Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

247 results about "Cloud service provider" patented technology

A cloud service provider, or CSP, is a company that offers some component of cloud computing -- typically infrastructure as a service (IaaS), software as a service (SaaS) or platform as a service (PaaS) -- to other businesses or individuals.

Data encryption transmission method and device in hybrid cloud environment, equipment and storage medium

The invention relates to the field of data encryption, in particular to a data encryption transmission method and device in a hybrid cloud environment, equipment and a storage medium. The method comprises the following steps: acquiring data to be transmitted; performing key field deep semantic analysis on the to-be-transmitted data, and performing dynamic layered encryption to obtain a plurality of layered encrypted transmission data packets; available transmission path detection is carried out on the hybrid cloud environment, dynamic end-to-end encryption is carried out, and a plurality of end-to-end encryption transmission links are constructed; performing distributed encryption transmission and dynamic transmission path decision on the plurality of layered encryption transmission data packets based on the plurality of end-to-end encryption transmission links, and constructing a dynamic transmission path adjustment strategy; detecting all user access behaviors in the hybrid cloud environment; and carrying out user cloud service provider classification on all the user access behaviors, carrying out personalized behavior modeling, and constructing a behavior portrait of each user. According to the invention, efficient and safe data encryption transmission for the hybrid cloud environment is realized.
Owner:SHENZHEN TRUSTED CLOUD TECH CO LTD

Security VPC security inspection orchestration and abstractions for all csps

A network device may receive one or more first user inputs in a security gateway creation user interface (UI) provided by a controller. A network device may query, by the controller, the CSP using Application Programming Interfaces (APIs) to retrieve information about applications within the at least one virtualized network environment including any services deployed within the at least one virtualized network environment. A network device may present a security status user interface that identifies the at least one virtualized network environment applications configured in the CSP account and a respective status indicating whether the at least one virtualized network environment is protected by the security gateway. A network device may receive a second user input within the security status user interface, the second user input is effective to enable protection of the at least one virtualized network environment by the security gateway.
Owner:CISCO TECHNOLOGY INC

Foundation model driven application that generates remediation actions for cloud resource misconfigurations

A cloud misconfiguration remediation application (“remediation application”) has been created that generates a remediation action for a resource misconfiguration detected with a CSPM policy. The remediation application includes a conversation agent that interacts with the foundation model according to a chain of prompts / input sequences. The conversation agent constructs the chain of prompts based on a template, the CSPM policy, metadata about the CSPM policy and the misconfigured cloud resource, and responses from the foundation model. The foundation model is implemented with retrieval augmented generation (RAG) that uses an embedding database built with remediation documentation of the CSP. Prompts from the conversation agent are augmented based on the implemented RAG. The remediation application aggregates the responses into a remediation action that can either be automatically performed or presented for consideration by a user.
Owner:PALO ALTO NETWORKS INC

System for cloud solution migration and management

The system can receive data, including a specification for a cloud solution, indicating a type of cloud solution and at least one requirement. The system can determine a list of cloud service providers with cloud infrastructure capable of hosting the cloud solution and an ability to satisfy the at least one requirement. The system can rank the cloud service providers based on the capability to host the cloud solution and the ability to satisfy the at least one requirement. The system can select the cloud service provider based on the ranking. The system can generate an implementation procedure based on an Application Programming Interface (API) specification, where the API specification determines a requirement for the cloud solution to be deployed on the cloud infrastructure. The system can deploy, using a large language model (LLM), the cloud solution on the cloud infrastructure in accordance with the implementation procedure.
Owner:T MOBILE US INC

System and methods for generation of a network topology and corresponding user interfaces

A distributed cloud computing system is disclosed that includes a controller configured to deploy network constructs including any of transit gateways, spoke gateways, subnets, or private networks and logic that, upon execution by one or more processors, causes performance of operations including: causing rendering of a graphical user interface that includes a display panel configured to display progress of a build process for a network topology graph, receiving first user input through the graphical user interface indicating selection of a first cloud service provider, a first access account, and a first cloud region, receiving second user input through the graphical user interface indicating selection of one or more of the network constructs to be deployed in the first cloud region, instructing the controller to deploy the one or more of the network constructs in the first cloud region according to the first user input and the second user input.
Owner:AVIATRIX SYSTEMS INC

Incremental enrichment of threat data

A threat management facility receives data from a variety of sources such as compute instances within an enterprise network, cloud service providers supporting the enterprise network, and third-party data providers such as geolocation services. In order to facilitate prompt notification of potential risks, the threat management facility may incrementally update data for use in threat assessments as the data becomes available from these different sources, and create suitable alerts or notifications whenever the currently accumulated data provides an indication of threat meeting a predetermined threshold.
Owner:SOPHOS LTD

Identity privacy protection system and method for safe sharing of power data

PendingCN121561950AData processing applicationsDigital data protectionChosen-plaintext attackAttack
The invention discloses an identity privacy protection system and method oriented to power data security sharing, which combine single-factor combination authentication and identity traceability and utilize the transparency and tamper resistance of a block chain. Comprising an electric power key generation center, an electric power cloud service provider, an electric power data owner, an electric power data user and a block chain, user identity privacy is ensured, safe identity verification is supported, identity traceability is achieved under necessary conditions, and meanwhile safe distribution of keys is achieved. In addition, services and resources are isolated by using groups, so that the flexibility and the expandability of the services and the resources are enhanced. Security analysis and experimental evaluation prove that the method can effectively resist selected plaintext attacks, and meanwhile, high efficiency and practicability are kept.
Owner:STATE GRID HENAN INFORMATION & TELECOMM CO

Cloud instance privacy security enhancement method based on security channel dynamic measurement

The invention discloses a cloud instance privacy security enhancement method based on security channel dynamic measurement, and the method comprises the steps: building a secure and credible communication channel through a secure communication client, and connecting the communication channel to a local user side through the Internet; a local user side deploys a TPCM secure communication module which is responsible for secure communication with the multi-cloud service rental instance. And the trusted software base is responsible for maintaining a measurement strategy and performing measurement judgment and control when a user process runs in the cloud service lease instance. The system specifically comprises a judgment mechanism module, a control mechanism module, a measurement mechanism module and a credible reference library. On the premise that infrastructures of cloud service providers are not trusted, in order to achieve safety and credibility of user remote cloud service lease instance data and application during operation and privacy protection of users, a measurement agent and a safety communication client are deployed in a cloud service lease instance; meanwhile, the tenant can perform deep monitoring on the process in the cloud instance, and it is ensured that sensitive information such as a monitoring strategy and reference data is not exposed to a cloud service provider.
Owner:BEIJING UNIV OF TECH

Cloud data integrity auditing method, system and device based on certificateless signature, medium and product

The invention discloses a cloud data integrity auditing method, system, device, medium and product based on certificateless signature, and relates to the technical field of network security, the method comprises the following steps: a key generation center obtains a data owner anonymous identity label based on a system master secret key and a data owner real identity label, and sends the data owner anonymous identity label to a server; obtaining a part of private keys of the data owner based on the anonymous identity identifier; the data owner verifies part of the private keys according to the anonymous identity identification, secretly selects the random number as the other part of the private keys if the verification is passed, and obtains a public key according to the other part of the private keys; the data owner obtains the label of each data block based on the two parts of private keys; the third-party auditor initiates an integrity challenge to the cloud service provider; the cloud service provider calculates audit evidence; and the third-party auditor verifies whether the to-be-audited file stored in the cloud is complete or not. According to the application, the TPA can be prevented from exploring privacy, certificate management is simplified, efficient and rapid identity authentication is realized, and real information of a user is hidden.
Owner:BEIJING INSTITUTE OF GRAPHIC COMMUNICATION

Model processing method and device, equipment, medium and product

The invention discloses a model processing method and device, equipment, a medium and a product. The method comprises the steps that each data owner trains an initial model based on training data to obtain a local model, and uploads the local model to a proxy server; the proxy server performs aggregation calculation on the local model set to obtain a global model, and sends the global model to the task publisher; if the task publisher detects that the global model does not reach convergence, performing performance test on the global model to obtain a target score corresponding to each data owner, screening the data owners based on the target scores corresponding to the data owners to obtain a data owner set, and storing the data owner set in a database; and sending the initial model to a data owner set, so that each data owner in the data owner set returns to execute the operation of training the initial model based on the training data by each data owner to obtain a local model, uploading the local model to the proxy server until the obtained global model converges, and sending the global model to the cloud service provider.
Owner:HANGZHOU XINYUN SEMICON GRP CO LTD

System and method for application-based micro-segmentation

A system and method for controlling the handling of intra-VPC and inter-VPC communications is described. First, a destination of a communication is determined it resides within a first virtual private cloud network (VPC) of a source of the communication. If so, filtering communications between the destination and the source is controlled by native cloud constructs associated with a cloud service provider (CSP) underlay network for the first public cloud network. Otherwise, filtering communication between the destination and the source is controlled by a spoke gateway. The spoke gateway is part of a cloud overlay network configured to provide a communication path between the first virtual private cloud network and the second private cloud network and using micro-segmentation to set and manage security policies.
Owner:AVIATRIX SYSTEMS INC

Security integration for cloud services

A threat management facility for an enterprise network integrates native threat management capabilities with threat data from a cloud service provider used by the enterprise. By properly authenticating to the cloud service and mapping data feeds from the cloud service to a native threat management environment, the threat management facility can extend threat detection and management capabilities beyond endpoint-centric techniques.
Owner:SOPHOS LTD

Locking system for exchange of items, services, and / or facilities

One or more techniques and / or systems are provided for generating locking codes. For example, a remote interface (e.g., hosted by a kiosk or a cloud service provider) may receive a request from a requestor for an unlocking code. The unlocking code may be used to unlock a lock, such as a lock integrated into or attached by a secondary means of attached to a containment component. The remote interface generates the unlocking code valid for a timespan. The unlocking code may be generated based upon a unique identifier of the containment component. The remote interface transmits the unlocking code to the requestor for unlocking the lock. In an example, the unlocking code is transmitting after a delay.
Owner:WEGELIN JACKSON WILLIAM

A service provider sla evaluation dynamic business model implementation method and system

The application belongs to the technical field of business intelligence evaluation, and specifically provides a service provider SLA evaluation dynamic business model implementation method and system. The method mainly comprises: obtaining SLA evaluation source data of a service provider, wherein the SLA evaluation source data comprises operator SLA data, enterprise end-to-end APM data, third-party network quality data and dependent link probe data between service providers; taking the service provider as a node, setting a credibility weight for each node according to a preset rule, determining a directed edge between nodes according to a preset dependent relationship between service providers, and determining a connection weight of the directed edge according to the dependent link probe data. The application realizes dynamic and accurate evaluation under multi-dimensional data fusion, improves the objectivity and credibility of SLA achievement rate evaluation results, and provides reliable decision support for enterprise screening of cloud service providers and optimization of service deployment.
Owner:CHINA COMPUTER DIGITAL (BEIJING) INFORMATION TECHNOLOGY CO LTD

Method and apparatus for performing memory reconfiguration without system reboot

PendingCN120723152AInput/output to record carriersSystem reconfigurationOperational system
The cloud service provider reconfigures the memory subsystem during routine operations while minimizing the amount of time the server is not online. Server downtime is reduced by offloading reconfiguration of system memory to an operating system with the assistance of a platform. The operating system enumerates potential memory configurations and associated performance characteristics of the memory subsystem in an abstract manner and performs reconfiguration of the memory subsystem without a cold reset. When the operating system considers that reconfiguration of the memory subsystem is necessary, the operating system checks the enumerated memory subsystem configuration provided by the system firmware. After selecting the memory subsystem configuration, the operating system initiates a reconfiguration process. The reconfiguration process saves any existing memory context to the secondary device, requests system firmware to perform memory subsystem reconfiguration, and restores the existing memory context from the secondary device after the memory subsystem reconfiguration has completed.
Owner:INTEL CORP

A blockchain supervision method and system supporting privacy protection

The present invention discloses a blockchain supervision method and system supporting privacy protection, the present invention includes: cloud service consumer CSC encrypts data d C ', encrypted private key sk C " and privacy requirements pr are put on the chain; the cloud service provider CSP puts the privacy policy pp on the chain, and the cloud service provider CSP initiates a decryption request; the blockchain runs the smart contract to perform a privacy compliance check based on the privacy requirements pr and privacy policy pp, and if it passes, it agrees that the cloud service provider CSP will decrypt the data d C 'Decrypted to data d C , processed (calculated or stored) into data d P And encrypted and uploaded to the chain; cloud service consumer CSC downloads and decrypts to obtain data d P The present invention can realize the functions of supervision, auditing and privacy protection, and has the advantages of being tamper-resistant, traceable, risk-resistant and privacy-enhanced. It is of great significance for balancing the needs of supervision and privacy protection and building an efficient and reliable cloud computing supervision mechanism.
Owner:NAT UNIV OF DEFENSE TECH +1

Cloud service management and control method and device, computer program product and storage medium

The embodiment of the invention provides a cloud service management and control method and device, a computer program product and a storage medium. In the embodiment of the invention, a cloud service management and control system can create a second private network in a first area where a cloud service provider is located as a cross-area access entrance of a cloud service provider side, and can create an exclusive fourth private network for the cloud service provider in other areas as required according to an access request of a user; as a cross-regional access exit of a user side, users in other regions except the region where the cloud service provider is located are supported to access any service provided by the cloud service provider in a cross-regional mode. Therefore, flexible expansion and contraction of the service area can be realized for the cloud service provider, and the cloud service provider does not need to deploy services in multiple areas, so that the service cost can be effectively saved.
Owner:ALIBABA CLOUD COMPUTING CO LTD

Virtual layer 2 network

To provide systems and methods for virtual Layer 2 networks.SOLUTION: The method comprises providing a virtual Layer 3 network within a virtualized cloud environment of a virtualized cloud network (VCN) 602. The virtual Layer 3 network may be hosted by the underlying physical network. The method also includes providing a virtual Layer 2 network deployed in the virtualized cloud environment and hosted by the underlying physical network of the cloud service provider infrastructure (CSPI) 601. The virtual Layer 2 network may be hosted by the underlying physical network.SELECTED DRAWING: Figure 6
Owner:ORACLE INT CORP

Token exchange service for customer workloads

A token exchange framework between two different cloud service providers is described herein. A multi-cloud infrastructure included in a first cloud environment provided by a first cloud service provider (CSP) receives a first request from a user associated with an account in a second cloud environment provided by a second CSP. The first request corresponds to use of a service provided by the first cloud environment and includes a first token issued by the second CSP. Based on verifying the first token with respect to a trust configuration corresponding to the second CSP, the multi-cloud infrastructure obtains a second token issued by the first CSP. The trust configuration is pre-generated and maintained by the first CSP in the first cloud environment. The multi-cloud infrastructure sends the second token to the service to enable the user to utilize the service provided by the first cloud environment.
Owner:ORACLE INT CORP

A video cloud transcoding task scheduling method based on HHO algorithm

The application discloses a video cloud transcoding task scheduling method based on a HHO algorithm, and belongs to the technical field of cloud computing optimization scheduling, and comprises the following steps: S1: splitting a video stream into multiple GOP tasks capable of independent transcoding through a video splitter; and S2: establishing a target function required by video cloud transcoding task scheduling.In the application, a Harris hawk optimization scheduler is designed to schedule video transcoding tasks, a reverse learning strategy and a logarithmic spiral factor are used to improve the HHO algorithm, the convergence speed and optimization precision of the application are improved, a double-target function of transcoding time and transcoding overhead is established, the improved HHO algorithm is used to iteratively optimize the target function, and the best mapping scheme of the video transcoding task and the virtual machine resource is found out.The application can reduce the video transcoding completion time, reduce the user cost overhead, better meet the QoS demand of video users, and improve the task scheduling efficiency of cloud service providers.
Owner:SHENZHEN UNIV

Resource charging method based on multi-cloud service

The invention discloses a resource charging method based on multi-cloud service, and particularly relates to the technical field of resource management and cost optimization. The method comprises the following steps of: constructing standardized multi-cloud service interaction path data by acquiring service flow billing related data configured by a user in a multi-cloud computing architecture; the method comprises the following steps: constructing a cross-cloud traffic loopback identification matrix by extracting data forwarding directions, node switching frequencies and loopback transmission modes among different cloud service providers; analyzing repeated charging and charging asymmetry characteristics of the cross-cloud traffic loopback, and generating an accumulated premium risk assessment index; the forwarding cost difference and the reverse charging threshold value between the cloud service nodes are analyzed, and path reconstruction priority scoring data are generated; the method comprises the following steps: constructing a cross-cloud path optimization objective function for minimizing accumulated charging cost, outputting optimized suggested path data, reconstructing a cross-cloud transmission path of business service, and adjusting cross-cloud node configuration; the cross-cloud resource utilization efficiency is improved, and the charging cost is effectively reduced.
Owner:CHINA BROADBAND NETWORK

Multi-region login

A system for providing login to a network of a cloud service provider via more than one region is described herein. For example, the system and approaches may store authentication information in multiple regions allowing for authentication in the multiple regions.
Owner:ORACLE INT CORP

Method and system for realizing service provider SLA (Service Level Agreement) evaluation dynamic business model

ActiveCN121940311ARealize dynamic and accurate assessmentimprove objectivityTransmissionThird partyEvaluation result
The invention belongs to the technical field of service intelligent evaluation, and particularly provides a service provider SLA evaluation dynamic service model implementation method and system, and the method mainly comprises the steps: obtaining the SLA evaluation source data of a service provider, the SLA evaluation source data comprises operator SLA data, enterprise end-to-end APM data, third-party network quality data, and dependency link probe data between service providers; the method comprises the following steps: by taking service providers as nodes, setting a credibility weight for each node according to a preset rule, determining directed edges between the nodes according to a preset dependency relationship between the service providers, and determining a connection weight of the directed edges according to dependency link probe data; according to the method, dynamic accurate evaluation under multi-dimensional data fusion is realized, the objectivity and credibility of an SLA achievement rate evaluation result are improved, and reliable decision support is provided for enterprises to screen cloud service providers and optimize service deployment.
Owner:CHINA COMPUTER DIGITAL (BEIJING) INFORMATION TECHNOLOGY CO LTD

Method to establish a secure channel

Method to establish a secure channel between the owner of a software payload and the software payload itself when running into a hardware-based trusted execution environment, HW TEE, at the instance of a cloud service provider, including sending, by the owner, a nonce to the software payload; generating, by the software payload, a payload key pair: public key and private key; mixing, by the software payload, the payload public key with the nonce; computing, by the HW TEE, an attestation using this nonce mixed with the payload public key; sending, by the software payload, the attestation, and the payload public key to the owner; verifying, by the owner, the attestation using the sent nonce mixed with the received payload public key; generating, by the software payload and the owner, a session key; and establishing a secure channel between the owner and the software payload running into the HW TEE.
Owner:THALES DIS FRANCE SA

A tenant sovereignty zone

The present disclosure relates to a system for secure processing and storing of sensitive data and non-sensitive data for a tenant in an execution environment of a cloud service. In the system according to the present disclosure, the sensitive data includes a plaintext sensitive data element. In contrast, the non-sensitive data does not include a plaintext sensitive data element. The execution environment of the system comprises a general execution area, wherein the general execution area allows full access by the cloud service provider, and a general application service running in the general execution area, wherein the general application service does not have access to the sensitive data, and wherein the general application service only processes the non-sensitive data. Furthermore, the execution environment of the system comprises a trusted execution area, and a trusted application service running in the trusted execution area.
Owner:COMFORTE AG

Computer and Network Interface Controller Securely Offloading Encryption Keys and Underlay IPsec Encryption Processing to the Network Interface Controller

Encryption operations are securely offloaded to a network interface controller (NIC). Encryption keys are securely transferred from a virtual machine (VM) to the NIC and data is securely transferred from encrypted VM memory to secure buffers in the NIC. The NIC handles the encryption and decryption operations in hardware, greatly increasing encryption performance while not reducing security. This is especially useful in cloud server environments, so the cloud service provider does not have access to the encryption keys or the unencrypted data. The offloaded operations are performed with numerous different communication protocols, including RDMA, QUIC, IPsec underlay and WireGuard.
Owner:DREAMBIG SEMICON INC

Method and system for data regulations-aware cloud storage and processing service allocation

The present disclosure a method for data regulations-aware cloud storage and processing service allocation. Conventional approaches fail to address the technical problem of data placement for storage as well as processing, considering multiple criteria. Further, the conventional approaches fail to address compliance with data regulations, tier pricing policy for multiple Cloud Service Providers (CSPs) which impacts storage and processing center selection and constraint satisfaction. The present disclosure proposes a joint optimization model for the selection of storage and processing services from multiple cloud service providers, taking into practical consideration of data regulations and tiered pricing, which has not been addressed in the prior art. To solve this hard multi-objective combinatorial optimization problem, the present disclosure utilizes a cost-reduction-based algorithm for obtaining optimal solution.
Owner:TATA CONSULTANCY SERVICES LTD