Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

14 results about "DMZ" patented technology

In computer security, a DMZ or demilitarized zone (sometimes referred to as a perimeter network or screened subnet) is a physical or logical subnetwork that contains and exposes an organization's external-facing services to an untrusted network, usually a larger network such as the Internet. The purpose of a DMZ is to add an additional layer of security to an organization's local area network (LAN): an external network node can access only what is exposed in the DMZ, while the rest of the organization's network is firewalled. The DMZ functions as a small, isolated network positioned between the Internet and the private network and, if its design is effective, allows the organization extra time to detect and address breaches before they would further penetrate into the internal networks.

Zero-trust cybersecurity enforcement in operational technology systems

In one embodiment, a method may implement a multi-layer cybersecurity model for a multi-layer distributed computer system which comprises a sensitive data resource, such as a computing environment with an operational technology (OT) layer with multiple zones, an information technology (IT) layer, a DMZ, and a cloud layer. The method can assess a policy based on a zero-trust model for the sensitive data resource. The method can receive one or more requests, at any layer of a multi-layer distributed computing system, to access the sensitive data resource and acquire identity information for a user account specified in the first request. The method can perform a multi-layer multi-factor authentication of the user account using the identity information and the multi-layer cybersecurity model. In response to authenticating the identity information, the method can acquire sensitive access data corresponding to the identity information. The method can determine a sensitive resource access value using the sensitive access data and the zero trust model. In response to determining the sensitive resource access value is above a predetermined threshold, the method can authenticate the user account.
Owner:XAGE SECURITY INC

One-way data security sharing method based on private cloud DMZ

The invention discloses a one-way data security sharing method based on a private cloud DMZ, particularly relates to the technical field of network security, and solves the problem of internal data security sharing under a strict one-way strategy of the private cloud DMZ. To-be-shared data and a sharing strategy are subjected to double encryption, binding and packaging through the sharing management server to generate a data sharing packet and an access credential, and the data sharing packet and the access credential are pushed to a DMZ area gateway server through a one-way network channel; during external access, the gateway locally decrypts and verifies strategy validity (including identity, timeliness and dynamic factors), and decrypts data response after verification is passed. According to the method, the risk that the DMZ is connected back to the intranet is eradicated, fine management and control of dynamic strategies are achieved, the method is compatible with an existing firewall architecture, access logs can be actively audited by the intranet, and a safe closed loop is formed.
Owner:XINJIANG UYGUR AUTONOMOUS REGION METEOROLOGICAL INFORMATION CENT (XINJIANG UYGUR AUTONOMOUS REGION METEOROLOGICAL ARCHIVES)

Network security protection method based on multiple heterogeneous isolation and related device

The invention discloses a network security protection method based on multiple heterogeneous isolation and a related device, the device comprises an intranet, an extranet and a DMZ area, the DMZ area is connected with the intranet and the extranet, a dual heterogeneous firewall and a Web application firewall are arranged in the DMZ area, and the method and the related device can improve the security of the intranet.
Owner:ZHUHAI TIANCHENG ADVANCED SEMICON TECH CO LTD

Subway signal system log intelligent analysis method, device, equipment and medium

PendingCN121644207AAlarmsSecuring communicationData aggregatorNetwork Compartment
The invention relates to a subway signal system log intelligent analysis method, device and equipment and a medium. The method is realized by constructing a multi-stage security architecture of an internal security network-network isolation region DMZ-public network, firstly, log data preprocessing and encryption are carried out in the network isolation region DMZ, secondly, reverse communication is blocked through unidirectional transmission hardware, and then, accurate analysis is carried out by utilizing a large model association version demand and log keywords, so that the log data encryption is realized. And finally, establishing a global knowledge base to mine common hidden dangers. Compared with the prior art, the method has the advantages that on the premise that absolute safety of the core production network is ensured, log data aggregation of the whole road network is achieved, and intelligent real-time analysis and early warning are carried out.
Owner:CASCO SIGNAL LTD

A multi-purpose network password service system

The application relates to the field of network password technology, and provides a multi-purpose network password service system, wherein a Web authentication service flow and a virtual machine access service flow of an Untrust domain are connected to a vLB in a DMZ domain and a vAG in the DMZ domain through SSLVPN and WAF; the vLB is connected to a login server through a firewall by the Web authentication service flow, and then connected to a desktop controller; the desktop controller is connected to a password service center through the Web authentication service flow; the password service center is connected to a user active directory AD through the firewall by the Web authentication service flow; the vAG is connected to the desktop controller through the virtual machine access service flow, and the vAG is connected to a user desktop through the firewall by the virtual machine access service flow; the user desktop is connected to the user active directory AD through the firewall by the virtual machine access service flow; and the password service center realizes the assistance of the cloud desktop of a customer in the password evaluation, and solves the problem of the password evaluation of the cloud desktop of the customer.
Owner:BEIJING HUIQUAN CHUANGAN TECHNOLOGY CO LTD

Kubernetes-based DMZ zone dynamic configuration access system, method, device and storage medium

The present application relates to a DMZ zone dynamic configuration access system, method, device and storage medium based on Kubernetes, wherein the system creates Ingress objects and Service objects corresponding to each computing service in the Kubernetes cluster through a deployment module, wherein the Ingress objects and Service objects are configured with corresponding forwarding rules; and the domain name resolution information of the CoreDNS component is configured; the terminal user's access request is forwarded to the Ingress controller through the Kubernetes cluster; the Ingress controller matches the corresponding forwarding rule based on the access request, and obtains the IP address of the computing service through the CoreDNS component, and the Ingress controller forwards the access request to the IP address, thereby realizing the convenience and scalability of the application in providing services to the outside world and improving the security of access to the internal network.
Owner:ZHEJIANG LAB

A meteorological data external service process and system based on DMZ security isolation

This invention discloses a meteorological data external service process and system based on DMZ secure isolation. The process includes the synchronous acquisition of shared meteorological data, meteorological data processing, and external service. A DMZ zone is introduced between the meteorological intranet and the Internet as an isolation zone for data transmission. Then, data element extraction and regional clipping are performed. The system includes a hardware support unit, a software support unit, a data service unit, a business support unit, a business application unit, and a user unit. The hardware support unit ensures the security of the intranet and DMZ through a tiered, one-way access policy via firewall. The software support unit supports the operation and service of upper-layer applications. The data service unit is responsible for acquiring meteorological data and industry-specific data. The business support unit provides business support. The business application unit provides meteorological data services and sharing functions to users. This invention enables secure transmission and efficient sharing of meteorological data for external service systems.
Owner:STATE QIXIANG INFORMATION CENT

Modular multifunctional air combat maneuverability instrumentation (ACMI) cybersecurity appliance

A multifunctional cybersecurity appliance is physically installable between a processing environment (e.g., an aircraft or other mobile platform) and external networks with which the processing environment is in communication. The modular appliance combines multiple cybersecurity and cryptographic modules within a hardened housing or chassis. For example, a perimeter firewall provides a demilitarized zone (DMZ) network providing a first line of defense by admitting or denying inbound traffic from suspicious addresses or ports. Cryptographic modules encrypt and decrypt secure data traffic. Next-generation firewall (NGFW) components provide further packet inspection of decrypted inbound traffic to guard against internal attacks. A security information and event management (SIEM) module monitors event logs from other components of the appliance and generates an alert when anomalous activity is detected.
Owner:ROCKWELL COLLINS INC

Modular and dynamic control of machines in network

The invention relates to a machine production line and a machine in the machine production line, in particular a machine in a machine production line for filling and packaging food and / or beverages. The machine includes an industrial computer (IPC) that implements a software-defined edge device for the machine and includes a virtual machine monitor. The virtual machine monitor provides a virtual operating platform to host and / or run corresponding services for operating the machine production line. According to an embodiment, the IPC or virtual machine monitor implements a non-military zone (DMZ) with its own network segment, within which a virtual operating platform is implemented. Further, the IPC may establish a connection with a network of the machine production line, the network interconnecting a plurality of machines, each including an IPC. The IPC is further designed such that it can distribute workloads between the machine and at least one second machine in the network of the machine production line.
Owner:KRONES AG

Network server connection

The invention relates to a network-server connection. The network-server connection (1) comprises an IoT network (2) and a DMZ server (3), wherein the IoT network (2) is configured to transmit IoT data (7, 9) to the DMZ server (3). Furthermore, the DMZ server (3) is configured to grant a user (6) of the DMZ server (3) access to the IoT data (7, 9).
Owner:ZF FRIEDRICHSHAFEN AG

An airport comprehensive energy management platform based on cloud deployment

The application discloses an airport comprehensive energy management platform based on cloud deployment, which comprises a server, storage resources, a bastion host, a cloud firewall security component, a safe access area and a DMZ external connection area; the server and the storage resources are arranged on an airport private cloud, the server adopts IaaS infrastructure level service provided by the airport private cloud, and the storage resources comprise cloud storage resources and a cloud database; the bastion host and the cloud firewall security component are used for operation and maintenance management and security protection of the server and the storage resources; the safe access area is used for connecting an energy subsystem through an energy data private network; and the DMZ external connection area is used for connecting an Internet of Things wireless metering instrument through an operator private network and connecting a third party platform or system through an Internet VPN tunnel; the application realizes panoramic monitoring, optimal scheduling and intelligent operation and maintenance of comprehensive energy by means of flat management of the airport energy subsystem on the basis of the airport private cloud and the integrated service network.
Owner:NR ELECTRIC CO LTD +1

Monitoring and data acquisition method and system based on MQTT edge-to-service

The invention discloses an SCADA method and system based on MQTT edge-to-service, and belongs to the technical field of industrial Internet of Things. The system adopts a five-layer architecture of an equipment layer, an edge layer, a centralized management and control layer, a development layer and a security isolation layer. The method is characterized in that edge nodes collect multi-protocol industrial equipment data at high frequency; the method comprises the following steps: integrating MQTTBroker and sFTP services by an edge controller deployed in a DMZ area to realize data aggregation, edge calculation and offline caching, and uploading data to a central server through independent dual channels; and the central server carries out centralized monitoring, analysis and instruction issuing. And the development layer realizes configuration multiplexing through a unified information model. The safety level is combined with DMZ isolation, double firewalls and transmission encryption to construct deep protection. The system solves the problems that a traditional SCADA system is difficult to expand, poor in heterogeneous compatibility, low in remote operation and maintenance efficiency and the like, and distributed monitoring which is low in cost, high in safety and easy to expand is achieved.
Owner:HONGJI TECHNOLOGY (SHANGHAI) CO LTD

Communication method, system and equipment of private edge cloud and cloud service platform, and medium

The invention provides a communication method, system and device for a private edge cloud and a cloud service platform and a medium, and relates to the technical field of cloud computing network communication, and the method comprises the steps: initiating an access request for the cloud service platform from an internal trusted network of the private edge cloud platform, transmitting the access request to a network non-military area of the private edge cloud platform through the first VPN tunnel; in a network non-military area of the private edge cloud platform, auditing and forwarding the access request to generate outbound traffic; and transmitting the outbound traffic from the network non-military area of the private edge cloud platform to the network non-military area of the cloud service platform through the second VPN tunnel, so that the cloud service platform provides response and / or service based on the outbound traffic. Based on the hierarchical network architecture, the private edge cloud can safely utilize resources and services of the cloud service platform, and the management efficiency and the operation and maintenance capability of the private edge cloud are improved.
Owner:SUPCON TECH CO LTD

Information security protection system for a power business environment management and control system

This invention relates to an information security protection system for a power business environment management and control system, comprising an external network unit, a DMZ zone, a security zone, and an internal information network. The external network unit is connected to the DMZ zone via a secure access platform and to the security zone via a firewall. The security zone is connected to the internal information network via isolation equipment. The DMZ zone includes a front-end access service module, a mobile message push service module, and an instant messaging service module. The external network unit includes external users and internal users. The security zone includes a back-end access service module, a basic service module, a platform service module, and an application service module. The internal information network includes a platform database, a marketing database, a data acquisition module, a data middleware platform, and an operation service module. This invention effectively improves the information security protection level of the power business environment management and control system, ensuring reliable system operation and data security.
Owner:STATE GRID FUJIAN ELECTRIC POWER CO LTD