Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

41 results about "Cloud computing security" patented technology

Cloud computing security or, more simply, cloud security refers to a broad set of policies, technologies, applications, and controls utilized to protect virtualized IP, data, applications, services, and the associated infrastructure of cloud computing. It is a sub-domain of computer security, network security, and, more broadly, information security.

Trusted cloud security confidential privacy level product service system and method

The invention discloses a trusted cloud security confidential privacy level product service method, and relates to the technical field of design of cloud computing security. The method comprises the following steps: acquiring a trusted cloud privacy security level and a hierarchical core security mechanism, establishing a binding relationship with a product, extracting technical features and performing quantitative scoring, and constructing a three-dimensional security matrix; obtaining a privacy grading service demand of the user, and establishing a demand matching model to screen a security preference grade product; obtaining different-dimension technical grade improvement times of the user security preference grade product, and carrying out synergistic effect analysis; if significant positive correlation exists, correlation analysis is carried out to obtain a dynamic correlation coefficient, a product optimization strategy is made, a three-dimensional security matrix is dynamically updated, and the trusted cloud security confidential privacy level product service system comprises a feature classification module, a product optimization module, a collaborative analysis module and an optimization updating module. According to the method, more accurate security product recommendation can be provided for the user, and the trusted cloud security service level is improved.
Owner:WUHAN TRUSTED CLOUD TECH CO LTD

Cloud environment intelligent identity authentication cross-domain docking method and system

The invention relates to the technical field of cloud computing and identity authentication security, and discloses a cloud environment intelligent identity authentication cross-domain docking method and system.The cloud environment intelligent identity authentication cross-domain docking method comprises the steps that heterogeneous identity data of multiple cloud platforms is collected and preprocessed, and a standardized identity data set is obtained; constructing a unified identity semantic model based on the standardized identity data set and generating a feature embedding vector; performing identity mapping conversion on the feature embedding vector by using a deep neural network to obtain a mapped identity feature vector; performing multi-factor adaptive trust evaluation in combination with the mapped identity feature vector and the real-time behavior data to obtain a dynamic trust evaluation result; generating an adaptive security token based on the dynamic credibility evaluation result; according to the method, the problems of cross-domain isomerism and dynamic trust evaluation of identity authentication in a cloud environment can be solved, and an effective solution is provided for cloud computing security.
Owner:ZHEJIANG HULUWA NETWORK GRP CO LTD

AI-based multi-cloud security management center system and method

The invention belongs to the technical field of cloud computing security, and discloses a multi-cloud security management center system and method based on AI. Aiming at the problems of difficulty in asset management, low safety operation efficiency, high labor cost and the like in a multi-cloud environment, the system lightens AI Agent through a data acquisition layer, acquires core resource data in real time by a differentiation strategy, and constructs a three-dimensional dynamic knowledge graph after standardization of a cross-cloud data conversion engine; the intelligent analysis layer integrates five-dimensional data such as logs and traffic by using a multi-modal fusion engine, and realizes attack link dynamic deduction (the accuracy rate reaches 98%) and intelligent alarm noise reduction (the false alarm rate is reduced to below 10%) based on a graph neural network; the strategy management layer generates a cross-cloud unified strategy in combination with domestic and overseas large-scale boards and a natural language processing technology; and the automatic execution layer realizes automatic vulnerability repair (the success rate is not lower than 90%) and AKSK authority dynamic management. The method comprises the whole process of data acquisition, knowledge graph construction, risk analysis, strategy generation and automatic disposal. According to the method, the asset management time can be shortened to 1 minute, the vulnerability repair period is shortened to 30 minutes from 48 hours, the safety operation labor cost is reduced by 70%, and an efficient, intelligent and low-cost safety management scheme is provided for the enterprise multi-cloud environment.
Owner:MITA BLUEPRINT TECHNOLOGY (SHENZHEN) CO LTD

Cloud computing security management system based on artificial intelligence

The invention provides a cloud computing security management system based on artificial intelligence, and relates to the technical field of computers, a data acquisition module of the system acquires network behavior information, system operation information, threat intelligence information, data outward transmission amount and authority change monitoring information of a cloud computing platform; the model calculation module processes the network behavior information, the system operation information and the threat intelligence information by using an anomaly detection model to obtain an anomaly detection result; the anomaly detection result represents the risk probability that the cloud computing platform suffers from different types of attacks; inputting the anomaly detection result, the data outward transmission amount and the authority change monitoring information into a context sensing evaluator to obtain a comprehensive risk score and an attack type classification result of the cloud computing platform; and the management execution module executes security control operation according to the comprehensive risk score and the attack type classification result. By applying the method provided by the invention, the attack risk detection precision in a complex attack scene can be improved.
Owner:HAINAN VOCATIONAL TECHN COLLEGE

Multi-tenant cloud policy conflict adaptive adjustment method and system

The invention discloses a multi-tenant cloud policy conflict adaptive adjustment method and system, and relates to the technical field of cloud computing security. The method comprises the following steps: converting access control policies of different levels in a multi-tenant cloud computing environment into a standardized policy description model; based on the standardized strategy description model, constructing an incremental strategy graph with a dependency relationship and a condition overlapping relationship; performing real-time analysis on the incremental policy graph based on a policy change event obtained by an event monitoring mechanism, identifying a potential conflict relationship between access control policies, and generating an access conflict event record; performing quantitative analysis and grading evaluation based on the access conflict event record, and generating a conflict risk evaluation record; based on the conflict risk assessment record and a predefined access conflict processing rule, adaptively generating an access conflict adjustment strategy and automatically executing the access conflict adjustment strategy; according to the method, the real-time detection and the self-adaptive correction of the access conflict strategy in the multi-tenant cloud environment are realized, and the consistency and the security of access permission authorization are ensured.
Owner:HANGZHOU JINYUAN BIAOJU TECH CO LTD

A method and system for verifying the trusted state of a virtual machine based on TIPU

PendingCN122365514AMemory addressTerm memory
This invention relates to the intersection of cloud computing security, trusted computing, and hardware acceleration technologies, and discloses a virtual machine trusted state verification method and system based on TIPU. The method includes: configuring a measurement task on the host side of the TIPU, the measurement task containing the memory address information of the target virtual machine and its corresponding expected hash value; the TIPU directly reading the memory data of the target virtual machine via DMA based on the memory address information to generate an actual hash value; the TIPU comparing the actual hash value with the expected hash value to determine whether the target virtual machine is in a trusted state; when the virtual machine is determined to be in an untrusted state, the TIPU calls a built-in root of trust to sign the verification result and generate a remote proof report. This invention obtains the mapping table from the client's physical address to the host's physical address through the virtualization platform interface via a host agent and pre-configures it to the TIPU. The TIPU only accesses the target virtual machine's memory, achieving virtual machine context awareness and effectively avoiding cross-virtual machine information leakage.
Owner:TIANFU JIANGXI LAB

Cloud host security reinforcement method and device, storage medium and electronic equipment

The present disclosure provides a cloud host security reinforcement method and device, a storage medium and an electronic device; and relates to the technical field of cloud computing security. The method comprises the following steps: obtaining application information of a cloud host resource, and publishing a to-be-reinforced cloud host according to the application information; scanning the to-be-reinforced cloud host to obtain a security scanning report of the to-be-reinforced cloud host; reinforcing the to-be-reinforced cloud host according to the application information and the security scanning report to obtain a security reinforcement result; verifying the security reinforcement result and outputting corresponding reinforced cloud host resources. In the process of starting the cloud host, the cloud host is scanned, reinforced, verified and delivered, so that the allocation and security reinforcement of the cloud host are integrated, the security of the cloud host is improved, and the security reinforcement efficiency of the cloud host is improved.
Owner:CHINA TELECOM CORP LTD

Cloud environment intelligent identity authentication cross-domain interfacing method and system

This invention relates to the fields of cloud computing and identity authentication security technology, and discloses a method and system for cross-domain intelligent identity authentication in a cloud environment. The method includes: collecting and preprocessing heterogeneous identity data from multiple cloud platforms to obtain a standardized identity dataset; constructing a unified identity semantic model based on the standardized identity dataset and generating feature embedding vectors; performing identity mapping transformation on the feature embedding vectors using a deep neural network to obtain mapped identity feature vectors; performing multi-factor adaptive trust assessment by combining the mapped identity feature vectors with real-time behavioral data to obtain dynamic trust assessment results; generating an adaptive security token based on the dynamic trust assessment results; and converting the adaptive security token into the protocol format required by the target system. This invention can solve the problems of heterogeneity and dynamic trust assessment in cross-domain identity authentication in a cloud environment, providing an effective solution for cloud computing security.
Owner:ZHEJIANG HULUWA NETWORK GRP CO LTD

Container data safe use method and system based on decentralized identity

The invention discloses a container data safe use method and system based on a decentralized identity, and relates to the technical field of cloud computing security, and the method comprises the steps: generating a decentralized identity bound with a container life cycle; initiating a data use request based on the decentralized identity; identity verification is executed, and data resources are distributed based on dynamic authorization and encryption of a runtime context; and decrypting and using the data resources in the protected memory of the container. According to the method, the decentralized identity is generated on the basis of the identifier during dynamic operation of the container, and an access control mechanism in the memory is combined, so that the technical defects that the identity is unhooked from the life cycle and the plaintext is exposed in the memory during operation of the data in an existing container data security scheme are overcome.
Owner:PANOVASIC TECHNOLOGY CO LTD

Device and method for realizing bare metal console with endogenous safety capability

The invention relates to the technical field of cloud computing security, in particular to a bare metal console implementation device and method with endogenous security capability, and the device comprises a user side agent module which is used for receiving a bare metal VNC console access request initiated by a user and distributing the request to three heterogeneous service agent nodes; operating systems and CPU (Central Processing Unit) frameworks of the three service agent nodes are different from one another, and service agent components corresponding to different bare metal VNC console access modes are respectively deployed on the nodes; the feedback control module is used for collecting running state data of the service agent node, generating judgment parameters and sending the judgment parameters to the strategy judgment module, and is used for executing release or link reset operation according to a judgment result of the strategy judgment module; and the strategy judgment module is used for carrying out consistency judgment on output results of the three service agent nodes based on the judgment parameters and feeding back a judgment result to the feedback control module. According to the invention, high security and high availability of bare metal VNC console access are realized.
Owner:SONGSHAN LAB

Multi-tenant cloud policy conflict adaptive adjustment method and system

The application discloses a multi-tenant cloud policy conflict adaptive adjustment method and system, and relates to the technical field of cloud computing security; the method comprises the following steps: converting access control policies of different levels in a multi-tenant cloud computing environment into a standardized policy description model; based on the standardized policy description model, an incremental policy graph with dependency relationships and conditional overlapping relationships is constructed; based on a policy change event obtained by an event listening mechanism, the incremental policy graph is analyzed in real time, potential conflict relationships between access control policies are identified, and an access conflict event record is generated; based on the access conflict event record, quantitative analysis and hierarchical evaluation are carried out, and a conflict risk evaluation record is generated; based on the conflict risk evaluation record and a pre-defined access conflict processing rule, an access conflict adjustment policy is adaptively generated and automatically executed; the application realizes real-time detection and adaptive correction of access conflict policies in a multi-tenant cloud environment, and guarantees the consistency and security of access permission authorization.
Owner:HANGZHOU JINYUAN BIAOJU TECH CO LTD

An outsourcing decryption method for protecting revocable user attributes based on cloud environment data

The application discloses an outsourcing decryption method for revoking user attributes based on cloud environment data protection and belongs to the technical field of cloud computing security. The application comprises an initialization algorithm, an encryption algorithm, a key generation algorithm, an outsourcing decryption algorithm and an attribute revocation algorithm. The method of the application is based on a cloud environment, public parameters are composed of a fixed number of group elements, there is no limitation on an attribute set used for encryption, user revocation can be performed at each attribute level instead of at a system level, and more fine-grained user access control is realized. Moreover, user information is not leaked in judgment of whether a user is revoked and outsourcing decryption. The scheme is proved to be safe under the complexity assumption of a composite order group. Through comparative analysis on the performance of similar schemes, the result shows that the scheme is more efficient and more flexible in the scene of user management in a cloud environment.
Owner:GANNAN NORMAL UNIV

Host and guest message tunnel communication method and system based on virtualized black box escape

The invention discloses a host and guest message tunnel communication method and system based on virtualized black box escape. The method comprises the following steps: firstly, detecting a key function address or symbol information of a host machine by using a QEMU vulnerability; secondly, capturing a command input by a user, and monitoring command execution result data returned by the host machine at the same time; and according to vulnerability detection and monitoring results, dynamically analyzing and generating a shellcode character string capable of triggering command execution of a host machine, and outputting the shellcode character string to a terminal. And finally, covering and writing the shellcode into a corresponding file reserved area, compiling, and when the virtual machine end runs, triggering host machine command execution through a QEMU vulnerability attack surface, and returning an execution result to the virtual machine end in real time by utilizing a message tunnel constructed by the vulnerability. The method is suitable for a typical cloud computing security scene in which a host machine is strictly isolated from a network and a user cannot directly interact with the host machine, and the visibility and troubleshooting efficiency of security problems in a virtual environment are improved.
Owner:HANGZHOU DIANZI UNIV

A trajectory data-based outsourcing cloud environment privacy protection infection mode mining method

The application belongs to the field of cloud computing security, and discloses a trajectory data-based outsourcing cloud environment privacy protection infection mode mining method, which is divided into two stages: the first stage: trajectory data preprocessing, encryption and outsourcing, first, the data owner pre-processes the trajectory data set to be uploaded, generates a corresponding encoding matrix for the trajectory data of each object, then generates a secure index matrix for the encoding matrix through a strong anti-collision one-way hash function, and finally uploads the encrypted trajectory data and the generated secure index matrix to a cloud server, and shares the key with authorized users; the second stage: a privacy protection infection mode mining method, first, the authorized user sends the infected object number to the cloud server, the cloud server performs infection mode mining after receiving the infected object number, and returns the mining result to the authorized user. The application can ensure high accuracy of the mining result, improve the mining efficiency, and is easy to implement.
Owner:NANJING UNIV OF POSTS & TELECOMM

A communication data leakage protection method in cloud computing environment

The present invention discloses a method for preventing communication data leakage in a cloud computing environment, which relates to the field of cloud computing security technology. The method comprises: obtaining a communication instruction containing a communication task to be executed and a corresponding communication link from a cloud computing platform, performing a data leakage risk test according to the task, collecting real-time protection parameters of the link to establish a protection mechanism if the test passes, introducing a risk prediction channel and combining the mechanism to predict the communication data leakage risk coefficient of the task to be executed, then optimizing and adjusting the protection mechanism based on the risk coefficient, threshold value and different constraint step sizes to construct an optimization mechanism, finally optimizing the communication link protection to obtain an optimized link, and executing the task in combination with the cloud computing platform. The method solves the technical problem in the prior art that the communication link in a cloud computing environment is poorly protected, resulting in communication data being vulnerable to leakage threats, and achieves the technical effect of improving the protection performance of the communication link in a cloud computing environment and reducing the risk of data leakage.
Owner:WUXI HUAFAN INFORMATION TECHNOLOGY CO LTD

Software security detection method, system and electronic device

The present application relates to the field of machine learning technology and cloud computing security. Disclosed are a software security detection method, a system and an electronic device. The method comprises: monitoring an access operation executed on a storage device by software to be subjected to detection, and acquiring behavioral data generated during the process of said software executing the access operation; inputting the behavioral data into a security detection model for detection, so as to obtain a detection result, the security detection model being obtained by means of training at least using an abnormal behavior sample, and the abnormal behavior sample being data generated by a software sample under an abnormal access operation; in response to the detection result being that the behavioral data is identified as abnormal behavioral data, determining that said software is in an abnormal access state; and, in response to the detection result being that the behavioral data is identified as normal behavioral data, determining that said software is in a normal access state. The present application solves the technical problem of low accuracy of software security detection.
Owner:CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD

AI based Cloud Computer security Detection device

ActiveGB6525662SAlgorithmCloud computing security
Owner:DEVA RAJU GANTAKORA

IaC safety real-time detection and self-repairing method and system based on large language model

The invention relates to the technical field of cloud computing security, and relates to an IaC security real-time detection and self-repairing method and system based on a large language model. The method comprises the following steps: monitoring a change event of an IaC file through an agent or a plug-in deployed in a version control system, an integrated development environment or a CI / CD assembly line, capturing a change code snippet and a context thereof, and carrying out security analysis; the change code is input into a large language model analysis engine subjected to security training, code analysis and security knowledge association query are carried out, and a structured diagnosis and repair report containing a repair code is generated; and according to an execution strategy defined by a user, executing a repair operation, and recording an operation result for model feedback learning. By integrating the intelligent analysis capability of the large language model, the real-time security detection, accurate vulnerability positioning, detailed risk interpretation and automatic repair of the IaC code are realized, so that the security baseline of the cloud native environment is remarkably improved.
Owner:SHANDONG INSPUR SCI RES INST CO LTD

Network security service function chain arrangement method and device of data processing unit, computer equipment, storage medium and program product

The invention relates to the technical field of cloud computing security services, and provides a network security service function chain arrangement method and device of a data processing unit, computer equipment, a storage medium and a program product. The method comprises the steps of obtaining a security service request of a to-be-deployed network security service function chain of a target service flow according to a network security demand of a type to which the target service flow belongs and a security service function of a data processing unit; obtaining a function chain deployment optimization objective function according to the multi-class resource load degree for arranging a to-be-deployed network security service function chain in the security service request at the deployment completion moment and the average utilization rate of acceleration subunits in the data processing unit at the deployment completion moment; and under the constraint of the multi-constraint condition, according to the to-be-deployed network security service function chain, obtaining a network security service function chain target arrangement scheme which enables the function chain deployment optimization target function to reach a preset optimization condition. By adopting the method, waste of resources and power consumption can be reduced.
Owner:SOUTHERN POWER GRID DIGITAL GRID RESEARCH INSTITUTE CO LTD

A Reinforcement Learning-Based Adaptive Policy Generation Method and System for Heterogeneous Resource Scheduling

This invention relates to a method and system for generating adaptive strategies for heterogeneous resource scheduling based on reinforcement learning, belonging to the field of cloud computing security. The system comprises a container module, a CVSS database exploitation module, a state mapping module, and a defense environment. The method includes: acquiring all container instances in the current cloud environment and storing them in a container pool; recording the heterogeneous attributes and replica count of each type of container instance; calculating the vulnerability exploitation difficulty and multi-dimensional heterogeneity indicators of the current container pool; and using a reinforcement learning model to determine the defense strategy, inputting the current container pool state into the model, deciding on the defense strategy, and calculating the reward value by weighted summation of the vulnerability exploitation difficulty and heterogeneity indicators of the container pool. This invention comprehensively considers the multi-dimensional heterogeneous attributes and real-time state information of containers, adaptively selecting the optimal defense strategy to reduce defense costs and improve the system's real-time response capability and defense effectiveness.
Owner:韩道岐

A data query method, apparatus, device, system, and storage medium

This invention discloses a data query method, apparatus, device, and storage medium. The invention relates to the field of cloud computing security service technology. The method includes: responding to a received data query request by obtaining definition information of a preset lightweight data storage format; parsing the definition information, and when model-introduced attribute information is parsed, obtaining model definition information of the data model specified by the model-introduced attribute information; performing a query operation on the data table specified by the obtained model definition information; and obtaining query result data in the lightweight data storage format based on the query results. In the method of this invention, by defining a lightweight data storage format, data can be assembled autonomously by accessing the database according to the definition information. Furthermore, when the data table structure or lightweight data storage format changes, there is no need to adjust the data access and assembly code, providing high flexibility.
Owner:CHINA CONSTRUCTION BANK

Cloud management platform authentication encryption method based on national secret

The invention discloses a cloud management platform authentication and encryption method based on national secret, particularly relates to the field of cloud computing security authentication, and is used for solving the problems of service interruption and compliance auditing caused by midway drift of authentication and encryption attributes in a link in a multi-cloud multi-tenant environment. Generating a negotiation fingerprint signature and a session policy identifier through the portal agent, and binding a session; the gateway writes a metadata head and sets read-only attribute transfer elements; performing signature verification matching by the micro-service entrance to generate session verification token cache verification; the strategy engine calculates a stability coefficient according to the session strategy identifier to execute a release rerouting or rejection decision; the platform summarizes verification results to update compatibility capability and synchronize with routing strategy issuing; the security semantic consistency of the whole link is ensured, the platform compatibility and the emergency response efficiency are improved, and the method is suitable for a state-password compatible cloud management scene.
Owner:BEIJING BOANTE INFORMATION TECH DEV CO

OpenStack network tunnel encryption method based on commercial cipher SM4

The invention discloses an OpenStack network tunnel encryption method based on commercial cipher SM4, and belongs to the technical field of cloud computing security, and the method comprises the steps: deploying encryption modules: deploying the encryption modules on network nodes and computing nodes of an OpenStack cluster, and the modules are integrated with an SM4 encryption algorithm and are used for constructing an encryption tunnel between virtual machines; establishing a key management system for generating, distributing and managing keys, and distributing a unique key pair for the virtual machine and a corresponding communication link to ensure the independence and security of communication; through three steps of data packaging, data transmission and data decryption, secure transmission and restoration of data communication between virtual machines are realized.
Owner:BEIJING ZHONGAN NEBULA SOFTWARE TECH CO LTD

A trusted cloud security confidentiality privacy level product service system and method

The present invention discloses a trusted cloud security confidentiality privacy grade product service method, which designs a cloud computing security technology field, including: obtaining a trusted cloud privacy security grade and a graded core security mechanism, establishing a binding relationship with the product, extracting technical features and quantifying the score, and constructing a three-dimensional security matrix; obtaining user privacy graded service requirements, establishing a demand matching model to screen security preferred grade products; obtaining the number of times the technical grade of different dimensions of the user's security preferred grade products has been upgraded, and performing a synergistic effect analysis; if there is a significant positive correlation, performing a correlation analysis to obtain a dynamic correlation coefficient, formulating a product optimization strategy, and dynamically updating the three-dimensional security matrix. A trusted cloud security confidentiality privacy grade product service system includes a feature classification module, a product optimization module, a collaborative analysis module, and an optimization and update module. The present invention can provide users with more accurate security product recommendations and improve the level of trusted cloud security services.
Owner:WUHAN TRUSTED CLOUD TECH CO LTD

A user authentication method, device, equipment, system and storage medium

The present invention discloses a user authentication method, apparatus, device, and storage medium. The present invention relates to the technical field of cloud computing security services. The method includes: being applied to a client, sending a first keyboard open notification message to a server; receiving first hash values corresponding to each key value on the keyboard returned by the server; generating a first hash key value combination based on the first hash values corresponding to each key value in the first sensitive information; and sending the first hash key value combination to the server. Being applied to the server, generating first hash values corresponding to each key value based on first initial salt values corresponding to each key value on the keyboard; sending the first hash values corresponding to each key value on the keyboard to the client; receiving the first hash key value combination sent by the client; and authenticating the user based on the first hash key value combination. The technical solution of the present invention enhances the security of the user password during transmission and further strengthens the uncrackability of the password on the basis of ensuring the original security performance.
Owner:CHINA CONSTRUCTION BANK