Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

19 results about "Embedded security" patented technology

Embedded system security is a strategic approach to protecting software running on embedded systems from attack. An embedded system is a programmable hardware component with a minimal operating system and software. New Trend in IoT: Digital Twin Tech.

Neuro-Generative Adversarial System for real-time detection and combating of malware morphing in high-density edge networks

ActiveDE202025106911U1Platform integrity maintainanceData packEmbedded security
A system for real-time detection and mitigation of morphing malware in high-density edge networks, consisting of: a data acquisition unit configured to receive, normalize, and encode multimodal telemetry data streams originating from at least one of the following domains: network traffic, process behavior, system call sequences, binary instruction traces, and control flow graphs; the data acquisition unit is further configured to compute feature embeddings over sliding time windows and apply privacy-preserving redactions prior to storage; a generative neural processor that is operationally coupled to the data acquisition unit and configured to generate synthetic morphing malware variants by learning probabilistic transformations of previously observed malicious data representations, maintaining semantic functionality while varying structural and behavioral features; a discriminative neural processor trained adversarially with the generative neural processor, wherein the discriminative neural processor is configured to detect morphing malware by evaluating a probability distribution over multimodal telemetry embeddings and classifying anomalous process and flow behaviors in real time; a coordination processor that is communicatively connected to both the generative neural processor and the discriminative neural processor and is configured to orchestrate adversarial co-training, regulate detection thresholds, calculate reinforcement-based penalties for false negative results, and trigger countermeasures as soon as a detection confidence level exceeds a predefined adaptive threshold; a secure, system-integrated inference and enforcement unit configured to perform low-latency countermeasures at the network edge, including selective packet filtering, flow isolation, process interruption, or system microsegmentation, based on instructions from the coordinating processor; and a hardware-embedded security enclave that is embedded in the system and configured to store cryptographic keys, neural model parameters, and integrity affirmation data to ensure the confidentiality, authenticity, and immutability of model artifacts and policy configurations.
Owner:ANAJAVADIDHODDI RAMACHANDRA NAIK CHAYAPATHI BENGALURU +7

Lightweight security protection method for file permission access in localized scene

The invention discloses a lightweight security protection method for file permission access in a localization scene, and belongs to the technical field of information security and localization system security. According to the method, the attack process is effectively delayed and automatic attacks are blocked through three aspects of technologies, including file access interception and underlying authority control, virtual Shell hiding and induction, and external command hiding and path migration. Meanwhile, a set of user-oriented file permission access and Shell obtaining and approving system is formulated, a set of file permission access management and control mechanism is formed, and safety energizing and force applying are carried out on a localized system. According to the lightweight security protection method, the limitation of a traditional method is broken through, a security policy is embedded into a file system and a command path, the lightweight security protection method is suitable for a domestic system in a specific scene, and on the premise that normal users and operation and maintenance process availability are guaranteed, attack chain execution can be effectively delayed, automatic attacks are prevented, and system security is enhanced.
Owner:BEIJING AEROSPACE WANYUAN TECH CO LTD

Relay protection embedded security gateway device

PendingCN121356870ANetwork connectionsSecuring communicationEmbedded securityProxy server
The invention relates to the technical field of embedded system network security, and provides a relay protection embedded security gateway device, which comprises a proxy server module for analyzing a downlink message to perform user login authentication, authority auditing and routing addressing, and performing auditing log recording and transparent forwarding on an uplink message, realizing one-to-many proxy communication based on the frame head addressing information; the authority auditing module is linked with the proxy server module and the auditing log module and is used for directly disconnecting the request which does not pass the authority verification; the audit log module is used for recording user operation events, permission change and system security events, supporting multi-format log storage and management and realizing log rolling recording and roll file exporting through a database; and the user management module is used for realizing full-life-cycle management of user identities and supporting password strength strategy configuration and a continuous wrong login locking mechanism. The method is suitable for network security protection of the power embedded device, and has the advantages of low invasiveness and high maintainability.
Owner:NANJING GUODIAN NANZI POWER GRID AUTOMATION CO LTD

Connectivity framework having unified stack and messaging protocol for embedded secure connectivity

An apparatus comprises a computing device including one or more processors, multiple peripheral communication devices of different communication protocol types operably connected to the one or more processors, and a memory to store processor-executable instructions comprising an application layer protocol stack. The processor-executable instructions are such that, when executed by the one or more processors, cause the one or more processors to perform operations for respective ones of messages to be communicated to and from the computing device via respective ones of the multiple peripheral communication devices. The operations comprise communicating the respective ones of messages via the respective ones of the multiple peripheral communication devices according to a unified messaging protocol that is common to the multiple peripheral communication devices.
Owner:MICROCHIP TECHNOLOGY INC

Digital document with enhanced security and tracking

PendingUS20260099612A1Digital data protectionEmbedded securityData set
Systems and methods for generating digital documents with embedded security features are provided. Methods may include receiving a first dataset comprising content data that was manually inputted by a system user, receiving a second dataset comprising an identifier associated with the system user, receiving a third dataset comprising a location associated with the system user, and cryptographically embedding, via a machine-learning (ML) module, the second and the third datasets into the first dataset to create a fourth dataset. In the fourth dataset, the first dataset may be visible to a human viewer while the second and the third datasets are invisible, and the second and third datasets may be extractable by a trusted system in possession of a cryptographic key. Methods may include generating an output document displaying the fourth dataset.
Owner:BANK OF AMERICA CORP

System, method and device for installing eSIM configuration file, and terminal equipment

PendingCN122069503ADigital data protectionSecurity arrangementEmbedded securityTicket
The invention relates to the technical field of embedded security, and discloses an installation system of an eSIM configuration file, which is applied to terminal equipment, and the installation system comprises a communication interface configured to receive an instruction data packet sent by an SM-DP + server, the instruction data packet comprises a security load and an execution bill, the security load is an eSIM configuration file encrypted based on a public key of an eSE asymmetric key pair; the fusion security domain comprises an eSE and an embedded universal integrated circuit card (eUICC), and the eSE is in secure communication with the eUICC; the routing logic unit is configured to route the instruction data packet to the eSE by hardware; wherein the eSE is configured to verify the execution bill, decrypt the security load based on a private key of the asymmetric key pair of the eSE after the verification is passed, so as to obtain an eSIM configuration file, and transmit the eSIM configuration file to the eUICC in a streaming manner; the eUICC is configured to perform an installation of the eSIM profile. According to the method, the security, reliability and anti-attack capability of eSIM configuration file installation can be improved. The invention further discloses an eSIM configuration file installation method and device and terminal equipment.
Owner:BEIJING TSINGTENG MICROSYSTEM CO LTD

Connectivity framework having unified stack and messaging protocol for embedded secure connectivity

An apparatus comprises a computing device including one or more processors, multiple peripheral communication devices of different communication protocol types operably connected to the one or more processors, and a memory to store processor-executable instructions comprising an application layer protocol stack. The processor-executable instructions are such that, when executed by the one or more processors, cause the one or more processors to perform operations for respective ones of messages to be communicated to and from the computing device via respective ones of the multiple peripheral communication devices. The operations comprise communicating the respective ones of messages via the respective ones of the multiple peripheral communication devices according to a unified messaging protocol that is common to the multiple peripheral communication devices.
Owner:MICROCHIP TECHNOLOGY INC

Firmware updating method and device for embedded equipment, equipment and storage medium

The embodiment of the invention provides a firmware updating method and device for embedded equipment, equipment and a storage medium. The method comprises the following steps: after acquiring a firmware micro-service pack for performing firmware updating on target firmware in embedded equipment, the embedded security element acquires and stores firmware state data of the target firmware, performs firmware updating on the target firmware based on the firmware micro-service pack in response to the storage of the firmware state data, and if the updating fails, performs firmware updating on the target firmware based on the firmware micro-service pack. And performing data recovery on the target firmware based on the firmware state data. The embodiment of the invention is used for realizing atomization updating of the target firmware in the embedded equipment.
Owner:BEIJING TSINGTENG MICROSYSTEM CO LTD

Random peripheral mapping apparatus and method for microcontroller

ActiveCN116257893BMicrocontrollerEmbedded security
The application discloses a random peripheral mapping device and method of a microcontroller, wherein the device comprises a data loading module, an advanced encryption module and a mapping table generating module connected in sequence; the data loading module is used for providing random data with a user identifier and transmitting the random data to the advanced encryption module; the advanced encryption module is used for generating a mapping table primitive based on the random data and transmitting the mapping table primitive to the mapping table generating module; and the mapping table generating module is used for generating a peripheral mapping table based on the mapping table primitive to provide a random peripheral address for the microcontroller to run software or access software. The device provides a random peripheral address for the microcontroller to run software or access software through the mapping table generating module, so that the operation of the software on the peripheral is no longer limited to fixed addresses, and the difficulty of attacking and cracking the product of the microcontroller and the running software in embedded security application is greatly increased.
Owner:HUADA SEMICON CO LTD

An embedded security subsystem and method for high-speed encryption and decryption

The application discloses a high-speed encryption and decryption embedded security subsystem and method. The system comprises an SPI interface, a DMA module, an arithmetic core array, a CPU and a system bus; the SPI interface is additionally provided with a transmission ready TR and a receiving ready RR special handshake signal line; the DMA module is divided into a sending DMA and a receiving DMA; the arithmetic core array comprises at least three parallel arranged arithmetic cores. The sending DMA responds to the TR signal to move data into an idle arithmetic core and starts operation; the receiving DMA moves the result to the SPI interface after the operation of the arithmetic core is completed and triggers the RR signal. Through the double DMA cooperation and the multi-arithmetic core pipeline scheduling, the SPI interface realizes the full-duplex parallel transmission of the command issuing and the response uploading, the CPU is only responsible for the initialization and does not participate in the real-time data processing, so that the interface bandwidth utilization and the encryption and decryption throughput are greatly improved, and the system is suitable for high-bandwidth real-time security application scenarios.
Owner:THE FIRST RES INST OF MIN OF PUBLIC SECURITY

Media distribution and management system and apparatus

A unified content delivery network system (UCDN) system formed by one or more networks of interoperable peer-to-peer networks. A hierarchical hybrid adaptive secure peer-assisted network system (referred to as SPAN-AI) using a hierarchical AI-driven approach under a unified secure content addressable architecture, the system is based on five key SPAN-AI subsystems: unified naming; unified discovery; hybrid adaptive routing; scalable publish subscribe; and embedded security; all five key SPAN-AI subsystems are securely integrated and jointly optimized via a hierarchical pluggable AI framework with associated simulation, training, and development pipelines embedded in AI agents with varying degrees of awareness and optimization capabilities at the peer-to-peer, edge, core, or other network levels (hierarchy).
Owner:GT SYST

Connectivity framework with session-layer security for embedded secure connectivity

A device comprises a computing device, including one or more processors, several peripheral communication devices of different communication protocol types, operationally connected to the one or more processors, and a memory for storing processor-executable instructions of an application-layer protocol stack. The processor-executable instructions are adapted so that, when executed by the one or more processors, they cause the one or more processors to perform operations for the respective secure communication sessions to be established with the respective target devices via the respective of the several peripheral communication devices.The processes involve establishing the respective secure communication sessions with the respective target devices via the respective of the multiple peripheral communication devices according to a message exchange of a mutual authentication and key exchange protocol common to the multiple peripheral communication devices.
Owner:MICROCHIP TECHNOLOGY INC

Lightweight embedded security file system

PendingCN121188807ADigital data protectionEmbedded securityFile system
The invention provides a lightweight embedded security file system, which relates to an embedded system and an information security technology, and is used for improving data reliability through multi-dimensional wear fine calculation, dynamic partition adjustment of physical block attribution and hierarchical redundancy. The storage reliability and efficiency, the space utilization rate, the data security and the service life of the storage medium can be improved. Specifically, storage areas are divided through the partition management module according to encryption grades, the parameter acquisition module acquires multi-dimensional parameters such as read-write times and temperature in real time, the wear calculation module calculates real-time wear in combination with parameter coefficients, and the dynamic regulation and control module migrates physical blocks for capacity expansion and performs visual early warning when the area utilization rate exceeds a threshold value.
Owner:NORTHERN INST OF AUTOMATIC CONTROL TECH

Flexible embedded security tag

A flexible security tag includes: an elongated inlay portion; a loop antenna mounted on the elongated inlay portion; an electrically-conductive member longitudinally extending across the elongated inlay portion, spaced apart from and inductively coupled to the loop antenna; and a radio frequency identifier (RFID) circuit mounted to the loop antenna. The flexible security tag is encapsulated within an elongated textile protective sleeve.
Owner:SENSORMATIC ELECTRONICS CORP

Connectivity framework with a unified stack and messaging protocol for embedded secure connectivity

A system comprises a computing device with one or more processors, several peripheral communication devices of different communication protocol types operationally connected to the one or more processors, and a memory for storing processor-executable instructions comprising an application-layer protocol stack. The processor-executable instructions are such that, when executed by the one or more processors, they cause the one or more processors to perform operations for each of the messages to be communicated to and from the computing device via each of the several peripheral communication devices.The processes involve communicating the respective messages via the respective of the several peripheral communication devices according to a uniform messaging protocol common to the several peripheral communication devices.
Owner:MICROCHIP TECHNOLOGY INC

Connectivity framework having session layer security for embedded secure connectivity

ActiveUS12701166B2Embedded securitySecure communication
An apparatus comprises a computing device including one or more processors, multiple peripheral communication devices of different communication protocol types operably connected to the one or more processors, and a memory to store processor-executable instructions of an application layer protocol stack. The processor-executable instructions are adapted such that, when executed by the one or more processors, cause the one or more processors to perform operations for respective ones of secure communication sessions to be established with respective destination devices via respective ones of the multiple peripheral communication devices. The operations comprise establishing the respective ones of secure communication sessions with the respective destination devices via the respective ones of the multiple peripheral communication devices according to an exchange of messages of a mutual authentication and key exchange protocol that is common to the multiple peripheral communication devices.
Owner:MICROCHIP TECHNOLOGY INC

Power distribution network energy storage system active false data attack defense method based on elastic controller

The application discloses a power distribution network energy storage system active false data attack defense method based on an elastic controller, belongs to the technical field of power distribution network energy storage system information detection, and comprises the following steps: S1, a physical dynamic model of a power distribution network battery energy storage system under false data attack is established; S2, a self-adaptive robust observer is designed to estimate the injected false data attack in real time; S3, based on the estimated false data attack, a detection criterion of the false data attack is given; and S4, when the false data attack is detected, the elastic controller is triggered to dynamically adjust the control instruction, attack compensation and system function maintenance are realized. The application firstly designs a self-adaptive observer to estimate the injected false data attack, and then by embedding security situation awareness into the controller design, active dynamic defense can be realized. That is, the control parameters are dynamically adjusted based on real-time attack detection, and attack fault tolerance is used to maintain the operation of key functions when part of the subsystems are damaged.
Owner:YANSHAN UNIV

A lightweight security protection method for file permission access in a localization scenario

ActiveCN121808766BPathPingEmbedded security
The application discloses a lightweight security protection method for file permission access in a localization scenario, and belongs to the technical field of information security and localization system security. The application effectively delays the attack process and blocks the automated attack through three technical aspects, including file access interception and underlying permission control, virtual Shell hiding and induction, and external command hiding and path migration. At the same time, a set of user-oriented file permission access and Shell acquisition approval system is formulated, forming a file permission access management and control mechanism, and empowering the localization system security. The lightweight security protection method breaks through the limitations of traditional methods, embeds security strategies into the file system and command path, and is suitable for localization systems in specific scenarios. Under the premise of ensuring the availability of normal users and operation and maintenance processes, the application can effectively delay the execution of attack chains, prevent automated attacks and enhance system security.
Owner:BEIJING AEROSPACE WANYUAN TECH CO LTD

Systems and methods for customer callback scheduler

PendingUS20260148309A1FinanceEmbedded securityUser device
A system for scheduling a callback includes instructions that, when executed by a processor, cause the processor to: generate a URL to schedule the callback, provide the URL with the embedded security token to a user device, receive information relating to a service request associated with the callback to be scheduled, receive a selection of the URL from the user device, determine a queue from which to retrieve a plurality of timeslots based on the information relating to the service request, retrieve the plurality of timeslots from the determined queue, the plurality of timeslots associated with an agent associated with the determined queue, transmit, to the user device, the plurality of timeslots, receive, from the user device, a selection of a timeslot, and schedule the callback at the selected timeslot.
Owner:STATE FARM MUTAL AUTOMOBILE INSURANCE COMPANY