Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

23 results about "Critical infrastructure" patented technology

Critical infrastructure (or critical national infrastructure (CNI) in the UK) is a term used by governments to describe assets that are essential for the functioning of a society and economy – the infrastructure.

System and Method for Analyzing Cyber Security Postures and Real-Time Asset Validation for Critical Infrastructure

A system and method for analyzing cybersecurity posture for an OT infrastructure includes categorizing a plurality of devices of one or more plants into levels, based on an exposure of each device to a communication network, identifying CVEs of components of the plurality of devices; assigning a severity value to the one or more CVEs of components and determining a plant cybersecurity posture score for the one or more plants; computing a critical infrastructure cybersecurity posture score for the OT infrastructure; and applying remediation to one or more vulnerable components based on a prioritization sequence.
Owner:ABB (SCHWEIZ) AG

A GNSS timing data prediction method and related equipment

This invention relates to the field of navigation and timing technology, specifically to a GNSS timing data prediction method and related equipment. The method involves acquiring Roland timing data when GNSS timing data is invalid and preprocessing it. The preprocessed data is then input into a trained single-hidden-layer extreme learning machine model. This model calculates the hidden-layer output matrix by randomly initializing the input layer weight matrix and bias vector, and solves for the output weights using regularized least squares. The model outputs a normalized GNSS timing data prediction value, which is then denormalized to obtain the final GNSS timing prediction result. This method combines the high stability of the Roland system with the efficient computational power of the extreme learning machine to achieve accurate GNSS timing data prediction. It is suitable for enhancing the resilience of positioning, navigation, and timing systems in critical infrastructure scenarios, ensuring the continuous operation of the system even when GNSS signals are interfered with or fail.
Owner:NAT TIME SERVICE CENT CHINESE ACAD OF SCI

Systems and methods for formal verification of computer platforms

Systems and methods for mathematical modeling of the hardware and software stack of commodity computer platforms are provided, enabling provable guarantees on memory, device, and program execution. This approach addresses the technical problem of reliance on system agents that rely on implicit trust in the operating environment, which can be exploited by sophisticated attackers using complex threats such as memory access exploits and code / data integrity exploits. The solution provides a proactive, mathematically-backed security solution that eliminates entire classes of cyberattacks by design, ensuring realizable guarantees on commodity computer platforms running hardware and software stack elements at the lowest operating level. This approach has significant advantages over current reactive cybersecurity methods, including reduced complexity and overhead, and increased confidence in the integrity of the system. The solution's main uses include providing mathematically-backed security and availability guarantees for critical infrastructure, financial institutions, and other organizations vulnerable to cyberattacks.
Owner:UBERSPARK INC

Key infrastructure network attack tracing method based on dynamic risk assessment

The invention discloses a key infrastructure network attack tracing method based on dynamic risk assessment, and particularly relates to the technical field of network and information security, session watermarks are generated through an entrance side, source aperture records are unified, a session chain is formed through cross-domain splicing, and a command sequence and assets are aligned; auditing records and measurement are extracted on the equipment side according to the command track, fluctuation irrelevant to the command is eliminated through adjacent comparison, and stable equipment response is obtained; a window alignment robust index and a command effect sensitive index are put forward, a discrimination rule is synthesized to generate a stripping sequence basis, commands are imported piece by piece in an isolation replay environment, a minimum command subset is selected in combination with a unified trade-off factor, and causal matching is verified through dynamic sorting of stripping strength coefficients. A matching result is backfilled to generate a responsibility-accounting label, settlement is performed to a dynamic risk vector, a disposal priority is formed, and the whole process can be audited and rechecked; the method solves the problems of evidence splitting, cause and effect unconfirmation and unstable responsibility of key infrastructures in a multi-hop environment.
Owner:WUHAN ANYU INFORMATION SECURITY TECH CO LTD

Power-Aware: DFOS Deployment A Hybrid Heuristic and Integer Linear Programming Strategy

A novel, two-stage Distributed Fiber Optic Sensor (DFOS) placement strategy and method that ensures resilient monitoring of critical infrastructure during electrical power supply failures. This strategy and method combines a heuristic algorithm, PURE (Power Source-aware Route Exploration), with Integer Linear Programming (ILP) optimization. The PURE algorithm explores potential DFOS routes while explicitly considering the dependency of DFOS devices on the electrical power distribution network, ensuring routes electrically powered by the same electrical power feeder are disjoint. Subsequently, the ILP selects the optimal set of DFOS placements to minimize the total number of deployed sensors while meeting critical infrastructure monitoring requirements, such as redundant monitoring for high-importance links. The method enhances the observability of critical links, achieving 100% monitoring coverage for important links during simulated power outages affecting an electric feeder.
Owner:NEC LABORATORIES AMERICA INC

Power grid network security anti-fact defense method based on multi-agent cooperation

The invention discloses a network security anti-fact defense method based on multi-agent collaboration, which comprises the following steps: deploying local defense agents with autonomous decision-making capability in different areas of a network, and setting a core defense agent oriented to global collaboration to carry out unified coordination and control on a multi-point linkage security policy; therefore, cross-region and cross-security domain cooperative defense is realized. The method is suitable for a power secondary system, an industrial control system, an industrial internet and other key infrastructure networks, and can also be popularized and applied to a cloud computing data center, a government affair private network and other network environments with complex topology and strict service continuity requirements. And the technical problems that an existing static boundary isolation and access control method lacks dynamic description capability on the influence of the service running state, the attack evolution process and cross-site linkage, and a timely, fine and interpretable defense decision is difficult to realize when the attack is quickly diffused or the service topology is frequently changed can be solved.
Owner:BENGBU POWER SUPPLY COMPANY STATE GRID ANHUI ELECTRIC POWER

Cross-domain collaborative emergency response and attack mitigation methods for critical infrastructure

This application relates to the field of cybersecurity technology and discloses a cross-domain collaborative emergency response and attack suppression method for critical infrastructure. The method includes: collecting and correlating security data from at least two independent security domains; performing identification and correlation analysis using a graph neural network model to generate a fused security posture describing a cross-domain attack chain; based on this fused security posture, generating an optimal collaborative response strategy with specific defensive actions and execution sequences through a preset attack-defense game model; parsing the strategy into layered security instructions to drive security execution devices within the target security domain to perform configuration operations; and coordinating security execution devices from multiple security domains to jointly address the cross-domain attack chain based on the configuration operations. This invention enables overall perception, intelligent collaborative decision-making, and integrated linkage suppression of high-level, cross-domain network attack chains, effectively improving the overall defense capabilities of critical infrastructure.
Owner:GUANGZHOU ELECTRIC POWER COMM NETWORK LTD

Reliable time synchronization device and method

PendingCN122293445ATime managementEngineering
This invention discloses a trusted time synchronization device and method, relating to the field of trusted time synchronization technology, including a trusted time management platform and a trusted time synchronization client. The trusted time management platform is used to complete platform identity authentication, service activation, time synchronization message and service management, real-time control of the time synchronization client, and time synchronization billing and evidence storage management. The trusted time synchronization client, based on dedicated hardware and a trusted execution environment, completes certificate application, login management, status reporting, time synchronization and metering management to achieve trusted time synchronization and accurate metering. This invention constructs a new trusted time synchronization system that is highly secure, verifiable, traceable, and operable, meeting the high reliability and commercial operation requirements of critical infrastructure for time benchmarks in the digital economy era.
Owner:SICHUAN TAIFU GROUND BEIDOU TECH CO LTD

Critical infrastructure blueprint selection for optimized response to state changing conditions

Critical infrastructure (CI) blueprint selection for optimized response to state changing conditions includes defining a hierarchy of interdependent CI elements of a community in a digital twin and receiving characterization data for different nodes of the digital twin. A fingerprint is generated for the hierarchy based upon the characterization and a blueprint which corresponds to the fingerprint retrieved from a data store, the blueprint defining a set of parameters to be applied to different computing elements of different nodes in the hierarchy determined to minimize a cascading effect of a state changing condition in one of the nodes. Finally, the set of parameters of the retrieved blueprint is applied to corresponding computing elements of the digital twin and a state changing condition is simulated in the digital twin in a selected node so as to compute the cascading effect of the state changing condition to other nodes dependent upon the selected node.
Owner:INLECOM GRP BV

Power-aware DFOS deployment a hybrid heuristic and integer linear programming strategy

A novel, two-stage Distributed Fiber Optic Sensor (DFOS) placement strategy and method that ensures resilient monitoring of critical infrastructure during electrical power supply failures. This strategy and method combines a heuristic algorithm, PURE (Power Source-aware Route Exploration), with Integer Linear Programming (ILP) optimization. The PURE algorithm explores potential DFOS routes while explicitly considering the dependency of DFOS devices on the electrical power distribution network, ensuring routes electrically powered by the same electrical power feeder are disjoint. Subsequently, the ILP selects the optimal set of DFOS placements to minimize the total number of deployed sensors while meeting critical infrastructure monitoring requirements, such as redundant monitoring for high-importance links. The method enhances the observability of critical links, achieving 100% monitoring coverage for important links during simulated power outages affecting an electric feeder.
Owner:NEC LABORATORIES AMERICA INC

Autonomous agentic ai defense framework for critical infrastructure

The present invention relates to an autonomous agentic artificial intelligence based defense system for protecting critical infrastructure from cyber threats through continuous, validated, and adaptive security operations. The system employs distributed processing units configured to analyze operational telemetry, network communication data, and control signals in real time to identify deviations from established infrastructure behavior. Artificial intelligence based characterization logic is applied to correlate detected deviations with stored threat profiles and infrastructure parameters, followed by multi-stage validation to confirm threat authenticity and severity. Adaptive learning mechanisms dynamically update characterization thresholds and validation parameters based on historical incidents and evolving attack patterns, enabling continuous improvement without manual reconfiguration.
Owner:BHAND NILESH DNYANESHWAR

Micro-service-based low-code development framework and method

PendingCN121433615ASoftware designSoftware reuseSoftware development processOperational system
The invention provides a low-code development framework and method based on micro-service, relates to the technical field of computers, and solves the technical problems that in the prior art, diversified software development requirements of enterprises are difficult to meet, and resource conflicts, deployment coupling and service avalanche are likely to occur in the software development process. The framework specifically comprises service support design, micro-service design, storage design and deployment design. The service support design is used for providing key infrastructure and public service for the micro-service system; the micro-service design is used for constructing a series of small micro-services capable of independently bearing a service function based on a service field and a responsibility boundary; the storage design is used for selecting an adaptive storage scheme according to data characteristics and business requirements; the deployment design is used for supporting deployment and operation of the micro-service application under different operating systems. The method is used for secondary development of software products and customized software.
Owner:ANHUI SUN CREATE ELECTRONICS

An artificial intelligence secure running system and method based on a hardware one-way data channel and a network-free kernel

This invention discloses an artificial intelligence (AI) secure operation system and method based on a hardware unidirectional data channel and a network-free kernel. The system includes a data access unit, an isolated AI computing unit, a hardware unidirectional data channel, and a security management terminal. The hardware unidirectional data channel enables unidirectional data transmission from the data access unit to the isolated AI computing unit at the physical layer. The isolated AI computing unit runs an operating system kernel stripped of general network communication protocol stacks, preventing processes running within it from actively establishing external network connections. By combining a hardware-level unidirectional transmission structure with kernel-level network capability limitations, an AI operating environment with unidirectional data input is constructed. This invention also supports collaborative computing with remote computing nodes through a controlled encrypted tunnel under the control of the security management terminal, and can be used in high-security AI deployment scenarios such as finance, government affairs, and critical infrastructure.
Owner:吴英杰

Dynamic formation and reconfiguration of standalone power systems for critical infrastructure

PCT designated stageWO2026146334A1Complex networkReliability engineering
A dynamic Stand-Alone Power System (SAPS) formation optimization system is developed to facilitate resilience in large utility sites with complex networks connected to multiple substations. The system ensures uninterrupted power to critical loads during substation outages while preventing reverse power flow (RPF). The system intelligently reconfigures the network at the feeder level and optimizes distributed energy resources (DERs). Operating in two phases, it first continuously evaluates how to form SAPS islands by allocating DERs to critical loads under current constraints, proactively preparing for outages and mitigating RPF risks. Once SAPS islands are formed, the system monitors and reassesses their configuration to improve service to critical loads. This adaptive and proactive approach enhances reliability and resilience in power distribution, ensuring essential operations are maintained even during disruptions.
Owner:EATON INTELLIGENT POWER LTD

Cascade time uncertainty-oriented infrastructure emergency repair cooperative scheduling method

PendingCN121981488ASpeed ​​up the optimization processAvoid unenforceability issuesOffice automationRepair timeRoad networks
The invention discloses an infrastructure emergency repair cooperative scheduling method for cascade time uncertainty, and relates to the technical field of emergency management and intelligent scheduling optimization. The method comprises the following steps: 1, carrying out structured modeling on a disaster infrastructure system, a failure unit, technicians and a road network topology; step 2, constructing a task allocation and collaborative path integrated optimization model with planning recovery time efficiency maximization as a target; 3, based on the mean variance and the normal quantile, establishing a probability constraint of step-by-step transmission and accumulation of the uncertainty of the repair duration and the arrival time along the path; step 4, realizing error controllable linearization of the square root relationship by adopting segmented secant lines; and 5, combining variable neighborhood search and integer programming local optimization to quickly solve and output an executable scheme. The method provided by the invention can effectively improve the timeliness of post-disaster first-aid repair and the robust performability of the scheme, and provides scientific decision support for the emergency first-aid repair of key infrastructures such as electric power, water supply, traffic, communication and the like.
Owner:BEIHANG UNIV

A patrol path decision method for unmanned systems in adversarial environments

This invention discloses a patrol path decision-making method for unmanned systems in adversarial environments, belonging to the field of autonomous unmanned systems and intelligent decision-making technology. The method includes: acquiring an undirected patrol topology graph of the physical environment to be patrolled; calculating the steady-state distribution of the target based on the value parameters, attack time parameters, and degree of each node; and defining a patrol strategy unpredictability index weighted by intra-strategy entropy and inter-strategy entropy. PSUI To address the uncertainty of strategies in terms of microscopic randomness and macroscopic diversity, a simulated annealing dual-entropy balance optimization algorithm is employed to maximize... PSUI To achieve the goal, a set of state transition matrix strategies is generated under the constraints of topological adjacency, row normalization, and target steady-state distribution. The unmanned system is then controlled to perform spatiotemporally decoupled patrols through random matrix switching and probabilistic transitions within the matrix. This invention unifies patrol strategy evaluation and optimization, significantly improves the unpredictability of patrol paths, and enhances the protection capabilities for critical infrastructure.
Owner:XIAMEN UNIV OF TECH

PTP network encryption and key management method, device, equipment, medium and product

The invention discloses a PTP network encryption and key management method and device, equipment, a medium and a product, and relates to the technical field of network security, and the method comprises the steps: obtaining a key pair distribution request, and generating and distributing an asymmetric public and private key pair to a target node based on the key pair distribution request; deploying the target node in the PTP network, and obtaining a data transmission encryption algorithm and a key request of the target node; the data transmission encryption algorithm and the key request comprise a node digital signature set based on an asymmetric public and private key pair; based on the PTP domain where the target node is located, correspondingly generating a data transmission encryption algorithm and a secret key, and distributing the algorithm and the secret key to the target node; wherein the basic nodes in different PTP domains are distributed with different data transmission encryption algorithms and keys, and the keys comprise a key for data communication and a key for PTP authentication. According to the invention, a comprehensive PTP security solution is provided for a high-security demand scene, and the PTP network security and reliability of the key infrastructure are improved.
Owner:THE FIFTH RES INST OF TELECOMM SCI & TECH CO LTD

Long-life filter device

To protect critical infrastructure from the adverse effects of volcanic ashfall, a natural phenomenon in Japan, we aim to provide a long-life filter system that can be used even during prolonged volcanic ashfall, and to meet the demand for proposals for volcanic ash filter systems. This system will protect major facilities and equipment from atmospheric volcanic ash or fine dust, ensure business continuity in emergencies, and protect defense facilities of national security agencies. The goal is to provide a long-life atmospheric dust filter system that blocks volcanic ash and atmospheric dust, allowing essential equipment such as cooling systems for critical machinery and facilities to always function normally. [Solution] A filter device in which a substantially corrugated filter material is attached to the filter surface, characterized in that the filter material is made of a material that prevents deformation of the attached shape of the filter material by air passing through the filter surface.
Owner:UNIPAC CO LTD

Containerized intelligent proxy gateway dynamic management system, method and equipment and storage medium

The invention discloses a containerized intelligent proxy gateway dynamic management system, method and device and a storage medium, the system integrates an intelligent routing function into a traffic scheduling module to form a decoupling type collaborative architecture of intelligent scheduling, deep analysis and multi-dimensional monitoring archiving, the technical contradiction that high-performance forwarding and deep analysis cannot be achieved at the same time is solved, and the system has a wide application prospect. And a dynamic rendering and script hot replacement mechanism is provided, so that the customization of system behaviors during operation is realized, the problem of rigid mirror image configuration of a static container is solved, enterprise-level resource isolation and process guarding capabilities are provided, the reliability of the system as a key infrastructure is guaranteed, and the system performance is improved. Through the asynchronous bypass monitoring archiving module, comprehensive monitoring of container states, performance indexes and user behaviors is achieved, specific protocols of all applications can be analyzed, user behavior data can be extracted and mapped to a unified interest label system, cross-application user portraits can be generated, and data support can be provided for commercial applications such as precision marketing and content recommendation.
Owner:CHUANGKE ZHILIAN (SHENZHEN) ELECTRONIC INFORMATION CO LTD

GNSS timing data prediction method and related equipment

The invention relates to the technical field of navigation and timing, in particular to a GNSS timing data prediction method and related equipment, and the method comprises the steps: obtaining and preprocessing Roland timing data when the GNSS timing data is invalid; and inputting the preprocessed data into a trained single hidden layer extreme learning machine model, calculating a hidden layer output matrix by the model through randomly initializing an input layer weight matrix and an offset vector, and solving an output weight by adopting a regularization least square method. And the model outputs a normalized GNSS timing data prediction value, and a final GNSS timing prediction result is obtained after reverse normalization processing. According to the method, high stability of the Rowland system and efficient computing power of the extreme learning machine are combined, accurate prediction of GNSS timing data is achieved, the method is suitable for positioning, navigation and time service toughness enhancement scenes of key infrastructures, and the continuous operation capacity of the system when GNSS signals are interfered or fail is guaranteed.
Owner:NAT TIME SERVICE CENT CHINESE ACAD OF SCI

Multi-stage network reconstruction recovery method based on structure perception

The invention discloses a multi-stage network reconstruction recovery method based on structure perception, which comprises the following steps of: identifying a path set influenced by a broken link in a network topological graph; generating a candidate path set for each influenced path in the network topological graph after the broken link is removed; for each candidate path, calculating the comprehensive structure similarity of the candidate path and the corresponding original path; calculating an end-to-end task success rate of each candidate path based on the real-time failure rate and path transmission delay of nodes and edges by considering a communication degradation factor; for each affected path, the candidate path with the maximum optimization objective function value is selected from the corresponding candidate path set to serve as a reconstruction path, a reconstruction result is output, and the optimization objective function comprises the comprehensive structure similarity. The method does not need training, can be completely explained and audited, and has remarkable engineering landing advantages in combat or key infrastructure scenes with extremely high requirements on safety and reliability.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Behavior feedback-based network space mapping method and system for gateway device communication

This invention provides a method and system for network space mapping of critical infrastructure devices based on behavioral feedback, belonging to the field of electronic digital processing technology. By analyzing the network IP addresses and connectivity status, port openness, communication protocol response characteristics, and service interaction information of different critical infrastructure devices, suspected critical infrastructure devices are classified and processed. Different mapping strategies are matched to critical infrastructure devices of different levels, thereby ensuring the effectiveness of mapping while reducing the impact on the operational stability of critical infrastructure devices. Access behaviors and interaction characteristics collected by decoy nodes are introduced into the network space mapping process. By performing correlation analysis between decoy behaviors and the characteristics of the mapping objects, the mapping results are verified and corrected, enabling the mapping results to distinguish between devices that only have network exposure and critical infrastructure devices that have been attacked and targeted, thus improving the authenticity of the mapping results.
Owner:XI AN JIAOTONG UNIV

Key infrastructure-oriented network attack risk grading early warning method

PendingCN122093186APrevent mismatching and misjudgmentavoid breakingSecuring communicationPathPingCyber-attack
The invention discloses a key infrastructure-oriented network attack risk grading early warning method, and relates to the technical field of industrial control network security, and the method comprises the steps: collecting a write instruction to form an information domain intention vector, collecting a physical domain background vector of target equipment, and generating a cross-domain synchronization tuple through time alignment; determining a state transition range, theoretical shortest physical time consumption and a physical reachable mark according to the cross-domain synchronization tuple and the physical dynamics constraint matrix library, and generating a classification matrix; according to the classification matrix, performing active mask bit inactivation and gating traversal on the physically unreachable nodes in the basic topology attack graph, and outputting an early warning level and a dangerous path sequence; blocking and retesting a physical state according to the early warning level and the dangerous path sequence, and generating a closed-loop log packet; according to the method, network alarm and physical state linkage judgment, attack path contraction and blocking result closed-loop right confirmation are realized.
Owner:HUNAN JIEYIXIN TECH CO LTD