Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

8684 results about "Computer security" patented technology

Computer security, cybersecurity or information technology security (IT security) is the protection of computer systems from the theft of or damage to their hardware, software, or electronic data, as well as from the disruption or misdirection of the services they provide.

Know your model and know your data systems and methods for transactions

In embodiments, systems and methods for configuring and deploying artificial intelligence driven transacting agents that are permitted to autonomously execute transactions on behalf of the individual or organization and configuring the transacting agent based on the agent configuration instructions and a set of predefined system prompts. The method further includes granting the transacting agent access to a digital wallet associated with the individual or organization and deploying the transacting agent to a public network, such that the transacting agent executes transactions on behalf of the individual or organization via one or more digital marketplaces using the digital wallet to which the transacting agent was granted access. In some embodiments, the transacting agent is granted access to the digital wallet using a consent token. In some embodiments, the method also includes hyper-personalizing and / or fine-tuning the agent.
Owner:STRONG FORCE TX PORTFOLIO 2018 LLC

Interactive analysis of multifaceted security threats within a compute environment

Data platforms described herein are configured to monitor a compute environment and facilitate interactive analysis of multifaceted security threats within the compute environment. Such a data platform may determine that one or more assets within the compute environment are possibly being targeted by a multifaceted security threat and present an interactive user interface. The user interface may be configured to display an identifier indicative of the multifaceted security threat, a set of selectable evidence items each associated with a different facet of the multifaceted security threat and assessed based on the monitoring of the compute environment, and a presentation pane for displaying information. As such, the data platform may detect a selection of a particular evidence item from the set of selectable evidence items and, in response to the selection, populate the presentation pane with information related to the particular evidence item. Corresponding methods, systems, and products are also disclosed.
Owner:FORTINET INC

Enhanced quality of service-level security for wireless communications

This disclosure describes systems, methods, and devices for quality of service (QOS)-level security configuration in a packet data unit (PDU) session. A device may identify a first user plane security indication received from an application function of a wireless network; identify a second user plane security indication received from the application function; generate, based on the first user plane security indication, a first security configuration for a first QoS flow of a PDU session; generate, based on the second user plane security indication, a second security configuration for a second QoS flow of the PDU session, the first security configuration different than the second security configuration; decode a first packet received, from the UE, in the first QoS flow using the first security configuration; and decode a second packet received, from the UE, in the second QoS flow using the second security configuration.
Owner:INTEL CORP

Systems and methods for detecting malicious webassembly modules under source code obfuscation

Systems, methods, and frameworks for detecting malicious WebAssembly (Wasm) modules under source code obfuscation are provided. The system is configured to accurately identify malicious behavior in Wasm modules irrespective of the specific malicious functionality and in the presence of source code obfuscation techniques. The detection process leverages a Vision Transformer (ViT) model to classify a Wasm module as benign or malicious, enabling robust identification of threats across diverse attack patterns. The system operates with substantially low runtime overhead on computing resources, making it suitable for integration into real-time web application environments.
Owner:FLORIDA INTERNATIONAL UNIVERSITY

Systems and methods for resolving code vulnerabilities through collaborative agents

Systems and methods for resolving code vulnerabilities through collaborative agents which may include accessing a code base of an identified vulnerability; configuring a plurality of autonomous agents, each comprising a predefined agent role associated with application security remediation process; executing a directed workflow of the plurality of agents, wherein the workflow is a conditional sequence of agent-driven processing steps for generating a proposed resolution to the identified vulnerability; and outputting a candidate resolution for the vulnerability based on results produced by the workflow.
Owner:HARNESS INC

Apparatus and method for secure communication and integration with secure and non-secure root ports

Secure communication provided with secure and non-secure root ports. One embodiment comprises: a plurality of cores; a memory controller to couple to a memory; an interconnect fabric coupled to the plurality of cores and the memory controller; and a root complex to support end-to-end encrypted channels between devices, the root complex comprising: a root port to receive non-posted requests from a requestor device, the root port to associate a first tag value with a non-posted request to indicate whether the non-posted request is received over an end-to-end encrypted channel; and a bridge device to transmit the non-posted request with the first tag value and to subsequently receive a completion message including the first tag value, wherein the root port is to determine whether the completion message is to be encrypted in accordance with the end-to-end encrypted channel based on the first tag value.
Owner:INTEL CORP

Systems and methods for digital asset management

ActiveUS20260023826A1Program/content distribution protectionData sourcePersonal account
In some aspects, a component may generate an identification for a personal account based at least in part on user-asset heuristics, wherein the personal account is heuristically distinguished from an administrative account based at least in part on a number of users associated with an account that is either the personal account or the administrative account. The component may determine an owner identity of the owner associated with the personal account by linking the identification with an identity in a data source based at least in part on one or more heuristically determined identity attributes.
Owner:TENABLE INC

Cyber security protection of electronic communications including detecting topic shifts

PendingUS20260019438A1Securing communicationOutbound communicationElectronic communication
Systems and methods for protecting electronic communications are described. A cyber security appliance may be configured to calculate a topic shift score for a communication by comparing a first lexical profile derived from the communication to a historical lexical profile established for an associated user. This analysis may be performed without using a large language model. The system may also parse communications to extract sensitive data and content from attachments, performing behavioral modeling on the extracted data. Based on the analysis, an autonomous response module may take a variety of mitigation actions. Furthermore, a security mailbox assistant module may perform a secondary, in-depth analysis on user-submitted communications and generate a deterministic report. For outbound communications, a data loss prevention architecture may divert messages for in-line analysis and may include a fail-safe timeout mechanism to ensure service continuity.
Owner:DARKTRACE HLDG LTD

Deterrent mat with spikes

The present disclosure provides a deterrent mat with spikes, which includes a base and a spike assembly. One end of the spike assembly is connected to the base and another end extends to a direction away from the base. The spike assembly at least includes a plurality of first deterrent spikes and a plurality of second deterrent spikes, and the first deterrent spikes and the second deterrent spikes are arranged on a same side. A height of the first deterrent spikes is less than that of the second deterrent spikes, and the first deterrent spikes and the second deterrent spikes are arranged alternately. By staggering the first deterrent spikes and the second deterrent spikes of different heights, the discomfort of animals during their climbing and staying may be effectively increased, thereby improving deterrent effects. The deterrent mat with spikes is simple structured and has good deterrent effects.
Owner:YIWU BEIXIN TECH CO LTD

Tamper-resistant end-to-end service data evidence storage method and system

The invention discloses a tamper-resistant end-to-end service data storage method and system, and relates to the technical field of service data storage methods, and the method comprises the steps: initializing a hardware security module and a monotone increasing clock in terminal equipment, building a unique identity identifier of the equipment, and preparing a log environment for recording service data; the method comprises the following steps: collecting current business data and associated meta-information thereof, and constructing input content of current data processing in combination with an equipment identity, a clock value, a data structure template and an abstract value generated by previous business data; hash operation is carried out on the input content to generate an abstract of the business data, the abstract is signed by using a hardware security module to form an equipment side digital signature, and the abstract, the signature and meta-information are written into a log only increasing but not changing and an offline queue; and after the terminal recovers the network connection, generating a unique idempotent key based on the abstract of the service data or the combination of the equipment identity and the clock, and submitting an evidence storage request containing the abstract and the signature to the server.
Owner:北京跃创三品文化科技有限公司

Ai-based malicious activity detection using a threat actor profile

Techniques are described herein that are capable of performing AI-based malicious activity detection using a threat actor profile. An alert is received. The alert indicates that a potentially anomalous event has occurred with regard to an entity. A profile of a threat actor is generated using information that describes behavior of the threat actor. An artificial intelligence (AI) model is triggered to determine whether the threat actor performs a malicious activity with regard to the entity by providing an AI prompt as an input to the AI model. The AI prompt includes the profile of the threat actor and a description of the potentially anomalous event. The AI prompt requests a determination whether the threat actor performs the malicious activity with regard to the entity.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Security protection method for power mobile application based on swan-gap microkernel

The invention relates to an electric power mobile application security protection method based on a swan gap microkernel, which comprises the following steps of: S1, establishing a hardware trust root, and storing a device root key and a certificate chain by utilizing a non-tampering storage area built in a chip; s2, establishing a complete trusted boot chain based on a hardware root of trust, and verifying the integrity and credibility of the next layer by each layer from Bootloader to a swan microkernel and then to an application program; s3, constructing a triple authentication system based on user identity, equipment identity and biological characteristics, and performing user authentication; s4, according to a user authentication result, realizing fine-grained authority control based on an RBAC model and ABAC, and ensuring that authority check can be executed during resource access every time by utilizing an IPC security mechanism of a swan micro kernel; and S5, creating an independent execution environment for each power application according to the process isolation capability of the swan microkernel, and ensuring that memories among the applications cannot be mutually accessed through virtual address space isolation. The reliability of power mobile application safety protection is effectively improved.
Owner:STATE GRID INFORMATION & TELECOMM GRP CO LTD +1

Secure provisioning and rotation of certificates for edge devices

A certificate management service (CMS) may securely provision and rotate certificates for edge devices. The CMS may pre-register a unique device ID of an edge device (e.g., provided by the device manufacturer). When the edge device is installed at the client's remote network, it is provisioned with a common bootstrap certificate that allows the edge device to initially establish a secure to connection to a local hub device and to request a client certificate. The CMS receives the request for the client certificate, which includes the unique device ID. Since the unique device ID was pre-registered at the CMS, the CMS authenticates the request for the client certificate. The CMS causes a signed client certificate to be delivered back to the edge device, which may be used by the edge device to establish subsequent secure connections.
Owner:AMAZON TECH INC

Apparatus, methods, and computer programs for protecting sensitive data

There is provided a method, computer program, and an apparatus for a network function service consumer, that causes the apparatus to perform: retrieving, from a first repository function, protected sensitive data; retrieving, from a second network function, at least one encrypted key; decrypting the retrieved at least one encrypted key using a private key associated with the network function service consumer to obtain a respective at least one key; and performing at least one of: decryption of the protected sensitive data using the at least one key to obtain sensitive data or integrity protected sensitive data; or verification of the integrity of the protected sensitive data using the at least one key.
Owner:NOKIA TECHNOLOGIES OY

Analysis and prioritization of vulnerabilities of connected vehicles

An automotive cybersecurity platform receives vulnerability alerts that may impact a connected vehicle. Software components of the connected vehicle are identified and listed. Software components that are affected by a vulnerability are identified using information from a vulnerability alert. An overall risk score of the vulnerability is determined based at least on whether the vulnerability can be triggered, how the vulnerability affects the connected vehicle when the vulnerability is triggered, and an intrinsic risk posed by the vulnerability. Remediation of the vulnerability is prioritized based at least on the overall risk score of the vulnerability.
Owner:VICONE CORP

Intelligently delivering a telephone call with identity attributes

Telephone calls can be intelligently delivered with identity attributes as described herein. In one example, a system can receives communication associated with a caller requesting to make a telephone call to a recipient, where the communication includes a recipient identifier associated with the recipient. The system can determine a terminating telecommunication service provider (TTSP) to which the telephone number is assigned. The system can then determine identification options available at the TTSP, where each identification option can be configured to provide one or more identity attributes associated with the caller to the recipient. The system can select one or more of the identification options based on a predefined policy and modify the communication to include the one or more identity attributes associated with the one or more selected identification options, thereby producing a modified communication. The system can then transmit the modified communication along a call route to the TTSP.
Owner:NUMERACLE INC

Method, device and computer program for cloud-authenticated pairing in wireless communication system, and recording medium therefor

The present disclosure relates to a method, device and computer program for cloud-authenticated pairing in a wireless communication system, and a recording medium therefor. A method for carrying out account-based pairing in a wireless communication system, according to one embodiment of the present disclosure, may comprise the steps in which: a seeker device acquires credential information of a provider device from a server; the seeker device acquires, from the provider device, an advertising packet comprising a hash value which is based on the credential information; and the seeker device establishes a connection with the provider device on the basis of the acquired credential information and the hash value which is based on the acquired credential information.
Owner:INTELLECTUAL DISCOVERY CO LTD

Multi-tenant adaptive cooperative defense method and system in hybrid cloud scene

The invention discloses a multi-tenant adaptive cooperative defense method and system in a hybrid cloud scene, and the method comprises the following steps: obtaining a remote credible proof of hardware, verifying the credibility of a tenant agent and the integrity of a code based on the remote credible proof, granting a mark, and detecting cloud information to generate a machine readable portrait containing key parameters; collecting local multi-mode log data coding embedding vectors of tenants, and after privacy processing, calculating that the abnormal confidence exceeds a threshold value by a local model to trigger current limiting or blocking; and constructing a hierarchical federated architecture containing local nodes of tenants, a regional cloud and a global control plane, encrypting aggregation parameters to generate a cross-tenant attack recognition global model and issuing the cross-tenant attack recognition global model to each tenant on the premise that log data is not out of a domain. According to the invention, integrity verification is carried out on the tenant side security agent through the trusted access mechanism, and the tenant portrait is constructed based on the trusted mark, so that the real and verifiable cooperative defense capability among a plurality of tenants is realized, and the cooperative process has dependency.
Owner:BEIJING GUOXIN LANDUN TECH CO LTD

Method to detect and prevent business email compromise (BEC) attacks associated with new employees

Techniques for an email-security detection system to analyze incoming emails for Business Email Comprise (BEC) attacks of targeted new email users in an enterprise based on peer models of email recipients in an enterprise and the conversation history of recipients. A method is disclosed that includes analyzing an incoming email and identifying one or more recipients of the incoming email in an enterprise network; analyzing contextual information in the incoming email for the email intent, and associating the email with a target recipient; applying a relational model associated with peers of the target recipient for detecting whether the incoming email is a business email compromise (BEC) attack directed to the target recipient; applying a relationship model of other recipients of the incoming email for detecting whether the BEC attack is associated with the target recipient; and determining, whether the incoming email is a BEC attack.
Owner:CISCO TECHNOLOGY INC

Secure Large Language Model Data Gateway

Aspects of the disclosure relate to providing a secure large language model data platform. The secure large language model uses a machine-learning large language model and gateway to prevent attacks and unauthorized access to enterprise-managed information and resources. The secure large language model may utilize pre-enrollment at a secure gateway providing a unique identification to each client. A private / public key pair may be generated and stored in the secure gateway database and large language model respectively. In some embodiments, a unique anonymization rule set may be generated and used for each client. Threat actors cannot query the large language model directly based on the pre-enrollment process. Unauthorized requests cannot be decrypted by the large language model due to missing paired keys.
Owner:BANK OF AMERICA CORP

Multi-protocol integration method and device, equipment, storage medium and program product

The invention relates to a multi-protocol integration method and device, equipment, a storage medium and a program product, which are applied to a bastion host, and the bastion host comprises a communication port. The method comprises the following steps: firstly, receiving a first access request generated based on a first protocol and sent by each client through a communication port, then, determining target equipment needing to be accessed by each client according to the first access request, then, determining a second protocol supported by each target equipment based on preset configuration of each target equipment, and finally, sending the second protocol to the client through the communication port. And converting each first access request based on the first protocol and the second protocol, determining a second access request of each client, and accessing the corresponding target device through the second access request. By adopting the method, the number of communication ports can be reduced, so that the network attack surface is reduced, potential security holes and threats are reduced, and the access security of the target equipment is improved.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Trustworthiness of a video data stream

Aspects of a trustworthiness check of a video data stream are described. According to a first aspect, a unique identifier which identifies a media asset to which a portion of a video data stream to be checked on trustworthiness belongs, is included into the trustworthiness check. According to a second aspect, a certificate of a content provider for performing the trustworthiness check is retrieved from a track of editors stored at an external resource. A third aspect provides a method for identifying a portion of a video data stream to be checked on trustworthiness using a digital signature. According to a fourth aspect, a digital signature for checking a portion of a video data stream is retrieved from an external resource.
Owner:FRAUNHOFER GESELLSCHAFT ZUR FORDERUNG DER ANGEWANDTEN FORSCHUNG EV

User equipment security key updates without random access

Embodiments include methods for a user equipment (UE) configured for mobility between cells of a radio access network (RAN). Such methods include receiving, from the RAN via a first cell, a first message that includes an indication to perform a security key update and updating one or more access stratum (AS) security keys based on the indication. Such methods include transmitting, to the RAN via a second cell, a second message that indicates a security key update has been performed. The second message is transmitted without the UE performing a random access (RA) to the second cell in conjunction with the security key update. Other embodiments include complementary methods for a RAN node, as well as UEs and RAN nodes configured to perform such methods. Figure 9 is selected for publication.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Systems and methods for reducing seed theft in planting operations

A method for transferring seed during a planting operation includes receiving, by a theft detection system, a first equipment identity of first equipment, receiving the seed into a seed bin of second equipment from the first equipment, determining, using a sensing device disposed on the second equipment and communicatively coupled to the theft detection system, a first weight value indicative of weight of the seed received into the seed bin from the first equipment, and at least one of transmitting, by the theft detection system using a satellite data communication protocol, the first weight value and the first equipment identity to a tracking system, and determining, by the theft detection system, whether any of the seed was stolen based on the first weight value and the first equipment identity and selectively generating and transmitting a notification to the tracking system indicating that the seed was stolen.
Owner:KUHNS PHILIP

Driving authority management method and device based on biological characteristic verification and medium

The invention provides a driving authority management method and device based on biological feature verification and a medium, and belongs to the technical field of vehicles. The method comprises the steps of collecting facial features, voiceprint data and driving behavior data by detecting a starting operation of a current driver; the identity of the current driver is recognized by using a multi-modal biological recognition algorithm, and the accuracy and anti-counterfeiting capability of identity verification are improved by adopting a bimodal fusion scheme of face recognition and voiceprint recognition; when it is determined that identity recognition of the current driver succeeds, a driving account is determined to judge whether the driver has the use permission or not, a binding relation of driver identity-account-function permission is established, and accurate matching of the intelligent driving permission and the driver qualification is achieved; the open state of the intelligent driving function is dynamically controlled based on a permission verification result, if the permission exists, the intelligent driving function is automatically prepared, if the permission does not exist, the function is locked, a clear prompt is given, and the safety risk that the intelligent driving function is used before being learned is avoided from the source.
Owner:CHINA FAW CO LTD

Trustworthiness of a video data stream

Aspects of a trustworthiness check of a video data stream are described. According to a first aspect, a unique identifier which identifies a media asset to which a portion of a video data stream to be checked on trustworthiness belongs, is included into the trustworthiness check. According to a second aspect, a certificate of a content provider for performing the trustworthiness check is retrieved from a track of editors stored at an external resource. A third aspect provides a method for identifying a portion of a video data stream to be checked on trustworthiness using a digital signature. According to a fourth aspect, a digital signature for checking a portion of a video data stream is retrieved from an external resource.
Owner:FRAUNHOFER GESELLSCHAFT ZUR FORDERUNG DER ANGEWANDTEN FORSCHUNG EV

Express processing method and system based on intelligent door lock, intelligent door lock and storage medium

The invention discloses an express processing method and system based on an intelligent door lock, the intelligent door lock and a storage medium, and the method comprises the steps: waking up a cat eye for visitor recognition when an express assistant function is started; if the courier is recognized, the courier is prompted through voice whether the user needs to sign for express delivery, whether a sign-in code is needed and whether a pick-up code is needed; determining a demand of a courier; if the demand of the courier is that the user needs to sign for express delivery or a sign-for code is needed, inputting a to-be-signed express delivery number, matching the sign-for code according to the to-be-signed express delivery number, and broadcasting the sign-for code; and if the demand of the courier is that a pickup code is needed, inputting a returned express number, matching a pickup code according to the returned express number, and broadcasting the pickup code. According to the invention, the express delivery signing and returning of the user are effectively processed through the intelligent door lock, the express delivery of the user is conveniently managed, and the safety, convenience and efficiency are improved.
Owner:SHENZHEN KAADAS INTELLIGENT TECH CO LTD

Methods and systems for prevention of attacks associated with the domain name system

The attack vectors for some denial-of-service cyber attacks on the Internet's Domain Name System (DNS) are bad, bogus, or unregistered domain name DNS requests to resolve domain names that are not registered in the DNS. Some other cyber attacks steal sensitive data by encoding the data in bogus domain names, or domain names otherwise not registered in the DNS, that are transferred across networks in bogus DNS requests. A DNS gatekeeper may filter in-transit packets containing DNS requests and may efficiently determine if a request's domain name is registered in the DNS. When the domain name is not registered in the DNS, the DNS gatekeeper may take one of a plurality of protective actions. The DNS gatekeeper drops requests determined not to be legitimate, which may prevent an attack.
Owner:CENTRIPETAL NETWORKS INC

Payment system, method and device, storage medium and electronic equipment

The embodiment of the invention discloses a payment system, which is characterized in that a non-accepting device receives commodity information of a to-be-settled commodity and a first collection amount sent by a merchant collection device on one hand, acquires a payment identifier of a payment user on the basis of non-contact communication with a user terminal on the other hand, and sends the payment information to the payment user on the basis of the payment identifier and the first collection amount; and settlement information associated with the commodity information of the to-be-settled commodity is generated and sent to a settlement system, and the settlement system determines a second collection amount according to a marketing rule corresponding to the commodity information and the first collection amount, and performs settlement payment according to the second collection amount and the payment identifier. Through the payment system, only the marketing rules need to be pre-configured in the settlement system, and the payment staff and the payment user do not need to carry out any additional operation, so that settlement payment can be carried out for the payment user by using the pre-configured marketing rules in the payment process of the payment user; the convenience of commercial tenants and users participating in marketing activities in an offline retail scene is effectively improved.
Owner:ALIPAY (HANGZHOU) INFORMATION TECH CO LTD