Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

135 results about "Access control list" patented technology

An access-control list (ACL), with respect to a computer file system, is a list of permissions attached to an object. An ACL specifies which users or system processes are granted access to objects, as well as what operations are allowed on given objects. Each entry in a typical ACL specifies a subject and an operation. For instance, if a file object has an ACL that contains (Alice: read,write; Bob: read), this would give Alice permission to read and write the file and Bob to only read it.

Request parameter value authority authentication method and system

ActiveCN121037115ADigital data protectionSecuring communicationAdvanced encryption standard algorithmDistributed cache
The invention provides a request parameter value authority authentication method and system, and relates to the technical field of network security, and the method comprises the steps: creating an access control list configuration and binding a service when a gateway registers the service, building the association mapping of a consumer and the service, and setting a parameter authority list; encrypting the sensitive field by adopting an advanced encryption standard algorithm and synchronizing the sensitive field to a distributed cache; and verifying the validity of the token when the service request is received, verifying the authority of the consumer, and verifying the parameter value. According to the invention, unauthorized access can be effectively prevented, the system security is improved, and the authentication efficiency is improved through the distributed cache.
Owner:北京科杰科技有限公司

Gateway port on-off control method, equipment and medium

The invention provides an on-off control method and device for a gateway port and a medium. The on-off control method comprises the steps of obtaining historical access log data and threat intelligence data of a target port in a gateway; based on the historical access log data and the threat intelligence data, performing time sequence analysis by using a pre-trained long-short-term memory network model to obtain a predicted security access time period of the target port in a future preset time period; generating a temporary port exposure preset rule of the target port according to the predicted security access time period; determining a traffic feature vector of the real-time traffic data packet of the target port; using a preset deep reinforcement learning agent to determine an on-off control instruction for the target port based on the traffic feature vector and a temporary port exposure preset rule; and executing the on-off control instruction to modify an access control list state of the gateway firewall to the target port. According to the method and the device, dynamic and refined gateway port on-off control can be realized, so that the service flexibility and security are considered.
Owner:LINGBO TECH (BEIJING) CO LTD

Restrict mobile to mobile communication dynamically in 5g user plane function

In one aspect, a method includes generating, using a User Plane Function (UPF) of a core element of a network, a query to retrieve information associated with one or more Data Network Names (DNNs) configured in at least one other UPF in the network; transmitting the query to a Network Repository Function (NRF); receiving a response from the NRF, the response including IP address subnets of the at least one other UPF associated with the one or more DNNs; dynamically generating an Access Control List (ACL) to block mobile-to-mobile communication between User Equipment (UEs) in the network, using the IP address subnets received as part of the response, wherein each of the UEs is assigned an IP address from among the IP address subnets; and blocking M2M communication using the ACL dynamically generated.
Owner:CISCO TECHNOLOGY INC

Configuration method and device of access control list, electronic equipment and storage medium

The invention provides an access control list configuration method and device, electronic equipment and a storage medium, and relates to the technical field of servers, and the method comprises the steps: collecting subnet information in a target containerization cluster, a configured access control list rule and security threat features in network traffic; the information is subjected to fusion analysis based on a predefined security policy so as to generate an access control list rule set containing different priorities, and then the rules are synchronized to a cluster virtual switch kernel according to the priorities so as to realize hierarchical control and dynamic protection of network traffic. The problems that a large-scale dynamic network environment is difficult to deal with, the automation level is low and malicious traffic cannot be efficiently intercepted due to the fact that manual configuration and static rule maintenance are relied on and deep integration of a containerized cluster network structure is lacked can be solved. The technical effects of improving the automation level of containerized cluster network management, enhancing the adaptability to a dynamic network environment, and realizing efficient interception of malicious traffic to guarantee network security are achieved.
Owner:JINAN INSPUR DATA TECH CO LTD

Preventing spam communications

Aspects of the present disclosure are directed to systems and methods for preventing spam communications. Implementations can implement an access control list that a communicator (e.g., a user device sending a text message, making a phone call, etc.) must be on in order to complete the communication with a recipient. If they are not on the access control list, the communicator can be prevented from sending the communication to the recipient, redirected to a registration process, or the communication can be tagged with an unverified status flag. In some implementations, the access control list can include a recipient's contacts, contacts of the recipient's contacts, authenticated entities (e.g., users and / or companies), previously verified entities, etc. In some implementations, a recipient can give out a temporary extension that a communicator can enter to complete communications with the recipient for a certain amount of time or for a certain number of uses.
Owner:UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)

Method, computer program product and field device for authorizing access to objects in a computerized system

A method for authorizing an entity (9) in a computerized system to access an object (12) includes the following steps: providing (S1) an access control list (ACL) that specifies access permissions for each object (12) to the object (12) in the computerized system; assigning (S2) capability requirement information to at least one of the objects in the access control list (ACL); assigning the capability information to at least one entity (9) in the computerized system; requesting (S11) access to the object (12) by the entity (9); checking whether the requesting entity (9) has access permissions according to the ACL; and authorizing (S5) access to the requested object (12) by the requesting entity (9) only if the capability information assigned to the requesting entity (9) matches the capability requirement information assigned to the requested object (12). The combination of ACL-based access to files and capabilities enhances the security of the system.
Owner:SIEMENS AG

Auditing access control lists of a network infrastructure

Systems and methods for auditing access control lists (ACLs) of a network infrastructure are provided. A plurality of network interfaces associated with a specified entity is identified. A plurality of access control lists (ACLs) is received. Each ACL of the plurality of ACL includes a plurality of rules associated with a respective network interface of the plurality of network interfaces. Network traffic metadata associated with the plurality of network interfaces is received. A corresponding set of rule utilization parameters is identified for each rule of the plurality of rules by matching the network traffic metadata to the plurality of rules.
Owner:GOOGLE LLC

Abnormity repairing method and device for virtual card, equipment and computer program product

The invention discloses a virtual card abnormity repairing method and device, equipment and a computer program product, and the method comprises the steps: obtaining real-time monitoring data of a first virtual card, and determining a real-time monitoring result of the first virtual card based on the real-time monitoring data; creating a second security domain corresponding to the first virtual card under the condition that the real-time monitoring result is that the security domain is in false death and a first security domain corresponding to the first virtual card meets a migration condition; and migrating the access control list and the key index of the first security domain to the second security domain.
Owner:SHENZHEN DACHENG COMM TECH CO LTD

Method and apparatus for dynamically expanding an access control list

The application provides a method and device for dynamically expanding an access control list. The method comprises the following steps: obtaining a first number of software ACL table entries of a first service module currently triggering a hardware access control list (ACL) configuration; obtaining a second number of software ACL table entries of a second service module of a current ACL dynamic expansion object; calculating a difference between the first number of software ACL table entries and the second number of software ACL table entries; when the difference exceeds a preset difference threshold, entering a hardware ACL resource overflow pre-check; and when the difference is less than the preset difference threshold, keeping the second service module as the ACL dynamic expansion object.
Owner:NEW H3C TECH CO LTD

Knowledge Graph Authorization

A computer-implemented method for determining access to resources using a knowledge graph includes obtaining a knowledge graph with multiple nodes connected by edges and receiving a request for a requestor to access a resource. The requestor is associated with a first node, and the resource is associated with a second node within the knowledge graph. The method includes determining a path between the first and second nodes and evaluating each node along the path. For each node, the method determines an access control list (ACL) stored separately from the knowledge graph and verifies the requestor's access based on the ACL. Based on determining that the requestor has access to all nodes along the path, the method includes determining that the requestor has access to the second node. The method includes returning, to the requestor, a response indicating access to the resource.
Owner:SERVICENOW INC

Message statistical method, switch chip and switch

The invention provides a message statistical method, a switch chip and a switch, a table look-up module obtains a condition index and a target storage position from statistical items when message information of a current message is matched with the statistical items in an ACL table or a forwarding table; a table look-up module determines a target configuration table item matched with the condition index from the configuration table; the target configuration table item comprises a statistical object and control data; a table look-up module obtains actual data corresponding to the statistical object from the message information; the logic judgment module judges whether the actual data meets the statistical condition corresponding to the condition index or not under the driving of the control data, and outputs a statistical signal; and the counting module updates the message counter at the target storage position when the statistical signal is true. According to the invention, the configuration table item of the statistical condition is recorded through the configuration table, and whether the actual data corresponding to the statistical object meets the statistical condition is judged through the logic judgment module, so that complex condition statistics can be realized under the condition of not wasting a large amount of ACL (Access Control List) resources.
Owner:SUZHOU CENTEC COMM CO LTD

Network access control list adjusting method based on flow analysis and optimization

The invention provides a network access control list adjusting method based on flow analysis and optimization, which comprises the following steps of: firstly, acquiring total flow information, and then dynamically constructing a network digital twinborn model based on the total flow information; constructing a causal derivation model based on a simulation result of the network digital twin model; analyzing and processing the real-time traffic by using a causal derivation model, and generating a plurality of network access control list change rules and corresponding deployment strategies; and then simulating the network access control list change rules and the deployment strategy thereof in the network digital twin model, and determining a target network access control list from each network access control list change rule based on a simulation result. According to the invention, a self-learning, dynamic risk quantification and strategy automatic generation and verification ACL tuning system is constructed, and the ACL tuning system is not only an optimization rule, but fundamentally changes the generation and management normal form of the ACL.
Owner:BEIJING ITECHSHARE NETWORK INFORMATION TECH CO LTD

Network monitoring method, computer readable storage medium and electronic device

The embodiment of the invention provides a network monitoring method, a computer readable storage medium and an electronic device, and the method comprises the steps: determining an ACL (Access Control List) negative list according to key features and network behavior features corresponding to different traffic data; and monitoring the network according to the ACL negative list and the network working mode. Therefore, through the embodiment of the invention, the problems that the traditional network monitoring mostly depends on manual rule matching, the rule writing difficulty is high, and the network cannot be accurately monitored can be solved, and the effect of improving the network security and stability is further achieved.
Owner:ZTE CORP

A user access control method, system, apparatus, device and storage medium

Embodiments of the present application provide a user access control method, system, device, electronic equipment and storage medium, the method comprising: receiving an access request sent by a client; the access request comprising identification information of a user; obtaining mapping information according to the identification information of the user; the mapping information comprising identification information and permission information of a target user mapped by the user; and performing an access operation corresponding to the access request according to the identification information and permission information of the target user. Without setting a file access control list for each user, only a small number of target users need to be configured in the server, and the access control requirements of a large number of users can be met by mapping the user to the target user.
Owner:JINAN INSPUR DATA TECH CO LTD

Message processing methods, devices, switches, storage media and software products

This application proposes a packet processing method, apparatus, switch, storage medium, and program product, applied to a driver chip. The method includes: receiving an analysis instruction, the analysis instruction including a first target feature and a first target packet operation type; generating multiple access control list entries based on the first target feature and the first target packet operation type; filtering target packets from target traffic that match the first target feature and the first target packet operation type based on the multiple access control list entries; and sending the target packets to a processor, so that the processor determines the performance indicators of the network to which the target packets belong based on the target packets. The embodiments of this application, by adding packet operation types to the analysis instruction, can generate access control list entries based on the first target feature and the packet operation type, thereby reducing the number of generated access control list entries and avoiding the problem of insufficient access control list entry resources.
Owner:NEW H3C TECH CO LTD

A method and system for offline identity authentication and rights management

The present invention relates to the technical field of identity authentication and rights management, and discloses a method and system for offline identity authentication and rights management. The method comprises the following steps: receiving an operation request from a target user for a target terminal; if the identity authentication client is offline, verifying the target user's digital certificate through a first authentication center of the identity authentication client to obtain a legitimacy verification result of the target user; if the target user is determined to be a legitimate user based on the legitimacy verification result, determining the target user's operating authority for the target terminal using the target user's access control list in a USB key; determining the target operating authority required for the operation instruction; and if the target user's operating authority for the target terminal includes the target operating authority, determining that the target user has the authority to execute the operation request on the target terminal. By implementing the present invention, user identity authentication and rights management can be achieved in an offline environment.
Owner:BEIJING SHENZHOU AEROSPACE SOFTWARE TECH CO LTD

A network control and scheduling method based on traffic awareness and path optimization

This invention discloses a network control and scheduling method based on traffic awareness and path optimization. It collects real-time traffic from network devices, extracts key features, and analyzes traffic pattern trends. Using these trends, the rule set is clustered according to the similarity of matching frequencies to form rule clusters. Within each cluster, rules are sorted based on matching frequency. The rule arrangement is analyzed to identify conflicting rule pairs. By assessing the severity of the conflicts, a conflict list with clear objectives is generated. This conflict list is then processed using a genetic algorithm to obtain an optimized rule sequence. Rigorous testing using simulated traffic yields a final rule set version. This final rule set version, passing all tests, is securely pushed to network devices, enabling real-time optimized access control list configuration. Network devices immediately operate based on the latest and optimal policies, thereby improving overall network security and data processing efficiency.
Owner:BEIJING ITECHSHARE NETWORK INFORMATION TECH CO LTD

A network table query and data packet processing method of a switch and related devices

PendingCN122268801ATransmissionExact matchLongest prefix match
The application provides a network table query method and data packet processing method of a switch and related devices. A plurality of binary classifiers are set in the on-chip memory of a switch processor. According to the output values of the exact match table, the longest prefix match table and the access control list, the pre-operation results corresponding to the output values are generated through hash operation, and the pre-operation results are pre-stored in the plurality of binary classifiers corresponding to the exact match table, the longest prefix match table and the access control list. When the network table query of the switch is performed, the plurality of binary classifiers can be used to output the output values of the switch network table in parallel based on the pre-operation results. The scheme realizes the isomorphism of the storage structures of the exact match table, the longest prefix match table and the access control list, and can dynamically allocate the storage resources of the on-chip memory when the network table query is performed, so as to adapt to the network table query in different time and different scenes.
Owner:HUAWEI TECH CO LTD +1

Memory access control list-based software security protection method and apparatus

The present application provides a memory access control list-based software security protection method and apparatus. The method comprises: acquiring a current memory operation generated by a memory access instruction at a runtime of a target program; based on a pre-stored memory access control list, performing matching on the current memory operation to obtain a memory operation matching result; and, based on the memory operation matching result, determining whether to execute the current memory operation or prevent the current memory operation. According to the method, the memory access instruction is monitored in real time by using the memory access control list for filtering the current memory operation, the hardware implementation is relatively lightweight, no additional overhead of runtime performance is introduced during monitoring, and range matching support needs to be provided only for certain less significant bits, thereby greatly reducing the hardware overhead, and also alleviating different types of vulnerabilities.
Owner:TSINGHUA UNIVERSITY

Systems and methods for data migration

Systems and methods for data migration are provided. A method for migrating bulk data from a first data platform to a second data platform includes: providing a virtual machine (VM) on a cloud service provider subscription, migrating access control list (ACL) information, one or more legal tags, and reference data from the first data platform to the second data platform, using the VM, analyzing data types of the bulk data, generating a file-generic data migration pipeline from the first data platform to the second data platform, using the VM, fetching storage records for the bulk data from the first data platform using the VM, migrating the bulk data from the first data platform to the second data platform, using the VM, validating the migrated bulk data in the second data platform, and synchronizing the migrated bulk data in the second data platform with changes made since the migrating began.
Owner:SCHLUMBERGER TECH CORP

Data access method, device, computer equipment and storage medium

The present invention relates to the field of data storage technology, and discloses a data access method, apparatus, computer equipment, and storage medium. The method includes: when a client mounts a shared directory of a storage end to a local mount point, regularly performing statistics on the performance status information of the client; for any client, when the performance status information of the client exceeds a preset threshold, generating an alarm message, reporting the alarm message to the storage end, so that the user can determine the information of the client to be restricted based on the alarm information of the storage end, and updating the blacklist of the storage end based on the information of the client to be restricted; receiving a data access request to the storage end sent by the client; parsing the data access request to obtain the target path of the data access request; if the target path is in the directory access controlled list and the client identifier corresponding to the client is not in the whitelist, then rejecting the data access request. The present invention improves the data security of the storage end.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

A method for protecting designated paths and files from tampering

The present application belongs to the technical field of computer data security, and particularly relates to a method for protecting specified paths and files from tampering, which comprises the following steps: registering a relevant main function code callback routine in a Windows file system filtering driver framework, and constructing an interception layer for intercepting I / O requests; constructing an access control list with PID and file object path as key values in a kernel non-paging memory; synchronously extracting PID and target file complete path in the callback routine, and judging according to system processes, exemption lists, and protection paths / types, and rejecting the request if it does not meet the conditions; and achieving dynamic management of strategies by establishing a control channel. The present application solves the problem of strategy failure caused by volume path changes by hiding file persistent volume IDs in the system; adopts hierarchical data structures and concurrent synchronization mechanisms to ensure efficient queries and little impact on disk IO performance; and supports multi-dimensional fine control with the help of multi-layer control switches and scenario-based templates.
Owner:成都傲梅科技有限公司

Incremental micro-segmentation system and incremental micro-segmentation method

An incremental micro-segmentation system includes a shared network and a network control device. The network control device is configured to perform operations of: retrieving multiple key values from a network flow; adding the multiple key values to be a policy rule of a temporary policy group based on an interested attribute of the temporary policy group of a candidate policy group set; computing a group score of each temporary policy group according to a recommended factor; when determining that the group score is greater than a threshold, generating a recommendation set including the temporary policy groups; and deploying the recommendation set to an access control list to make the temporary policy groups be enforced.
Owner:TXONE NETWORKS INC

Restrict mobile to mobile communication dynamically in 5G user plane function

ActiveUS12684461B2Ip addressUser equipment
In one aspect, a method includes generating, using a User Plane Function (UPF) of a core element of a network, a query to retrieve information associated with one or more Data Network Names (DNNs) configured in at least one other UPF in the network; transmitting the query to a Network Repository Function (NRF); receiving a response from the NRF, the response including IP address subnets of the at least one other UPF associated with the one or more DNNs; dynamically generating an Access Control List (ACL) to block mobile-to-mobile communication between User Equipment (UEs) in the network, using the IP address subnets received as part of the response, wherein each of the UEs is assigned an IP address from among the IP address subnets; and blocking M2M communication using the ACL dynamically generated.
Owner:CISCO TECHNOLOGY INC

Parameter configuration method and device of motor vehicle door control list, computer readable storage medium and computer program product

PendingCN122372508ASimulationData transmission
This invention provides a method, apparatus, computer-readable storage medium, and computer program product for configuring parameters of a vehicle access control list. The method includes: invoking the access control list when the vehicle starts, the access control list storing initial values ​​for each parameter; during data transmission based on the initial values, the transmission priority of driving-related control command data is higher than that of non-driving-related data; acquiring the current vehicle speed in real time, determining whether the current speed is lower than a preset speed threshold; if so, updating each parameter in the access control list to obtain optimized values, with the transmission priority of driving-related control command data and non-driving-related data being the same during data transmission; if not, maintaining each parameter at the initial value; and updating each parameter in the access control list to the initial value when the vehicle is turned off. This embodiment can improve the user experience when using non-driving-related services in the vehicle.
Owner:CHENGDU BOYN TIANFU SOFTWARE TECH CO LTD

Methods and systems for authorizing a client device to a service

A method of authorizing a client device to a service includes, by an electronic device: defining an access control list that includes permissions for authorized clients of a customer, creating authorization tokens and encoding the ACL into each of the authorization tokens, and distributing the authorization tokens to the authorized clients. The method includes, by a data center that provides a service to one or more of the authorized clients: receiving a service request to provide the service to a first client in which the request includes a submitted authorization token, decoding the submitted authorization token to identify a received ACL in the submitted authorization token, analyzing the received ACL to determine whether the first client is an authorized client and the permissions in the received ACL grant the first client permission to access the service, and if so, providing the service to the first client.
Owner:PUBNUB INC

User Trust Measurement Methods and Systems in Zero-Trust Network Environments

ActiveCN116455668BSolving the trust measurement problemReduce the risk of attack spreadingSecuring communicationInternet privacyRemote control
This invention discloses a user trust measurement method and system in a zero-trust network environment. It pre-collects user information, token information, device information, and system information, and generates an access control list. When a device sends a request, a risk assessment is performed on the request, followed by authentication. Based on historical access data, the request status is determined. Based on the authentication result and request status, it is determined whether authorization is allowed. If authorization is not allowed, the request is marked as a device anomaly. Based on the device's abnormal behavior, it is determined whether the device belongs to the category of remote control anomalies. If so, the access permissions of devices connected to and interacting with this device in the access control list are updated. This reduces the risk of network attack risk propagation in a zero-trust network environment.
Owner:SOUTHEAST UNIV

Permissions management for queries in a graph

Systems, methods, and software described herein manage permissions in association with a query to a graph. In one example, a method of managing the permissions includes identifying a request for a query operation. In response to the request, the method further provides for identifying an access control list (ACL) in association with the query operation and identifying whether the query operation is permitted based on the ACL. The method further includes, in response to determining that the query operation is permitted, initiating the query operation.
Owner:TIGERGRAPH INC

Authentication method, device, system and non-volatile computer readable storage medium

The present disclosure relates to an authentication method, device, system and nonvolatile computer readable storage medium, and relates to the technical field of communication. The authentication method comprises the following steps: receiving authentication information of a multicast receiver for joining a multicast, wherein the authentication information comprises identification information of a multicast group or a multicast source to which the multicast receiver applies to join; determining an access control list of a matched multicast group or multicast source according to the authentication information; and performing authentication on the multicast receiver according to the access control list, so as to judge whether the multicast receiver is allowed to join the multicast.
Owner:CHINA TELECOM CORP LTD