is created via the processing circuitry by traversing the relationships and nodes of the social graph, and in step 6880 participants are notified and requested to connect to and become part of the situation network.

[0215] Referring to FIG. 19 , if the threat is determined to be a threat to the public in test 6760, the system proceeds to the flowchart labeled B in FIG. 17 , where a connection to the social graph is created in step 6910. In step 6920, the system or device then transmits public threat projection parameters via the processing circuitry. These parameters may include the expected radius of the threat, the level of the threat, the number of individuals believed to be under threat by the event, the duration of the event, whether it is an ongoing or ended crisis, the expected duration of the event, e.g., a weather event, and other parameters that may be useful in creating a situation network. In step 6930, a test is performed by the device via the processing circuitry, or more typically, within the social graph, to determine whether the event is verifiable. In some embodiments, test 6930 is performed by monitoring other indications of a public crisis transmitted by other devices or individuals. If the crisis is determined to be verified, a situation network is created in step 6940, and participants are notified and invited to join the situation network in step 6950. If the public threat is not verifiable, the system stops in step 6960 and eventually returns to the monitoring step 6710.

[0216] Referring to FIG. 23A, a simplified triple store database is shown for forming a situational network for a 911 call. These are the data points considered for each individual to determine whether an invitation to the situational network should be extended. In some embodiments, data and associations are stored as semantic triples consisting of a subject, predicate, and object. As will be understood by those skilled in the art, triples can be manipulated into more complex forms by pointing to another triple as the object. FIG. 23A lists an example of meaningful associations that allow for the identification of related individuals. For example, EMS1 is currently responding to an event; however, EMS2 is nearby, has specialized equipment, and can easily be invited into the network if its equipment is needed. Furthermore, both Police Departments 1 and 2 are within the dispatch area, but Police Department 1 was prioritized due to its history of success in violent calls such as this one.

[0217] FIG. 23B shows a table of exemplary pairs of node operators and association operators for an exemplary 911 situation network. These node operators represent the decision-making process regarding whether to extend an invitation to a particular participant and have them join the situation network, while the association operators represent the changing and adapting parameters necessitating the addition of those parties to the situation network. As will be understood by those skilled in the art, these node and association operators can be generated from multiple sources of data. In some embodiments, they are triple store databases or stored social graphs. An exemplary projection of participants proceeds as follows: an emergency situation is identified and a decision is made whether to form a situation network. From here, the projection operators define the parties needing assistance, the affected parties, and the parties who should be alerted. For example, the association operator of the victim's vitals can be measured from a safety smart device, as discussed in FIG. 12A, and if the vitals begin to deteriorate, a decision to invite a paramedic into the emergency situation network is made in response to changing the association operator. In some embodiments, the situational network will have access to a database that stores information such as paramedic skills and delivered equipment, allowing for more complex projections. For example, if a safety smart device detects a dangerous fall through accelerometer data, a specific paramedic with access to a cervical collar may be invited into the network.

[0218] Referring to FIG. 23J, a simplified triple store database is shown capturing data about individuals within a business enterprise. Each entry in the database, or "semantic triple," consisting of a subject, predicate, and object, forms a description of a resource within the organization. For example, a triple with the subject "Marketing Manager," the predicate "Finished," and the object "Leadership Training" indicates that an individual in the role of Marketing Manager has completed leadership training. Triples can represent various types of information, including, but not limited to, personal preferences, work habits, certifications, and relationships between individuals. This structured format allows for easy querying of the data and enables the identification of patterns and correlations, allowing for the projection of situational network participants. In FIG. 23J, a wide variety of stored workplace data is used to project teams for time-sensitive tasks. In one example, "Marketing Manager" and "Marketing 1" both have entries indicating they prefer morning meetings. This is likely indicative of peak productivity and effective team alignment. Conversely, "Marketing 2" may prefer afternoon meetings, so including this individual in a morning meeting may not be optimal for their productivity or team effectiveness.

[0219] In some embodiments, beyond explicit data, the database can infer new relationships through a set of predefined inference rules and an initial ontology that defines the meaning of predicate relationships. An ontology in this context is a formal representation of knowledge in this context, consisting of a set of concepts, classes / categories, and the relationships between them. In FIG. 23J, an example ontology defining predicates is given: "The predicate 'likes' is defined to indicate an individual's strong tendency or habit. The predicate 'has had success with' indicates successful professional interactions. The predicate 'had lunch with' indicates a personal trust relationship between individuals. Inference rules can be created for team formation, such as "If two or more individuals prefer the same time slot for a certain activity and there is evidence of successful professional interactions or trust between colleagues, infer that they are suitable to be on the same team." Other inference rules also exist for other team scenarios; one such example is "If an individual completes a specific training, they will be invited to a leader role."

[0220] Referring to Figure 23J, the following inference can be made: "Given that Marketing Manager and Marketing 1 both prefer morning meetings and have had meals together (indicating a trusting relationship), it can be inferred that they are likely to work well together during morning meetings. Additionally, Sales 1 has a track record of success with Marketing 1, suggesting they have a successful working relationship. Although Sales 1's meeting time preference is not stated, their previous success justifies their invitation to join the team. In this scenario, Marketing 2 is not selected due to its time preference for afternoon meetings, indicating an incompatibility in productivity time. Additionally, IT 1 is not selected for the team despite possessing relevant skills. This is because the database, through its inherent inference rules, may determine that IT is not required for the assigned task. Using these rules, the database projects the necessary participants and sends out invitations, creating the final team of Marketing 1, Marketing Manager, and Sales 1."

[0221] Figure 23K shows an example list of projection operators for role identification and team building. Node operators store specific team roles and desired team qualities. Association operators indicate methods for identifying individuals within the business who best fit the roles listed in the node operators. This format allows for the use of a simple semantic language to query and invoke the situation network for team formation. When a team is needed, a list of required roles is provided to the database. Through analysis of each role's paired association operator, projections can be formed to invite relevant individuals into the situation network. For example, a team is formed to include a leader, a subject matter expert, and a fast-learning new employee. It is determined that the final team members should be individuals who can play a coordinating role and minimize conflict. The database is searched for users who regularly use company-provided meditation tools and / or have completed emotional intelligence training. If multiple matches are found, a weighting process is used to cumulatively evaluate the best match due to the fact that these attributes are highly correlated with the skills required for a coordinating role.

[0222] In some embodiments, location information can be utilized in forming a situation or multi-network situation network to identify the location of users, equipment, vehicles, or other persons or objects that may need to be added to the situation network. Their locations can be stored as information associated with a node or as an association to a node representing the individual or object. Several techniques can be used to determine the location of a person or object.

[0223] The use of global positioning satellite (GPS) information can also be used to determine location. For example, a GPS device in a smartphone, vehicle, or other object can be used to determine the location or position of the person / object.

[0224] In some embodiments, in addition to standard GPS information, several enhanced GPS techniques can also be used. Enhancements to GPS positioning capabilities can be based on advanced techniques that can significantly improve accuracy, reliability, and performance. Exemplary methods include: Differential GPS (DGPS): This technique uses a network of fixed, ground-based reference stations to broadcast the difference between the position indicated by GPS satellites and a known, fixed position. This helps correct for GPS signal errors caused by atmospheric interference, improving accuracy. Real-time kinematic (RTK) GPS: RTK is a type of DGPS that uses carrier phase enhancement to provide real-time corrections and achieve centimeter-level accuracy. It is especially useful in surveying, agriculture, and other applications requiring high precision. Assisted GPS (A-GPS): Primarily used in cell phones and other portable devices, A-GPS improves start-up performance (time to first fix). It uses an internet connection to provide data about satellite positions, which speeds up the time it takes for a GPS receiver to find a position. GNSS extension: This involves the use of additional satellite navigation systems such as Russia's GLONASS, the European Union's Galileo, or China's BeiDou. By having access to more satellites, receivers can improve accuracy and reliability, especially in difficult environments such as built-up urban areas. Multi-frequency GPS: Using a GPS receiver that can access multiple frequencies can help mitigate the effects of ionospheric delays and further improve accuracy. Advanced signal processing: Implementing advanced algorithms for signal processing can improve error detection and mitigation, improving GPS accuracy under difficult conditions such as under dense foliage or in urban areas with tall buildings. Integration with Inertial Navigation Systems (INS): Combining GPS data with that from an inertial navigation system, which uses accelerometers and gyroscopes to calculate position and orientation, can provide more accurate and persistent location information, especially when the GPS signal is weak or unavailable. Geostationary Satellite-Based Augmentation Systems (SBAS): These systems, such as the US's WAAS, Europe's EGNOS, and India's GAGAN, provide corrections and alignment information to improve GPS accuracy. Use of AI and machine learning: Implementing AI and machine learning algorithms can help predict and correct errors and optimize the processing of GPS signals for improved accuracy and efficiency. Network RTK (NRTK): This is an extension of RTK that uses a network of reference stations to create a more robust and accurate correction model.

[0225] These techniques, often used in combination, can significantly improve the performance of GPS systems in a variety of applications, enabling projection operators to define more precise locations and locations of people or objects. In some use cases, such as 911 / emergency services use cases, improved GPS can be used to locate individuals within one meter or less. This can be important in emergency situations such as fires, earthquakes, or terrorist events.

[0226] In 5G networks, location determination can be performed using multiple-input multiple-output (MIMO) technology. MIMO is a method of using multiple transmit and receive antennas to double the capacity of a wireless link and take advantage of multipath propagation. The following techniques can be used to assist location determination in 5G networks. Angle of Arrival (AoA): MIMO systems can estimate the angle of arrival of a signal. By using multiple antennas, the system can determine the direction from which the signal is arriving. By comparing AoA information from different base stations, the location of a device can be triangulated. Time Difference of Arrival (TDoA): This technique relies on the difference in time it takes for a signal from a mobile device to arrive at various base stations. Because the speed of radio waves is known, calculating the difference in arrival time helps estimate the device's distance from each base station. Combining this data from multiple base stations can accurately determine the device's location. Beamforming: MIMO enables more advanced beamforming, where the focus of a signal beam can be adjusted to target a specific area or device. Beamforming improves signal strength and quality, which can increase the accuracy of location determination. 5G Higher Frequency Bands: 5G networks use higher frequency bands (such as millimeter wave), which result in more precise location capabilities due to their shorter wavelengths. These frequencies enable more accurate AoA and TDoA measurements. Signal Fingerprinting: This method involves creating a database of signal characteristics at various locations. By comparing signal characteristics observed from a device with the database, the system can infer the location of the device. Enhanced data rates and capacity: The improved data rates and capacity in 5G, facilitated by MIMO, will enable the transmission of more complex and detailed location information, further improving location accuracy.

[0227] In some embodiments, in the event of a local emergency, a 911 caller calls emergency services using a cellular and IP-enabled mobile device. The call is routed through a Mobile Positioning Center (MPC), and various techniques are used to determine the caller's location. These techniques vary depending on the sophistication of the technology at each PSAP and MPC, but most commonly include a combination of A-GPS, TDoA, and AoA. The MPC then relays the calling device's updated location information to the Public Safety Access Point (PSAP). For calls from landline telephone numbers, the ANI (Automatic Number Identification) is sent along with the call to the PSAP. Dispatchers can then use this identifier to request the landline's stored address from an Automatic Location Information (ALI) database. For 911 calls made from mobile devices, the p-ANI (Pseudo Automatic Number Identification) is passed to the PSAP as an identifier for the calling device. In Next Generation 911 (NG911) embodiments, emergency calls can be made via Voice over Internet Protocol (VoIP) through a softphone or other Internet-enabled device. In these cases, location is determined by the VoIP provider through Wi-Fi positioning. If this information is not available, a statically configured address can be accessed through an AI database.

[0228] The combination of identity and location data assists in the creation of a social graph. 911 dispatchers working at a PSAP can use this social graph to request the creation of a situation network. This situation network can connect directly affected parties with parties who should be notified of the emergency, such as family, friends, and employers. If necessary, agencies such as police or other organizations can initiate hierarchical situation networks, as shown in Figure 8, to provide direct lines of communication to people affected by the emergency.

[0229] 20 depicts an example where a social graph / social network database stores information, including images or templates (facial recognition templates), stored with associations. As can be appreciated by those skilled in the art, a social graph / network can include users, user images, places, events, and other items stored as nodes, and associations (likes, attendance), stored as associations.

[0230] In some embodiments, in operation, an image is uploaded and a face template can be generated from the image. Rather than searching through a large number of images and templates (potentially totaling billions or even tens of billions of images) that may be stored within the system, an operator can define associations, e.g., based on the location (e.g., where the uploaded image was taken) or associations (e.g., people who have "liked" the location), to generate a set of candidate images. The uploaded image or templates generated from the uploaded image can be tested against the candidates.

[0231] 21 depicts an exemplary architecture in which a social network / graph operates using a series of social network servers connected across a network (e.g., the Internet). Users utilize terminals or other devices in conjunction with a query server to both upload images and generate queries. As discussed, queries can include both node and link operators that define a search and generate a set of matching candidates.

[0232] In some embodiments, a genetic database can be included in the search (either as part of the social network or as a separate database), as illustrated in Figure 20. Genetic information, either derived from the image or collected by the user, is included in the query and projection operators, which are transmitted from the query server to the social network and genetic database. In some embodiments, the types of genetic data used include Y-DNA, autosomal DNA, and mitochondrial DNA, as well as a combination of identified single nucleotide polymorphisms (SNPs).

[0233] Artificial intelligence (AI) can be highly effective at mining social networks, discovering nodes and associations relevant to particular situations, and subsequently creating situation networks. Several AI techniques can be applied, including, but not limited to: Data Collection and Mining: AI algorithms can collect vast amounts of data from social networks. This data includes user profiles, posts, comments, likes, shares, and network connections. This information, along with statistics associated with the information (e.g., number and type of likes, frequency of connection use), can be used as parameters in projection to identify relevant nodes / parties that should be added to the context network. Natural Language Processing (NLP): AI tools can use NLP to understand and interpret text within posts and comments. NLP is useful for sentiment analysis, topic detection, and identifying key words and phrases relevant to the situation being analyzed. This information, along with associated statistics (e.g., parties consistently using specific words or showing consistent positive or negative sentiment), can be used in projections to identify relevant nodes / parties that should be added to a situation network. For example, parties that show consistent positive sentiment toward an event, product, or other individual can be added to a situation network with similar events, products, or individuals. This can be particularly useful for advertising applications, where a situation network is formed to identify individuals for targeted advertising purposes. Pattern Recognition and Machine Learning: AI tools can be used to perform pattern recognition and identify trends and commonalities in the data. Machine learning models can learn from this data and identify the types of nodes (individuals, groups, or topics) that are most relevant to the situation. In some embodiments, trends and commonalities are used as projection operators to project related nodes / users from the social graph or hierarchical graph. Network Analysis: AI performs network analysis to understand how different nodes are connected. This involves analyzing who is connected to whom and the information flow through the network. This helps identify influential nodes and the strength of associations between different nodes. When applied to network security, the identification of nodes and their interconnections can be used to project related nodes and isolated threats or project actors from attacks. Predictive Analytics: AI can predict future trends and behaviors by analyzing past and current data. This is useful in anticipating how a situation may evolve based on current network dynamics. In the context of situation networking, prediction can be used as an operator in projection to identify relevant nodes that are likely to behave in a certain way based on past actions and add them to the relevant situation network. Anomaly Detection: AI excels at detecting anomalies or outliers in data patterns. This is useful in identifying anomalous behavior or emerging threats in social networks. Anomalies can be used to include or exclude nodes from the situational network. Projection operators can incorporate criteria, including anomaly parameters.

[0234] 13 is a simplified block diagram illustrating a computing device 6300 and illustrates some of the components that may be included within a computing device arranged to operate in accordance with embodiments herein. The computing device 6300 may be a client device (e.g., a device actively operated by a user), a server device (e.g., a device that provides computing services to client devices), or some other type of computing platform. Some server devices may operate as client devices from time to time to perform certain operations, and some client devices may incorporate server features.

[0235] In some embodiments, the computing device 6300 includes a processor 6302 (e.g., processing circuitry), a memory 6304 (e.g., non-transitory memory), a network interface 6306 (display circuitry), and an input / output unit 6308 (e.g., input / output circuitry), all of which may be coupled by a system bus 6310 or similar mechanism. In some embodiments, the computing device 6300 may include other components and / or peripheral devices (e.g., removable storage, printers, etc.). The non-transitory memory may store instructions that, when executed by the circuitry, control the I / O circuitry, any other suitable circuitry, or a combination thereof, to perform the functions of the context application, as described above. Instructions for implementing any of the embodiments of the context application discussed herein may be encoded on a non-transitory computer-readable medium. The computer-readable medium may be non-transitory, including, but not limited to, volatile and non-volatile computer memory or storage devices such as hard disks, floppy disks, USB drives, DVDs, CDs, media cards, register memory, processor cache, random access memory (RAM) on DRAM integrated circuits, read-only memory, etc.

[0236] In some embodiments, the processor 6302, e.g., processing circuitry, may be one or more of a central processing unit (CPU), a coprocessor (e.g., a mathematical, graphics, or encryption coprocessor), a digital signal processor (DSP), a network processor, and / or any type of computer processing element, such as some form of integrated circuit or controller, that performs processor operations. In some cases, the processor 6302 may be one or more single-core processors. In other cases, the processor 6302 may be one or more multi-core processors with multiple independent processing units. The processor 6302 may also include register memory for temporarily storing instructions and associated data being executed, and cache memory for temporarily storing recently used instructions and data.

[0237] In some embodiments, memory 6304 may be any form of computer-usable memory, including, but not limited to, random access memory (RAM), read-only memory (ROM), and non-volatile memory (e.g., flash memory, hard disk drives, solid-state drives, compact discs (CDs), digital video discs (DVDs), and / or tape storage). Thus, memory 6304 represents both a main memory unit as well as long-term storage. Other types of memory may include biological memory.

[0238] In some embodiments, memory 6304 may store program instructions and / or data on which the program instructions may operate. As an example, memory 6304 may store these program instructions on a non-transitory computer-readable medium such that the instructions are executable by processor 6302 to perform any of the methods, processes, or operations disclosed herein or in the accompanying drawings.

[0239] As shown in FIG. 13 , memory 6304 may include firmware 6304A, kernel 6304B, and / or applications 6304C. Firmware 6304A may be program code used to boot or otherwise start some or all of computing device 6300. Kernel 6304B may be an operating system, including modules for memory management, scheduling, and management of processes, input / output, and communications. Kernel 6304B may also include device drivers that allow the operating system to communicate with hardware modules (e.g., memory units, networking interfaces, ports, and buses) of computing device 6300. Applications 6304C may be one or more user-space software programs, such as a web browser or email client and any software libraries used by these programs. Memory 6304 may also store data used by these and other programs and applications.

[0240] In some embodiments, the network interface 6306 may take the form of one or more wired interfaces, such as Ethernet (e.g., Fast Ethernet, Gigabit Ethernet, etc.). The network interface 6306 may also support communication via one or more non-Ethernet media, such as coaxial cable or power line, or via wide area media, such as Synchronous Optical Networking (SONET) or Digital Subscriber Line (DSL) technology. The network interface 6306 may additionally take the form of one or more wireless interfaces, such as IEEE 802.11 (Wi-Fi), BLUETOOTH, Global Positioning System (GPS), or wide area wireless interfaces. However, other forms of physical layer interfaces and other types of standard or proprietary communication protocols may also be used via the network interface 6306. Furthermore, the network interface 6306 may comprise multiple physical interfaces. For example, some embodiments of the computing device 6300 may include Ethernet, BLUETOOTH, and Wi-Fi interfaces.

[0241] In some embodiments, the input / output unit 6308 may facilitate user and peripheral device interaction with the computing device 6300. The input / output unit 6308 may include one or more types of input devices, such as a keyboard, a mouse, a touchscreen, etc. Similarly, the input / output unit 6308 may include one or more types of output devices, such as a screen, a monitor, a printer, and / or one or more light-emitting diodes (LEDs). Additionally or alternatively, the computing device 6300 may communicate with other devices using, for example, a universal serial bus (USB) or a high-definition multimedia interface (HDMI) port interface.

[0242] In some embodiments, one or more computing devices, such as computing device 6300, may be deployed to support an aPaaS architecture. The exact physical location, connectivity, and configuration of these computing devices may be unknown and / or unimportant to the client devices. Thus, the computing devices may be housed in various remote data center locations and may be referred to as “cloud-based” devices.

[0243] 14 depicts a cloud-based server cluster 6400, according to an example embodiment. In FIG. 14, the operation of a computing device (e.g., computing device 6300) may be distributed among server devices 6402, data storage 6404, and routers 6406, all of which may be connected by a local cluster network 6408. The number of server devices 6402, data storage 6404, and routers 6406 in the server cluster 6400 may depend on the computing tasks and / or applications assigned to the server cluster 6400.

[0244] For example, server devices 6402 can be configured to perform various computing tasks of computing device 6300. Accordingly, computing tasks can be distributed among one or more of server devices 6402. To the extent these computing tasks can be performed in parallel, such distribution of tasks can reduce the total time to complete these tasks and return results. For purposes of simplicity, both server cluster 6400 and individual server devices 6402 can be referred to as "server devices." It should be understood that this nomenclature implies that one or more distinct server devices, data storage devices, and cluster routers can be involved in server device operations.

[0245] In some embodiments, data storage 6404 may be a data storage array including a drive array controller configured to manage read and write access to a group of hard disk drives and / or solid state drives. The drive array controller, alone or in conjunction with the server devices 6402, may also be configured to manage backup or redundant copies of data stored in data storage 6404 and to protect against drive failure or other types of failure that prevent one or more of the server devices 6402 from accessing units of data storage 6404. Other types of memory besides drives may also be used.

[0246] In some embodiments, router 6406 may include networking equipment configured to provide internal and external communications for server cluster 6400. For example, router 6406 may include one or more packet switching and / or routing devices (including switches and / or gateways) configured to provide network communications between (i) server devices 6402 and data storage 6404 via local cluster network 6408, and / or (ii) server cluster 6400 and other devices via communication link 6410 to network 6412.

[0247] Additionally, the configuration of the router 6406 may be based, at least in part, on the data communication requirements of the server devices 6402 and data storage 6404, the latency and throughput of the local cluster network 6408, the latency, throughput, and cost of the communication links 6410, and / or other factors that may contribute to cost, speed, fault tolerance, resilience, efficiency, and / or other design goals of the system architecture.

[0248] As an example, data storage 6404 may include any form of database, such as a structured query language (SQL) database. Various types of data structures may store information within such a database, including, but not limited to, tables, arrays, lists, trees, and tuples. Furthermore, any database within data storage 6404 may be monolithic or distributed across multiple physical devices.

[0249] In some embodiments, the server device 6402 may be configured to transmit data to and receive data from the data storage 6404. This transmission and retrieval may take the form of SQL queries or other types of database queries and the output of such queries, respectively. Additional text, images, video, and / or audio may be included as well. Furthermore, the server device 6402 may organize the received data into web page or web application representations. Such representations may take the form of markup languages ​​such as Hypertext Markup Language (HTML), Extensible Markup Language (XML), or some other standardized or proprietary format. Furthermore, the server device 6402 may have the capability to execute various types of computerized scripting languages, such as, but not limited to, Perl, Python, PHP Hypertext Preprocessor (PHP), Active Server Pages (ASP), JAVASCRIPT®, etc. Computer program code written in these languages ​​may facilitate the provision of web pages to client devices and client device interaction with the web pages. Alternatively, or in addition, JAVA® may be used to facilitate the generation of web pages and / or provide web application functionality.

[0250] The present disclosure further provides the following embodiments. 1. A computer-based method for creating a situation network, comprising: a. projecting a plurality of candidate participants for a situation network from a database of electronic records, the projection being based on one or more combinations of nodes and associations between the nodes; b. transmitting an invitation to at least a portion of the potential participants to join the situational network; c. receiving two or more than two approvals to join the situation network from the set of active participants; d. Establishing network connections between active participants to create a situation network; A method comprising: 2. A computer-based method for creating a situation network, comprising: a. projecting a plurality of candidate participants for a situation network from a database of electronic records associated with the first network, the projection being based on one or more combinations of nodes and associations between the nodes; b. creating an intermediate database including potential participants and at least one contact field for the potential participants; c. transmitting the intermediate database from a first server associated with the first network to a second server associated with a second network; d. transmitting an invitation to at least some of the potential participants to join the situation network on the second network; e. receiving two or more than two approvals to join the situation network from the set of active participants; f. establishing network connections between active participants on the second network to create a situation network; A method comprising: 3. A computer-based method for creating a situation network in a metaverse, comprising: a. establishing a node on a first set of servers that represents a physical situation; b. establishing nodes on a second set of servers that represent virtual situations in the metaverse that correspond to the physical situations; c. projecting, from a database of electronic records, a plurality of candidate participants for a situation network associated with the physical situation, the projection being based on one or more combinations of nodes and associations between the nodes; d. transmitting an invitation to at least a portion of the potential participants to join the context network within the metaverse; e. receiving two or more than two approvals from a set of active participants to join the context network within the metaverse; f. establishing network connections between active participants and nodes representing virtual situations in the metaverse; A method comprising:

Claims

1. 1. A method comprising: Identifying the geographic area affected by the situation; identifying a plurality of devices associated with a plurality of users within the identified geographic area; causing the plurality of devices to enter a situational mode, wherein the devices in the situational mode are configured to share protected data; obtaining, for each respective device of the plurality of devices, secured data from each of the plurality of devices, the secured data comprising contact list information from a respective plurality of communication modes available on the respective device; generating a data structure based on the contact list information for each of the plurality of devices, the data structure identifying connections between users of the plurality of users and identifying available communication modes for each connection; establishing a plurality of group communication channels for a plurality of subsets of the plurality of devices based on the data structure, each group communication channel of the plurality of group communication channels enabling communication via one of the available communication modes; A method comprising:

2. For each device of the plurality of devices, determining a subset of the plurality of subsets to which an individual device belongs; identifying a communication mode for each of the determined subset of group communication channels; disabling or throttling communication modes other than the identified communication mode on the individual device; The method of claim 1 further comprising:

3. 10. The method of claim 1, wherein the available communication modes comprise one or more of: (a) messaging applications installed on the plurality of devices; (b) physical network interfaces present on the plurality of devices; or (c) a combination of the messaging applications and the physical network interfaces.

4. causing a particular device of the plurality of devices to enter the status mode, 2. The method of claim 1, comprising making the particular device available for access over a network to at least one of: (a) data stored on the particular device that is inaccessible over the network when the particular device is not in the situational mode; or (b) a sensor data stream from at least one sensor of the particular device that is inaccessible over the network when the particular device is not in the situational mode.

5. said generating said data structure comprising: generating a graph in which each user of the plurality of users is represented by a node; generating edges for the graph, each edge connecting two nodes of the graph and identifying available communication modes for communication between user devices associated with the two nodes; The method of claim 1 , comprising:

6. Identifying the geographic area affected by the condition may include: The method of claim 1 , comprising obtaining motion data indicative of an emergency situation from motion sensors of the plurality of devices.

7. Identifying the geographic area affected by the condition may include: The method of claim 1 , comprising identifying multiple calls to emergency services from the multiple devices.

8. The method of claim 1 , further comprising transmitting information related to the situation to each of the plurality of devices via the established plurality of group communication channels.

9. receiving sensor data from the plurality of devices in the situational mode; constructing a 3D representation of the identified geographic area based on the sensor data; and generating said 3D representation on an extended reality (XR) display for display; The method of claim 1 further comprising:

10. The method of claim 9 , further comprising transmitting at least a portion of the 3D representation to each of the plurality of devices via the established plurality of group communication channels.

11. 1. A system comprising: processing circuitry, Identifying the geographic area affected by the situation; identifying a plurality of devices associated with a plurality of users within the identified geographic area; causing the plurality of devices to enter a situational mode, wherein the devices in the situational mode are configured to share protected data; obtaining, for each respective device of the plurality of devices, secured data from each of the plurality of devices, the secured data comprising contact list information from a respective plurality of communication modes available on the respective device; generating a data structure based on the contact list information for each of the plurality of devices, the data structure identifying connections between users of the plurality of users and identifying available communication modes for each connection; processing circuitry configured to perform an input / output network comprising: establishing a plurality of group communication channels for a plurality of subsets of the plurality of devices based on the data structure, each group communication channel of the plurality of group communication channels enabling communication via one of the available communication modes; an input / output circuitry configured to: A system comprising:

12. The processing circuitry further comprises, for each device of the plurality of devices: determining a subset of the plurality of subsets to which an individual device belongs; identifying a communication mode for each of the determined subset of group communication channels; disabling or throttling communication modes other than the identified communication mode on the individual device; The system of claim 11 configured to:

13. 12. The system of claim 11, wherein the available communication modes comprise one or more of: (a) messaging applications installed on the plurality of devices; (b) physical network interfaces present on the plurality of devices; or (c) a combination of the messaging applications and the physical network interfaces.

14. the processing circuitry further comprising: Making a particular device available for access over a network to at least one of: (a) data stored on the particular device that is inaccessible over the network when the particular device is not in the situational mode; or (b) a sensor data stream from at least one sensor of the particular device that is inaccessible over the network when the particular device is not in the situational mode.

12. The system of claim 11, configured to cause the particular device of the plurality of devices to enter the situational mode by

15. the processing circuitry further comprising: generating a graph in which each user of the plurality of users is represented by a node; generating edges for the graph, each edge connecting two nodes of the graph and identifying available communication modes for communication between user devices associated with the two nodes; The system of claim 11 , configured to generate the data structure by:

16. the processing circuitry further comprising: The system of claim 11 , configured to identify the geographic area affected by an emergency situation by obtaining motion data indicative of the situation from motion sensors of the plurality of devices.

17. the processing circuitry further comprising: The system of claim 11 , configured to identify the geographic area affected by the condition by identifying multiple calls to emergency services from the multiple devices.

18. the processing circuitry further comprising: The system of claim 11 , configured to transmit information related to the situation to each of the plurality of devices via the established plurality of group communication channels.

19. the processing circuitry further comprising: receiving sensor data from the plurality of devices in the situational mode; constructing a 3D representation of the identified geographic area based on the sensor data; and generating said 3D representation on an extended reality (XR) display for display; The system of claim 11 configured to:

20. 1. A system comprising: a means for identifying the geographic area affected by the situation; means for identifying a plurality of devices associated with a plurality of users within the identified geographic area; means for causing the plurality of devices to enter a situational mode, wherein devices in the situational mode are configured to share protected data; and means for obtaining, for each respective device of the plurality of devices, secured data from each of the plurality of devices, the secured data comprising contact list information from a respective plurality of communication modes available on the respective device; means for generating a data structure based on the contact list information for each of the plurality of devices, the data structure identifying connections between users of the plurality of users and identifying available communication modes for each connection; means for establishing a plurality of group communication channels for a plurality of subsets of the plurality of devices based on the data structure, each group communication channel of the plurality of group communication channels enabling communication via one of the available communication modes; A system comprising: