Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

6 results about "Extended Access Control" patented technology

Extended Access Control (EAC) is a set of advanced security features for electronic passports that protects and restricts access to sensitive personal data contained in the RFID chip. In contrast to common personal data (like the bearer’s photograph, names, date of birth, etc.) which can be protected by basic mechanisms, more sensitive data (like fingerprints or iris images) must be protected further for preventing unauthorized access and skimming. A chip protected by EAC will allow that this sensitive data is read (through an encrypted channel) only by an authorized passport inspection system.

Power grid data epitaxial access control method and system

The invention discloses a power grid data epitaxial access control method and system, and relates to the technical field of cross-region and cross-domain sharing of power grid data. According to the main technical scheme, a static label is adopted to provide constraint access control for a data calling party, and a dynamic label is adopted to provide propagation access control for a next data calling party, so that when a plurality of iterative data calling parties exist, the data calling parties are subjected to data calling; according to the invention, the static label associated with the target power grid data and the continuously updated dynamic label are utilized to realize propagation monitoring of the target power grid data in cross-geographic areas and / or cross-business fields, so that an effective power grid data epitaxial access control solution is provided.
Owner:INFORMATION & COMMUNICATION BRANCH STATE GRID JIBEI ELECTRIC POWER CO LTD +2

Scalable access control checking for cross-address-space data movement

Methods and apparatus relating to scalable access control checking for cross-address-space data movement are described. In an embodiment, a memory stores an Inter-Domain Permissions Table (IDPT) having a plurality of entries. At least one entry of the IDPT provides a relationship between a target address space identifier and a plurality of requester address space identifiers. A hardware accelerator device allows access to a target address space, corresponding to the target address space identifier, by one or more of requesters, corresponding to the plurality of requester address space identifiers, respectively, based at least in part on the relationship provided by the at least one entry of the IDPT. Other embodiments are also disclosed and claimed.
Owner:INTEL CORP

A power grid data extension access control method and system

This application discloses a method and system for extended access control of power grid data, relating to the field of cross-regional and cross-domain sharing of power grid data. The main technical solution of this application is as follows: This application uses static tags to provide constrained access control for data callers, and uses dynamic tags to provide propagation access control for the next data caller. Then, when there are multiple iterative data callers, by utilizing the static tags associated with the target power grid data and the continuously updated dynamic tags, it realizes the propagation monitoring of the target power grid data across geographical regions and / or across business domains, thereby providing an effective solution for extended access control of power grid data.
Owner:INFORMATION & COMMUNICATION BRANCH STATE GRID JIBEI ELECTRIC POWER CO LTD +2

Security design and architecture for multi-tenant HADOOP clusters

This application discloses a security design and architecture for multi-tenant Hadoop clusters. In one embodiment, in a multi-tenant Hadoop cluster comprising multiple tenants and multiple applications, a method for identifying, naming, and creating a multi-tenant directory structure in the multi-tenant Hadoop cluster may include: (1) identifying multiple groups of a directory structure selected from groups consisting of a superuser group, multiple tenant groups, and at least one application group; (2) creating a valid directory for each of the groups; (3) adding each of the multiple users to one of the multiple tenant groups and the application group; (4) creating a tenant directory and a home directory for the users; and (5) assigning an owner, group owner, default permissions, and extended access control lists to the tenant directory and the home directory.
Owner:JPMORGAN CHASE BANK NA

Trust-based verification system and method for scalable access control and cyber-security qualifications

Provided are a platform and a computer-implemented process of controlling access to a restricted resource by verifying qualifications in compliance with a regulatory security framework. A computing system receives a configuration package including a qualification set, a threshold trust for a qualification, a plurality of different sources that could potentially provide information indicative of the qualification, and a different trust level to be assigned to each of the sources. The computing system also receives the information indicative of the qualification from a first source. A first trust level assigned to the first source is compared to the threshold trust associated with the qualification. Responsive to a determination that the first trust level satisfies the trust threshold, the qualification is flagged as being verified without human intervention to control access to the restricted resource.
Owner:CYBERSTAR SOFTWARE LLC

Delivery method, system and medium supporting transaction rollback and ownership synchronization update

The application discloses a delivery method and system supporting transaction rollback and ownership synchronous update and a medium, and belongs to the technical field of data security. The transaction house is composed of a storage management server, an ownership management server and a key management server. The storage management server stores data ciphertext for a long time; the key management server provides key use services for legal users in a trusted execution environment with the assistance of the ownership management server, and trustingly deletes the use permission of the buyer when the use period expires, so that the cross-domain extended access control of the data seller to the data is realized. The core functions such as key management, data encryption and decryption and data use are carried out in an isolated safe environment, the buyer needs to use the key and data according to the strategy legally and regularly, and the key and data cache are immediately cleared after the data use is completed, so that the data is avoided from being illegally held, used or even resold, and the risk of data leakage and abuse is obviously reduced.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA