Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

352 results about "Cloud service provider" patented technology

A cloud service provider, or CSP, is a company that offers some component of cloud computing -- typically infrastructure as a service (IaaS), software as a service (SaaS) or platform as a service (PaaS) -- to other businesses or individuals.

Trusted cloud security confidential privacy three-dimensional grade product service system and method

PendingCN120528631ASecuring communicationComputer networkProduct-service system
The invention belongs to the technical field of cloud security services, and provides a trusted cloud security confidential privacy three-dimensional level product service method, which comprises the following steps that: a cloud service provider matches products and services with different security levels by separating differentiated demands of an application development service provider and a final user in confidential, privacy and security dimensions; configuring different security modules for the product, performing hardware and software type selection matching, and determining a product type in combination with an end-to-end scene; then deploying a dynamic strategy adjustment mechanism, monitoring abnormal access in real time and adaptively adjusting a protection strategy; and continuously optimizing the security configuration. The invention discloses a trusted cloud security confidential privacy three-dimensional grade product service system, which is used for realizing a trusted cloud security confidential privacy three-dimensional grade product service method. The method is beneficial for transparently solving the security demand and conflict problem of the cloud service provider, the application development service provider and the final user, and promoting the healthy development of the cloud computing market.
Owner:WUHAN TRUSTED CLOUD TECH CO LTD

Inventory monitoring for cloud resource protection in real time

Disclosed are systems, apparatuses, methods, and computer-readable media for inventory monitoring in a multi-cloud network environment. A method includes receiving user input via a controller's interface, wherein the input includes first account information granting access to a first virtual private cloud and a second virtual private cloud, both hosted by a cloud service provider (CSP). The controller queries the first and second virtual private clouds using the respective account information and the CSP's APIs to identify resources, gathering them into an inventory, and maintains a mapping of tags to the resources, associating each tag with a specific security policy. The controller forwards a first subset of tag-resource mappings to a first security gateway in the first virtual private cloud, enabling automatic application of corresponding security policies upon instantiation of tagged resources.
Owner:CISCO TECHNOLOGY INC

Limits on resource usage

Techniques including receiving, by a cloud environment of a cloud service provider, a requested resource usage for a resource associated with a subscription of a user account with the cloud service provider. The techniques further include determining, as part of managing resources at a subscription level independent of managing resources at a user account level, a resource usage by the subscription. The techniques further include determining that a usage limit for the resource is greater than the resource usage. Based on the usage limit being greater than the resource usage, the techniques further include determining that a remaining resource allocation for the subscription is greater than or equal to the requested resource usage. Based on the remaining resource allocation being greater than or equal to the requested resource usage, the techniques further include providing the resource to the user account and updating the resource usage.
Owner:ORACLE INT CORP

Network information security dynamic early warning method and system based on knowledge graph

The invention discloses a network information security dynamic early warning method and system based on a knowledge graph, and relates to the technical field of network information security. According to the method, network equipment logs, threat intelligence texts and flow metadata are acquired in real time through a multi-source heterogeneous data acquisition module, and a dynamic knowledge graph is constructed by adopting a streaming knowledge extraction technology. And predicting a threat propagation path by using a graph attention network and gating loop unit hybrid model, and generating a hierarchical defense strategy in combination with a three-dimensional risk assessment value. The system comprises a multi-modal data acquisition module, a dynamic knowledge graph construction module, a threat propagation dynamics modeling module, a self-adaptive strategy generation module, a digital twinborn verification module and the like, and the effectiveness of a defense strategy is verified by simulating an attack path. According to the method, dynamic early warning and automatic response of network security are realized, the network protection capability is effectively improved, and the method is suitable for scenes such as enterprise network security protection and cloud service provider security protection.
Owner:SANYA UNIVERSITY

Data encryption transmission method and device in hybrid cloud environment, equipment and storage medium

The invention relates to the field of data encryption, in particular to a data encryption transmission method and device in a hybrid cloud environment, equipment and a storage medium. The method comprises the following steps: acquiring data to be transmitted; performing key field deep semantic analysis on the to-be-transmitted data, and performing dynamic layered encryption to obtain a plurality of layered encrypted transmission data packets; available transmission path detection is carried out on the hybrid cloud environment, dynamic end-to-end encryption is carried out, and a plurality of end-to-end encryption transmission links are constructed; performing distributed encryption transmission and dynamic transmission path decision on the plurality of layered encryption transmission data packets based on the plurality of end-to-end encryption transmission links, and constructing a dynamic transmission path adjustment strategy; detecting all user access behaviors in the hybrid cloud environment; and carrying out user cloud service provider classification on all the user access behaviors, carrying out personalized behavior modeling, and constructing a behavior portrait of each user. According to the invention, efficient and safe data encryption transmission for the hybrid cloud environment is realized.
Owner:SHENZHEN TRUSTED CLOUD TECH CO LTD

Security VPC security inspection orchestration and abstractions for all csps

A network device may receive one or more first user inputs in a security gateway creation user interface (UI) provided by a controller. A network device may query, by the controller, the CSP using Application Programming Interfaces (APIs) to retrieve information about applications within the at least one virtualized network environment including any services deployed within the at least one virtualized network environment. A network device may present a security status user interface that identifies the at least one virtualized network environment applications configured in the CSP account and a respective status indicating whether the at least one virtualized network environment is protected by the security gateway. A network device may receive a second user input within the security status user interface, the second user input is effective to enable protection of the at least one virtualized network environment by the security gateway.
Owner:CISCO TECHNOLOGY INC

Foundation model driven application that generates remediation actions for cloud resource misconfigurations

A cloud misconfiguration remediation application (“remediation application”) has been created that generates a remediation action for a resource misconfiguration detected with a CSPM policy. The remediation application includes a conversation agent that interacts with the foundation model according to a chain of prompts / input sequences. The conversation agent constructs the chain of prompts based on a template, the CSPM policy, metadata about the CSPM policy and the misconfigured cloud resource, and responses from the foundation model. The foundation model is implemented with retrieval augmented generation (RAG) that uses an embedding database built with remediation documentation of the CSP. Prompts from the conversation agent are augmented based on the implemented RAG. The remediation application aggregates the responses into a remediation action that can either be automatically performed or presented for consideration by a user.
Owner:PALO ALTO NETWORKS INC

On-cloud semi-homomorphic encryption method capable of resisting private key tracking

The invention discloses an on-cloud semi-homomorphic encryption method capable of resisting private key tracking, which comprises the following steps of: S1, generating a blind identity based on the real identity of a data user, and performing identity de-association processing; s2, the attribute authority generates a binding key pair based on the blind identity and returns the binding key pair; s3, the data user discloses a real identity and a public key to the data owner; s4, the data owner encrypts the plaintext after verifying the public key to form a ciphertext set; s5, uploading the ciphertext set to a cloud service provider, and performing classified storage; s6, the cloud service provider receives the analysis request and performs homomorphic addition aggregation on the ciphertext set to generate an aggregated ciphertext; and S7, the data user uses the private key to decrypt the aggregated ciphertext, and a plaintext analysis result is recovered. According to the method, the identity privacy of the user is protected while encrypted data analysis is realized, and the method has the characteristics of untraceability and lightweight deployment.
Owner:SHANXI TAIYIAN CRYPTOGRAPHIC TESTING CENTER CO LTD

System for cloud solution migration and management

The system can receive data, including a specification for a cloud solution, indicating a type of cloud solution and at least one requirement. The system can determine a list of cloud service providers with cloud infrastructure capable of hosting the cloud solution and an ability to satisfy the at least one requirement. The system can rank the cloud service providers based on the capability to host the cloud solution and the ability to satisfy the at least one requirement. The system can select the cloud service provider based on the ranking. The system can generate an implementation procedure based on an Application Programming Interface (API) specification, where the API specification determines a requirement for the cloud solution to be deployed on the cloud infrastructure. The system can deploy, using a large language model (LLM), the cloud solution on the cloud infrastructure in accordance with the implementation procedure.
Owner:T MOBILE US INC

Secure cluster membership for a multi-cloud security platform

Disclosed are systems, apparatuses, methods, and computer-readable media for secure cluster membership for a multi-cloud security platform. A method includes: in response to receiving a start message to start a first instance of a gateway service, transmitting a boot message to a cloud service provider to cause the cloud service provider to boot an image corresponding to the gateway service, the boot message including boot script information; receiving a join message from the first instance to join a gateway service cluster; and configuring the first instance with the gateway service cluster based on credentials included in the join message.
Owner:CISCO TECHNOLOGY INC

Architecture and services provided by multi-cloud infrastructure

Techniques are described for providing a multi-cloud control plane (MCCP) in a first cloud infrastructure, including in a first cloud environment provided by a first cloud service provider, that enable services and / or resources provided in the first cloud infrastructure to be used by users of a second cloud environment, where the second cloud environment is different from the first cloud environment. The multi-cloud infrastructure enables a user associated with an account of a second cloud service provider to use a first service of a set of one or more cloud services from the second cloud infrastructure. The multi-cloud infrastructure creates a link between the account of the second cloud service provider and the lease created in the first cloud infrastructure to enable the user to use the first service.
Owner:ORACLE INT CORP

Subscription to a service provided by a first cloud service provider via a second cloud service provider

Techniques are disclosed for a method including providing, by a first computing resource of a first cloud service provider (CSP), a first service to a user having a first user account with a second CSP, the first service provided via a first private network of the user with the second CSP. The method further including transmitting data between a second private network communicatively coupled with the first private network, the second private network associated with a second user account of the user with the first CSP. The method further including associating, by a second computing resource of the first CSP, the first private network and the second private network with a subscription of the second user account with the first CSP, the subscription available via the second CSP.
Owner:ORACLE INT CORP

System and methods for generation of a network topology and corresponding user interfaces

A distributed cloud computing system is disclosed that includes a controller configured to deploy network constructs including any of transit gateways, spoke gateways, subnets, or private networks and logic that, upon execution by one or more processors, causes performance of operations including: causing rendering of a graphical user interface that includes a display panel configured to display progress of a build process for a network topology graph, receiving first user input through the graphical user interface indicating selection of a first cloud service provider, a first access account, and a first cloud region, receiving second user input through the graphical user interface indicating selection of one or more of the network constructs to be deployed in the first cloud region, instructing the controller to deploy the one or more of the network constructs in the first cloud region according to the first user input and the second user input.
Owner:AVIATRIX SYSTEMS INC

Personalized internal services via a privacy-constrained content promotion platform

Techniques are described for providing personalized content in applications without revealing personal details to content providers. A base machine learning model is loaded to a cloud environment that is private to a tenant organization. The base machine learning model is used to generate a custom machine learning model specific to the tenant organization based on user interactions within the tenant organization and content categories specific to the tenant organization. The custom machine learning model is used to select content categories for which to provide instances of content items to users based on user interactions with applications. Engagement with the instances of content items is tracked in a user-specific manner privately by the tenant organization, in a tenant-specific manner privately by a cloud services provider, and in a content-specific manner by the content provider. Feedback is provided to the custom machine learning model based on engagement with instances of content items.
Owner:ORACLE INT CORP

Single configuration for multi-cloud firewall deployment

Disclosed are systems, apparatuses, methods, and computer-readable media for configuring resources of a service distributed across multiple cloud service providers. A method includes: receiving a request to configure a firewall in a cloud service provider, the request including a tag including a name that identifies a single firewall configuration information; and providing derived firewall information from the single firewall configuration information based on an identity of the cloud service provider and the tag, wherein the single firewall configuration information includes network information for connecting the firewall to a private network in the cloud service provider.
Owner:CISCO TECHNOLOGY INC

Incremental enrichment of threat data

A threat management facility receives data from a variety of sources such as compute instances within an enterprise network, cloud service providers supporting the enterprise network, and third-party data providers such as geolocation services. In order to facilitate prompt notification of potential risks, the threat management facility may incrementally update data for use in threat assessments as the data becomes available from these different sources, and create suitable alerts or notifications whenever the currently accumulated data provides an indication of threat meeting a predetermined threshold.
Owner:SOPHOS LTD

Connectionless-virtual private network for secure cloud to user communication over the internet using a plurality of servers

The disclosure provides a system / method / scheme to securely send data from a cloud, or cloud service provider, to users via a secure connectionless system, referred to herein as a C-VPN communication infrastructure (C-VPN CI). In one example a method of communicating from a cloud service provider to a user via a C-VPN CI includes: (1) obtaining, by a cloud service provider, security parameters from a SDE Cloud server operating on a computing system of the cloud service provider, wherein the security parameters include a set of mathematical rules and values for converting plain text to ciphertext, (2) creating a secure communication using the security parameters received from the SDE Cloud server, wherein the secure communication includes a secure header and secure data, and (3) sending the secure communication to the user via a generic electronic message delivery system.
Owner:TALATI FAMILY

Identity privacy protection system and method for safe sharing of power data

PendingCN121561950AData processing applicationsDigital data protectionChosen-plaintext attackAttack
The invention discloses an identity privacy protection system and method oriented to power data security sharing, which combine single-factor combination authentication and identity traceability and utilize the transparency and tamper resistance of a block chain. Comprising an electric power key generation center, an electric power cloud service provider, an electric power data owner, an electric power data user and a block chain, user identity privacy is ensured, safe identity verification is supported, identity traceability is achieved under necessary conditions, and meanwhile safe distribution of keys is achieved. In addition, services and resources are isolated by using groups, so that the flexibility and the expandability of the services and the resources are enhanced. Security analysis and experimental evaluation prove that the method can effectively resist selected plaintext attacks, and meanwhile, high efficiency and practicability are kept.
Owner:STATE GRID HENAN INFORMATION & TELECOMM CO

Systems and methods of cloud-based multifactor authentication

A method may include receiving, by a multifactor authentication (MFA) service instantiated on a computing system, a token generated by a cloud services provider and associated with a user device. The MFA service may be instantiated within a tenancy of the cloud services provider. The method may include determining, by the computing system, an authorized cloud service instantiated within the tenancy. The method may include receiving, by the computing system, a request to access the authorized cloud service by the user device, where the request may include a multi-factor authentication request. The method may include generating, by the MFA service instantiated on the computing system, a one-time pad (OTP). The method may include providing, by the MFA service instantiated on the computing system, the OTP to the user device such that the user device accesses the authorized cloud service.
Owner:MCMILLEN HOLDINGS INC DBA RYANTECH

Spot Instance Instability Heatmaps

A system collects data about spot instances across different regions and different cloud service providers and analyzes the collected data to identify any spot instances that have experienced disruptive failures, such as interruptions and failure to provision resources. The system evaluates how stable the spot instances are in each region for each cloud service provider based on the disruptive failures occurred on the spot instances and creates an interactive visual representation of the stability of these spot instances across different regions and cloud service providers.
Owner:CAST AI GROUP INC

Cloud instance privacy security enhancement method based on security channel dynamic measurement

The invention discloses a cloud instance privacy security enhancement method based on security channel dynamic measurement, and the method comprises the steps: building a secure and credible communication channel through a secure communication client, and connecting the communication channel to a local user side through the Internet; a local user side deploys a TPCM secure communication module which is responsible for secure communication with the multi-cloud service rental instance. And the trusted software base is responsible for maintaining a measurement strategy and performing measurement judgment and control when a user process runs in the cloud service lease instance. The system specifically comprises a judgment mechanism module, a control mechanism module, a measurement mechanism module and a credible reference library. On the premise that infrastructures of cloud service providers are not trusted, in order to achieve safety and credibility of user remote cloud service lease instance data and application during operation and privacy protection of users, a measurement agent and a safety communication client are deployed in a cloud service lease instance; meanwhile, the tenant can perform deep monitoring on the process in the cloud instance, and it is ensured that sensitive information such as a monitoring strategy and reference data is not exposed to a cloud service provider.
Owner:BEIJING UNIV OF TECH

Cloud data integrity auditing method, system and device based on certificateless signature, medium and product

The invention discloses a cloud data integrity auditing method, system, device, medium and product based on certificateless signature, and relates to the technical field of network security, the method comprises the following steps: a key generation center obtains a data owner anonymous identity label based on a system master secret key and a data owner real identity label, and sends the data owner anonymous identity label to a server; obtaining a part of private keys of the data owner based on the anonymous identity identifier; the data owner verifies part of the private keys according to the anonymous identity identification, secretly selects the random number as the other part of the private keys if the verification is passed, and obtains a public key according to the other part of the private keys; the data owner obtains the label of each data block based on the two parts of private keys; the third-party auditor initiates an integrity challenge to the cloud service provider; the cloud service provider calculates audit evidence; and the third-party auditor verifies whether the to-be-audited file stored in the cloud is complete or not. According to the application, the TPA can be prevented from exploring privacy, certificate management is simplified, efficient and rapid identity authentication is realized, and real information of a user is hidden.
Owner:BEIJING INSTITUTE OF GRAPHIC COMMUNICATION

System for cloud solution migration and management

The system can receive data, including a specification for a cloud solution, indicating a type of cloud solution and at least one requirement. The system can determine a list of cloud service providers with cloud infrastructure capable of hosting the cloud solution and an ability to satisfy the at least one requirement. The system can rank the cloud service providers based on the capability to host the cloud solution and the ability to satisfy the at least one requirement. The system can select the cloud service provider based on the ranking. The system can generate an implementation procedure based on an Application Programming Interface (API) specification, where the API specification determines a requirement for the cloud solution to be deployed on the cloud infrastructure. The system can deploy, using a large language model (LLM), the cloud solution on the cloud infrastructure in accordance with the implementation procedure.
Owner:T MOBILE US INC

Machine learning-based system for cost and carbon footprint optimization in multi-cloud computing environments

A machine learning-based system for optimizing costs and carbon footprint in multi-cloud computing environments, consisting of: a data aggregation layer (101) for collecting real-time data on costs, resource usage and carbon emissions from multiple cloud service providers; a machine learning engine (102) to predict future costs and Carbon emissions based on historical data and current cloud service parameters; a multi-objective optimization engine (103) that selects deployment strategies to minimize both costs and carbon emissions according to predefined constraints; and a workload orchestration layer (104) for executing the optimized deployment plan.
Owner:DOSANAPUDI UDAY KUMAR NARAYANAPURAM +4

Game packet delivery method and game packet delivery system

A game packet delivery method and a game packet delivery system are provided. The method includes executing a game program by a user device; and transmitting at least one game packet related to the game program between the user device and a game server via a telecom server and a shared router in response to the execution of the game program. The shared router belongs to a decentralized network node, and the transmission of at least one game packet does not involve any server provided by cloud service providers. Therefore, the efficiency of transferring game packets between the user device and the game server can be improved, thereby improving the game experience of the end user. Besides, because the transmission of game packets does not go through the backbone network of the cloud service providers, it can also ensure the privacy of online games for users.
Owner:ASUSTEK COMPUTER INC

Model processing method and device, equipment, medium and product

The invention discloses a model processing method and device, equipment, a medium and a product. The method comprises the steps that each data owner trains an initial model based on training data to obtain a local model, and uploads the local model to a proxy server; the proxy server performs aggregation calculation on the local model set to obtain a global model, and sends the global model to the task publisher; if the task publisher detects that the global model does not reach convergence, performing performance test on the global model to obtain a target score corresponding to each data owner, screening the data owners based on the target scores corresponding to the data owners to obtain a data owner set, and storing the data owner set in a database; and sending the initial model to a data owner set, so that each data owner in the data owner set returns to execute the operation of training the initial model based on the training data by each data owner to obtain a local model, uploading the local model to the proxy server until the obtained global model converges, and sending the global model to the cloud service provider.
Owner:HANGZHOU XINYUN SEMICON GRP CO LTD

Processing and sending usage information of a private cloud network available from a first cloud service provider to a second cloud service provider

Techniques are disclosed for providing, by a first computing resource of a first cloud service provider (CSP), a first service to a user having a first user account with a second CSP, the first service provided via a first private network of the user with the second CSP. The techniques further include transmitting data between a second private network communicatively coupled with the first private network, the second private network associated with a second user account of the user with the first CSP. The techniques further include collecting, by a second computing resource of the first CSP, usage data associated with at least one of the first private network or the second private network. The techniques further include transmitting, by the second computing resource of the first CSP, the usage data to a second service of the second CSP.
Owner:ORACLE INT CORP

Used cached summaries for efficient access analysis for cloud provider entities

An access policy analysis system may use stored policy summaries to efficiently perform access analysis. A request that causes an access analysis of an entity in a cloud service provider with respect to a resource hosted in the cloud service provider may be received. An access policy summary generated for the entity based on a set of access policies applied by an access management system of the cloud service provider may be obtained. An access policy summary generated for the resource based on the set of access policies may be obtained. A tree structure that describes a hierarchy of entities in the cloud service provider may be traversed to identify a parent node of the entity in the hierarchy of entities. The access analysis may then be generated based on the access policy summaries for the identified node in the tree structure, for the entity and for the resource.
Owner:RAPID7 INC