Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

7536 results about "Access control" patented technology

In the fields of physical security and information security, access control (AC) is the selective restriction of access to a place or other resource while access management describes the process. The act of accessing may mean consuming, entering, or using. Permission to access a resource is called authorization.

Convergent Intelligence Fabric for Multi-Domain Orchestration of Distributed Agents with Hierarchical Memory Architecture and Quantum-Resistant Trust Mechanisms

A system and method for implementing a convergent intelligence fabric (CIF) for distributed artificial intelligence operations. The CIF architecture integrates tensor-theoretic foundations, probabilistic cache management, precision-aware memory operations, quantum-resistant security, and neural-based optimization within a unified framework. The system orchestrates asynchronous, multi-hop data flow among computational resources while maintaining data security through per-block encryption and identity-based access control. Key components include a universal multi-model KV cache subsystem, agent-parallel disaggregation pipelines, reinforcement learning-based orchestration, and neuromorphic memory integration. Advanced implementations incorporate graphon-enhanced memory for sparse graph sequences, multi-modal cognitive persistent memory, and quantum-resistant asynchronous multi-domain trust protocols. The system enables efficient cross-agent collaboration, sophisticated knowledge sharing, and secure cross-domain operations while optimizing computational resources and maintaining strict privacy guarantees across distributed AI deployments.
Owner:QOMPLX INC

Deep learning-based facial recognition system with privacy-preserving features

The present invention provides a facial recognition system using deep learning methodologies while integrating privacy-preserving capabilities. This system employs convolutional neural networks (CNNs) to extract and classify facial features, ensuring high accuracy in recognition tasks. Moreover, the system addresses privacy concerns by incorporating techniques such as facial feature encryption and anonymization, thereby enhancing user privacy and data security. This invention is applicable across various domains, including security, surveillance, access control, and personalized services, where facial recognition is utilized while preserving individual privacy.
Owner:TRIPATHI BHASKAR +11

Cloud desktop security access control method based on zero-trust architecture

The invention discloses a cloud desktop security access control method based on a zero-trust architecture, belongs to the technical field of network security, and is used for solving the problems of difficulty in hidden attack detection, cross-cloud attack chain breakage and conflict between security control and service continuity in a multi-cloud environment. Firstly, user identity attributes, session metadata and service call logs are aggregated, an identity-resource-behavior triple dynamic graph is constructed, cross-session association features are extracted, and a multi-dimensional behavior baseline is generated. And quantifying the access deviation degree based on the behavior baseline, triggering sensitive operation traceability analysis, constructing a time sequence risk propagation model, identifying latent attack features, predicting a penetration path and outputting a risk propagation coefficient. And finally, dynamically generating a process-level micro-isolation strategy according to a risk result, gradually adjusting the authority through a nonlinear authority attenuation function, inserting a secondary authentication node when unexpected resource jump is detected, reconstructing a communication white list, and realizing collaborative optimization of security protection and service continuity.
Owner:SHENZHEN HUITUO INFORMATION TECH CO LTD

Business data security protection method and system for digital enterprise management

The invention provides a service data security protection method and system for digital enterprise management, and the method comprises the steps: obtaining an access request sequence initiated by a target user at a service operation terminal, generating a dynamic access control strategy vector according to a historical behavior track associated with an access operation identifier, and carrying out the dynamic access control strategy vector; analyzing the dynamic access control strategy vector through a strategy decoder, and generating a real-time access permission instruction; based on the real-time access permission instruction, performing homomorphic encryption mapping on a sensitive data segment in the request context information to generate a ciphertext transmission channel, and performing security parameter synchronization on the ciphertext transmission channel and the cross-department conjoint analysis model; and calling a federated learning framework to carry out multi-modal feature fusion on the real-time operation flow of the service operation terminal, generating an abnormal operation confidence score, triggering a cross-level interception protocol when the abnormal operation confidence score exceeds a dynamic threshold, and rolling back the current session state to a security baseline version. According to the invention, the accuracy and response timeliness of anomaly detection can be improved.
Owner:BEIJING CHINASOFT LINKAGE TECHNOLOGY CO LTD

AI dynamic secure transmission system based on SASE framework

The invention relates to the technical field of integration of artificial intelligence security and network security, and discloses an AI dynamic security transmission system based on an SASE framework, which realizes security access control based on AI dynamic identity verification through an SASE integration access module, acquires and predicts network performance change in real time by using a network state sensing module, and transmits the network performance change to a network server. Equipment, environment and data content are subjected to multi-dimensional analysis by means of a security risk assessment module, a quantitative risk score is generated, and a transmission protocol, parameters and encryption strength are dynamically adjusted according to a network state and the risk score by means of a dynamic transmission optimization module and a self-adaptive encryption module; the problem that safety protection and transmission efficiency are difficult to cooperate in a traditional architecture is effectively solved, low-delay and high-reliability data transmission service can be provided for AI application in a complex network environment, meanwhile, self-adaptive dynamic protection of the whole data transmission process is achieved, and data safety is comprehensively guaranteed.
Owner:BEIJING XINDA WANGAN INFORMATION TECH CO LTD

Smart park safety protection system and method based on intelligent video analysis and multi-mode integration

The invention discloses a smart park safety protection system and method based on smart video analysis and multi-mode integration, and relates to the technical field of smart park management. The system comprises a camera, an environment microphone and an access control terminal which are deployed in a park, an edge computing node is used for extracting structured video, audio and access control features, a central server realizes multi-modal space-time alignment through a self-calibration module, a multi-modal fusion module constructs a joint representation vector based on a low-rank tensor algorithm, and the joint representation vector is used for realizing multi-modal space-time alignment. And the security decision module identifies an abnormal event and triggers a response strategy in combination with a classification and anomaly detection model. According to the invention, multi-mode cooperative identification, high-robustness behavior analysis and intelligent response linkage are realized, and the real-time performance, accuracy and intelligent level of a park security system are improved.
Owner:SUQIAN NANYOU DIGITAL ECONOMY IND RES INST +1

Cloud-edge collaborative intelligent storage node dynamic deployment method and system

The invention discloses a cloud-edge collaborative intelligent storage node dynamic deployment method and system. The method comprises the following steps: monitoring performance indexes such as edge node data traffic and storage resource state in real time; a deep learning algorithm combining time sequence analysis and an LSTM neural network is adopted to analyze traffic information, and a data access demand is predicted; edge nodes and cloud storage resource configuration are dynamically adjusted based on a prediction result, and an intelligent scheduling algorithm, a data cold and hot separation strategy and a self-adaptive fragmentation technology are introduced to allocate resources; the storage node layout is optimized in real time, and an optimal data distribution path is selected through a reinforcement learning strategy; data security and access control are realized by adopting end-to-end encryption, multi-level access control and block chain technologies. The system comprises a monitoring acquisition module, a prediction analysis module, a resource scheduling module, a path optimization module and a security control module. According to the method, the utilization efficiency of storage resources is improved, data delay is reduced, system stability and data security are enhanced, and the method is suitable for a cloud edge collaborative storage scene.
Owner:NANJING NANDA SIWEI TECHNOLOGY DEVELOPMENT CO LTD

Multi-tenant zero-trust security system based on micro segmentation

The invention relates to the technical field of communication, in particular to a micro-segmentation-based multi-tenant zero-trust security system, which comprises a tenant network topology sensing module for acquiring network structures and service dependencies of tenants and generating a tenant-level network topology graph and a communication graph; a strategy rule automatic generation module generates a micro-segment access control strategy; the context-aware risk assessment module collects a user identity, an equipment state and a behavior track, and generates an access risk score; the strategy dynamic adjustment and application module updates the access control strategy; and the tenant isolation and zero-trust interaction module deploys a security sandbox to complete trust verification and isolation protection of cross-tenant requests. According to the method, the micro-segmentation strategy is generated by automatically identifying the service dependency boundary, the access control rule is dynamically adjusted based on the context, and refined isolation and risk-driven defense in a multi-tenant environment are realized in combination with the security sandbox and the zero-trust mechanism, so that the security and controllability of the system are remarkably improved.
Owner:中亿(深圳)信息科技有限公司

Safety control method and system for remote control of Internet of Things

The invention relates to the technical field of management of the Internet of Things, and discloses a security control method and system for remote control of the Internet of Things, and the system comprises a security remote control platform, a zero-trust gateway, an authentication module, a security policy engine, edge proxy equipment and an encryption communication module. And the authentication module is used for performing identity authentication on the equipment and the user. The security policy engine dynamic access control table comprises access rule entries and associated signature information, and is issued to the edge proxy device through the zero-trust gateway. And the edge proxy device stores the dynamic access control table, verifies the signature information based on the platform public key, and performs matching and verification according to the access rule entry when receiving the control instruction. And the encryption communication module is used for performing encryption transmission on the access control table, the control instruction and the execution result. According to the invention, the whole process of remote control of the Internet of Things is dynamic, secure and credible, and the anti-attack capability and operation reliability of the system are effectively improved.
Owner:JINLANCHEN (BEIJING) TECHNOLOGY CO LTD

Zero-trust network dynamic access control method based on AI behavior portrait

The invention discloses a zero-trust network dynamic access control method based on an AI behavior portrait, and the method comprises the following steps: 1, collecting multi-source real-time behavior data during an access request; 2, constructing an AI behavior portrait engine based on historical data, inputting the integrated multi-source behavior data, calculating a behavior deviation degree through the AI behavior portrait engine, and outputting a risk score; 3, dynamic strategy decision making, wherein a decision making engine executes hierarchical control according to the risk score; 4, continuous session monitoring and real-time adjustment are carried out; step 5, when risk upgrading is detected in the session, degrading the session authority, limiting high-risk operation, terminating the session, and retaining evidence obtaining data; step 6, audit event generation and portrait updating; and step 7, strategy optimization closed loop. According to the method, the risk score is calculated in real time based on the AI behavior portrait, transition from static authorization to dynamic permission adjustment is realized, and internal threats such as voucher stealing and the like are effectively blocked.
Owner:JINGDEZHEN SHANJIANG TECHNOLOGY CO LTD

Data security dynamic evaluation system and protection method

The invention discloses a data security dynamic evaluation system and a protection method, belongs to the technical field of information security, and is used for solving the problem of terminal equipment access control and behavior risk dynamic collaborative protection. The method comprises the following steps: generating fingerprints through terminal equipment features, verifying authorization, inputting access feature slices into a time sequence model by authorized terminal equipment, generating a trust score based on cosine similarity of a behavior sequence and a prediction sequence, and constructing a Markov model to dynamically select an authentication mode according to the trust score; calculating a risk index by combining network and geographic information, and distributing the risk index to a real or virtual environment; and the unauthorized terminal equipment distributes the virtual environment after registration. Differentiated monitoring is carried out, a time sequence library is established in the virtual environment, and doubt scores are generated through sequence matching; the state deviation of the real environment is calculated through a hidden Markov model, and the risk score is generated by fusing the multi-dimensional features. And based on the result management authority, the suspicion terminal equipment isolates and shrinks the authority, the compliance terminal equipment authenticates and migrates, and the access is regulated and controlled according to the minimum privilege principle and the time window mechanism.
Owner:TIBET YANRUI INFORMATION SECURITY TECHNOLOGY CO LTD

Network egress access control with untrusted intermediary

A network egress request is received from a container service within a cloud data platform. A cryptographically signed egress policy associated with the network egress request is received by a trusted service controller of the cloud data platform. The network egress request is validated against the cryptographically signed egress policy. Based on the validation, a determination of whether the network egress request complies with the cryptographically signed egress policy is established. Upon validation, the network egress request is granted or denied based on the determination.
Owner:SNOWFLAKE INC

Industrial control system security policy adaptive configuration method and device and readable storage medium

The invention relates to an industrial control system security policy adaptive configuration method and device and a readable storage medium. According to the method, a control instruction stream, a process variable sampling value and link layer message metadata are synchronously collected, an association hypergraph fusing network semantics, control semantics and physical semantics is constructed to represent a system state, and a sampling period is divided into a plurality of time slots with fixed lengths. In each time slot, self-supervised learning is utilized to extract a topology embedded vector group, and a system operation rule is represented. A robustness envelope interval is generated by calculating a statistical distance between a current time slot and a historical baseline, and is used for driving a reinforcement learning model to generate a security policy parameter set. And executing corresponding access control, traffic shaping and integrity verification operations in the next time slot, generating receipt vector feedback model update according to an execution result, outputting a micro-policy patch with a hash signature and a timestamp, and sending the micro-policy patch to the edge security gateway to realize deployment, thereby realizing closed-loop adaptive optimization of the security policy in the dynamic environment.
Owner:SUZHOU IND & IND CO LTD

Trust-enabled artificial intelligence and non-human identity orchestrator framework

Described herein are techniques for secure orchestration and publication control among agents (e.g., distributed agents), such as non-human identities (NHI), using cryptographic certificates, trust rules, and / or an Information-Centric Networking (ICN) architecture. In an example, a framework establishes identity for human and non-human identities-such as AI agents, services, and autonomous workloads—via cryptographically signed publications and / or collections. Trust policies can be defined and enforced through signed, verifiable trust rules, enabling access control, provenance validation, and / or policy delegation across federated domains. The disclosed techniques can enable multi-agent systems (MAS), zero-trust enforcement, and / or secure cross-domain communication using ICN-named role-based certificates and programmable trust shims. The disclosed techniques can also enable decentralized validation and selective replication of data while maintaining traceability and fine-grained control of agent behavior.
Owner:OPERANT NETWORKS

Time Alignment of Layer 1 / Layer 2 Triggered Mobility

A wireless device receives, from a base station, a radio resource control (RRC) reconfiguration message comprising a layer 1 / layer 2 triggered mobility (LTM) configuration. The LTM configuration comprises an LTM candidate configuration of a candidate cell and a value of a time alignment timer for determining whether a timing advance (TA) value of the candidate cell is valid. The wireless device receives, from the base station, a downlink control information (DCI) indicating the candidate cell and to transmit a random access preamble for acquiring the TA value of the candidate cell. Based on the DCI, the wireless device transmits, via the candidate cell, the random access preamble for acquiring the TA value of the candidate cell. The wireless device receives, from the base station, a medium access control (MAC) control element (CE) indicating an identifier of the LTM candidate configuration of the candidate cell and the TA value.
Owner:OFINNO LLC

Trusted management and control network platform construction method and device, electronic equipment and storage medium

The invention belongs to the field of network security, and relates to a trusted management and control network platform construction method and device, electronic equipment and a storage medium, the method comprises the following steps: constructing a basic security architecture and a trusted base, the basic security architecture being used for providing a unified root of trust and a management core for collaborative operation of upper security components; based on the basic security architecture and the trusted base, implementing multi-dimensional trusted verification and dynamic access control; an intelligent boundary protection and depth detection system is deployed and is used for constructing an intelligent, three-dimensional and self-adaptive security defense line at the boundary of each region of the network, and various known and unknown threats can be identified and blocked; constructing a unified secure communication tunnel and a cross-domain transmission guarantee; defining and realizing a standardized security function interface and a collaboration protocol; and a continuous trust evaluation and automatic operation management and control closed loop is established. The overall security is enhanced, the secure transmission of data is ensured, the compatibility and collaboration of the system are improved, and the security operation intelligence is realized.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Computer network security access control management method based on big data

The invention relates to the technical field of computer network security, and discloses a computer network security access control management method based on big data. The method comprises the following steps: constructing a network security situation knowledge graph, collecting a real-time access behavior sequence through a probe, and synchronizing the real-time access behavior sequence to the knowledge graph; simulating a network entity interaction state in the knowledge graph, and predicting a threat propagation path and a potential intrusion behavior; setting a dynamic access control strategy, constructing a multi-dimensional feature matrix in combination with a real-time access behavior sequence association influence degree and a strategy execution priority constraint condition, calculating a strategy conflict risk score by using a deep learning model, comparing with a preset threshold to judge whether a conflict exists or not, and if yes, reconstructing the strategy; and automatically executing access blocking, session termination and data encryption operations according to the reconstructed strategy, recording an execution log and security feedback data, and updating the knowledge graph in real time. According to the method, the dynamic property and the security of access control are improved, and security threats in a complex network environment can be effectively handled.
Owner:SHANXI ELECTRIC POWER CO POWER COMM CENT

Method and system for safely sharing traffic edge computing data

The invention relates to the technical field of traffic data processing, and discloses a traffic edge computing data security sharing method and system, and the method comprises the steps: collecting traffic edge computing network multi-source heterogeneous data, and carrying out the classification standardization processing to generate a structured data set; designing a dynamic data sharing security protocol based on a multi-party security computing protocol and a homomorphic encryption algorithm; verifying the authority of a requester in a multi-level manner by using an attribute-based access control model and a zero-knowledge proof mechanism, and generating a dynamic access token; storing data by adopting a fragmentation storage and redundancy encryption strategy, and recording storage information through a hash chain; and dynamically adjusting the encryption strength and the sharing strategy according to the network threat level and the data sensitivity. The method effectively guarantees safe sharing of traffic data, accurately controls access authority, improves storage and sharing efficiency, adapts to complex network environment changes, and provides powerful support for development of an intelligent traffic system.
Owner:ZHENGZHOU UNIV +1

Cross-platform education data privacy protection analysis system

The invention provides a cross-platform education data privacy protection analysis system, and relates to the technical field of data privacy protection. The cross-platform education data privacy protection analysis system comprises a multi-modal data acquisition unit, a dynamic privacy analysis engine, a federal learning processing core module, a block chain enhanced access control system, a privacy watermark traceability module and a compliance autonomy unit. Dynamic coupling of scene sensitivity and data protection intensity is realized through a dynamic privacy risk scoring equation and an adaptive differential privacy noise equation; the problems of privacy disclosure, compliance verification and traceability and responsibility investigation in cross-platform education data sharing are solved by combining federal learning, block chain evidence storage and privacy watermarking technologies. According to the method, the privacy risk assessment precision is remarkably improved, the model precision loss is reduced, full-life-cycle data security management and control are supported, and the method is suitable for multiple scenes such as K12 education and college educational administration.
Owner:JIUJIANG DIGITAL IND DEV CO LTD

Data processing method based on computer software development

The invention discloses a data processing method based on computer software development, which belongs to the technical field of data processing, and comprises the following steps: S1, constructing an adaptive analysis engine driven by a knowledge graph, and carrying out multi-modal data semantic modeling and context labeling by adopting a multi-modal data feature fusion technology; and S2, designing a cross-node distributed data cleaning and dynamic fragmentation optimization strategy based on a differential privacy and feature space alignment technology, and through hierarchical deployment of a national cryptographic algorithm and homomorphic encryption, realizing data full life cycle security protection, ensuring data asset security by static storage encryption, and supporting security calculation requirements by ciphertext operation; attribute-based encryption fine-grained access control accurately matches a data use permission, and a block chain technology ensures traceability and tamper-proofing of data operation; the problem that a traditional encryption scheme is insufficient in flexibility is solved while the compliance requirement is met, and a trusted infrastructure is established for cross-domain data sharing.
Owner:XUZHOU CHIBA NETWORK TECH CO LTD

Vehicle-mounted edge computing data recording system and method based on protocol adaptive analysis

The invention relates to the technical field of network communication, and discloses a vehicle-mounted edge computing data recording system and method based on protocol adaptive analysis, and the system comprises a multi-protocol network access controller which is used for capturing an original data frame and extracting a physical feature triple; the identification analysis engine is used for executing hash operation on the triple to generate a physical feature code and retrieving a physical logic address mapping table; the direct memory access controller is used for responding to a target memory address pointer hit by retrieval and directly writing a data load into an input buffer area of the functional operation module, and by constructing a direct addressing mechanism based on Hash mapping, thorough decoupling of vehicle-mounted heterogeneous network physical topology and edge computing logic is achieved.
Owner:SHANGHAI JUPO TECH CO LTD

Multi-user access control method and device of equipment, equipment and medium

The invention relates to the technical field of equipment access control, can be applied to business scenes of financial science and technology, medical health and the like, and discloses a multi-user access control method and device of equipment, the equipment and a medium, and the method comprises the following steps: receiving a scanning result containing an equipment identity code and operator identification information; generating a verification token based on a scanning result, embedding a time efficiency parameter, distributing the verification token to a user terminal, receiving user characteristic data, establishing a binding relationship with the equipment identity code and the operator identification information, carrying out time efficiency and integrity verification, generating a verification result, and controlling the equipment access authority and generating an operation record according to the verification result. Through a binding mechanism among the equipment identity code, the operator identification information and the user characteristic data, and in combination with the verification token embedded with the aging control parameter, effective management and control of the operation access behavior under the scene that multiple persons use the same equipment at the same time are realized.
Owner:CHINA PING AN LIFE INSURANCE CO LTD

Security protection method and apparatus for customer service management system

PCT designated stageWO2025222719A1Securing communicationData setData access
The present invention relates to the technical field of network security protection. Disclosed are a security protection method and apparatus for a customer service management system. The method comprises: acquiring an employee data set, and performing permission assignment, so as to generate an employee operation permission set; performing identity verification on an access user, and determining a data management operation permission range of the access user; acquiring a sensitive data set for encryption processing, and storing same in a customer service management system; accessing data of the customer service management system, implementing an access control policy, and performing risk assessment, so as to generate a system risk level; extracting detected anomalous data, synchronizing same to a security protection network, and outputting a protection control policy; and executing the protection control policy for security assessment, regularly updating the protection control policy, and performing intelligent security protection on the customer service management system. The present invention solves the technical problem in the prior art that customer service management systems have low security protection capacity, which leads to difficulty in preventing network attacks, thus achieving the technical effect of improving the security protection capacity of customer service management systems.
Owner:SHANGHAI HANDPAL INFORMATION TECHNOLOGY SERVICE CO LTD

Security guarantee system for cross-domain communication and data sharing of network platform software

The invention relates to the technical field of computer network security, in particular to a security guarantee system for cross-domain communication and data sharing of network platform software, which comprises a data security transmission module, an identity authentication and access control module, an encryption module, a security audit and anomaly detection module and an anti-interference disaster recovery module. According to the invention, through linkage of equipment fingerprint end-to-end encryption, threat adaptive dynamic key updating and a timestamp-random number anti-replay mechanism and AI risk pre-judgment, reinforcement learning path planning, digital twinning pre-verification and fault automatic switching technologies, collaborative guarantee of key security and transmission continuity in cross-domain audio transmission is realized; encryption intensity is dynamically upgraded along with threats, a transmission path is optimized in advance, and it is ensured that the audio stream resists various network attacks and interferences in low-delay transmission.
Owner:ICLOUDSHIELD SECURITY TECHNOLOGY CO LTD

Health data encryption storage method and device, equipment and storage medium

The invention relates to a health data encryption storage method and device, equipment and a storage medium, and the method comprises the steps: obtaining to-be-processed health data, carrying out the sensitivity analysis and grade division of the health data, and obtaining health data sub-blocks; performing encryption preprocessing on the health data sub-blocks, and performing group data protection according to a preset differential privacy algorithm to obtain encrypted data blocks; generating an initial master key through a hardware security module, and performing derived hierarchical encryption on the encrypted data block to obtain a data encryption key; performing fragmentation processing and regular distributed storage on the data encryption key to obtain a dynamic security key; and performing metadata separation storage on the encrypted data according to the dynamic security key, and performing data permission determination according to a preset role-based access control mechanism to obtain an encrypted isolation database. According to the invention, efficient security protection can be maintained under different application scenes and access permissions, and the risk of data leakage is reduced.
Owner:SHENZHEN MATERNITY & CHILD HEALTHCARE HOSPITAL +1

Method and system for realizing USB flash disk equipment interaction based on flash memory encryption technology

The invention relates to the technical field of cores, and discloses a method and a system for realizing USB flash disk equipment interaction based on a flash memory encryption technology, which comprises the following steps of: dividing an encryptable data block of a flash memory controller, and determining a dynamic entropy weight of the encryptable data block by utilizing an equipment interaction instruction and a random noise characteristic signal; generating a self-adaptive key generation sequence capable of encrypting data blocks through an address allocation mode and a dynamic entropy weight of a flash memory controller; calculating a side channel leakage risk index of the flash memory controller, and setting a security level label of an encryptable data block in combination with a self-adaptive key generation sequence; the method comprises the following steps: setting a differentiated security protection mechanism of an encipherable data block by constructing an access control matrix of the encipherable data block and an encryption risk area of a flash memory controller; and generating a secure interaction scheme of the USB flash disk equipment based on the self-adaptive key generation sequence in combination with the differential security protection mechanism and the access control matrix. According to the invention, the interaction safety and reliability of the USB flash disk equipment can be improved.
Owner:SHENZHEN LINGCHUANG IND CO LTD

New energy station operation site safety monitoring and early warning method

The invention is applicable to the technical field of safety monitoring and early warning, and provides a new energy station operation site safety monitoring and early warning method, which comprises the following steps: collecting multi-source heterogeneous data in real time through an edge computing unit deployed in an operation site; analyzing the video stream in real time by using a preset artificial intelligence visual analysis model, identifying personnel violation behaviors, equipment abnormal states and environmental risk factors, performing cross validation in combination with an electronic access control state and a work ticket permission state, and generating a primary alarm signal when it is detected that preset condition information is not matched; risk grade evaluation is carried out based on the primary alarm signal and environmental risk factors, and a dynamic early warning instruction is generated and synchronized to a station level platform; and the station control layer triggers video review of the associated area, a linkage access control system locks the dangerous area, early warning information is pushed to the target terminal, and an emergency processing plan is generated. And the real-time response speed and the active protection capability of a high-risk operation scene are effectively improved.
Owner:HEBEI DATANG INT RENEWABLE POWER CO LTD

Encryption-based power grid cross-domain operation and maintenance data secure transmission method and system

The invention relates to the technical field of data encryption and transmission, in particular to a power grid cross-domain operation and maintenance data secure transmission method and system based on encryption, and the method comprises the steps: pre-judging a current risk through a historical network security event, dividing a network environment into different risk intervals based on a risk level evaluation value, encryption strategies with different intensities are correspondingly matched, so that refined security management and control with higher risk and stronger protection are realized; a triple progressive identity authentication system of an equipment layer, a dynamic layer and a biological layer is constructed, a dynamic permission management and control mechanism driven by identity attributes and risk levels is constructed, a basic permission boundary is determined based on inherent identity attributes of an operation and maintenance terminal, and permission strength and validity period are dynamically adjusted in combination with a risk level evaluation value. And finally, generating an access control strategy only adapted to the current terminal, the current risk and the current access request, so as to perform data encryption and transmission through the target encryption strategy and the access control strategy, thereby ensuring the security of data transmission.
Owner:STATE GRID SIJI DIGITAL TECH (BEIJING) CO LTD +1

Access control system for buildings

Access control system (1) for buildings (2) with a stationary unit (20) and a mobile unit (10), wherein the mobile unit (10) has a mobile transceiver (11) which is designed to transmit wirelessly and encrypted signals (S) for authentication and authorization of the mobile unit (10) with respect to the stationary unit (20) and for control of the stationary unit (20) by the mobile unit (10) to a stationary transceiver (21) of the stationary unit (20), wherein the stationary unit (20) comprises a control device (22) which is designed to determine a position of the mobile unit (10) relative to the stationary unit (20) from the signals (S) transmitted from the mobile transceiver (11) to the stationary transceiver (21) and to control a function if a control command for triggering the function is transmitted to the stationary unit (20) by a mobile unit (10) authenticated and authorized by the stationary unit (20) and / or the position of the mobile unit (10) is within a predetermined access area (30), and wherein the control device (22) is designed to determine an angle (ϕ) from which the signals (S) were received from the signals (S) transmitted from the mobile transceiver (11) to the stationary transceiver (21), to determine a measured distance (rg) between the stationary transceiver (21) and the mobile transceiver (11) from a signal (S) received at the stationary transceiver (21) from the mobile transceiver (11) and from the measured distance (rg) and a vertical distance (rv) stored as a correction value in the control device (22) between the stationary transceiver (21) and the mobile transceiver (11), to determine a horizontal distance between the stationary transceiver (21) and the mobile transceiver (11) in the polar coordinate system lying in the horizontal plane as a distance (r) from which the signals (S) were received, so that the position of the mobile unit (10) can be specified as polar coordinates of a polar coordinate system lying in a horizontal plane, in whose coordinate origin the stationary transceiver (21) is arranged.
Owner:MARQUARDT GMBH

Multi-level dynamic authorization and access control method and system based on identity token

The invention provides a multilevel dynamic authorization and access control method and system based on an identity token, and relates to the technical field of network security, and the method comprises the steps: generating a user main token of a binding terminal, constructing a resource access domain knowledge graph, carrying out the feature coding, predicting an access intention based on knowledge enhancement features and user historical behaviors, and achieving the dynamic grouping of resources. A permission certificate is generated through homomorphic encryption, verifiability is ensured through zero-knowledge proof, a verification program is deployed in a distributed network, and collaborative detection and certificate revocation of abnormal access are achieved. According to the invention, the security and flexibility of access control are improved, and the dynamic adaptive capacity of authority management is enhanced.
Owner:BEIJING BLOCK FAST CHAIN TECH CO LTD