Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

4498 results about "Authorization" patented technology

Authorization is the function of specifying access rights/privileges to resources, which is related to information security and computer security in general and to access control in particular. More formally, "to authorize" is to define an access policy. For example, human resources staff are normally authorized to access employee records and this policy is usually formalized as access control rules in a computer system. During operation, the system uses the access control rules to decide whether access requests from (authenticated) consumers shall be approved (granted) or disapproved (rejected). Resources include individual files or an item's data, computer programs, computer devices and functionality provided by computer applications. Examples of consumers are computer users, computer Software and other Hardware on the computer.

Zero-trust network dynamic access control method based on AI behavior portrait

The invention discloses a zero-trust network dynamic access control method based on an AI behavior portrait, and the method comprises the following steps: 1, collecting multi-source real-time behavior data during an access request; 2, constructing an AI behavior portrait engine based on historical data, inputting the integrated multi-source behavior data, calculating a behavior deviation degree through the AI behavior portrait engine, and outputting a risk score; 3, dynamic strategy decision making, wherein a decision making engine executes hierarchical control according to the risk score; 4, continuous session monitoring and real-time adjustment are carried out; step 5, when risk upgrading is detected in the session, degrading the session authority, limiting high-risk operation, terminating the session, and retaining evidence obtaining data; step 6, audit event generation and portrait updating; and step 7, strategy optimization closed loop. According to the method, the risk score is calculated in real time based on the AI behavior portrait, transition from static authorization to dynamic permission adjustment is realized, and internal threats such as voucher stealing and the like are effectively blocked.
Owner:JINGDEZHEN SHANJIANG TECHNOLOGY CO LTD

Data security dynamic evaluation system and protection method

The invention discloses a data security dynamic evaluation system and a protection method, belongs to the technical field of information security, and is used for solving the problem of terminal equipment access control and behavior risk dynamic collaborative protection. The method comprises the following steps: generating fingerprints through terminal equipment features, verifying authorization, inputting access feature slices into a time sequence model by authorized terminal equipment, generating a trust score based on cosine similarity of a behavior sequence and a prediction sequence, and constructing a Markov model to dynamically select an authentication mode according to the trust score; calculating a risk index by combining network and geographic information, and distributing the risk index to a real or virtual environment; and the unauthorized terminal equipment distributes the virtual environment after registration. Differentiated monitoring is carried out, a time sequence library is established in the virtual environment, and doubt scores are generated through sequence matching; the state deviation of the real environment is calculated through a hidden Markov model, and the risk score is generated by fusing the multi-dimensional features. And based on the result management authority, the suspicion terminal equipment isolates and shrinks the authority, the compliance terminal equipment authenticates and migrates, and the access is regulated and controlled according to the minimum privilege principle and the time window mechanism.
Owner:TIBET YANRUI INFORMATION SECURITY TECHNOLOGY CO LTD

Anonymization in a low power physical asset tracking system

Systems and methods are described for transmitting broadcasts by Peripherals, receiving the broadcasts by Centrals, and communicating with a Backend by Centrals. Specifically, a Peripheral may generate and transmit an encrypted broadcast packet to a Central, the Central may transmit the encrypted observation information to the Backend, which may decrypt the broadcast packet. Additionally, a Central may transmit a request for authorization to connect to a Peripheral to the Backend. If authorized by the Backend, the Central may connect to the Peripheral. Further, a Central may receive a plurality of broadcasts over a period of time. The Central may store information about the broadcasts and, at the conclusion of the period of time, transmit the information about the broadcasts and the last-received broadcast to the Backend.
Owner:SAMSARA INC

Zero-trust multi-party security data exchange method

The invention relates to the technical field of network and information security, in particular to a zero-trust multi-party security data exchange method, which comprises the following steps of: generating a zero-trust token and a capability authorization bill and constructing context description data; authentication encryption is performed on the plaintext fragment, attribute-based encryption is performed on the data one-time key, and a policy bearing ciphertext container is assembled; in the trusted execution environment, authentication decryption is completed through a one-time secret key of data recovery through joint challenge and threshold deblocking, or strategy migration and transfer are achieved through proxy re-encryption; and aggregating the decryption event and the forwarding event by vector commitment, generating a time anchor, and mapping the time anchor into a next round of random base. According to the invention, fine-grained authorization of the key layer, no plaintext transfer, event-level verifiable auditing and rapid revocation are realized.
Owner:杭州市余杭区巡察保障中心

Data ownership verification and authorization control method based on zero knowledge proof

The invention discloses a data ownership verification and authorization control method based on zero knowledge proof. The method comprises the following steps: constructing a traceable Merk tree structure on a block chain or a distributed account book; a data owner calculates data fingerprints and packages the data fingerprints into declaration nodes to be inserted into the traceable Merk tree; storing the ownership zero knowledge proof and the traceable Merk tree root hash into a block chain together; the verification party executes the zero-knowledge verifier contract on the chain to complete ownership verification without reading original data or identity plaintext; access control is realized after on-chain verification of the service party; triggering local heavy hash to update the traceable Merk tree root hash, and broadcasting a revocation event on a chain; and confirming legality of evolution and authorization change of all nodes. According to the method, the historical traceability and structural consistency of the data ownership and authorization relationship are ensured, and efficient traceability and anomaly detection of the node evolution chain are also realized.
Owner:SHENZHEN ENAIDA TECHNOLOGY DEVELOPMENT CO LTD

Managing digital artifact access using agentic artificial intelligence models

Systems and methods disclosed herein automatically authorize, audit, and manage usage of protected digital content via agentic artificial intelligence (AI) models. A data access / usage request is received (e.g., from a graphical user interface) that is associated with digital assets licensed from third parties. The system uses a first AI agent set to identify the digital content and retrieve corresponding access policies from a distributed database. The system uses a second AI agent set (same as or different from the first AI agent set) to evaluate the request against the retrieved policy to generate a permission set and / or settlement instructions. The system uses a third AI agent set (same as or different from the first and / or second AI agent sets) to embed digital watermarks and / or cryptographic signatures into the accessed content, and to record an audit trail of access, authorization, and / or settlement events in a distributed ledger or database.
Owner:CITIBANK N A

Urban multi-mode digital twin data asset safety management method

The invention discloses an urban multi-mode digital twin data asset security management method, and relates to the technical field of urban digital twin and data security, and the method comprises the steps: firstly building a unified access gateway, converging multi-department and multi-type data, and generating sensitivity annotation and privacy level metadata; performing differential privacy or desensitization and dynamically calibrating parameters at the local part of the data provider according to the labels; bookkeeping access, authorization and training on a permission alliance chain, and performing fine-grained permission control; through on-chain authorization, each node only uploads disturbed and encrypted model update, and a global model is obtained after secure aggregation; the governance layer continuously monitors logs, budget and model indexes and triggers strategy closed-loop regulation and control; and multi-agent reinforcement learning of a privacy agent and a performance agent is further introduced, a unified multi-target optimizer is formed through distillation, privacy, federation and permission strategies are refreshed online, and collaborative analysis and compliance sharing operation without data out of a domain are realized.
Owner:INHENG TECHNOLOGY (SHANGHAI) CO LTD

Access control policy optimization

Techniques include optimizing a base access control policy, resulting in a residual access control policy, which is then indexed. Upon receiving an access request, the system retrieves the residual access control policy from the index using the request's attributes. The access request is then evaluated against the residual policy to make an authorization decision, which is promptly returned. This streamlined process efficiently evaluates and determines authorization, enhancing the speed and accuracy of access control decisions.
Owner:AMAZON TECH INC

Systems And Methods For Determining Electric Pulses To Provide To An Unattended Machine Based On Remotely-Configured Options

A system receives, from a server, information about a first set of remotely-configured options for an unattended machine. In response to receiving the information about the first set of remotely-configured options, the system displays user interface objects that allow for selection of respective options in the first set of remotely-configured options. After detecting a selection of a first user interface object, the system receives, from the server, specifications regarding electric pulses to be provided to the unattended machine by a pulse-providing device. After sending an authorization grant and the specifications to the pulse-providing device, the system receives an indication that the electric pulses were provided to the unattended machine according to the specifications.
Owner:PAYRANGE INC

Door lock Bluetooth cooperative processing method and system

The invention discloses a door lock Bluetooth cooperative processing method and system, and the method comprises the steps: a door lock A detects a doorbell trigger signal, carries out the sorting and integrity verification of encrypted fragmented data, and obtains a face feature ciphertext data block; based on the face feature ciphertext data block, performing decryption processing to obtain a plaintext face feature vector, and performing similarity comparison to generate a dynamic pairing code; according to the verification success result of the dynamic pairing code, the door lock B is triggered to send a calling confirmation request to the door lock A, and a cooperative authorization result between the door locks is obtained; and based on a collaborative authorization result, the platform sends a navigation instruction to the robot, and the robot generates a task summary after completing face recognition and unlocking operation, synchronously cleans temporary data, and obtains a closed-loop execution record of an on-behalf call process. According to the embodiment of the invention, efficient, safe and intelligent cooperative door lock control can be realized.
Owner:HANGZHOU DIANZI UNIV +1

Ai agent interfaces and controls for email and other electronic communications

Systems and methods are provided for managing AI (Artificial Intelligence) agents interactions with electronic communications that are displayed at an electronic communications interface, such as an email interface. The systems parse electronic communications to determine whether they correspond to new or existing requests and actions to be performed when responding to the request(s). The systems also generate notifications identifying the set of actions with visual identifiers that visually distinguish the set of actions based on whether they have been completed or not and whether they need authorization to be completed. The systems also display selectable controls for controlling how the AI agent performs the actions.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Dynamic knowledge graph driven cross-department government affair data collaboration method and system

The embodiment of the invention provides a dynamic knowledge graph-driven cross-department government affair data collaboration method and a dynamic knowledge graph-driven cross-department government affair data collaboration system. The method is applied to the technical field of computer science and technology, and comprises the steps of obtaining cross-department government affair service data and corresponding policy rule data, constructing a data knowledge graph and a policy knowledge graph, performing incremental updating and consistency verification on the knowledge graphs based on preset event information, and extracting a newest service state and a newest policy rule. A minimum necessary data view and an authorization range are generated through joint reasoning, efficient and safe collaboration of cross-department government affair data is achieved on the basis, and accurate authorization and compliance management of data access are achieved. According to the scheme, only necessary data is provided and the access permission is strictly controlled in cross-department government affair data collaboration, so that the data sharing efficiency, security and compliance are remarkably improved, and meanwhile, the risks of unauthorized access and redundant data transmission are reduced.
Owner:JIANGSU FENGYUN TECH SERVICE CO LTD

MEC federation broker and manager enabling secure cross-platform communication

Various systems and methods are described implementing a multi-access edge computing (MEC) based system to realize MEC federation management and broker functions for MEC frameworks. In an example, performing edge federation management functions of edge computing systems, to establish a partnership among multiple edge federation managers as a federation, include: using system data attributes to establish the partnership; using authentication data attributes to enable the edge federation managers to securely authenticate; using authorization data attributes to enable the edge federation managers to perform authorization; using availability zone data attributes to define zones in the federation; and using management and settlement information data attributes to enable management of resources in the federation. Further operations include communicating the data attributes via respective connections with the edge federation managers, and the use of defined interfaces and operations.
Owner:INTEL CORP

Government affair data dynamic authorization management method based on secure multi-party computing

The invention discloses a government affair data dynamic authorization management method based on secure multi-party computing, and relates to the field of government affair data security authorization management, and the method comprises the steps: distributing a unique identity identifier for each participant, generating an asymmetric key pair through employing a national secret SM2 algorithm, registering a public key and mechanism attribute information to an alliance chain smart contract, and generating an identity certificate package; and based on attribute information in the identity credential packet, the participants cooperatively generate anti-quantum dynamic attribute-based encryption key fragments through a secure multi-party computing protocol, and the anti-quantum dynamic attribute-based encryption key fragments are distributed to the participants by adopting a threshold secret sharing technology. Threshold decryption and token verification are achieved through an alliance chain verification intelligent contract, an authorization record is generated, an access control strategy of an edge computing node is configured according to the authorization record, an oblivious transmission protocol is adopted to respond to data query, and an audit node monitors an access log, dynamically adjusts attribute weight parameters and synchronizes the attribute weight parameters to a key fragment.
Owner:CHINA NAT INST OF STANDARDIZATION

Electric power communication analysis system and method based on big data

The invention discloses an electric power communication analysis system and method based on big data, and the method comprises the steps: collecting multi-source heterogeneous data, carrying out the sensitivity grading, and generating labels; gathering the data to a big data platform, and completing storage, partitioning and index construction; an asynchronous main control chain mechanism is constructed, high-optimal data is dispatched for rapid anomaly judgment, and other data is processed in parallel; performing desensitization mapping on the high-sensitivity data to generate a short-time mapping bill and performing desensitization analysis; issuing a local task for the low-confidence exception, collecting backflow data, and verifying and determining a high-risk event; restoring the sensitive data in the authorization window, and destroying the bill and the secret key after abnormity analysis is completed; and triggering network regulation based on an analysis result, and recording the whole process to an audit log. By introducing an asynchronous scheduling and reversible desensitization mechanism, high-efficiency anomaly analysis and whole-process traceability of the electric power communication big data on the premise of ensuring safety and compliance are realized.
Owner:GUANGAN POWER SUPPLY COMPANY STATE GRID SICHUANELECTRIC POWER

Information security management method and system based on digital medical treatment

PendingCN121366684ASemantic analysisDigital data protectionCiphertextInformation security management
The invention relates to the technical field of information security management, and discloses an information security management method and system based on digital medical treatment. The method comprises the following steps: verifying doctor professional qualification, patient authorization range, data sensitivity level and time permission validity in a multi-institution medical data access request, and generating a permission verification result; analyzing ontology semantic attributes and sensitivity characteristics of medical search keywords input by a user, and determining a corresponding hierarchical encryption strategy based on the permission verification result; performing homomorphic encryption transformation on the medical term synonym set according to the hierarchical encryption strategy, and constructing a medical ciphertext database; and receiving a medical query request, executing symptom disease association matching and ciphertext state logical reasoning operation in the medical ciphertext database, and outputting an encrypted state search result. According to the method, the privacy leakage risk caused by search behavior trajectory analysis is effectively prevented, and the security and availability of medical data are improved.
Owner:SHENZHEN HEALTH DEV RES & DATA MANAGEMENT CENT

Multi-tenant-based centralized authentication and authorization system, method, equipment and medium

The invention provides a multi-tenant-based centralized authentication and authorization method, system, device and medium, and belongs to the technical field of security and identity management, and the system comprises a unified portal layer, an authentication layer, an authorization layer, a strategy center and an audit monitoring layer. The unified portal layer receives a user request, identifies and injects a tenant identifier, and executes WAF rule verification, JWT signature verification and Token blacklist check; the authentication layer performs user or client credential verification on different accessed identity sources, generates and issues a JWT, and monitors the life cycle of a token; the authorization layer extracts an authority statement in the JWT and a locally cached strategy snapshot; the strategy center provides centralized storage, version management and visual editing of multi-tenant strategies; through cooperative work of each layer, accurate identification, unified authentication, centralized strategy management and comprehensive audit monitoring of tenants are realized. And the security, the expandability and the management efficiency of the system are effectively improved.
Owner:QINGDAO PORT INT CO LTD +1

Permission verification method and system applied to OA examination and approval

The invention discloses a permission verification method and system applied to OA examination and approval, and relates to the technical field of permission verification, and the method comprises the steps: receiving an examination and approval request triggered by an OA system, carrying out the extraction according to the examination and approval request, and obtaining user identity information and an examination and approval content label set; triggering a multi-level permission verification mechanism based on the user identity information, and generating a dynamic verification rule set; performing permission verification on the approval content label according to the dynamic verification rule set, and formulating a target verification rule; and executing the target verification rule to perform multi-level cross verification on the user permission, generating a permission verification report according to a verification result, and feeding back the permission verification report to the OA system to trigger a subsequent approval process. The technical problems of low approval process efficiency and inaccurate authority control caused by fixed static rule configuration in the authority verification process in the prior art are solved, and the technical effects of improving the authority verification flexibility and accuracy and enhancing the approval process safety and intelligent level are achieved.
Owner:SHENZHEN ZHONGKE SHUJIAN TECH CO LTD

Method and system for constructing trusted data space based on data sharing

The invention provides a credible data space construction method and system based on data sharing, and relates to the technical field of data processing.The method comprises the steps that S1, in response to a request of a user for sharing target data, credible preprocessing is conducted on the target data to obtain credible data; s2, establishing a decision-making capability model for a user to autonomously perform credible authorization on the credible data; s3, analyzing a multi-dimensional sharing risk of the trusted data; s4, planning an optimal authorization auxiliary unit sequence based on the multi-dimensional sharing risk and the decision ability model; s5, in the process that the user autonomously performs credible authorization on the credible data, sequentially executing the authorization auxiliary units in the optimal authorization auxiliary unit sequence; and S6, aggregating the credible data subjected to credible authorization to construct a credible data space. According to the method, the credibility and the security in the data sharing process are remarkably improved, and the quality of the shared data and the protection of user privacy are ensured.
Owner:EASY CREDIT (XIAMEN) CREDIT SERVICE TECH CO LTD +2

Multi-agent collaborative decision-making system and method based on knowledge Token

The invention discloses a multi-agent collaborative decision-making system and method based on knowledge Token, and the method comprises the following steps: S1, constructing a knowledge base architecture, executing the content Hash calculation, and generating an original fingerprint in an original fidelity layer; s2, extracting content, packaging the content into knowledge Token, and writing identification, semantics, source, authority, value, contract, association, traceability and health information; s3, activating a knowledge layer, constructing a vector index and mapping knowledge graph nodes; s4, unifying an index layer, matching task requirements, and screening and verifying candidate Tokens to obtain an authorization set; s5, the multiple agents generate local decisions and fuse values and semantics to form a collaborative result; and S6, binding a Token identifier after consistency verification, generating a collaborative decision and recording data consanguinity information. According to the method, multi-agent collaborative decision-making is realized through the knowledge Token and the knowledge graph, and the decision-making accuracy and traceability are improved.
Owner:COLORFUL PRISM (HANGZHOU) INFORMATION TECHNOLOGY SERVICES CO LTD

Large model dynamic protection method and system based on zero-trust architecture

The invention provides a large model dynamic protection method and system based on a zero-trust architecture. The method comprises the steps that a security proxy gateway receives an access request; authenticating an initiating main body of the access request, collecting context information and transmitting the context information to a strategy decision point; the strategy decision point calculates a trust score in real time based on a dynamic trust evaluation model and performs real-time evaluation in combination with an access control strategy to generate a dynamic authorization judgment result; if the access is allowed, forwarding the access request to a large language model server, and performing input security filtering; the large language model server generates response content and performs output security filtering; and returning the final response subjected to the output security filtering to the initiating main body through the security proxy gateway. According to the method, a multi-layer protection framework is constructed, a dynamic trust evaluation model is introduced, and a content filtering layer is deployed, so that continuous permission verification, risk adaptive control and full-link content security protection are realized, and the service security of a large model is effectively guaranteed.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

Dynamic verification method for informatization system based on zero-trust architecture

The invention discloses an informatization system dynamic verification method based on a zero-trust architecture, and the method comprises the steps: collecting and standardizing user operation requests of all business systems, and achieving unified resource and organization identification; a distributed encryption operation log link is constructed through an end-to-end encryption protocol, and safe synchronization and tampering prevention of an operation behavior abstract are guaranteed; extracting a multi-dimensional right decision variable, inputting the multi-dimensional right decision variable into an adaptive artificial intelligence decision model, dynamically generating a reversible permission factor set, and supporting fine-grained and rollback permission authorization and real-time automatic revocation; the log chain is encrypted and recorded in the whole process, intelligent abnormity monitoring and end-to-end traceability are combined, the consistency and compliance auditing of the global permission state are supported, and the security, traceability and intelligent self-adaptive treatment capacity of sensitive operation in the multi-organization cooperation environment are effectively improved.
Owner:GUANGDONG YUEMI TECH SERVICE CO LTD

Subscription-based techniques for communicating third-party information

Methods, systems, and devices for wireless communications are described. A first network entity of a first service provider may obtain, from a first user equipment (UE), an invite message for initiating a call between with a second UE that includes an identity associated with the first UE and an authorization server. Based on whether the first UE is subscribed to a third-party information service, the first network entity may obtain third-party information from the authorization server. The first network entity may output the invite message to a second network entity of a second service provider, where the invite message output by the first network entity includes the third-party information in accordance with whether the third-party information is obtained. Based on whether the second UE is subscribed to a third-party information verification service, the second network entity may verify the third-party information and output the invite message to the second UE.
Owner:QUALCOMM INC

Creating access control policies from access request event logs

Disclosed are systems and methods that automatically generate access control policies based on access request log entries generated for an existing endpoint. For example, existing systems that utilize authorization control logic (or no authorization control logic) can continue processing access requests as normal and produce access request log entries for each access request. The disclosed implementations process those access request log entries, for example, using a large language model, and generate an access control policy set for the endpoint that includes one or more access control policies determined from the access request log entries.
Owner:AMAZON TECH INC

Dynamic function menu generation method and device, equipment and medium

The invention relates to the technical field of data security, can be applied to business scenes of financial science and technology, medical health and the like, and discloses a dynamic function menu generation method, device, equipment and medium, which comprises the following steps: acquiring an access request containing equipment type information sent by a user terminal, analyzing an authentication state of a user account and an associated license state, and sending the access request to the user terminal; and generating a dynamic session context defining function access qualification and an interface rendering strategy, loading a function menu strategy model containing function item set and permission mapping, determining a target permission level, matching a target function item subset with a rendering strategy, and generating and sending a function menu instance to the user terminal. The dynamic session context is generated in real time in combination with the user authentication state and the license state, linkage of permission judgment and interface rendering is driven, the function menu has the capacity of dynamic switching according to the session state, menu generation and accurate issuing based on actual authorization and the equipment environment are achieved, and unauthorized access is effectively avoided.
Owner:PING AN TECH (SHENZHEN) CO LTD

Methods and apparatuses for data integrity in retrieval-augmented generation (RAG) chatbots using original data sources for validation, segmentation, authorization, and monetization

A retrieval-augmented generation method for a large language model receives a user query and generates a vector embedding of the user query. The vector embedding of the user query is stored in an embedding vectors space. Also stored in the embedding vectors space are embeddings of documents retrieved from a corpus of information / A retrieval-based artificial intelligence (Al) model identifies which documents are relevant to the user query according to a similarity measure applied to the vector embedding of the user query and the vector embeddings of the documents. The generative Al model receives the user query and the documents identified as relevant to the user query and generates new content, based on the user query and the documents identified as relevant to the user query.
Owner:TECTONIQ INC

Multi-modal data desensitization method, system, equipment and medium

The invention provides a multi-modal data desensitization method, system and device and a medium, and belongs to the technical field of information security. The method comprises the following steps: firstly, acquiring multi-modal original data based on preset access information and acquisition frequency, and after standardized preprocessing, positioning sensitive information by using a classification recognition algorithm and generating an analysis report. Then, according to a report, matching a strategy from a desensitization strategy library bound with the sensitivity level, adjusting a dynamic confusion algorithm parameter to desensitize, integrating and generating desensitized multi-modal data, and recording and storing a mapping relationship between the original data and the desensitized data; and if a restoration request is received, after authorization verification is passed, reverse desensitization restoration data is carried out by using the mapping relation. Besides, full-process feedback information is collected, the desensitization effect is quantitatively evaluated according to a preset index, the desensitization strategy and algorithm are iteratively optimized accordingly, and effective desensitization and safety management of multi-modal data are achieved.
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

Server-enforced activation of conditional digital entitlements via freshness-bounded verification and audit-coupled commit paths

A computer-security architecture removes activation authority from client-facing purchase flows. A server records a digital entitlement in an INACTIVE state and issues a presentation artifact. A verification service accepts messages only from trusted origins carrying freshness-bounded evidence and validates using (i) stateless keyed recomputation over a time-windowed payload, (ii) confirmation that token-rail authorization data maps to a registered association within a policy freshness bound, or (iii) a server-maintained session. Activation occurs only on an authoritative commit path that enforces no activation without a durable audit record and effective-once behavior: either a single ACID transaction that conditionally updates state and writes an insert-only audit in the same commit, or an append-only activation ledger with idempotent materialization. Access controls deny issuance-facing code permission to set ACTIVE. Expiration is timer-free via batch or TTL evaluation.
Owner:LUNDQUIST JOSEPH PATRICK

Terminal security access control method and device, computer equipment and storage medium

The invention belongs to the technical field of network security, and relates to a terminal security access control method and device, computer equipment and a storage medium, the method comprises the following steps: deploying an infrastructure for terminal security access, the infrastructure comprising a client, a security system and a server component; the method comprises the following steps: performing initial registration on terminal equipment, and realizing unique binding of a terminal identity and loading of a basic security policy by acquiring an equipment fingerprint, issuing a certificate and configuring a policy; the user identity and the equipment credibility are verified in real time through a multi-factor dynamic authentication mechanism; through signature verification and encrypted transmission, application and network communication authentication is carried out, and application legality, communication channel security and operation environment credibility are ensured; and after the authentication is passed, trusted connection is established, fine-grained authorization is implemented, and security isolation of a service layer is realized through dynamic token and API management and control. The problems that in existing terminal access control, the authentication dimension is single, the authorization granularity is rough, and dynamic management and control are lacked are effectively solved.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Methods and apparatus for detecting asset misuse, loss, or piracy in a supply chain using neural networks

A system and method are disclosed for tracking and verifying authenticity, loss, fraud, or unauthorized use of assets within a supply chain. The method includes scanning a multimodal tag (e.g., QR code and NFC tag) associated with an asset to generate scan data comprising a hash code, asset identifier, and verification URL. The scan data is transmitted to an application server of a parent organization, where a controller retrieves associated location and organization identifiers. The controller determines authorization status, compares the hash code with reference values in a verification database, and performs authenticity checks to classify the asset as genuine, lost, duplicated, or pirated. The system integrates with a CRM platform to register new child organizations using data synchronization objects comprising payloads, callout instructions, and error handling. AI-based analysis may detect route deviations, fraudulent insertions, or asset misuse patterns based on route history and scanning behavior.
Owner:LOCATORX INC