Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

420 results about "Cloud networking" patented technology

Encrypted autonomous agent verification in multi-tiered distributed systems across global or cloud networks

Systems and methods disclosed herein perform privacy-preserving evaluations of artificial intelligence (AI) agents. A first AI agent associated with a first entity obtains a machine-readable data structure defining one or more operative boundaries for a second AI agent associated with a second entity. The system generates a unique fixed reference value representing the machine-readable data structure by applying a first transformation operation set, and transmits the unique fixed reference value to a multi-agent storage to store the value. The system receives, via the multi-agent storage, a verification artifact from the second AI agent that indicates an observed value based on internal operational data of the second AI agent corresponding to the operative boundaries. The first AI agent determines a verification status of the verification artifact by comparing the unique fixed reference value with the observed value, and autonomously generates a verification record including a representation of the verification status.
Owner:CITIBANK N A

Connectivity for virtual private label clouds

Techniques for facilitating connectivity to vPLCs created in a CSP-provided infrastructure in a region. Within the CSP-provided infrastructure in a region, when the destination of a packet is determined to be an endpoint associated with a particular vPLC, the packet is tagged with information related to the particular vPLC. The vPLC-related information for the particular vPLC can include, for example, a vPLC identifier identifying the particular vPLC, an identifier identifying a customer associated with the endpoint, a virtual cloud network identifier identifying a virtual cloud network (VCN) belonging to the particular vPLC and where the endpoint is part of the VCN, and other vPLC-related information. The packet is then routed or communicated within the CSP-provided infrastructure in a region along with the tagged vPLC-related information. The vPLC-related information is used as part of the connectivity and for routing of packets within the CSP-provided infrastructure in a region.
Owner:ORACLE INT CORP

Explicit proxy solutions for 5g security with service access service edge (SASE) with service provide network attach to prisma sase

Techniques for providing explicit proxy solutions for 5G Service Access Service Edge (SASE) with service provider network attach are disclosed. In some embodiments, a system, a process, and / or a computer program product for providing explicit proxy solutions for 5G SASE with service provider network attach includes receiving data plane traffic associated with a User Equipment (UE) from a mobile core network at a Secure Access Service Edge (SASE) cloud network via a service provider network attach using an interconnect between the mobile core network and the SASE cloud network; enforcing a security policy on data plane traffic associated with the UE based on contextual information associated with the UE to provide secured data plane traffic using the security policy configured per user group and / or per user; and forwarding the secured data plane traffic from the SASE cloud network to its original destination if allowed by the security policy, and blocking or dropping the data plane traffic from the SASE cloud network if not allowed by the security policy.
Owner:PALO ALTO NETWORKS INC

Jade defect intelligent detection method and system based on machine vision and deep learning

The invention relates to the technical field of computer vision, and discloses a jade defect intelligent detection method and system based on machine vision and deep learning, and the method comprises the following steps: S1, based on a high-resolution industrial camera and a laser three-dimensional scanner, adopting a multi-mode synchronous collection strategy, and rotating a jade sample through a precise motion control system, a jade surface high-resolution two-dimensional color image and high-precision three-dimensional point cloud data are respectively obtained, and a jade multi-mode original data set is generated. A high-resolution two-dimensional color image and high-precision three-dimensional point cloud data are integrated through a multi-modal synchronous acquisition strategy, and multi-dimensional feature expression under unified coordinates is constructed, so that the limitation of a single data source is effectively overcome; an image registration algorithm and a feature pyramid network are combined with a point cloud network to perform multi-modal feature fusion, complementarity of color texture and geometric morphology information is enhanced, and image quality is optimized based on adaptive histogram equalization and non-local mean filtering.
Owner:SHENZHEN BAIHAI DIGITAL INTELLIGENCE TECHNOLOGY CO LTD

Encrypted autonomous agent verification in multi-tiered distributed systems across global or cloud networks

Systems and methods disclosed herein perform privacy-preserving evaluations of artificial intelligence (AI) agents. A first AI agent associated with a first entity obtains a machine-readable data structure defining one or more operative boundaries for a second AI agent associated with a second entity. The system generates a unique fixed reference value representing the machine-readable data structure by applying a first transformation operation set, and transmits the unique fixed reference value to a multi-agent storage to store the value. The system receives, via the multi-agent storage, a verification artifact from the second AI agent that indicates an observed value based on internal operational data of the second AI agent corresponding to the operative boundaries. The first AI agent determines a verification status of the verification artifact by comparing the unique fixed reference value with the observed value, and autonomously generates a verification record including a representation of the verification status.
Owner:CITIBANK N A

Application acceleration on cloud networks

Techniques are described for routing traffic through an interconnect cloud gateway based on cloud traffic routing indicators. The interconnect cloud gateway can advertise the cloud traffic routing indicators, which can include cloud indicators and transport gateway indicators. The cloud indicators can include cloud tags utilized to route cloud traffic. The transport gateway indicators can include transport gateway flags utilized to identify private networks utilized to route the cloud traffic. The cloud traffic can routed during normal private network operation through private networks, which can be dynamically replaced by public networks due to occurrences of failures preventing the data traffic from being routed through the private networks and to cloud networks.
Owner:CISCO TECHNOLOGY INC

Virtual Agent For Container Orchestration System

Techniques for a container orchestration system are disclosed. A virtual agent may be executed in a first service tenancy of a cloud network manager. The virtual agent may be executed on a virtual node of a container orchestration system. A container orchestration API server may be executed in a second service tenancy of the cloud network manager. A request from the container orchestration API server to the virtual agent may be routed through a customer tenancy of a customer of the cloud network manager.
Owner:ORACLE INT CORP

Crop harvesting progress monitoring method and system based on multi-source remote sensing data fusion and depth time sequence analysis

The invention discloses a crop harvesting progress monitoring method and system based on multi-source remote sensing data fusion and depth time sequence analysis, and the method comprises the steps: obtaining multi-source remote sensing image data of a to-be-monitored region, carrying out the standardization processing of the multi-source remote sensing image data, and obtaining the processed remote sensing image data; constructing a fusion cloud removal network, and performing fusion cloud removal on the processed remote sensing image data to obtain cloudless image data; performing space-time fusion on the cloudless image data by using an enhanced space-time adaptive reflectivity fusion model to obtain a continuous cloudless optical image sequence; constructing a depth time sequence classification model based on a convolutional neural network and a long-short term memory network, and inputting the continuous cloudless optical image sequence into the depth time sequence classification model to obtain a crop harvesting monitoring result; and performing spatial superposition on the crop harvesting monitoring result and the field piece vector boundary data of the to-be-monitored area to obtain a harvesting progress diagram of the to-be-monitored area.
Owner:ANHUI YIGANG INFORMATION TECH CO LTD

Disaster recovery resource scheduling method and device based on heterogeneous cloud environment

The invention discloses a disaster recovery resource scheduling method and device based on a heterogeneous cloud environment, and the method comprises the steps: constructing a multi-dimensional resource portrait model and a cross-cloud network topological graph in the heterogeneous cloud environment, and generating a standardized resource vector set and a topological affinity scoring matrix; aggregating the local SLA default risk prediction model of each cloud node through federated learning, and performing fine tuning through transfer learning to obtain a global prediction model; calculating load fluctuation entropy based on the SLA constraint template and real-time load data, and inputting the load fluctuation entropy into a global model to predict and obtain an SLA default probability set; constructing and solving a dynamic weight multi-objective optimization function to obtain an optimal takeover cloud node list and a migration strategy identifier set; a target cloud node and a migration strategy are determined through SLA simulation verification, and an adaptive execution adapter is called to complete virtual machine incremental snapshot migration or cross-cloud arrangement deployment of containerized services. According to the invention, intelligent and automatic scheduling of disaster recovery resources is realized, and the fault takeover speed and the cross-cloud resource utilization rate are improved.
Owner:SHENZHEN SHUCUN TECH CO LTD

Next gen zero trust network access (ZTNA) and virtual private network (VPN) including cloud secure access service edge (SASE)

Techniques for leveraging the MASQUE protocol to provide remote clients with full application access to private enterprise resources are described herein. One or more network nodes may be configured to execute a MASQUE proxy service to provide a remote client device with full access to an enterprise / private application resource executing on an application node and hosted in an enterprise / application network, behind the MASQUE proxy service. In some examples, the MASQUE proxy service may execute on a single proxy node hosted at an edge of a cloud network or at an edge of an enterprise network. Additionally, or alternatively, a first instance of the MASQUE proxy service may execute on a first proxy node hosted at an edge of a cloud network (e.g., an ingress proxy node) and a second instance of the MASQUE proxy service may execute on a second proxy node hosted at an edge of the enterprise network.
Owner:CISCO TECHNOLOGY INC

Method and system for managing virtual private cloud (VPC) network configuration

PendingCN120982072ATransmissionWeb tablesMajorization minimization
In order to manage virtual private cloud (VPC) network configuration, a network topology and configuration of each network element are firstly obtained, and then a reachability intention including a target function and an intention attribute is defined. In one embodiment, a network representation is generated that describes how traffic is processed in a network element through an operable filter function, and a minimization problem is defined by converting the network representation into a MaxSAT formula that is used to minimize the number of decision variables to be modified. And according to a target function, defining a decision weight for the decision variable, and obtaining a solution of a minimization problem through a MaxSAT resolution algorithm weighted by the decision weight to generate an optimized network configuration.
Owner:HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD

Controller-based traffic filtering and address modification

In communication with components of a cloud platform, namely a software-defined network constructed to overlay at least one public cloud network, a controller features a virtual processor and a data store. The data store includes network address translation (NAT) processing logic configured to determine whether a control plane message from tenant resources is associated with a network address overlapping condition, which represents a first network address included in the control plane message overlaps a network address range relied upon by either (a) at least one of the components of the cloud platform or (b) a component associated with other tenant resources. The NAT processing logic is further configured to alter routing data stores that maintain routing information for each of the components of the cloud platform to substitute the first network address with a first virtual network address for subsequent data message routing.
Owner:AVIATRIX SYSTEMS INC

Context-aware drift tiering and dynamic remediation of security drift events in a public cloud network

A computer implemented method for managing and remediating security drift in a public cloud network is disclosed. A security drift event may be received at a contextual impact classification engine of a server. An impact tier for the received security drift event may be assigned at the contextual impact classification engine. A queue shaping orchestrator at the server may reorder a queue with entries that include the received security drift event based on the assigned impact tier. A remediation engine of the server may determine a remediation for the received security drift event based on the assigned impact tier, and / or one or more contextual inputs received by the server.
Owner:SALESFORCE INC

System and Method for Network Policy-Based Traffic Management of Data Flows

A system featuring a controller and a plurality of nodes operating as a Kubernetes cluster. The plurality of nodes includes a master node communicatively coupled to the controller, and an ingress node being configured to (i) access the master node to obtain at least a first attribute associated with a data flow received by the ingress node based on a network address associated with a source of the data flow, (ii) determine one or more network policies applicable to the data flow based on at least the first attribute, and (iii) determine a classification identifier based on the one or more network policies. The classification identifier provides context associated with the data flow and a reliable association between an application and the data flow associated with the application during propagation of the data flow over a cloud network.
Owner:AVIATRIX SYSTEMS INC

Automated cloud buildout and / or run state management using cloud hosted orchestration of configuration and installation of cloud services

Systems and methods are provided for implementing automated cloud buildout and / or run state management using cloud hosted orchestration of configuration and installation of cloud services. A configuration file, which outlines configurations and services to be applied to servers installed within a data center, is used by a computing system to orchestrate configuration or reconfiguration of the servers during buildout operations and / or run state operations of a cloud network(s). The computing system monitors for configuration changes or inconsistencies in the servers, as compared with the configuration file. If the configurations have been changed or are otherwise inconsistent with the configuration file, the computing system automatically restores, resets, or reconfigures the first servers or services / apps to be consistent with the configurations as outlined in the configuration file. A user interface may be provided to enable a user to view statuses of the buildout operations and / or the run state operations.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Cross-virtual private cloud network scheduling method, system, equipment and medium

The invention discloses a cross-virtual private cloud network scheduling method based on a cloud computing infrastructure, a cross-virtual private cloud network scheduling system based on the cloud computing infrastructure, electronic equipment and a readable storage medium, and the method comprises the steps: obtaining network configuration information of a virtual private cloud; establishing a cross-virtual private cloud access channel according to the network configuration information, wherein the access channel comprises a peer-to-peer connection channel and a terminal node channel; configuring an address translation rule and a routing rule for the access channel; and carrying out forwarding and access control on the network access flow among the applications and / or the computing resources in the virtual private cloud according to an address conversion rule and a routing rule. Uniform configuration and dynamic management of the network access path are realized while independence of each virtual private cloud is kept, so that the access relationship across the virtual private cloud is clearer, configuration is more concentrated, operation and maintenance are more simplified, and interconnection flexibility and manageability in a cloud multi-network environment are improved.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Tunnel traffic flow detection method based on video cloud networking technology

The invention relates to the technical field of traffic information collection, in particular to a tunnel traffic flow detection method based on a video cloud networking technology, and the method comprises the following steps: obtaining video flow data collected by each monitoring camera in a tunnel in real time; performing compression coding processing on the video stream data; performing noise filtering and frame synchronization preprocessing on the coded video data; in a preset edge computing node, inputting the structured video data into a vehicle flow detection model to extract vehicle feature parameters in the video frame; performing tracking association on the target vehicle in the video frame through an asymmetric Kalman filtering algorithm, and comparing the vehicle flow detection data with a preset vehicle flow threshold; and in the cloud analysis platform, analyzing the structured detection data through the tunnel traffic flow prediction model. According to the invention, noise filtering and time-space alignment can be carried out on the collected vehicle operation video data, and the accuracy of tunnel traffic flow detection is improved.
Owner:贵州道坦坦科技股份有限公司

Centralized management cloud connecting multiple enterprise networks

This disclosure provides systems, methods and apparatus, including computer programs encoded on computer storage media, for centralized management cloud connecting multiple enterprise networks. A network agent may be deployed within a private cellular network and act as an interface between the node(s) of the private cellular network and a cloud network controller. The network agent may obtain a local-based request to initiate a cloud-based procedure associated with network parameter(s), the network parameter(s) being associated with cloud network credential(s) that correspond to the private cellular network. The network agent may output a cloud-based request to the cloud network controller to initiate the cloud-based procedure. The cloud-based request may indicate at least a portion of the network parameter(s) and omit at least a portion of local credential(s) of the private cellular network. The cloud-based request may hide the cloud network credentials of the private cellular network from the cloud network controller.
Owner:QUALCOMM INC

Monitoring and preventing spoofing, tampering, and denial of service attacks on cloud containers

A computing platform may train, using historical node performance information and historical application parameter information, a node selection model, which may configure the model to select nodes for application cloud deployment. The computing platform may receive a request to deploy an application to a cloud network. The computing platform may select a node, of the plurality of nodes of the cloud network, to which the application should be deployed. The computing platform may queue, along with other applications scheduled for deployment to the plurality of nodes, the application for deployment to the node. After identifying that the application is first in the queue, the computing platform may deploy the application to the node of the cloud network, which may create, at the node, a container corresponding to the application.
Owner:BANK OF AMERICA CORP

System and method for performing a backup operation

A backup agent for performing a backup operation is provided. The backup agent comprises a memory storing one or more processor-executable routines and a processor communicatively coupled to a data storage system and configured to access unstructured data stored in therein. The processor comprises a master node and a plurality of proxy nodes. The master node is configured to perform a backup operation by generating a plurality of threads to perform a scan operation; wherein during the scan operation a plurality of batches of data stored on a data storage device is scanned. The processor is further configured to create a global queue of the plurality of batches of data upon completion of the scan and assign the plurality of batches of data from the global queue to a plurality of proxy nodes and / or to the master node. The master node and each proxy node are configured to perform an upload operation by uploading the assigned batch of data on the cloud network; wherein the master node and the proxy nodes operate concurrently.
Owner:DRUVA INC

Network traffic forwarding method and device, electronic equipment and storage medium

The invention provides a network traffic forwarding method and device, electronic equipment and a storage medium, and is applied to an intelligent network card, the method comprises the following steps: obtaining link quality information measured by the intelligent network card for a cross-cloud link; reporting the link quality information to a forwarding gateway in the cloud; receiving a path selection strategy issued by the forwarding gateway, the path selection strategy being generated by the forwarding gateway based on the link quality information and preset strategy information; and forwarding the network traffic according to the path selection strategy. Therefore, real-time perception of cross-cloud link quality and quick path selection based on real-time quality are realized, the problem of path selection strategy lag caused by the fact that detection and decision-making functions are concentrated on a control level in the background technology is fundamentally solved, and the quality and real-time performance of cross-cloud network transmission are remarkably improved.
Owner:BEIJING KINGSOFT CLOUD NETWORK TECH CO LTD +1

System and method for application-based micro-segmentation

A system and method for controlling the handling of intra-VPC and inter-VPC communications is described. First, a destination of a communication is determined it resides within a first virtual private cloud network (VPC) of a source of the communication. If so, filtering communications between the destination and the source is controlled by native cloud constructs associated with a cloud service provider (CSP) underlay network for the first public cloud network. Otherwise, filtering communication between the destination and the source is controlled by a spoke gateway. The spoke gateway is part of a cloud overlay network configured to provide a communication path between the first virtual private cloud network and the second private cloud network and using micro-segmentation to set and manage security policies.
Owner:AVIATRIX SYSTEMS INC

Multi-channel frequency modulation signal real-time monitoring system

The invention discloses a multi-channel frequency modulation signal real-time monitoring system which comprises at least one monitoring node and a remote cloud platform. The monitoring nodes simultaneously receive multiple paths of frequency modulation signals through the multi-channel radio frequency receiving unit, the signal processing unit demodulates and detects multiple quality parameters such as field intensity, signal-to-noise ratio, frequency offset and multipath interference, the main control unit generates alarm information, and finally the alarm information is uploaded to the cloud platform through the communication unit integrated with 4G / 5G and Wi-Fi. And the cloud platform is responsible for storing and analyzing data and pushing alarms and information display to the authorized user terminal. According to the invention, a multi-core DSP parallel processing architecture, dual-path power supply and battery redundancy power supply and multi-parameter association intelligent alarm logic are adopted, cloud networking management is realized, and the problems of few monitoring channels, low efficiency, insufficient intelligent degree and difficult remote operation and maintenance in the prior art are solved. Therefore, efficient, reliable and intelligent remote monitoring of multi-channel FM signals is realized.
Owner:HANGZHOU ZHONGCHUAN DIGITAL EQUIP CO LTD

Network unified monitoring and operation and maintenance management system in multi-cloud environment

The invention relates to a network unified monitoring and operation and maintenance management system in a multi-cloud environment, and belongs to the technical field of cloud computing and network operation and maintenance crossing. The system is characterized in that an intelligent perception and adaptation access module performs bidirectional communication with a heterogeneous cloud platform through a dynamic protocol adaptation engine, and an edge preprocessing unit completes data primary processing and security authentication; the data processing and analysis module constructs a stream batch integrated architecture, establishes a cross-cloud unified topology model by using a knowledge graph technology, and realizes multi-dimensional data analysis through a distributed time sequence database; the strategy generation and scheduling module performs strategy pre-verification, issues an operation and maintenance instruction through a transaction consistency mechanism, and establishes a closed-loop feedback loop to continuously optimize a decision; the unified operation and maintenance portal module integrates three-dimensional topology, visualizes security situations and operation and maintenance decisions, and provides fault traceability and strategy interaction capability. According to the invention, unified monitoring, intelligent analysis and automatic operation and maintenance of a multi-cloud network environment are realized.
Owner:SHANGHAI WANGYUE INFORMATION TECHNOLOGY CO LTD

Multi-operator core SASE for 5g sase

Techniques for providing multi-operator core SASE solutions (e.g., for 5G SASE) are disclosed. In some embodiments, a system, a process, and / or a computer program product for providing multi-operator core SASE solutions for 5G SASE includes receiving mobile network traffic, at a Secure Access Service Edge (SASE) cloud network, via a service provider interconnect between a plurality of mobile service provider networks and the SASE cloud network; monitoring the mobile network traffic at the SASE cloud network from the plurality of mobile service provider networks for a tenant of the SASE cloud network provider; enforcing a security policy based on one or more parameters associated with the mobile network traffic, wherein the security policy is associated with the tenant of the SASE cloud network provider; and forwarding the secured data plane traffic from the SASE cloud network to its original destination if allowed by the security policy, and block or drop the data plane traffic from the SASE cloud network if not allowed by the security policy.
Owner:PALO ALTO NETWORKS INC