Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

12545 results about "Computer security" patented technology

Computer security, cybersecurity or information technology security (IT security) is the protection of computer systems from the theft of or damage to their hardware, software, or electronic data, as well as from the disruption or misdirection of the services they provide.

Secure Systems of Guardrails for Securing the Use of Large Language Models (LLMS)

The present disclosure includes computer-implemented methods of guardrails for securely using large language models (LLMs). The method comprises monitoring user data flow using an application programming interface (API) and receiving an administrative policy from an administration communication interface. The method involves dynamically applying a plurality of LLM input inspectors to LLM input data. The application of the plurality of LLM input inspectors is based on the administration policy. The dynamic application of the plurality of LLM input inspectors is in sequence for latency optimization. The plurality of LLM input inspectors serve as LLM input guardrails for a plurality of secure deployed large language models (LLMs). The plurality of LLM input inspectors are configured by the administrative policy and validate the LLM input data to validated LLM input data based on the administration policy. Additionally, the method comprises dynamically applying a plurality of LLM output inspectors to LLM output data.
Owner:WITNESSAI INC

Security Methods and Systems for Multi-Agent Generative AI Applications

A system and method for securing inter-process communications (IPCs) between generative AI and external tool servers, including intercepting IPCs having a requested operation, performing a security analysis on the IPCs for security threats, performing a permission validation for permissions for the requested operation of each IPC, and either approving or blocking the requested operation of each IPC based on the security analysis and the permission validation.
Owner:MADISETTI VIJAY

Know your model and know your data systems and methods for transactions

In embodiments, systems and methods for configuring and deploying artificial intelligence driven transacting agents that are permitted to autonomously execute transactions on behalf of the individual or organization and configuring the transacting agent based on the agent configuration instructions and a set of predefined system prompts. The method further includes granting the transacting agent access to a digital wallet associated with the individual or organization and deploying the transacting agent to a public network, such that the transacting agent executes transactions on behalf of the individual or organization via one or more digital marketplaces using the digital wallet to which the transacting agent was granted access. In some embodiments, the transacting agent is granted access to the digital wallet using a consent token. In some embodiments, the method also includes hyper-personalizing and / or fine-tuning the agent.
Owner:STRONG FORCE TX PORTFOLIO 2018 LLC

Systems and methods for controlling rights related to digital knowledge

Systems and methods for controlling rights related to digital knowledge are disclosed. A sample system may include an input system to receive digital knowledge from a user, a tokenization system to tokenize the digital knowledge and a ledger management system to create, manage, and store things on a distributed ledger and provide provable access to the digital knowledge. A smart contract system may create a smart contract including triggering action is and respond with a defined smart contract action on an occurrence of the triggering event. The smart contract system may also process commitments to the smart contract.
Owner:STRONG FORCE TX PORTFOLIO 2018 LLC

Handling of certificates by intermediate actors

Handling of certificates by intermediate actors, including: receiving, by a proxy and from a client, a client certificate and a first private key; generating, by the proxy and based on the client certificate and the first private key, an intermediate certificate; generating, by the proxy and in response to a request from the client to connect to a destination, an alternate certificate for the destination; and providing, to the client, a certificate chain comprising the alternate certificate, the intermediate certificate, and the client certificate.
Owner:FORTINET INC

Communication method and device

The invention provides a communication method and device, and the method can be suitable for IOT or A-IOT scenes exemplarily. In the method, a tag device receives a first paging message sent by a reader-writer, the first paging message comprising first indication information indicating a first access opportunity; based on the first access opportunity, sending a first D2R message including a first identifier to the reader-writer, the first identifier being an identifier randomly generated by the first Internet of Things device; a first R2D message sent by the reader-writer is received, the first R2D message comprises a temporary identifier allocated to the first Internet of Things device, the temporary identifier comprises a second identifier and further comprises an identifier of the first paging message and / or an identifier of the first access opportunity, and the second identifier comprises all or part of identifiers in the first identifier. According to the method, the probability of conflict of the temporary identifiers allocated to the tag equipment by the reader-writer can be reduced, so that the network access success rate and the communication reliability of the equipment are improved.
Owner:HONOR DEVICE CO LTD

Methods, architectures, apparatuses, and systems for decentralized data control and access management

Procedures, methods, architectures, apparatuses, systems, devices, and computer program products for decentralized data control and access management. For example, a data owner may perform a subscription procedure to obtain verification credentials and an index (e.g., address, identifier) to public data control and access information. The data owner may perform a registration procedure to register ownership of data using the public data control and access information. The public data control and access information may include a public key. The public key is paired with a private trapdoor key to form a key pair. The data owner and a data consumer may perform an access procedure to grant access to registered data. For example, the registration procedure may verify collisions between a token hash, a data hash, and a data owner hash based on use of the key pair.
Owner:INTERDIGITAL PATENT HOLDINGS INC

Interactive analysis of multifaceted security threats within a compute environment

Data platforms described herein are configured to monitor a compute environment and facilitate interactive analysis of multifaceted security threats within the compute environment. Such a data platform may determine that one or more assets within the compute environment are possibly being targeted by a multifaceted security threat and present an interactive user interface. The user interface may be configured to display an identifier indicative of the multifaceted security threat, a set of selectable evidence items each associated with a different facet of the multifaceted security threat and assessed based on the monitoring of the compute environment, and a presentation pane for displaying information. As such, the data platform may detect a selection of a particular evidence item from the set of selectable evidence items and, in response to the selection, populate the presentation pane with information related to the particular evidence item. Corresponding methods, systems, and products are also disclosed.
Owner:FORTINET INC

Malicious prompt management for large language models

A method includes receiving, at a server from a user device, a user prompt segment to a large language model (LLM), obtaining an additional prompt segment from a prompt data source, identifying a electronic address in the prompt segment, replacing the electronic address with a placeholder to generate a updated prompt segment, generating a LLM prompt comprising the updated prompt segment and the user prompt segment, and sending the LLM prompt to the LLM. The method further includes receiving a response to the LLM prompt from the LLM, the response comprising the placeholder, replacing the placeholder with the electronic address to generate an updated response, and sending the updated response to the user device.
Owner:INTUIT INC

Enhanced quality of service-level security for wireless communications

This disclosure describes systems, methods, and devices for quality of service (QOS)-level security configuration in a packet data unit (PDU) session. A device may identify a first user plane security indication received from an application function of a wireless network; identify a second user plane security indication received from the application function; generate, based on the first user plane security indication, a first security configuration for a first QoS flow of a PDU session; generate, based on the second user plane security indication, a second security configuration for a second QoS flow of the PDU session, the first security configuration different than the second security configuration; decode a first packet received, from the UE, in the first QoS flow using the first security configuration; and decode a second packet received, from the UE, in the second QoS flow using the second security configuration.
Owner:INTEL CORP

Pool guardian and surveillance safety systems and methods

Drowning remains the leading cause of death for kids under the age of four. Provided herein are software and hardware technologies that allow for monitoring of water that rivals the performance of a real lifeguard human that may be assigned in doing surveillance of a pool. By incorporating at least two cameras with different points of views, high-definition speakers to interact with the responsible parties in a natural way, and computing power to process all the visual information to flawlessly track all the patrons and recognize their gestures, the system may possibly exceed a human performance in guarding the pool.
Owner:KOURAI INC

Systems and methods for detecting malicious webassembly modules under source code obfuscation

Systems, methods, and frameworks for detecting malicious WebAssembly (Wasm) modules under source code obfuscation are provided. The system is configured to accurately identify malicious behavior in Wasm modules irrespective of the specific malicious functionality and in the presence of source code obfuscation techniques. The detection process leverages a Vision Transformer (ViT) model to classify a Wasm module as benign or malicious, enabling robust identification of threats across diverse attack patterns. The system operates with substantially low runtime overhead on computing resources, making it suitable for integration into real-time web application environments.
Owner:FLORIDA INTERNATIONAL UNIVERSITY

Systems and methods for resolving code vulnerabilities through collaborative agents

Systems and methods for resolving code vulnerabilities through collaborative agents which may include accessing a code base of an identified vulnerability; configuring a plurality of autonomous agents, each comprising a predefined agent role associated with application security remediation process; executing a directed workflow of the plurality of agents, wherein the workflow is a conditional sequence of agent-driven processing steps for generating a proposed resolution to the identified vulnerability; and outputting a candidate resolution for the vulnerability based on results produced by the workflow.
Owner:HARNESS INC

Service management and orchestration for private and public mobile networks

A Private Mobile Network (PMN) orchestrator sends, to a controller for a public mobile network, a message indicating one or more network functions for a private mobile network slice for a private mobile network and configuration information for the private mobile network slice. In some examples, the message is a Global System for Mobile communications Association (GSMA) NEtwork Slice Type (NEST) extended to specify the one or more network functions for the private mobile network slice and the configuration information for the private mobile network slice. The message enables the public mobile network to deploy a public mobile network slice that extends the private mobile network slice.
Owner:JUNIPER NETWORKS INC

Apparatus and method for secure communication and integration with secure and non-secure root ports

Secure communication provided with secure and non-secure root ports. One embodiment comprises: a plurality of cores; a memory controller to couple to a memory; an interconnect fabric coupled to the plurality of cores and the memory controller; and a root complex to support end-to-end encrypted channels between devices, the root complex comprising: a root port to receive non-posted requests from a requestor device, the root port to associate a first tag value with a non-posted request to indicate whether the non-posted request is received over an end-to-end encrypted channel; and a bridge device to transmit the non-posted request with the first tag value and to subsequently receive a completion message including the first tag value, wherein the root port is to determine whether the completion message is to be encrypted in accordance with the end-to-end encrypted channel based on the first tag value.
Owner:INTEL CORP

Systems and methods for digital asset management

In some aspects, a component may generate an identification for a personal account based at least in part on user-asset heuristics, wherein the personal account is heuristically distinguished from an administrative account based at least in part on a number of users associated with an account that is either the personal account or the administrative account. The component may determine an owner identity of the owner associated with the personal account by linking the identification with an identity in a data source based at least in part on one or more heuristically determined identity attributes.
Owner:TENABLE INC

Automated security testing systems using multi-tiered language models

PendingUS20250335601A1Platform integrity maintainanceLocal languageSecurity testing
Cost-effective cyber security risk countermeasure systems and methods enable LLM-based automated security testing for managed cybersecurity services, without leaking sensitive information about target systems. In embodiments, this is accomplished by utilizing flexible local language models that identify and filter target system specific information when communicating with a public large language model to obtain highly accurate security testing patterns.
Owner:HITACHI LTD

Domain-knowledge guided agent framework for automated system analysis

There are provided systems and methods for a domain-knowledge guided agent framework for automated system analysis. An online transaction processor or other service provider may provide computing services and platforms to entities, which may require compliance enforcement for different policies, regulations, and the like. To provide compliance review, investigations, and enforcement in a computing system of a service provider, the service provider may implement an intelligent and automated agent and framework that may utilize different large language models for processing compliance investigation requests and queries. The agent may utilize the models to plan and execute tasks using an available toolkit of computing operations and capabilities for compliance investigation. A data guard module may also be used to ensure data privacy and security is maintained. Within a main task, sub-tasks may be executed by models with specific domain knowledge.
Owner:PAYPAL INC

Malicious encrypted traffic decryption method and system based on memory data analysis

The invention discloses a malicious encrypted traffic decryption method and system based on memory data analysis, and the method comprises the steps: reading process activity data of a target computer; determining a target malicious process, and obtaining a target malicious process identifier; reading the memory space of the target malicious process to obtain memory data; capturing a network communication data packet of the target malicious process; determining candidate memory data; sequentially moving and extracting byte sequences; calculating an information entropy value and a hash value of each byte sequence; selecting byte sequences of which the information entropy values are greater than a preset threshold value and the hash values are not repeated in all byte sequences, and generating a key candidate set; and performing decryption operation on the network communication data packet by using each byte sequence in the key candidate set as a decryption key to obtain an effective decryption key and decrypted data content. According to the invention, decryption and analysis of malicious encrypted traffic are realized.
Owner:北京中睿天下信息技术有限公司

Cyber security protection of electronic communications including detecting topic shifts

PendingUS20260019438A1Securing communicationOutbound communicationElectronic communication
Systems and methods for protecting electronic communications are described. A cyber security appliance may be configured to calculate a topic shift score for a communication by comparing a first lexical profile derived from the communication to a historical lexical profile established for an associated user. This analysis may be performed without using a large language model. The system may also parse communications to extract sensitive data and content from attachments, performing behavioral modeling on the extracted data. Based on the analysis, an autonomous response module may take a variety of mitigation actions. Furthermore, a security mailbox assistant module may perform a secondary, in-depth analysis on user-submitted communications and generate a deterministic report. For outbound communications, a data loss prevention architecture may divert messages for in-line analysis and may include a fail-safe timeout mechanism to ensure service continuity.
Owner:DARKTRACE HLDG LTD

Method and device for sharing host based on multiple input devices and electronic device

The invention discloses a method for sharing a host based on multiple input devices, and belongs to the technical field of computers, and the method comprises the following steps: after a management user logs in a multi-seat configuration tool, creating second seats with the same number as new input devices according to a Udev rule, and enabling the management user to be a user operating the input device corresponding to a first seat of the host; according to a binding instruction sent by the management user, the second seats and the new input devices are bound one by one, and operation users of the input devices corresponding to the second seats are common users; according to a permission configuration instruction sent by the management user, configuring an application window permission for each common user; and sending the binding relationship between the second seat and the new input device and the application window authority to a window manager, so that the window manager manages the application window according to the binding relationship and the application window authority. According to the invention, the problems of disordered management and complex configuration when multiple users share one host window are solved, and more flexible and efficient equipment management experience is provided for the users.
Owner:UNIONTECH SOFTWARE TECH CO LTD

Providing Access Continuity via Tenant-Specific Private Clouds

Systems and methods for providing continued access via a tenant-specific private cloud include monitoring an operation state of a cloud-based system to detect disruptions based on predefined conditions; enabling a disaster recovery mode in response to detecting a disruption in the cloud-based system; and responsive to activation of the disaster recovery mode, redirecting traffic associated with a tenant from the cloud-based system to a tenant-specific private cloud, the tenant-specific private cloud being configured to enforce tenant-specific policies and maintain access to internet, Software-as-a-Service (SaaS) applications, and private applications.
Owner:ZSCALER INC

Decentralized systems and methods for response generation to API calls

The present disclosure provides a system for decentralized handling of application programming interface (API) calls. The system comprises a peer-to-peer network including a plurality of nodes, each node being a user device, a relayer, or a resolver. Each node includes at least one hardware processor and at least one non-transitory memory storing instructions. When executed, the instructions cause the node to receive an encrypted API request from a user device, forward the encrypted API request to at least one resolver node, process the API request to generate an API response, and transmit the API response back to the user device. The peer-to-peer network may comprise a mesh network and utilize a Remote Procedure Call (RPC) architectural style. The system enables decentralized management of API calls without relying on centralized servers.
Owner:DEGENSOFT LTD

Security VPC security inspection orchestration and abstractions for all csps

A network device may receive one or more first user inputs in a security gateway creation user interface (UI) provided by a controller. A network device may query, by the controller, the CSP using Application Programming Interfaces (APIs) to retrieve information about applications within the at least one virtualized network environment including any services deployed within the at least one virtualized network environment. A network device may present a security status user interface that identifies the at least one virtualized network environment applications configured in the CSP account and a respective status indicating whether the at least one virtualized network environment is protected by the security gateway. A network device may receive a second user input within the security status user interface, the second user input is effective to enable protection of the at least one virtualized network environment by the security gateway.
Owner:CISCO TECHNOLOGY INC

Handling privileges while changing geographical regions

Techniques for handling vehicle privileges while changing geographical regions are disclosed. In some embodiments, a user equipment (UE) may be configured to, based on a determination that the UE is within a first geographical region associated with a first authority, receive first privilege information from a first wireless node within the first geographical region; based on a determination that the UE is within an overlapping region, operate the UE according to the first set of behavioral rules; and receive second privilege information from the second wireless node within the second geographical region, the second privilege information configured to enable the UE to operate according to a second set of behavioral rules determined by the second authority while within the second geographical region and not within the overlapping region.
Owner:QUALCOMM INC

Communication method and apparatus

This application relates to the field of communication technologies, and discloses a communication method and apparatus. A first communication apparatus receives capability information, where the capability information indicates that a second communication apparatus supports at least one of encrypting or decrypting a first message. The first communication apparatus encrypts the first message to obtain a second message, and sends the second message with a first timestamp, where the first timestamp indicates the sending time of the second message. According to the foregoing method, the first communication apparatus sends an encrypted message (that is, the second message) and the timestamp when the encrypted message is sent to the second communication apparatus, so that encrypted transmission can be performed on a message (for example, a clock synchronization message) that needs to be stamped, thereby improving security of the message transmission.
Owner:HUAWEI TECH CO LTD

Deterrent mat with spikes

The present disclosure provides a deterrent mat with spikes, which includes a base and a spike assembly. One end of the spike assembly is connected to the base and another end extends to a direction away from the base. The spike assembly at least includes a plurality of first deterrent spikes and a plurality of second deterrent spikes, and the first deterrent spikes and the second deterrent spikes are arranged on a same side. A height of the first deterrent spikes is less than that of the second deterrent spikes, and the first deterrent spikes and the second deterrent spikes are arranged alternately. By staggering the first deterrent spikes and the second deterrent spikes of different heights, the discomfort of animals during their climbing and staying may be effectively increased, thereby improving deterrent effects. The deterrent mat with spikes is simple structured and has good deterrent effects.
Owner:YIWU BEIXIN TECH CO LTD

Access method, device and equipment and computer readable storage medium

The invention discloses an access method, device and equipment and a computer readable storage medium, which are applied to the technical field of computers, and comprise the following steps: loading a consistency label list corresponding to an authorized access consistency domain; when an access request is initiated to a target consistency domain in the shared memory, performing permission verification on the access request through the consistency label list and the target consistency domain; when the permission verification is passed, determining whether an access conflict exists or not through a local access state cache and the type of the access request; if the access conflict exists, a controller arbitration engine is triggered, and the access request is executed according to an arbitration result; and if the access conflict does not exist, executing the access request. According to the method, the consistency label list and the access state cache are formulated for each device, the consistency problem existing when multiple devices access the shared memory in an existing system is solved, and efficient, low-conflict and flexible consistency guarantee can be achieved under the scene that multiple devices concurrently access the shared memory.
Owner:SHANDONG YUNHAI GUOCHUANG CLOUD COMPUTING EQUIP IND INNOVATION CENT CO LTD

Patient care system with conditional alarm forwarding

A patient care system is disclosed that includes a medical device such as an infusion pump. The medical device generates a data message containing information such as the status of the therapy being delivered, operating data or both. An alarm generating system assesses the data message from the pump and generates an alarm message if certain conditions established by a first set of rules are met. The alarm message is assessed according to a second set of rules as to whether to suppress the alarm message. The data message contains a required input for both the first and second algorithms. A dispatching system is adapted to forward the alarm message to an alarm destination according to a third set of rules. The alarm destination expresses an alarm upon receipt of the alarm message.
Owner:ICU MEDICAL INC