Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

28 results about "Cloud computing security" patented technology

Cloud computing security or, more simply, cloud security refers to a broad set of policies, technologies, applications, and controls utilized to protect virtualized IP, data, applications, services, and the associated infrastructure of cloud computing. It is a sub-domain of computer security, network security, and, more broadly, information security.

Multi-tenant cloud policy conflict adaptive adjustment method and system

The invention discloses a multi-tenant cloud policy conflict adaptive adjustment method and system, and relates to the technical field of cloud computing security. The method comprises the following steps: converting access control policies of different levels in a multi-tenant cloud computing environment into a standardized policy description model; based on the standardized strategy description model, constructing an incremental strategy graph with a dependency relationship and a condition overlapping relationship; performing real-time analysis on the incremental policy graph based on a policy change event obtained by an event monitoring mechanism, identifying a potential conflict relationship between access control policies, and generating an access conflict event record; performing quantitative analysis and grading evaluation based on the access conflict event record, and generating a conflict risk evaluation record; based on the conflict risk assessment record and a predefined access conflict processing rule, adaptively generating an access conflict adjustment strategy and automatically executing the access conflict adjustment strategy; according to the method, the real-time detection and the self-adaptive correction of the access conflict strategy in the multi-tenant cloud environment are realized, and the consistency and the security of access permission authorization are ensured.
Owner:HANGZHOU JINYUAN BIAOJU TECH CO LTD

A method and system for verifying the trusted state of a virtual machine based on TIPU

PendingCN122365514AMemory addressTerm memory
This invention relates to the intersection of cloud computing security, trusted computing, and hardware acceleration technologies, and discloses a virtual machine trusted state verification method and system based on TIPU. The method includes: configuring a measurement task on the host side of the TIPU, the measurement task containing the memory address information of the target virtual machine and its corresponding expected hash value; the TIPU directly reading the memory data of the target virtual machine via DMA based on the memory address information to generate an actual hash value; the TIPU comparing the actual hash value with the expected hash value to determine whether the target virtual machine is in a trusted state; when the virtual machine is determined to be in an untrusted state, the TIPU calls a built-in root of trust to sign the verification result and generate a remote proof report. This invention obtains the mapping table from the client's physical address to the host's physical address through the virtualization platform interface via a host agent and pre-configures it to the TIPU. The TIPU only accesses the target virtual machine's memory, achieving virtual machine context awareness and effectively avoiding cross-virtual machine information leakage.
Owner:TIANFU JIANGXI LAB

Cloud host security reinforcement method and device, storage medium and electronic equipment

The present disclosure provides a cloud host security reinforcement method and device, a storage medium and an electronic device; and relates to the technical field of cloud computing security. The method comprises the following steps: obtaining application information of a cloud host resource, and publishing a to-be-reinforced cloud host according to the application information; scanning the to-be-reinforced cloud host to obtain a security scanning report of the to-be-reinforced cloud host; reinforcing the to-be-reinforced cloud host according to the application information and the security scanning report to obtain a security reinforcement result; verifying the security reinforcement result and outputting corresponding reinforced cloud host resources. In the process of starting the cloud host, the cloud host is scanned, reinforced, verified and delivered, so that the allocation and security reinforcement of the cloud host are integrated, the security of the cloud host is improved, and the security reinforcement efficiency of the cloud host is improved.
Owner:CHINA TELECOM CORP LTD

Cloud environment intelligent identity authentication cross-domain interfacing method and system

This invention relates to the fields of cloud computing and identity authentication security technology, and discloses a method and system for cross-domain intelligent identity authentication in a cloud environment. The method includes: collecting and preprocessing heterogeneous identity data from multiple cloud platforms to obtain a standardized identity dataset; constructing a unified identity semantic model based on the standardized identity dataset and generating feature embedding vectors; performing identity mapping transformation on the feature embedding vectors using a deep neural network to obtain mapped identity feature vectors; performing multi-factor adaptive trust assessment by combining the mapped identity feature vectors with real-time behavioral data to obtain dynamic trust assessment results; generating an adaptive security token based on the dynamic trust assessment results; and converting the adaptive security token into the protocol format required by the target system. This invention can solve the problems of heterogeneity and dynamic trust assessment in cross-domain identity authentication in a cloud environment, providing an effective solution for cloud computing security.
Owner:ZHEJIANG HULUWA NETWORK GRP CO LTD

Container data safe use method and system based on decentralized identity

The invention discloses a container data safe use method and system based on a decentralized identity, and relates to the technical field of cloud computing security, and the method comprises the steps: generating a decentralized identity bound with a container life cycle; initiating a data use request based on the decentralized identity; identity verification is executed, and data resources are distributed based on dynamic authorization and encryption of a runtime context; and decrypting and using the data resources in the protected memory of the container. According to the method, the decentralized identity is generated on the basis of the identifier during dynamic operation of the container, and an access control mechanism in the memory is combined, so that the technical defects that the identity is unhooked from the life cycle and the plaintext is exposed in the memory during operation of the data in an existing container data security scheme are overcome.
Owner:PANOVASIC TECHNOLOGY CO LTD

Device and method for realizing bare metal console with endogenous safety capability

The invention relates to the technical field of cloud computing security, in particular to a bare metal console implementation device and method with endogenous security capability, and the device comprises a user side agent module which is used for receiving a bare metal VNC console access request initiated by a user and distributing the request to three heterogeneous service agent nodes; operating systems and CPU (Central Processing Unit) frameworks of the three service agent nodes are different from one another, and service agent components corresponding to different bare metal VNC console access modes are respectively deployed on the nodes; the feedback control module is used for collecting running state data of the service agent node, generating judgment parameters and sending the judgment parameters to the strategy judgment module, and is used for executing release or link reset operation according to a judgment result of the strategy judgment module; and the strategy judgment module is used for carrying out consistency judgment on output results of the three service agent nodes based on the judgment parameters and feeding back a judgment result to the feedback control module. According to the invention, high security and high availability of bare metal VNC console access are realized.
Owner:SONGSHAN LAB

Multi-tenant cloud policy conflict adaptive adjustment method and system

The application discloses a multi-tenant cloud policy conflict adaptive adjustment method and system, and relates to the technical field of cloud computing security; the method comprises the following steps: converting access control policies of different levels in a multi-tenant cloud computing environment into a standardized policy description model; based on the standardized policy description model, an incremental policy graph with dependency relationships and conditional overlapping relationships is constructed; based on a policy change event obtained by an event listening mechanism, the incremental policy graph is analyzed in real time, potential conflict relationships between access control policies are identified, and an access conflict event record is generated; based on the access conflict event record, quantitative analysis and hierarchical evaluation are carried out, and a conflict risk evaluation record is generated; based on the conflict risk evaluation record and a pre-defined access conflict processing rule, an access conflict adjustment policy is adaptively generated and automatically executed; the application realizes real-time detection and adaptive correction of access conflict policies in a multi-tenant cloud environment, and guarantees the consistency and security of access permission authorization.
Owner:HANGZHOU JINYUAN BIAOJU TECH CO LTD

An outsourcing decryption method for protecting revocable user attributes based on cloud environment data

The application discloses an outsourcing decryption method for revoking user attributes based on cloud environment data protection and belongs to the technical field of cloud computing security. The application comprises an initialization algorithm, an encryption algorithm, a key generation algorithm, an outsourcing decryption algorithm and an attribute revocation algorithm. The method of the application is based on a cloud environment, public parameters are composed of a fixed number of group elements, there is no limitation on an attribute set used for encryption, user revocation can be performed at each attribute level instead of at a system level, and more fine-grained user access control is realized. Moreover, user information is not leaked in judgment of whether a user is revoked and outsourcing decryption. The scheme is proved to be safe under the complexity assumption of a composite order group. Through comparative analysis on the performance of similar schemes, the result shows that the scheme is more efficient and more flexible in the scene of user management in a cloud environment.
Owner:GANNAN NORMAL UNIV

A trajectory data-based outsourcing cloud environment privacy protection infection mode mining method

The application belongs to the field of cloud computing security, and discloses a trajectory data-based outsourcing cloud environment privacy protection infection mode mining method, which is divided into two stages: the first stage: trajectory data preprocessing, encryption and outsourcing, first, the data owner pre-processes the trajectory data set to be uploaded, generates a corresponding encoding matrix for the trajectory data of each object, then generates a secure index matrix for the encoding matrix through a strong anti-collision one-way hash function, and finally uploads the encrypted trajectory data and the generated secure index matrix to a cloud server, and shares the key with authorized users; the second stage: a privacy protection infection mode mining method, first, the authorized user sends the infected object number to the cloud server, the cloud server performs infection mode mining after receiving the infected object number, and returns the mining result to the authorized user. The application can ensure high accuracy of the mining result, improve the mining efficiency, and is easy to implement.
Owner:NANJING UNIV OF POSTS & TELECOMM

AI based Cloud Computer security Detection device

ActiveGB6525662SAlgorithmCloud computing security
Owner:DEVA RAJU GANTAKORA

IaC safety real-time detection and self-repairing method and system based on large language model

The invention relates to the technical field of cloud computing security, and relates to an IaC security real-time detection and self-repairing method and system based on a large language model. The method comprises the following steps: monitoring a change event of an IaC file through an agent or a plug-in deployed in a version control system, an integrated development environment or a CI / CD assembly line, capturing a change code snippet and a context thereof, and carrying out security analysis; the change code is input into a large language model analysis engine subjected to security training, code analysis and security knowledge association query are carried out, and a structured diagnosis and repair report containing a repair code is generated; and according to an execution strategy defined by a user, executing a repair operation, and recording an operation result for model feedback learning. By integrating the intelligent analysis capability of the large language model, the real-time security detection, accurate vulnerability positioning, detailed risk interpretation and automatic repair of the IaC code are realized, so that the security baseline of the cloud native environment is remarkably improved.
Owner:SHANDONG INSPUR SCI RES INST CO LTD

Network security service function chain arrangement method and device of data processing unit, computer equipment, storage medium and program product

The invention relates to the technical field of cloud computing security services, and provides a network security service function chain arrangement method and device of a data processing unit, computer equipment, a storage medium and a program product. The method comprises the steps of obtaining a security service request of a to-be-deployed network security service function chain of a target service flow according to a network security demand of a type to which the target service flow belongs and a security service function of a data processing unit; obtaining a function chain deployment optimization objective function according to the multi-class resource load degree for arranging a to-be-deployed network security service function chain in the security service request at the deployment completion moment and the average utilization rate of acceleration subunits in the data processing unit at the deployment completion moment; and under the constraint of the multi-constraint condition, according to the to-be-deployed network security service function chain, obtaining a network security service function chain target arrangement scheme which enables the function chain deployment optimization target function to reach a preset optimization condition. By adopting the method, waste of resources and power consumption can be reduced.
Owner:SOUTHERN POWER GRID DIGITAL GRID RESEARCH INSTITUTE CO LTD

A Reinforcement Learning-Based Adaptive Policy Generation Method and System for Heterogeneous Resource Scheduling

This invention relates to a method and system for generating adaptive strategies for heterogeneous resource scheduling based on reinforcement learning, belonging to the field of cloud computing security. The system comprises a container module, a CVSS database exploitation module, a state mapping module, and a defense environment. The method includes: acquiring all container instances in the current cloud environment and storing them in a container pool; recording the heterogeneous attributes and replica count of each type of container instance; calculating the vulnerability exploitation difficulty and multi-dimensional heterogeneity indicators of the current container pool; and using a reinforcement learning model to determine the defense strategy, inputting the current container pool state into the model, deciding on the defense strategy, and calculating the reward value by weighted summation of the vulnerability exploitation difficulty and heterogeneity indicators of the container pool. This invention comprehensively considers the multi-dimensional heterogeneous attributes and real-time state information of containers, adaptively selecting the optimal defense strategy to reduce defense costs and improve the system's real-time response capability and defense effectiveness.
Owner:韩道岐

A data query method, apparatus, device, system, and storage medium

This invention discloses a data query method, apparatus, device, and storage medium. The invention relates to the field of cloud computing security service technology. The method includes: responding to a received data query request by obtaining definition information of a preset lightweight data storage format; parsing the definition information, and when model-introduced attribute information is parsed, obtaining model definition information of the data model specified by the model-introduced attribute information; performing a query operation on the data table specified by the obtained model definition information; and obtaining query result data in the lightweight data storage format based on the query results. In the method of this invention, by defining a lightweight data storage format, data can be assembled autonomously by accessing the database according to the definition information. Furthermore, when the data table structure or lightweight data storage format changes, there is no need to adjust the data access and assembly code, providing high flexibility.
Owner:CHINA CONSTRUCTION BANK

Cloud management platform authentication encryption method based on national secret

The invention discloses a cloud management platform authentication and encryption method based on national secret, particularly relates to the field of cloud computing security authentication, and is used for solving the problems of service interruption and compliance auditing caused by midway drift of authentication and encryption attributes in a link in a multi-cloud multi-tenant environment. Generating a negotiation fingerprint signature and a session policy identifier through the portal agent, and binding a session; the gateway writes a metadata head and sets read-only attribute transfer elements; performing signature verification matching by the micro-service entrance to generate session verification token cache verification; the strategy engine calculates a stability coefficient according to the session strategy identifier to execute a release rerouting or rejection decision; the platform summarizes verification results to update compatibility capability and synchronize with routing strategy issuing; the security semantic consistency of the whole link is ensured, the platform compatibility and the emergency response efficiency are improved, and the method is suitable for a state-password compatible cloud management scene.
Owner:BEIJING BOANTE INFORMATION TECH DEV CO

OpenStack network tunnel encryption method based on commercial cipher SM4

The invention discloses an OpenStack network tunnel encryption method based on commercial cipher SM4, and belongs to the technical field of cloud computing security, and the method comprises the steps: deploying encryption modules: deploying the encryption modules on network nodes and computing nodes of an OpenStack cluster, and the modules are integrated with an SM4 encryption algorithm and are used for constructing an encryption tunnel between virtual machines; establishing a key management system for generating, distributing and managing keys, and distributing a unique key pair for the virtual machine and a corresponding communication link to ensure the independence and security of communication; through three steps of data packaging, data transmission and data decryption, secure transmission and restoration of data communication between virtual machines are realized.
Owner:BEIJING ZHONGAN NEBULA SOFTWARE TECH CO LTD

Virtual machine vcpu isolation method, system and device and medium

The invention discloses a virtual machine vcpu isolation method, system and device and a medium, and relates to the technical field of cloud computing security virtualization, and the method comprises the steps: determining a virtual machine variable value of a CPU according to a target CPU number; determining the type of the CPU according to the virtual machine variable value of the CPU, and carrying out binding scheduling on the VCPU thread and the corresponding target CPU according to a CPU scheduling strategy; responding to the target CPU to start a virtual machine, and updating a virtual machine variable value of the target CPU according to a virtual machine-CPU number mapping table so as to isolate association between a non-VCPU thread and the target CPU; the method can be applied to a cloud computing virtual machine CPU resource isolation scene, the virtual machine operation safety and reliability are improved, the virtual machine CPU isolation and execution efficiency is improved, and the problems that in the prior art, a VCPU and a target CPU cannot be accurately matched, core binding interface monitoring is limited, and CPU isolation fails are solved.
Owner:浙江众合科技股份有限公司

Cross-architecture unified deployment method for network security drilling scene

The invention provides a cross-architecture unified deployment method for a network security drill scene, belongs to the technical field of cloud computing security, and can at least partially solve the problems of low deployment efficiency, error proneness and complex maintenance caused by manual adaptation of different architectures when a drill scene is deployed in a hybrid architecture resource pool. The method comprises the following steps: acquiring a deployment template containing a mirror image logic identifier; determining a processor architecture type of a target computing node deployed by the virtual machine; based on the mirror image logic identifier and the processor architecture type, querying a mirror image warehouse to obtain a target mirror image identifier matched with the mirror image warehouse; and using the obtained target mirror image identifier to replace the mirror image logic identifier in the deployment template to generate an executable deployment list. According to the method, the mirror image logic identifier and the dynamic mapping mechanism are introduced, so that'one-time writing and cross-framework automatic deployment 'of the drill scene is realized, the user operation is simplified, and the deployment failure risk caused by framework mismatching is eliminated.
Owner:HUANENG POWER INT INC +1

A cross-modal retrieval method supporting authorized access

The application relates to a cross-modal retrieval method supporting authorized access, and relates to the field of cloud computing security. A vector inner product encryption scheme FBIPE realizes the privacy of data and query requests, and an authorized key tree guarantees low-interactive authorized access. First, text / images in a database / query request are converted into text / image vectors by using a cross-modal hashing technology, and all the vectors are encrypted by using the FBIPE. Then, an independent key is generated for each vector in the database by using the authorized key tree, and the corresponding text / image vector ciphertext is re-encrypted by using the key. Finally, in the cross-modal retrieval process, authorized access is completed because the authorized key corresponding to unauthorized access data cannot be restored. The whole authorized cross-modal retrieval method is based on lightweight cryptography primitives, and the designed authorized key tree can realize low-interactive authorization, and the overall operation efficiency is high.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Multi-keyword query method based on vector inner product encryption

The invention provides a multi-keyword query method based on vector inner product encryption, and relates to the field of cloud computing security. The core idea of the invention is to ensure that each query user has a unique key through a re-encryption technology, and at the same time, the addition secret is shared and fused into a double-cloud framework. On the basis of the EIPE, each query user can encrypt a query keyword vector by using an independent key, meanwhile, the file keyword vector can be safely stored through secret sharing, and finally, multi-keyword query is realized through safe inner product calculation. According to the method, the privacy of the file keyword and the query keyword can be guaranteed, meanwhile, it can be guaranteed that each query user has different secret keys, and the method is more suitable for the real environment; according to the method, it is ensured that each query user has different secret keys through a re-encryption thought, and meanwhile, query keyword vector privacy is ensured based on addition secret sharing; the method is based on the lightweight encrypted primitive, and the query efficiency can be effectively improved.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

A multi-keyword query method based on vector inner product encryption

The application provides a multi-keyword query method based on vector inner product encryption, and relates to the field of cloud computing security.The core idea of the application is to ensure that each query user has a unique key through re-encryption technology, and to integrate additive secret sharing into a double cloud framework.Based on EIPE, each query user can encrypt the query keyword vector with an independent key, and the file keyword vector can be securely stored through secret sharing.Finally, multi-keyword query is realized through secure inner product calculation.This method can guarantee the privacy of file keywords and query keywords, and ensure that each query user has a different key, making it more suitable for real-world environments.The method ensures that each query user has a different key through re-encryption, and ensures the privacy of the query keyword vector based on additive secret sharing.The method is based on lightweight encryption primitives, which can effectively improve query efficiency.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Cross-modal retrieval method supporting authorized access

The invention discloses a cross-modal retrieval method supporting authorized access, and relates to the field of cloud computing security. The vector inner product encryption scheme FBIPE realizes the privacy of data and query requests, and the authorization key tree ensures low-interaction authorization access. The method comprises the following steps: firstly, converting a text / image in a database / query request into text / image vectors by utilizing a cross-modal hash technology, and encrypting all the vectors by utilizing FBIPE; then, generating an independent key for each vector in the database by using the authorization key tree, and re-encrypting the corresponding text / image vector ciphertext by using the key; finally, in the cross-modal retrieval process, due to the fact that the authorization key corresponding to the unauthorized access data cannot be recovered, authorized access is completed. The whole authorization cross-modal retrieval method is based on lightweight cryptographic primitives, and the designed authorization key tree can realize low-interaction authorization and is high in overall operation efficiency.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

A security algorithm switching method, device, apparatus and storage medium

The application discloses a kind of security algorithm switching method, device, equipment and storage medium.The present application relates to the technical field of cloud computing security service.The method comprises: obtaining the target transaction information of target transaction applied with first security algorithm in current algorithm proportion stage;Wherein, the first security algorithm includes national secret algorithm;It is judged whether target transaction information satisfies preset stage adjustment condition;If it is satisfied, then from current algorithm proportion stage to the next algorithm proportion stage of first security algorithm application proportion greater than current algorithm proportion stage is switched to.This application can automatically switch the security algorithm of transaction to national secret algorithm, reduce human intervention, reduce labor cost, improve the robustness and intelligence of the system, reduce the impact on transaction, enhance the availability and stability of transaction system.And without suspending the system for algorithm switching, reduce the impact of algorithm switching on transaction system.
Owner:CHINA CONSTRUCTION BANK +1

Heterogeneous resource scheduling adaptive strategy generation method and system based on reinforcement learning

The invention relates to a heterogeneous resource scheduling adaptive strategy generation method and system based on reinforcement learning, and belongs to the field of cloud computing security. The system comprises a container module, a CVSS database utilization module, a state mapping module and a defense environment. The method comprises the steps that all container instances in a current cloud environment are obtained and stored in a container pool, heterogeneous attributes and the number of copies of each container instance are recorded, and the heterogeneous attributes comprise an operating system, a CPU architecture, container runtime and the type of application software; calculating vulnerability utilization difficulty and multi-dimensional heterogeneous indexes of the current container pool; and utilizing a reinforcement learning model to decide a defense strategy, inputting the state of the current container pool into the model, deciding the defense strategy, and performing weighted summation on the vulnerability utilization difficulty and the isomerism index of the container pool to calculate a reward value. According to the method, the multi-dimensional heterogeneous attribute and the real-time state information of the container are comprehensively considered, and the optimal defense strategy is adaptively selected, so that the defense cost is reduced, and the real-time response capability and the defense effect of the system are improved.
Owner:韩道岐