Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

61 results about "Administrative domain" patented technology

An administrative domain is a service provider holding a security repository permitting to easily authenticate and authorize clients with credentials. This particularly applies to computer network security.

Cross-domain computing task processing method, program product, equipment and medium

The invention discloses a cross-domain computing task processing method, a program product, equipment and a medium, and relates to the technical field of cloud computing. The method comprises the following steps: determining a computing node for executing a cross-domain computing task in a cross-domain collaborative scene, and generating an identity certificate bound with the computing node based on a hardware credible state of the node; collecting security policies of a plurality of management domains for conflict detection and decision, and generating a conflict-free session policy; scheduling the cross-domain computing task to a target computing node meeting a preset credible requirement, and issuing a revocable dynamic session token; and recording the operation information of the cross-domain calculation task in the whole life cycle as an audit event, and generating a chained audit log which is linked by the hash value and is digitally signed through a preset verifiable audit interface. By means of the technical scheme, it can be ensured that the whole life cycle of any computing task meets the closed-loop safety requirements of identity credibility, permission controllability, execution propriability and behavior traceability in the complex distributed computing environment.
Owner:JINAN INSPUR DATA TECH CO LTD

Shipborne intelligent network security protection architecture and method

The invention provides a shipborne intelligent network security protection architecture and method, and relates to the technical field of network security, and the architecture comprises a security domain division module which is used for dividing a shipborne network into three physically isolated security domains, including a key task domain, an operation management domain and a crew life domain; the longitudinal protection strategy module is used for generating a longitudinal strategy comprising a protection instruction, a communication control instruction and a risk quantification instruction based on the security domain structure; and the risk calculation module is used for detecting intra-domain equipment access behaviors by trapping addresses in the key task domain, collecting intra-domain network traffic and service unit logs, and outputting a service asset quantized value, a vulnerability severity quantized value and a threat behavior deviation degree according to a risk quantization instruction. According to the invention, accurate identification, graded response and efficient disposal of shipborne network threats are realized, and the safety of a ship key system is guaranteed.
Owner:SHANGHAI JINGZHI INTELLIGENT TECH CO LTD

DNS Validation to Avoid Inadvertent Subzone Creation

Methods, systems, and apparatuses are described herein for management of a Domain Name System (DNS) system. The system comprises numerous improvements, many related to CNAME records of the DNS. A computing device may manage authentication for a DNS using shared authentication credentials of a first authentication framework. In this manner, a wide variety of users might authenticate themselves using a first framework and use authentication credentials for a second framework to access a DNS. The computing device may further protect DNS servers from Denial of Service (DoS) attacks by bifurcating read and write requests to a DNS to different servers, such that attacks on read requests do not affect all of the DNS. The computing device may further validate DNS requests using, for example, natural language processing to avoid typographical errors inadvertently creating DNS zones.
Owner:CAPITAL ONE SERVICES LLC

Domain name resource record TTL tampering traceability positioning method based on analytic chain reasoning

The invention discloses a domain name resource record TTL tampering traceability positioning method based on analytic chain reasoning, and belongs to the technical field of Internet security monitoring. The method comprises the following steps: deploying a system which comprises a special server for managing a domain name, a plurality of repeaters and a plurality of recursive resolvers located at the upstream of the repeaters, and setting a TTL reference value stored in the special server; selecting a target transponder, and initiating a plurality of DNS query requests with time intervals to the target transponder by a user; and determining a cache mode of the target transponder based on the TTL value in the response corresponding to each DNS query request, and determining an object tampering the TTL reference value based on the cache mode of the target transponder and the TTL value in the response corresponding to each DNS query request. The method is used for realizing hierarchical positioning of TTL tampering responsibilities.
Owner:NAT UNIV OF DEFENSE TECH +1

Shared authentication via DNS request routing

Methods, systems, and apparatuses are described herein for management of a Domain Name System (DNS) system. The system comprises numerous improvements, many related to CNAME records of the DNS. A computing device may manage authentication for a DNS using shared authentication credentials of a first authentication framework. In this manner, a wide variety of users might authenticate themselves using a first framework and use authentication credentials for a second framework to access a DNS. The computing device may further protect DNS servers from Denial of Service (DOS) attacks by bifurcating read and write requests to a DNS to different servers, such that attacks on read requests do not affect all of the DNS. The computing device may further validate DNS requests using, for example, natural language processing to avoid typographical errors inadvertently creating DNS zones.
Owner:CAPITAL ONE SERVICES LLC

DNS Load Balancing Via Request Routing

Methods, systems, and apparatuses are described herein for management of a Domain Name System (DNS) system. The system comprises numerous improvements, many related to CNAME records of the DNS. A computing device may manage authentication for a DNS using shared authentication credentials of a first authentication framework. In this manner, a wide variety of users might authenticate themselves using a first framework and use authentication credentials for a second framework to access a DNS. The computing device may further protect DNS servers from Denial of Service (DOS) attacks by bifurcating read and write requests to a DNS to different servers, such that attacks on read requests do not affect all of the DNS. The computing device may further validate DNS requests using, for example, natural language processing to avoid typographical errors inadvertently creating DNS zones.
Owner:CAPITAL ONE SERVICES LLC

Unmanned aerial vehicle cross-domain service function link accessing method based on alliance chain

The invention discloses an alliance chain-based unmanned aerial vehicle cross-domain service function link accessing method, which comprises the following steps of: 1, initializing a system and configuring an alliance chain, generating a global password parameter and a root key by a trusted mechanism, and finishing domain registration and certificate chain storage by each management domain edge server; 2, blockchain-driven identity management is carried out, and the unmanned aerial vehicle completes chain registration and anti-counterfeiting registration certificate acquisition through a domain edge server to which the unmanned aerial vehicle belongs; 3, deploying a flexible threshold signature algorithm to realize multi-domain joint signature and Byzantine fault tolerance; 4, executing a cross-domain SFC security authentication protocol, including SFC pre-verification and security authorization certificate issuing, first node verification starting, hop-by-hop key negotiation and handover certificate transmission, and on-chain auditing; and 5, based on the topology centrality and the path coverage, dynamically electing an orchestrator to realize load balancing. According to the invention, safe access and identity authentication of the cross-domain service function chain of the unmanned aerial vehicle are realized, safety, efficiency and expandability are balanced, and reliable guarantee is provided for cross-domain cooperation of the unmanned aerial vehicle.
Owner:NANJING UNIV OF AERONAUTICS & ASTRONAUTICS

Methods and apparatus to manage transmissions between domains and memory

Methods and apparatus to manage transmissions between domains and memory are disclosed. An example electronic communications security system disclosed herein includes media storage; a first host bus adapter (HBA) serial attached small computer system interface (SCSI) (SAS) card to: communicatively couple a first domain to the media storage; and enable transmission of first data from the first domain to the media storage; and a second HBA SAS card that is write-block enabled to: communicatively couple a second domain to the media storage; enable access of the first data from the media storage by the second domain; and prevent second data from exiting the second domain.
Owner:THE BOEING CO

Multi-administrative domain network verification method and system

The present disclosure provides a multi-administrative domain network verification method, comprising: converting router configuration files of respective application servers into input formats determined by a secure multi-party computation protocol to ensure compatibility between the respective application servers; performing simulation processing on the router configuration files meeting the input formats to enable the multi-administrative domain network to generate a secret data plane after convergence; and performing data plane verification on the secret data plane to obtain verification results about respective attributes of the multi-administrative domain network. The present disclosure also provides a multi-administrative domain network verification system.
Owner:XIAMEN UNIV

Method, device, and system for managing domain name resolution

A domain name system DNS resolver may only allow those DNS requests that use an unencrypted communication protocol for domain name resolution by blocking DNS requests that use an encrypted communicati
Owner:CAMBIUM NETWORKS

A multi-controller deployment method for SD-MANET based on improved Pied Kingfisher algorithm

The present invention discloses a method for deploying multiple controllers in an SD-MANET (Mobile Self-Organizing Network) based on an improved Pied Kingfisher algorithm, belonging to the technical field of mobile self-organizing networks. The method comprises: obtaining network topology information of the SD-MANET; constructing an undirected graph representing the network topology; defining the controller deployment problem as a multi-objective optimization problem; solving the multi-objective optimization problem using the improved Pied Kingfisher optimization algorithm to obtain an optimal controller deployment solution; and deploying controllers and their management domains in the SD-MANET environment based on the optimal controller deployment solution. The present invention simultaneously optimizes three key metrics: link failure rate, latency, and load balancing, achieving significant results in reducing link failure rate and latency, prioritizing link stability and latency performance, and thereby improving the overall reliability and efficiency of the SD-MANET network.
Owner:NANJING UNIV OF INFORMATION SCI & TECH

Massive constellation hierarchical routing planning method for concurrent tasks

The application discloses a large-scale constellation hierarchical routing planning method for concurrent tasks, and belongs to the technical field of mega constellation management and routing planning.The application is used for solving the problem of constellation routing planning under large-scale concurrent tasks and large-scale nodes.The application comprises the following steps: dividing a large-scale constellation into constellation management domains, determining the shortest domain-level path from a starting constellation management domain to a terminal constellation management domain for each task, determining the initial entry domain endpoint and the initial exit domain endpoint of each constellation management domain based on a global routing reference direction, adjusting the exit domain endpoint of a congested node to obtain a final exit domain endpoint and a corresponding final entry domain endpoint, and dividing the tasks in the constellation management domain into rounds according to the estimated time sequence of the tasks to arrive at the constellation management domain, and selecting a low-load next-hop satellite node for each round of task.The application reduces the complexity of constellation routing planning under large-scale concurrent tasks and large-scale nodes, and realizes the optimization of network load balancing performance.
Owner:NANJING UNIV OF AERONAUTICS & ASTRONAUTICS +1

Methods for obtaining memory access permissions, electronic devices and storage media

This application provides a method, electronic device, and storage medium for obtaining memory access permissions. The method includes: checking the management domain to which the transaction belongs and the physical address accessed based on permissions; performing a multi-level MTT cache parallel lookup operation to obtain the hit results of the multi-level MTT cache; and determining the memory access permissions based on the hit results of the multi-level MTT cache. The memory access permission acquisition method of this application first caches the multi-level page table results of IO-side device transactions under a specific management domain. In subsequent access permission checks, a multi-level page table cache parallel lookup strategy replaces the traditional serial page table process, allowing IO-side device transactions to simultaneously determine the hit results of the multi-level page table cache and obtain access permissions based on the hit results. This strategy not only significantly improves the speed of permission checks but also reduces the frequency of memory access and bandwidth consumption. Furthermore, it efficiently adapts to access scenarios of IO-side devices in different management domains, further improving the overall efficiency of permission checks.
Owner:SANECHIPS TECH CO LTD

Spacecraft modular computing cloud platform and OpenStack reconfigurable method

The invention provides a spacecraft modular computing cloud platform and an OpenStack reconfigurable method.According to the platform, a plurality of computing nodes are interconnected through a high-speed bus and matched with a dual-redundancy PMC board card to achieve hardware monitoring and fault control, a system deconstructs OpenStack into an SGC containerized service unit, and on-demand cutting deployment and resource scheduling are achieved in combination with an assembly bus; and designing a multi-stage operation process, such as a platform power-up management domain, computing node power-up diagnosis, software starting registration, cloud service initialization, business virtual machine deployment and a second-level fault detection and automatic recovery mechanism. Compared with the prior art, the deployment and maintenance cost is greatly reduced, the reliability and flexibility of the system are improved, the problems that the original OpenStack fault processing is time-consuming and depends on manpower are solved, and the method is suitable for high-reliability demand scenes such as spacecraft on-board data processing and edge calculation.
Owner:HANGKE XINCHUANG (BEIJING) INFORMATION TECH CO LTD

Communication method and communication apparatus

A communication method and a communication apparatus. The communication method includes: accessing a data model, to obtain a target state of a managed object in an NFV MANO management domain in the data model; and invoking a first function from a function set based on the target state, where the first function is used for transition from an existing state of the managed object to the target state. Therefore, the data model and the function set are integrated in the NFV MANO management domain, so that data and a function operation of the managed object in the NFV MANO management domain are separated, to implement a simplified, agile, and scalable intent-driven management architecture.
Owner:HUAWEI TECH CO LTD

Refined permission and behavior monitoring method under global security environment

The invention provides a refined permission and behavior monitoring method in a global security environment, which comprises the following steps of: constructing access permissions of different users, and setting the access permissions according to a minimum permission principle; constructing management domains of different administrators according to different authority discrete mechanisms; login of a user and an administrator is carried out through a two-factor authentication and biological recognition method, login behaviors are monitored, and abnormal login behaviors are obtained; monitoring the operation behaviors after the user and the administrator log in, and automatically logging out when the operation behaviors are overtime; and meanwhile, monitoring and risk assessment are carried out on the user interaction behavior after login, a risk assessment result is given, and the user interaction behavior is monitored or intervened according to the risk assessment result.
Owner:BEIJING HONGSHAN INFORMATION TECH RES CO LTD

Distributed secure communication method, device and equipment based on quantum key distribution

The invention discloses a distributed secure communication method and device based on quantum key distribution, equipment and a medium, and the method comprises the steps: receiving a communication request from a first user terminal in the same management domain, and the request comprises the identification of a second user terminal in other management domains; determining a second key management node of other management domains according to the identifier of the second user terminal; sending a negotiation key request to a second key management node through a quantum key distribution protocol, so that the second key management node returns a request response according to the negotiation key request; determining a session key through a quantum key distribution network according to the request response; and the session key is issued to the first user terminal, so that the first user terminal encrypts the communication message according to the session key, thereby effectively overcoming the system performance bottleneck under the high-concurrency request, and meeting the communication requirements with relatively high requirements on real-time performance and security.
Owner:中电信量子信息科技集团有限公司

Cyber-threat analyses using machine learning and prior observations

A cyber-security analysis method uses machine learning (ML) technology to classify cyber-threat indicators, for example, as malicious or benign, by generating a threat score. The method includes receiving, at a compute device, a cyber-threat indicator (IUE) and associated verdicts from a set of sources. Augmenting the verdicts associated with the IUE with verdicts associated with at least one related indicator having a defined relationship with the IUE. The relationship between the IUE and the at least one related indicator can be operational, e.g., based on an administrative domain, or functional, e.g., based on a protocol specification. The cyber-threat score is generated for the IUE based on the ML model and the combined verdicts of the IUE and the at least one related indicator.
Owner:GOOGLE LLC

Distributed tracking and verification of objects using a blockchain system

ActiveUS12652182B2Cryptography processingDigital data protectionDomain nameRegistration authority
A system for managing domain registrations configured to connect to a blockchain wallet running on a client device. The blockchain wallet includes associated keys for a blockchain system. The system is further configured to inspect the blockchain wallet for a first non-fungible token (NFT) associated with a first domain name, and check with a domain name service (DNS) registry on whether the first domain name is registered at the DNS registry. The DNS registry is configured to receive registration information associated with one or more domains. In response to the first domain name being registered at the DNS registry, performing one or more of (i) expiring the first NFT in the blockchain wallet, (ii) adding a second NFT to the blockchain wallet, (iii) adding a fungible token to the blockchain wallet, (iv) removing the first NFT from the blockchain wallet, or (v) exchanging the first NFT for the fungible token.
Owner:UKCI HLDG LTD

Asset management system based on Internet of Things

The invention discloses an asset management system based on the Internet of Things, and belongs to the technical field of asset management, and the system specifically comprises the steps: installing an asset identity chip on an asset, and forming verifiable physical binding; the edge gateway initiates response verification on the chip, generates an initial handover record, a record position, a department and a keeper, and writes the record into a cross-domain account book; respectively signing chip responses by the original management domain and the new management domain during cross-domain transfer, generating a double-signature handover record, uploading the record, stopping using an old voucher and binding the new management domain; a witness abstract is generated and cached in a transportation off-network stage, an edge gateway additionally records an uplink after network access, and a time window is bridged; during management domain query, the edge gateway collects all handover records, generates a state packet in combination with the current response of the chip, and restores a complete history according to a time sequence; and triggering a chip termination instruction during scrap recovery, outputting a termination declaration, generating a handover termination record by the edge gateway, and uploading the handover termination record to complete asset identity state storage.
Owner:HANGZHOU HUIXIJIN TECHNOLOGY CO LTD

Systems and Methods for Settlement Interfaces in Cellular Networks Using Blockchain Technology

The present system relates to settling transactions in a network environment using blockchain technology. The system comprises multiple network operator domains, each with network infrastructure components. A first operator domain includes a gateway for managing device connections and a blockchain interface for managing transaction settlements. A settlement management domain maintains transaction records for multiple network operators. The blockchain is configured to record and settle transactions. The system facilitates network operator provisioning, transaction initiation, and settlement. The gateway manages device connections using WiFi, 4G, 5G, or 6G technologies, and the blockchain interface interacts with the blockchain for real-time settlement of transactions. The settlement management domain uses an Settlement Service API for real-time reporting and settlement verification.
Owner:NOVA LABS INC

Federal learning-based cross-domain traffic data congestion prediction method and system

The invention discloses a cross-domain traffic data congestion prediction method and system based on federated learning, and relates to the technical field of intelligent traffic. Comprising the following steps: S1, initial grouping: extracting static attribute features and dynamic behavior features, and determining a grouping aggregation center corresponding to each client group; s2, dynamic optimization: according to the grouping aggregation center, setting an aggregation center model of each client group, and dynamically optimizing model parameters of the aggregation center model; and S3, model deployment: according to the new grouping model parameters, adjusting and setting grouping aggregation center model parameters of each expressway management domain, and according to a comparison result between the lifting amplitude within the preset time period and a preset amplitude threshold value, determining an update state of a grouping aggregation center model. According to the invention, the congestion rule of a specific type of expressway can be learned more finely, so that the prediction accuracy of congestion modes in different scenes can be improved.
Owner:SICHUAN INTELLIGENT TRANSPORTATION SYST MANAGEMENT CO LTD

System and method for managing domain name system records

Aspects of the subject disclosure may include, for example, a device including a processing system including a processor; and a memory that stores executable instructions that, when executed by the processing system, facilitate performance of operations of: receiving domain name system (DNS) record changes; identifying errors from the DNS record changes; discarding the DNS record changes responsive to the errors identified; scheduling the DNS record changes responsive to a lack of errors identified; translating the DNS record changes into protocol specific formats; and provisioning the protocol specific formats of the translated DNS record changes. Other embodiments are disclosed.
Owner:AT&T INTELLECTUAL PROPERTY I L P

Network element management method, system and device under service-oriented architecture

The present disclosure relates to the technical field of communication, in particular to a method, system and device for network element management under service-oriented architecture, a computer readable storage medium and an electronic device. The method comprises: receiving registration information of a service-oriented network element, obtaining management domain information of the service-oriented network element; transmitting the management domain information of the service-oriented network element to a management platform, so that the management platform establishes a communication link with the service-oriented network element according to the management domain information. The technical scheme of the embodiment of the present disclosure overcomes the problem that the efficiency of docking of the newly added network element is not clear.
Owner:CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1

Data transmission system and method for data networking

The invention provides a data transmission system and method for data networking, and relates to the technical field of data communication. The system comprises a data flow terminal configured with a first network interface and a second network interface; the data circulation support platform is configured to send a network demand parameter to the private network resource scheduling unit after determining a participant needing data transmission; and a private network resource scheduling unit configured to allocate network resources based on the virtual private network resource pool and the bandwidth resource pool, and communicate with another private network resource scheduling unit in a cross-management domain scene to cooperatively complete end-to-end resource allocation, an access voucher is issued to the data circulation terminal, and virtual private network configuration and a bandwidth template are issued to the private network transmission network; and the private network forwarding network establishes an isolated virtual private network channel according to the virtual private network configuration and the bandwidth template and executes bandwidth scheduling. According to the embodiment of the invention, safe isolation and efficient linkage of the control surface and the data surface can be ensured.
Owner:CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1

Shared Authentication Via DNS Request Routing

Methods, systems, and apparatuses are described herein for management of a Domain Name System (DNS) system. The system comprises numerous improvements, many related to CNAME records of the DNS. A computing device may manage authentication for a DNS using shared authentication credentials of a first authentication framework. In this manner, a wide variety of users might authenticate themselves using a first framework and use authentication credentials for a second framework to access a DNS. The computing device may further protect DNS servers from Denial of Service (DoS) attacks by bifurcating read and write requests to a DNS to different servers, such that attacks on read requests do not affect all of the DNS. The computing device may further validate DNS requests using, for example, natural language processing to avoid typographical errors inadvertently creating DNS zones.
Owner:CAPITAL ONE SERVICES LLC

Equipment management method and identity verification method based on digital certificate

The embodiment of the invention provides an equipment management method and an identity verification method based on a digital certificate. The method is applied to a device management system, and comprises the following steps: an identity authentication end receives a device activation request carrying a digital certificate sent by a user terminal, performs first identity authentication on a user according to the digital certificate to obtain an identity authentication result of the user terminal, and sends the device activation request to the user terminal when the identity authentication result indicates that the authentication is passed; the identity authentication end sends first management information corresponding to the device activation request to a device management end, and the device management end determines and activates a first managed device from a plurality of managed devices in a management domain based on the first management information; according to the method, the security and reliability of identity authentication are improved, and the management of a plurality of managed devices in the management domain is realized.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD +2

Urban railway online key updating device, method and system and storage medium

The invention provides an online key updating device, method and system for urban railways and a storage medium. The device comprises a key management center, a certificate management center and key using equipment, the key management center is responsible for key encryption, secure connection establishment and key management; the certificate management center is responsible for issuing, updating, revoking and the like of the digital certificate; the secret key using device is responsible for digital certificate application and state query, secure connection establishment and online secret key management message processing; the method comprises the steps of login verification, secret key updating instruction issuing, identity verification, ciphertext information transmission, digital envelope manufacturing, secret key information distribution, feedback information reading and secret key updating condition verification. According to the method, a digital certificate management system is introduced, it is ensured that interaction content in the key updating process is completely encrypted, intercept and tampering risks of a man-in-the-middle are avoided, and key management safety is ensured.
Owner:SHANGHAI SHENTIE INVESTMENT CO LTD +1

Authority management method and device, computer equipment and storage medium

The invention relates to an authority management method and device, computer equipment and a storage medium. The method comprises the following steps: respectively attributing authority resource partitions of a target system to corresponding management domains, and establishing authority association data of a plurality of management main bodies and a plurality of partition resources; in response to the received permission change instruction, determining an instruction sending main body and an instruction target main body, and determining a corresponding instruction target management domain; traversing the instruction target resource, and constructing a management authority tree of the instruction sending main body in an instruction target management domain; and selecting permission leaf nodes from the management permission tree and generating permission change information so as to change the management permission of the instruction target main body to the instruction target resource. By adopting the method, the clear management domain boundary can be established based on the resource partition, the authority action range is limited according to the management domain, and the management authority tree is constructed to accurately generate the change information, so that the technical problems that the authority action range is difficult to limit and the authority change cannot be accurately controlled in the prior art are solved.
Owner:CHINA ASSET MANAGEMENT CO LTD

Method, device, and system for managing domain name resolution

A method, device, and system for managing Domain Name System (DNS) filtering is disclosed. The method may include blocking an end-device from accessing a domain for a predefined time duration using an encrypted communication protocol to access a domain name resolution service. The method may further include determining failure of the end-device to switch to an unencrypted communication protocol to access the domain name resolution service, after expiry of the predefined time duration. The method may include identifying the end-device as a headless device; and permitting the end-device to access the domain name resolution service using the encrypted communication protocol.
Owner:CAMBIUM NETWORKS