Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

10 results about "Group Policy" patented technology

Group Policy is a feature of the Microsoft Windows NT family of operating systems that controls the working environment of user accounts and computer accounts. Group Policy provides centralized management and configuration of operating systems, applications, and users' settings in an Active Directory environment. A set of Group Policy configurations is called a Group Policy Object (GPO). A version of Group Policy called Local Group Policy (LGPO or LocalGPO) allows Group Policy Object management without Active Directory on standalone computers.

Software engine for abstracting security controls in one-way transfer systems

Examples of the present disclosure describe systems and methods for implementing a software-based security abstraction engine in a one-way transfer (OWT) system. In examples, data is received at a first device in the OWT system. A first set of policies is identified based on a dataflow identifier associated with the transfer of the data. A policy engine associated with the first set of policies applies the first set of policies to the data to create digital signatures. The digital signatures are evaluated by the security abstraction engine to determine whether the set of digital signatures is valid. If the digital signatures are determined to be valid, a second set of policies is applied to the data. The data is then transmitted to a second device or destination in the OWT system based on the dataflow identifier.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Methods for data encryption, decryption, and authentication using different policy classes

A computer-implemented method for satisfying gateway proofs and an integrity check to retrieve decryption value sets for a ciphertext received by a recipient computing device may include performing four gateway proofs of determining whether: (1) a group policy of the ciphertext's header matches a group policy of the recipient computing device; (2) a USUP of the header matches a USUP of the recipient computing device; (3) a first unique identifier from a ciphertext policy of the header matches a unique identifier of the recipient computing device; and (4) a second unique identifier from the ciphertext policy of the header matches the ciphertext's length. An integrity check may be performed and the recipient computing device can retrieve the decryption value sets if the gateway proofs and integrity check are satisfied.
Owner:ATOFIA LLC

SYNTHESIS OF GUIDELINES FOR THE ENFORCEMENT OF GROUP-BASED GUIDELINES FOR UNKNOWN FLOWS

A computer-executable procedure, comprising: Determining a first set of policies (152) defined for a switch (103) when handling a packet, wherein a policy includes at least one policy entry based on a target role and wherein the at least one policy entry includes a source role, a traffic attribute and an action to be performed for the packet; Receiving an incoming packet at the switch, where the destination of the incoming packet is unknown; Representing the first set of policies as a matrix, where a first entry in the matrix corresponds to the source role as a row and the destination role as a column, and specifies the traffic attribute and the action of the at least one policy entry; Replacing the action in the first entry with the target role if the action indicates that the packet should be allowed, and with a null value if the action indicates that the packet should be rejected, in order to obtain an initial data structure with entries that specify a multitude of traffic attributes for each source role and a corresponding set of allowed target roles for each traffic attribute; Resolving an overlapping pair comprising a first traffic attribute and a second traffic attribute to obtain a second data structure; Finding that a third traffic attribute for a source role in the second data structure does not comply with a policy; Removing the third traffic attribute from the second data structure to obtain a second set of synthesized policies (154), where a first decision model based on the first set of guidelines leads to the same result as a second decision model based on the second set of synthesized guidelines; Allowing or rejecting the forwarding of the incoming packet at the switch using the second decision model; in response to allowing the incoming packet to be forwarded to a local host; and as a reaction to the rejection, the dismissal of the incoming package.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Method for controlling enforcement policies across policy enforcement points of distributed access control system and method for constraining policies of access control system governing authorization access to digital data resources

PCT designated stageWO2026174507A1Digital dataSystems management
A method of controlling enforcement policies (220, 506) for multiple policy enforcement points, PEPs (208A-N, 310), in a distributed access control system (202) is provided. The system operates across various geographic locations, with each PEP positioned at a specific site. The method involves receiving declaration record messages (210, 302) from each PEP, which include identifiers, locations, protected resources, and enforceable actions (314, 404, 504). Execution record messages (212, 402, 508) specifying actions to enforce, dependencies (406) between actions, a report (408) on the action status (410), and conditions (414) determining which PEPs are responsible for enforcement are also received from each PEP. Each PEP uses these messages to dynamically adjust enforcement policies to ensure coordinated control over access to digital data resources. This method helps the system efficiently handle access requests, respect action dependencies, and maintain synchronization among PEPs, thereby improving security and consistency across distributed locations. A method of constraining the use of policies of an access control system (102) which governs an authorization related to a subject's (104) access to a digital data resource (106) is provided. The method includes establishing a hierarchy of policies including: (i) a first set of policies defined as governance policies (108, 202, 302), which are used to govern an authorization during the lifecycle of the authorization; (ii) a second set of policies defined as authorization policies (110, 204, 304), which manage access rights to the digital data resource by the subject in the access control system; and (iii) a third set of policies defined as enforcement policies (112, 206, 306), which specify how decisions and actions related to the access rights are to be enforced by the access control system. The method includes using the governance policies in the first set of policies in the hierarchy to set constraints on the authorization policies in the second set of policies and on the enforcement policies in the third set of policies, to orchestrate the authorization throughout the lifecycle of the authorization.
Owner:HUAWEI TECH CO LTD

Shortest path bridging (SPB) security group policy

Disclosed herein are system, method, and computer program product aspects for implementing a security group policy. Some aspects of this disclosure relate to a method for applying a security group policy. The method includes receiving a first frame from a source device and assigning a source security group identifier (ID) to the first frame. The method further includes generating a second frame based on the first frame and the source security group ID and identifying a target security group ID for the second frame. The method also includes applying one or more forwarding decisions to the second frame based on the source security group ID and the target security group ID.
Owner:EXTREME NETWORKS INC

Policy processing method and communication device

PendingUS20260254668A1Group PolicyCommunication device
A method for processing a policy, performed by a first network element, includes: determining a policy for a UE in a UE group and an execution condition of the policy. A method for processing a policy includes: receiving, by a second network element, a group policy for a UE group and an execution condition of the group policy; and generating, by the second network element, a group QoS profile, a group PDR, or both the group QoS profile and the group PDR for the UE group according to the group policy and the execution condition of the group policy. The group QoS profile, the group PDR or both the group QoS profile and the group PDR are configured to allow the group policy to be executed, and the execution condition of the group policy is satisfied.
Owner:BEIJING XIAOMI MOBILE SOFTWARE CO LTD

Network migration method, system, electronic device, storage medium and program product

PendingCN122640316AInternet trafficGroup Policy
The application discloses a network migration method and system, electronic equipment, storage medium and program product, and relates to the technical field of Internet, which comprises the following steps: generating a migration plan according to a network migration request, network related information, first configuration information of a network to be migrated and second configuration information of a target network; establishing a transition tunnel to generate network traffic on a first network card of the target network; generating an initial security group policy according to the network traffic and deploying the initial security group policy to the first network card to obtain a performance index and a policy accuracy rate of the target network; if the performance index is within a preset baseline range and the policy accuracy rate reaches a gating threshold, adjusting the policy according to a preset weight to determine a traffic switching step, and switching network traffic corresponding to the network to be migrated to the target network. The application solves the problem that traffic switching during migration of a traditional network easily leads to service interruption, and the network after migration can only be verified after the migration is completed, and potential performance degradation defects in the traditional network cannot be found in time.
Owner:JINAN INSPUR DATA TECH CO LTD

Automated user profile provisioning and threat remediation in multi-tenant cloud networks

A cloud network for automatically provisioning of user and group profiles using direct synchronization in multi-tenant systems. It involves a plurality of end-user devices, each equipped with a local application and user interface, and a mid-link server. The mid-link server facilitates the creation of configuration snippets for user directories via the user interface, receives threat information associated with an end-user, and identifies a high-risk user from the plurality of end-users based on the threat information. In response to identified high-risk users, the mid-link server remediates threat by dynamically adjusting user directory privileges, the remediation comprises restricting access of the high-risk user in accordance with policies and assigning them to a high-risk group with a lower set of privileges and removing them from the high-risk group when the threat is remediated. The user directory is deployed using the snippet based on the user policies and the group policies.
Owner:NETSKOPE INC

Policy coordination method for group of user equipment and communication device

ActiveUS12689871B2Group PolicyUser equipment
The present disclosure provide a policy coordination method for a group of user equipment (UEs), the method includes receiving a policy request, where the policy request is related to a group policy for the group of UEs; and performing, according to the policy request and pre-stored group policy information, policy coordination on the group of UEs, where the pre-stored group policy information indicates a policy required to be adopted by each UE in the group of UEs for various group policies of the group of UEs.
Owner:BEIJING XIAOMI MOBILE SOFTWARE CO LTD

Shortest path bridging (SPB) security group policy

Disclosed herein are system, method, and computer program product aspects for implementing a security group policy. Some aspects of this disclosure relate to a method for applying a security group policy. The method includes receiving a first frame from a source device and assigning a source security group identifier (ID) to the first frame. The method further includes generating a second frame based on the first frame and the source security group ID and identifying a target security group ID for the second frame. The method also includes applying one or more forwarding decisions to the second frame based on the source security group ID and the target security group ID.
Owner:EXTREME NETWORKS INC