Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

177 results about "Access control list" patented technology

An access-control list (ACL), with respect to a computer file system, is a list of permissions attached to an object. An ACL specifies which users or system processes are granted access to objects, as well as what operations are allowed on given objects. Each entry in a typical ACL specifies a subject and an operation. For instance, if a file object has an ACL that contains (Alice: read,write; Bob: read), this would give Alice permission to read and write the file and Bob to only read it.

Data link security management and control system and method based on dynamic encryption

The invention relates to the technical field of intelligent control, in particular to a dynamic encryption-based data link security management and control system and method.The dynamic encryption-based data link security management and control system comprises a dynamic encryption engine, a key management cluster, a link monitoring unit and a security policy execution array, the switching between the SM9 cryptographic algorithm and the quantum resistance NTRU algorithm is supported; the key management cluster realizes distributed key negotiation and storage through a block chain smart contract, and establishes a bidirectional authentication channel with the dynamic encryption engine; the link monitoring unit is integrated with a multi-dimensional flow probe, and continuously collects link delay jitter, data packet entropy characteristics and protocol compliance indexes; the security policy execution array is deployed at a boundary node of a data link, and is configured with a dynamic access control list and a hardware-level data purification module. Therefore, the problems of insufficient encryption algorithm resistance, significant key update delay, multi-dimensional threat sensing blind areas, dynamic strategy response delay and the like in the prior art are solved.
Owner:YUXI POWER SUPPLY BUREAU OF YUNNAN POWER GRID

Control method and system of Internet of Things gateway based on AI computing power

The invention relates to the technical field of network management, in particular to an Internet of Things gateway control method and system based on AI computing power, and the method comprises the following steps: obtaining channel real-time signal intensity, noise level and occupancy proportion, monitoring protocol type and transmission condition, analyzing the relationship between retransmission times and interference, deducing protocol combination interference and throughput, and obtaining a real-time channel signal intensity, noise level and occupancy proportion. And configuring an optimal scheduling scheme, evaluating resource consumption and load states, packaging and requesting permission entrustment, and judging permission information in combination with an interaction record and an access control list. According to the method, different protocol distribution combinations are simulated and deduced, the data throughput of the whole network is further estimated and optimized, potential protocol conflicts are reduced, the use efficiency and the overall performance of network resources are effectively improved, consumption of a local computing unit and network bandwidth is comprehensively considered, packaging processing of request information is optimized, and the network performance is improved. And the real-time response capability and manageability of the network state are obviously improved.
Owner:中亿(深圳)信息科技有限公司

MCU information protection method and device, electronic equipment and readable storage medium

The invention relates to the technical field of microcontrollers, and provides an MCU information protection method and device, electronic equipment and a readable storage medium, and the method comprises the steps: checking a storage access request according to an access control list; wherein the access control list comprises an authorized storage area and an authorized operation type corresponding to the authorized storage area; the storage access request is used for accessing a target storage area of the MCU; according to the debugging secret key, an interface debugging request is checked, and the interface debugging request is used for debugging a target debugging interface of the MCU; identifying a target code instruction of the MCU, and performing pre-execution verification and dynamic monitoring on the target code instruction; adjusting the clock frequency and the clock phase of the MCU according to the load change information and the power consumption change information of the MCU; and implementing encryption measures on the target data transmission channel of the MCU by using the encryption algorithm. According to the technical scheme provided by one or more embodiments of the invention, the data security and the anti-attack capability of the MCU can be improved.
Owner:镁佳(北京)科技有限公司

Request parameter value authority authentication method and system

ActiveCN121037115ADigital data protectionSecuring communicationAdvanced encryption standard algorithmDistributed cache
The invention provides a request parameter value authority authentication method and system, and relates to the technical field of network security, and the method comprises the steps: creating an access control list configuration and binding a service when a gateway registers the service, building the association mapping of a consumer and the service, and setting a parameter authority list; encrypting the sensitive field by adopting an advanced encryption standard algorithm and synchronizing the sensitive field to a distributed cache; and verifying the validity of the token when the service request is received, verifying the authority of the consumer, and verifying the parameter value. According to the invention, unauthorized access can be effectively prevented, the system security is improved, and the authentication efficiency is improved through the distributed cache.
Owner:北京科杰科技有限公司

Interface-based ACLS in a layer-2 network

Systems and methods of interface-based ACLs in a virtual Layer-2 network. The method can include sending a packet from source compute instance in a virtual network to a destination compute instance via a destination virtual network interface card (destination VNIC) within a first virtual layer 2 network and evaluating an access control list (ACL) for the packet with a source virtual network interface card (source VNIC). ACL information relevant to the packet can be embedded in the packet. The VSRS can receive the packet and can identify the destination VNIC within the first virtual layer 2 network for delivery of the packet based on information received with the packet and mapping information contained within a mapping table. The VSRS can access ACL information from the packet and can apply the ACL information to the packet.
Owner:ORACLE INT CORP

Enterprise application management and migration on a web proxy

A computer-implemented method for management of an application on an enterprise network which accesses external networks via a web proxy. The method comprises obtaining enriched metadata concerning an application executed on the enterprise network, the enriched metadata including at least source code information and ownership information, identifying application traffic on the enterprise network based on proxy log data, source IP and destination URL, generating an access control list (ACL) based on the enriched metadata and identified application traffic, the ACL including a source address of the application and a list of allowed destination addresses, converting the ACL into a proxy policy that can be processed by a web proxy to permit access by the application to the destination addresses in the ACL, and establishing data communication between the application and an external network based on the proxy policy.
Owner:MORGAN STANLEY SERVICES GROUP INC

Large-scale hybrid strategy implementation method, device and equipment

PendingCN120165954ASecuring communicationHigh level techniquesData streamTernary content addressable memory
The invention discloses a method, a device and equipment for realizing a large-scale hybrid strategy. The method comprises the following steps of: receiving a message and analyzing the message to extract a field representing a data stream feature; generating intermediate state information according to an entry number, a port attribute and the field obtained through analysis, and obtaining a label through table look-up operation; fields, intermediate state information and labels of the messages are combined according to strategy rules defined by different storage blocks and compared with strategy entries in the storage blocks; and implementing a corresponding processing behavior on the message according to a comparison result. According to the method, parallel searching and processing behaviors of large-scale mixed policies can be realized, the method is suitable for more than hundreds of thousands of policy routing deployment and access control lists of various matching field combinations, and high-power-consumption and high-cost TCAM (Ternary Content Addressable Memory) storage can be avoided.
Owner:YUNHE ZHIWANG (SHANGHAI) TECHNOLOGY CO LTD

Gateway port on-off control method, equipment and medium

The invention provides an on-off control method and device for a gateway port and a medium. The on-off control method comprises the steps of obtaining historical access log data and threat intelligence data of a target port in a gateway; based on the historical access log data and the threat intelligence data, performing time sequence analysis by using a pre-trained long-short-term memory network model to obtain a predicted security access time period of the target port in a future preset time period; generating a temporary port exposure preset rule of the target port according to the predicted security access time period; determining a traffic feature vector of the real-time traffic data packet of the target port; using a preset deep reinforcement learning agent to determine an on-off control instruction for the target port based on the traffic feature vector and a temporary port exposure preset rule; and executing the on-off control instruction to modify an access control list state of the gateway firewall to the target port. According to the method and the device, dynamic and refined gateway port on-off control can be realized, so that the service flexibility and security are considered.
Owner:LINGBO TECH (BEIJING) CO LTD

Pooling of network processing resources

Examples described herein relate to a switch configured to allocate packet processing resources, from a pool of packet processing resources, to multiple applications, wherein the pool of packet processing resources comprise configurable packet processing pipelines of one or more network devices and packet processing resources of one or more servers. In some examples, the configurable packet processing pipelines and the packet processing resources are to perform one or more of: network switch operations, microservice communications, and / or block storage operations. In some examples, the network switch operations comprise one or more of: application of at least one access control list (ACL), packet forwarding, packet routing, and / or Virtual Extensible LAN (VXLAN) or GENEVE termination. In some examples, the microservice communications comprise one or more of: packet routing between microservices and / or load balancing of utilized microservices.
Owner:INTEL CORP

End-to-end encryption with password access

Presented herein are techniques to implement end-to-end encryption. A method includes, encrypting content C with an encryption key EK to obtain encrypted content C′, generating a key encrypting key KEK based on a password, encrypting the encryption key EK with the key encrypting key KEK to obtain an encrypted encryption key EK′, storing the encrypted content C′ and the encrypted encryption key EK′ such that the encrypted content C′ and the encrypted encryption key EK′ are accessible to a content consumer via a link, sending the link and the password to the content consumer, and in response to a request, received via the link, for the encrypted content C′ and the encrypted encryption key EK′, sending the encrypted content C′ and the encrypted encryption key EK′ to the consumer based on the content consumer being on an access control list.
Owner:CISCO TECHNOLOGY INC

Data access method and device, equipment, storage medium and program product

The invention discloses a data access method and device, equipment, a storage medium and a program product, and relates to the technical field of data security. The method comprises the following steps: classifying stored data according to ownership and sensitivity of the data to obtain data of multiple levels; according to the access control list and a role-based access control method, determining the access authority of each level of data; determining a data use control strategy according to the access authority of the data of each level and the parameter information of the user; determining a target data use control strategy of the second equipment according to a received data access request of the second equipment and the data use control strategy; and sending the target data use control strategy to a second device, so that the second device accesses and / or uses target data corresponding to the data access request according to the target data use control strategy. According to the scheme, the problem that in an existing data encryption method, a data owner cannot accurately control the use mode of data is solved.
Owner:CHINA MOBILE INFORMATION TECHNOLOGY CO LTD +1

Restrict mobile to mobile communication dynamically in 5g user plane function

In one aspect, a method includes generating, using a User Plane Function (UPF) of a core element of a network, a query to retrieve information associated with one or more Data Network Names (DNNs) configured in at least one other UPF in the network; transmitting the query to a Network Repository Function (NRF); receiving a response from the NRF, the response including IP address subnets of the at least one other UPF associated with the one or more DNNs; dynamically generating an Access Control List (ACL) to block mobile-to-mobile communication between User Equipment (UEs) in the network, using the IP address subnets received as part of the response, wherein each of the UEs is assigned an IP address from among the IP address subnets; and blocking M2M communication using the ACL dynamically generated.
Owner:CISCO TECHNOLOGY INC

Concurrent automatic adaptive storage of datasets in graph databases

A method of managing digital entities in data repositories comprises storing one or more data objects in a non-graph data repository into one or more nodes and edges of a graph, comprising transforming an access control list (ACL) of a first data object into an ACL node and transforming a version of a second data object into a version node in a graph data repository; electronically receiving a search query associated with a user account for a shortest path between two specified nodes of the graph; executing the search query against the graph data repository to generate a result set of nodes including only nodes corresponding to most recent versions of the one or more data objects that are visible to the user account under applicable ACLs.
Owner:PALANTIR TECHNOLOGIES INC

Configuration method and device of access control list, electronic equipment and storage medium

The invention provides an access control list configuration method and device, electronic equipment and a storage medium, and relates to the technical field of servers, and the method comprises the steps: collecting subnet information in a target containerization cluster, a configured access control list rule and security threat features in network traffic; the information is subjected to fusion analysis based on a predefined security policy so as to generate an access control list rule set containing different priorities, and then the rules are synchronized to a cluster virtual switch kernel according to the priorities so as to realize hierarchical control and dynamic protection of network traffic. The problems that a large-scale dynamic network environment is difficult to deal with, the automation level is low and malicious traffic cannot be efficiently intercepted due to the fact that manual configuration and static rule maintenance are relied on and deep integration of a containerized cluster network structure is lacked can be solved. The technical effects of improving the automation level of containerized cluster network management, enhancing the adaptability to a dynamic network environment, and realizing efficient interception of malicious traffic to guarantee network security are achieved.
Owner:JINAN INSPUR DATA TECH CO LTD

Preventing spam communications

Aspects of the present disclosure are directed to systems and methods for preventing spam communications. Implementations can implement an access control list that a communicator (e.g., a user device sending a text message, making a phone call, etc.) must be on in order to complete the communication with a recipient. If they are not on the access control list, the communicator can be prevented from sending the communication to the recipient, redirected to a registration process, or the communication can be tagged with an unverified status flag. In some implementations, the access control list can include a recipient's contacts, contacts of the recipient's contacts, authenticated entities (e.g., users and / or companies), previously verified entities, etc. In some implementations, a recipient can give out a temporary extension that a communicator can enter to complete communications with the recipient for a certain amount of time or for a certain number of uses.
Owner:UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)

Method, computer program product and field device for authorizing access to objects in a computerized system

A method for authorizing an entity (9) in a computerized system to access an object (12) includes the following steps: providing (S1) an access control list (ACL) that specifies access permissions for each object (12) to the object (12) in the computerized system; assigning (S2) capability requirement information to at least one of the objects in the access control list (ACL); assigning the capability information to at least one entity (9) in the computerized system; requesting (S11) access to the object (12) by the entity (9); checking whether the requesting entity (9) has access permissions according to the ACL; and authorizing (S5) access to the requested object (12) by the requesting entity (9) only if the capability information assigned to the requesting entity (9) matches the capability requirement information assigned to the requested object (12). The combination of ACL-based access to files and capabilities enhances the security of the system.
Owner:SIEMENS AG

Auditing access control lists of a network infrastructure

Systems and methods for auditing access control lists (ACLs) of a network infrastructure are provided. A plurality of network interfaces associated with a specified entity is identified. A plurality of access control lists (ACLs) is received. Each ACL of the plurality of ACL includes a plurality of rules associated with a respective network interface of the plurality of network interfaces. Network traffic metadata associated with the plurality of network interfaces is received. A corresponding set of rule utilization parameters is identified for each rule of the plurality of rules by matching the network traffic metadata to the plurality of rules.
Owner:GOOGLE LLC

Abnormity repairing method and device for virtual card, equipment and computer program product

The invention discloses a virtual card abnormity repairing method and device, equipment and a computer program product, and the method comprises the steps: obtaining real-time monitoring data of a first virtual card, and determining a real-time monitoring result of the first virtual card based on the real-time monitoring data; creating a second security domain corresponding to the first virtual card under the condition that the real-time monitoring result is that the security domain is in false death and a first security domain corresponding to the first virtual card meets a migration condition; and migrating the access control list and the key index of the first security domain to the second security domain.
Owner:SHENZHEN DACHENG COMM TECH CO LTD

Method and apparatus for dynamically expanding an access control list

The application provides a method and device for dynamically expanding an access control list. The method comprises the following steps: obtaining a first number of software ACL table entries of a first service module currently triggering a hardware access control list (ACL) configuration; obtaining a second number of software ACL table entries of a second service module of a current ACL dynamic expansion object; calculating a difference between the first number of software ACL table entries and the second number of software ACL table entries; when the difference exceeds a preset difference threshold, entering a hardware ACL resource overflow pre-check; and when the difference is less than the preset difference threshold, keeping the second service module as the ACL dynamic expansion object.
Owner:NEW H3C TECH CO LTD

Management method and system of access control list and computer readable storage medium

The invention discloses an access control list management method and system and a computer readable storage medium, belongs to the field of servers, and considers the form that a manager carries out digital signature through a signature server, not only can the legality of a target access control list proposed by a user be verified, but also the validity of the target access control list can be verified. According to the method, the signature server and the service server, high efficiency can be realized through interaction with the service server, so that the signature server performs legality verification on the target access control list sent by the service server, performs digital signature and returns the target access control list after the target access control list passes the legality verification, and the service server executes access control according to the target access control list subjected to digital signature. A traditional firmware updating mode is broken through, a user can actively submit updating and sign server real-time verification, the updating period of the access control list is shortened from a long period depending on manufacturer firmware upgrading to real-time response, the management efficiency is improved, the problem that the updating period is long and tedious is solved, and the flexibility and the real-time performance of the system are enhanced.
Owner:SHANDONG YUNHAI GUOCHUANG CLOUD COMPUTING EQUIP IND INNOVATION CENT CO LTD

Knowledge Graph Authorization

A computer-implemented method for determining access to resources using a knowledge graph includes obtaining a knowledge graph with multiple nodes connected by edges and receiving a request for a requestor to access a resource. The requestor is associated with a first node, and the resource is associated with a second node within the knowledge graph. The method includes determining a path between the first and second nodes and evaluating each node along the path. For each node, the method determines an access control list (ACL) stored separately from the knowledge graph and verifies the requestor's access based on the ACL. Based on determining that the requestor has access to all nodes along the path, the method includes determining that the requestor has access to the second node. The method includes returning, to the requestor, a response indicating access to the resource.
Owner:SERVICENOW INC

Message statistical method, switch chip and switch

The invention provides a message statistical method, a switch chip and a switch, a table look-up module obtains a condition index and a target storage position from statistical items when message information of a current message is matched with the statistical items in an ACL table or a forwarding table; a table look-up module determines a target configuration table item matched with the condition index from the configuration table; the target configuration table item comprises a statistical object and control data; a table look-up module obtains actual data corresponding to the statistical object from the message information; the logic judgment module judges whether the actual data meets the statistical condition corresponding to the condition index or not under the driving of the control data, and outputs a statistical signal; and the counting module updates the message counter at the target storage position when the statistical signal is true. According to the invention, the configuration table item of the statistical condition is recorded through the configuration table, and whether the actual data corresponding to the statistical object meets the statistical condition is judged through the logic judgment module, so that complex condition statistics can be realized under the condition of not wasting a large amount of ACL (Access Control List) resources.
Owner:SUZHOU CENTEC COMM CO LTD

Network access control list adjusting method based on flow analysis and optimization

The invention provides a network access control list adjusting method based on flow analysis and optimization, which comprises the following steps of: firstly, acquiring total flow information, and then dynamically constructing a network digital twinborn model based on the total flow information; constructing a causal derivation model based on a simulation result of the network digital twin model; analyzing and processing the real-time traffic by using a causal derivation model, and generating a plurality of network access control list change rules and corresponding deployment strategies; and then simulating the network access control list change rules and the deployment strategy thereof in the network digital twin model, and determining a target network access control list from each network access control list change rule based on a simulation result. According to the invention, a self-learning, dynamic risk quantification and strategy automatic generation and verification ACL tuning system is constructed, and the ACL tuning system is not only an optimization rule, but fundamentally changes the generation and management normal form of the ACL.
Owner:BEIJING ITECHSHARE NETWORK INFORMATION TECH CO LTD

Network monitoring method, computer readable storage medium and electronic device

The embodiment of the invention provides a network monitoring method, a computer readable storage medium and an electronic device, and the method comprises the steps: determining an ACL (Access Control List) negative list according to key features and network behavior features corresponding to different traffic data; and monitoring the network according to the ACL negative list and the network working mode. Therefore, through the embodiment of the invention, the problems that the traditional network monitoring mostly depends on manual rule matching, the rule writing difficulty is high, and the network cannot be accurately monitored can be solved, and the effect of improving the network security and stability is further achieved.
Owner:ZTE CORP

A method, device and related equipment for access control list (ACL) policy management

The present application discloses a method for managing access control list (ACL) policies. The ACL policy management method includes: dividing multiple proxy modules into multiple policy execution groups; wherein, the proxy module is a module in the client for executing ACL policies; abstracting the system network structure of the proxy module and the policy execution group into a policy management tree; wherein, the child nodes in the policy management tree inherit the ACL policies configured in the parent nodes; receiving user-configured policies, mapping the user-configured policies to target ACL policies based on the policy management tree, and sending the target ACL policies to the proxy modules in the corresponding policy execution groups. The present application can improve the configuration efficiency of ALC policies. The present application also discloses an access control list (ACL) policy management device, an electronic device, and a storage medium, which have the above beneficial effects.
Owner:SANGFOR TECH INC

A user access control method, system, apparatus, device and storage medium

Embodiments of the present application provide a user access control method, system, device, electronic equipment and storage medium, the method comprising: receiving an access request sent by a client; the access request comprising identification information of a user; obtaining mapping information according to the identification information of the user; the mapping information comprising identification information and permission information of a target user mapped by the user; and performing an access operation corresponding to the access request according to the identification information and permission information of the target user. Without setting a file access control list for each user, only a small number of target users need to be configured in the server, and the access control requirements of a large number of users can be met by mapping the user to the target user.
Owner:JINAN INSPUR DATA TECH CO LTD

Network congestion reason test method and device, equipment, storage medium and computer program product

The invention discloses a network congestion reason test method, device and equipment, a storage medium and a computer program product, and the method comprises the steps: starting an ECN marking function in a Spine-Leaf networking architecture of a data center, and carrying out the statistics of the number of ECN messages marked by Spine equipment and Leaf equipment due to congestion; configuring an access control list at the uplink port of the ToR device, and counting the number of messages marked by the ECN of the uplink port of the ToR device; and comparing the number of the ECN messages with the number of the messages marked by the ECN, and determining a network congestion reason according to a comparison result. As the number of the ECN messages marked by the Spine equipment and the Leaf equipment due to congestion is compared with the number of the messages marked by the ECN of the uplink port of the ToR equipment, and the network congestion reason is determined according to the comparison result, compared with the prior art, the efficiency and the accuracy of identifying the congestion reason are improved.
Owner:WUHAN FS COM TECHNOLOGY CO LTD

Message processing methods, devices, switches, storage media and software products

This application proposes a packet processing method, apparatus, switch, storage medium, and program product, applied to a driver chip. The method includes: receiving an analysis instruction, the analysis instruction including a first target feature and a first target packet operation type; generating multiple access control list entries based on the first target feature and the first target packet operation type; filtering target packets from target traffic that match the first target feature and the first target packet operation type based on the multiple access control list entries; and sending the target packets to a processor, so that the processor determines the performance indicators of the network to which the target packets belong based on the target packets. The embodiments of this application, by adding packet operation types to the analysis instruction, can generate access control list entries based on the first target feature and the packet operation type, thereby reducing the number of generated access control list entries and avoiding the problem of insufficient access control list entry resources.
Owner:NEW H3C TECH CO LTD

A method and system for offline identity authentication and rights management

The present invention relates to the technical field of identity authentication and rights management, and discloses a method and system for offline identity authentication and rights management. The method comprises the following steps: receiving an operation request from a target user for a target terminal; if the identity authentication client is offline, verifying the target user's digital certificate through a first authentication center of the identity authentication client to obtain a legitimacy verification result of the target user; if the target user is determined to be a legitimate user based on the legitimacy verification result, determining the target user's operating authority for the target terminal using the target user's access control list in a USB key; determining the target operating authority required for the operation instruction; and if the target user's operating authority for the target terminal includes the target operating authority, determining that the target user has the authority to execute the operation request on the target terminal. By implementing the present invention, user identity authentication and rights management can be achieved in an offline environment.
Owner:BEIJING SHENZHOU AEROSPACE SOFTWARE TECH CO LTD

A network control and scheduling method based on traffic awareness and path optimization

This invention discloses a network control and scheduling method based on traffic awareness and path optimization. It collects real-time traffic from network devices, extracts key features, and analyzes traffic pattern trends. Using these trends, the rule set is clustered according to the similarity of matching frequencies to form rule clusters. Within each cluster, rules are sorted based on matching frequency. The rule arrangement is analyzed to identify conflicting rule pairs. By assessing the severity of the conflicts, a conflict list with clear objectives is generated. This conflict list is then processed using a genetic algorithm to obtain an optimized rule sequence. Rigorous testing using simulated traffic yields a final rule set version. This final rule set version, passing all tests, is securely pushed to network devices, enabling real-time optimized access control list configuration. Network devices immediately operate based on the latest and optimal policies, thereby improving overall network security and data processing efficiency.
Owner:BEIJING ITECHSHARE NETWORK INFORMATION TECH CO LTD