Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

1259 results about "Internet Protocol" patented technology

The Internet Protocol (IP) is the principal communications protocol in the Internet protocol suite for relaying datagrams across network boundaries. Its routing function enables internetworking, and essentially establishes the Internet.

Secure browser and browsing security

A communications system for providing secure access to a digital resource of a group of digital resources accessible via the internet, the system comprising: a data processing hub accessible via an IP (internet protocol) address; and a plurality of user equipment (UEs) useable to communicate via the internet, each configured to have a cyber secure isolated environment (CISE) isolated from ambient software in the UE, and comprising a secure web browser (SWB); wherein the hub and CISE are configured so that digital resources in motion and at rest in CISE are visible to the hub.
Owner:PALO ALTO NETWORKS INC

Cyber secure communications system

A communications system for providing secure access to a digital resource of a group of digital resources accessible via the internet, the system comprising: a data processing hub accessible via an IP (internet protocol) address; and a plurality of user equipment (UEs) useable to communicate via the internet, each configured to have a cyber secure isolated environment (CISE) isolated from ambient software in the UE, and comprising a secure web browser (SWB); wherein the hub and CISE are configured so that digital resources in motion and at rest in CISE are visible to the hub.
Owner:PALO ALTO NETWORKS INC

Data channel communications associated with an internet protocol multimedia subsystem

Various aspects of the present disclosure generally relate to wireless communication. In some aspects, a first network node may obtain a data channel establishment request comprising session description protocol (SDP) information corresponding to a multimedia call session between a first user equipment (UE) and a second UE, the SDP information including a data channel application identifier corresponding to a data channel application. The first network node may provide, to a second network node, a data channel service request that indicates the data channel application identifier. The first network node may obtain, from the second network node, a service response comprising a data channel control policy associated with the data channel application identifier and may allocate, based at least in part on the data channel control policy, media resources corresponding to at least one application data channel. Numerous other aspects are described.
Owner:QUALCOMM INC

Provisioning of encrypted DNS services

The present specification provides a system and method for determining that an endpoint device has connected to an untrusted external internet protocol (IP) network; and establishing a secure DNS connection from the endpoint device to a trusted DNS server via a proxy, wherein the proxy authenticates the trusted DNS server via a client identity certificate and a server certificate.
Owner:MCAFEE LLC

IPSec VPN security gateway communication method fused with post quantum cryptography technology

The invention discloses an IPSec (Internet Protocol Security) VPN (Virtual Private Network) security gateway communication method fused with a post quantum cryptography technology, which comprises the following steps of: S1, in a first-stage main mode of IKE (Internet Key Exchange) key agreement, replacing a traditional single SM2 algorithm and a digital certificate based on an SM2 cryptographic algorithm with an SM2 and PQC mixed algorithm and a mixed PQC digital certificate; s2, the initiator and the responder respectively use the PQC encryption key pair and the PQC signature key pair to carry out key exchange and data signature, and simultaneously use the SM2 encryption key pair and the SM2 signature key pair to carry out key exchange and data signature; s3, in the message 1, the initiator sends a security alliance load containing the attribute of the fused SM2 and PQC algorithm to the responder; s4, in the message 2, the responder feeds back a PQC series hybrid certificate and an SA proposal; and S5, in the message 3 and the message 4, the initiator and the responder complete key exchange and verification. According to the invention, the security of the IPSec VPN security gateway can be improved, and quantum computing attacks can be resisted.
Owner:HEBEI PRIME NUMBER INFORMATION SECURITY CO LTD +1

Threat policy fine-tuning based on the vulnerability of a subnet as a source of a malicious attack

An embodiment includes detecting by a system a request, responsive to the detecting of the request, computing by a Compute component of the system a plurality of internet protocol addresses in a subnet. The embodiment includes computing by an Analysis component of the system a threat metric for each of the plurality of internet protocol addresses. The embodiment includes determining by the Reputation component of the system a threat score for the subnet where the threat score is based on the threat metric. The embodiment also includes sending by the system the threat score representative of a vulnerability of the subnet as a source of a malicious attack.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Methods and apparatuses for enabling computing aware traffic steering using internet protocol (IP) address anchoring

PCT designated stageWO2025168644A1TransmissionCATSEngineering
Procedures, methods, architectures, apparatuses, systems, devices, and computer program products for enabling computing aware traffic steering (CATS) using internet protocol (IP) address anchoring are described. One method may include receiving a request for a service that is offered by two or more nodes in a network domain associated with a network element. The request comprises information indicating an identifier associated with the service and CATS requirements to assist the network element to determine which one of the nodes to select to instantiate the service. The method may include determining, based on an ability of the nodes to provide the service under the CATS requirements, which one of the nodes to select to instantiate the service, and sending information indicating an allocated internet protocol (IP) prefix associated with the selected one of the nodes that is instantiating the service.
Owner:INTERDIGITAL CE PATENT HOLDINGS SAS

Systems and methods for dynamic distributed name resolution

Systems and methods for dynamic distributed name resolution. In various embodiments, steps include receiving a request from a user to access a destination service; resolving an Internet Protocol (IP) address for the destination service based on one or more characteristics of the request; enforcing one or more controls on the request based on a configuration provided by an owner of the destination service; and providing access to the destination service to the user based on the one or more controls.
Owner:ZSCALER INC

Terminal self-discovery method, forwarding equipment and readable storage medium

The invention provides a terminal self-discovery method, forwarding equipment and a readable storage medium. The method comprises the steps that a first message sent by a first terminal is received, the first terminal is located in a first local area network, the first message comprises an identifier of the first local area network and an internet protocol IP address of the first terminal, and the first terminal needs to be self-discovered in a second local area network; multicast is carried out on a second message in the second local area network, and the second message comprises the identification of the second local area network and the IP address of the first terminal; a response message sent by a second terminal is received, the second terminal is located in the second local area network, and the destination IP address of the response message is the IP address of the first terminal. According to the method, terminal self-discovery can be realized across local area networks, that is, the first terminal in the first local area network can discover the second terminal in the second local area network through a self-discovery technology.
Owner:HUAWEI TECH CO LTD

Service aware proxy-call session control function (P-CSCF) traffic routing

Solutions for service aware proxy-call session control function (P-CSCF) traffic routing include: receiving, at a master P-CSCF in a pool of a plurality of P-CSCFs, internet protocol (IP) multimedia subsystem (IMS) traffic from a device; determining, by the master P-CSCF, a traffic type (e.g., 5G, 4G, SMS, WiFi, etc.) of the IMS traffic from the device; based on at least the traffic type of the IMS traffic from the device, selecting, by the master P-CSCF, a serving P-CSCF from the pool for the device; and forwarding, by the serving P-CSCF for the device, the IMS traffic from the device to an IMS. In some examples, the serving P-CSCF selection also includes loading considerations. In some examples, an alternate P-CSCF is available for failover as the new master P-CSCF. In some examples, a network includes multiple pools of P-CSCFs, with each pool having its own master P-CSCF and alternate P-CSCF.
Owner:T MOBILE US INC

Voice optimization method and device for internet protocol voice communication, equipment, storage medium and program product

The invention discloses a voice optimization method and device for internet protocol voice communication, equipment, a storage medium and a program product, and relates to the technical field of data processing, and the voice optimization method for internet protocol voice communication comprises the steps: obtaining network features and voice data of a voice communication network; performing network jitter prediction based on network features, and dynamically adjusting an adaptive jitter buffer based on a prediction result; performing data enhancement processing based on the voice data to obtain enhanced voice data; caching enhanced voice data based on the dynamically adjusted adaptive jitter buffer area; and encoding and decoding the enhanced voice data in the adaptive jitter buffer area to obtain optimized voice data. Through processing of network characteristics and voice data, voice optimization of Internet protocol voice communication can be carried out more comprehensively. By adjusting the adaptive jitter buffer area, high adaptation to a complex network environment is realized, and the quality of voice communication is effectively guaranteed.
Owner:SHENZHEN DINSTAR TECH

Real-time anomaly detection and tracing method and system for cloud storage logs

PendingCN121864488AOvercome the disadvantage of being unable to sense load fluctuationsEliminate timing disruptionsSecuring communicationPathPingAlgorithm
The invention relates to the technical field of log detection, in particular to a real-time anomaly detection and tracing method and system for a cloud storage log, and the method comprises the following steps: calculating an authentication failure proportion based on a user identifier and an internet protocol address, constructing a proportion change sequence, comparing an abrupt change threshold, screening candidate sections, fitting a slope, and aggregating anomaly records; calculating a fluctuation difference sequence, extracting a causal fracture node, recombining a subsequence graph, extracting a cross-node record and correcting a timestamp, connecting a transmission edge based on the timestamp, and accounting time consumption to construct a traceability path. According to the method, the serious defect that a fixed threshold value cannot sense system load fluctuation is overcome by constructing a dynamic proportion change slope, a causal fracture node is established to drive log atlas recombination so as to break an information barrier of a cross-node distributed environment, and a median function is used for correcting time migration to eliminate disorder interference caused by clock asynchronization; and the accurate risk tracing is realized by connecting the correction timestamp with the access transmission edge.
Owner:SHANGHAI XINGZIYA NETWORK TECH CO LTD

Battery system control device and operating method thereof

A battery system control apparatus according to an embodiment disclosed herein includes: a communication circuit configured to allow one or more battery management systems (BMSs) to communicate with a network switch connected to a network; and a processor configured to transmit, through the communication circuit, a check signal to internal internet protocol (IP) addresses that can be allocated at the network switch, receive a response signal to the check signal from at least one internal IP address among the internal IP addresses that can be allocated, and transmit the response signal to the network switch via the communication circuit. And generating a media access control (MAC) address-identification information table by assigning a media access control (MAC) address of the BMS included in the response signal to the identification information.
Owner:LG ENERGY SOLUTION LTD

Method and apparatus for providing edge service

Embodiments of the present disclosure provide methods and apparatus for providing edge service. A method performed at a first network function comprises: receiving, a request for querying information associated to a location of a terminal device; wherein the request includes an internet protocol, IP, address of the terminal device; obtaining, from a second network function, a global identifier of the terminal device, based on the IP address of the terminal device; obtaining a location of the terminal device, based on the global identifier or the IP address of the terminal device; and transmitting, information associated to the location of the terminal device.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

End-to-end IMS network slicing

An Internet Protocol (IP) Multimedia Subsystem (IMS) network slice manager and orchestrator receives first performance requirements associated with a first network slice of a mobile network. The IMS network slice manager and orchestrator determines, based on the first performance requirements, first configuration data associated with a first IMS network slice of an IMS network, where the first IMS network slice is linked to the first network slice of the mobile network. The IMS network slice manager and orchestrator configures and provisions, based on the first configuration data, the first IMS network slice in the IMS network.
Owner:VERIZON PATENT & LICENSING INC

Reliable emergency short message service over internet protocol (IP) multimedia subsystem (IMS)

Techniques are described for sending an emergency related Short Message Service message (SM) from a user equipment (UE) to a Public Safety Answering Point (PSAP) with higher reliability and security and lower delay than with previous techniques. Following detection of a user input emergency SM, a UE establishes a Session Initiation Protocol (SIP) dialogue with a PSAP, where the SIP dialogue has no active SIP media, which can be compliant with SIP protocol rules. The emergency SM is sent to the PSAP in association with the SIP dialogue, as are any subsequent SMs, and PSAP SM replies are similarly returned to the UE. Media such as voice may be added and previous restrictions on support of UEs that are roaming or in limited service state can be overcome.
Owner:QUALCOMM INC

Real-time relay transmission method, device and system for fax data

The embodiment of the invention provides a real-time relay transmission method, device and system for fax data, which are applied to a first client front-end device, the first client front-end device is in communication connection with a first fax machine, and the method comprises the following steps: after the first fax machine and a second fax machine are connected in a call, the first client front-end device transmits the fax data to the second fax machine; the first client front-end equipment receives fax data sent by a first fax machine; the first client front-end equipment converts the fax data into an image file; the first client front-end equipment decomposes the image file into a plurality of image units, and a plurality of data packets are obtained after the image units are packaged through an internet protocol; and the first client front-end equipment sends the plurality of data packets to a second fax machine in real time through an Internet session protocol link.
Owner:SHENZHEN FLYINGVOICE NETWORK COMMUNICATION TECHNOLOGY CO LTD

Local isolation in a browser

A communications system for providing secure access to a digital resource of a group of digital resources accessible via the internet, the system comprising: a data processing hub accessible via an IP (internet protocol) address; and a plurality of user equipment (UEs) useable to communicate via the internet, each configured to have a cyber secure isolated environment (CISE) isolated from ambient software in the UE, and comprising a secure web browser (SWB); wherein the hub and CISE are configured so that digital resources in motion and at rest in CISE are visible to the hub.
Owner:PALO ALTO NETWORKS INC

Systems and methods for mitigating DDoS attacks on internet protocol networks

A system and method to protect resource servers from DDOS attacks is disclosed. A proxy gateway hides resource server using IP subnet addressing and receives authenticated IP packets. A cryptographic hash is generated, and destination IP packets address / ports are encrypted using a secret, algorithm, client IP address, resource server IP address, and port. The cryptographic hash and destination server are mapped into existing IP packet addresses, ports, or payload bits. The IP packets are routed to a redirect node in the public IP subnet of the proxy gateway. At the redirected node, the cryptographic hash is validated, and the resource server IP address and the port are extracted from mapping. Redirect node maps the clients public IP / port to an internal IP address and port associated with resource server and tunnels the IP packets from the redirect node to the resource server using the internal IP address and port.
Owner:INCEPTION SECURITY SOLUTIONS LLC

Determining a time to permit a communications session to be conducted

A method, apparatus and system for routing a communication in a communication system between a first participant device, on an Internet Protocol (IP) network, associated with a first participant, and a second participant device associated with a second participant. The method comprises receiving a second participant identifier associated with the second participant device, causing the at least one processor to access a user profile that is specific to the first participant and associated with a plurality of first participant attributes, comparing the second participant and at least one first participant attribute and identifying whether at least one route exists, producing route information to an Internet Protocol (IP) address on a first communication network or associated with a gateway to the second communication network, and establishing the communication to the second participant. At least one of the networks may utilize Public Switched Telephone Network (PSTN) compatible numbers for identifying a route for the communication.
Owner:VOIP PAL COM INC

Smart old-age care service construction method based on Fabric block chain and big data AI

The invention discloses an intelligent old-age care service construction method based on a Fabric block chain and big data AI, and the method comprises the following steps: S1, collecting multi-source heterogeneous data of old people, and carrying out the standardization processing of the data; s2, performing classified storage on the standardized data processed in the step S1 on the basis of a Hyperledger Fabric block chain and an IPFS (Internet Protocol File System) distributed network; s3, constructing a multi-modal AI health early warning and decision model architecture, analyzing the standardized data stored in the step S2, and generating a health risk early warning and personalized nursing scheme; s4, cross-institution data authorization sharing is carried out through the block chain smart contract, an automatic process triggering rule of the smart contract is preset, and cross-institution real-time data sharing and business collaboration are carried out; and S5, configuring an aging-suitable interaction terminal, receiving health risk early warning, a personalized nursing scheme and a business cooperation event process in real time, capturing user interaction operation, and returning operation data to the step S3 to perform AI model optimization on the multi-mode AI health early warning and decision model architecture.
Owner:ZHANGZHOU CITY UNIV

Distributor function, locator function and methods in a communications network

A method performed by a distributor function for handling a subscription to expose Internet protocol Multimedia Subsystem (IMS) exposure data in a communications network is provided. The exposure data is related to a User Equipment (UE) connected to an IMS network comprised in the wireless communications network. The distributor function is comprised in any one out of a first network node or a first IMS node. The distributor function receives (1001) a request requesting a subscription to expose IMS exposure data related to the UE. The request is originating from a second network node operating outside of the IMS network. The distributor function obtains (1002), from a locator function, data identifying a second IMS node supporting exposure capabilities and serving the UE. The locator function is comprised in any one out of the first IMS node or a third network node. The distributor function sends (1003) to the identified second IMS node, a subscription request to expose data related to the UE. The subscription request instructs the second IMS node to notify a network exposure function of a triggering occurrence fulfilling a triggering condition, to expose exposure data, when detected by the second IMS node. The network exposure function is located in the first network node. The notification enables the network exposure function to notify the second network node of the detected triggering occurrence.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Multi-segment SD-WAN through cloud DC transit nodes

A method implemented by a first cloud gateway (GW). The method includes receiving, from a first customer premises edge device (CPE) over a software defined wide area network (SD-WAN) path, a data packet including an outer layer internet protocol (IP) header and a generic network virtualization encapsulation (GENEVE) header. The GENEVE header includes one or more sub-type length values (TLVs). The method also includes extracting a destination address from the one or more sub TLVs within the GENEVE header. And the method further comprises the steps of updating the destination IP address in the outer-layer IP header to the extracted destination address, and forwarding the data packet to a second CPE according to the updated destination IP address.
Owner:HUAWEI TECH CO LTD

GENERATIVE ARTIFICIAL INTELLIGENCE (GenAI)-DRIVEN ENHANCEMENTS TO AN INTERNET PROTOCOL (IP) MULTIMEDIA SUBSYSTEM (IMS)

PendingUS20260135892A1TransmissionData miningData store
Aspects of the subject disclosure may include, for example, collecting data relating to at least one CSCF of an IMS, resulting in collected data, extracting one or more features or metrics from the collected data, resulting in extracted data, storing the extracted data in one or more vector databases, causing a query to be submitted to the one or more vector databases for retrieving information regarding the at least one CSCF, resulting in retrieved information, analyzing the retrieved information using one or more AI models, and generating an output based on the analyzing for modifying an operation relating to the at least one CSCF. Other embodiments are disclosed.
Owner:AT&T INTELLECTUAL PROPERTY I L P

Service Function Proxy for Service Chaining in SRv6 Networks

A node in a Segment Routing Internet Protocol version 6 (SRv6) network with the node configured as a Service Function (SF) Proxy in the SRv6 network, the node includes circuitry configured to, subsequent to installation of a Segment Identifier (SID) for a Service Function Chain (SFC), receive a packet with the SID included therein, remove all Segment Routing (SR) information from the packet, send the packet on an interface associated with an SR-unaware SF, and receive the packet on the interface after processing by the SR-unaware SF, wherein the packet from the interface is associated as returning traffic from the SF.
Owner:CIENA CORP

Method for realizing multi-CPU (Central Processing Unit) architecture large cluster simulation and pressure test

The invention provides a method for realizing multi-CPU (central processing unit) architecture large cluster simulation and pressure testing, which belongs to the technical field of cloud containers, and comprises the following steps: (1) directly agenting apisever through an ipvs (internet protocol version) mode; (2) averagely distributing pods of the kubemark to different agents to share pressure; and (3) the reading and writing speed is increased through an etcd memory mapping mode. By means of the method, simulation and pressure testing of a large cluster can be smoothly achieved.
Owner:INSPUR ENTERPRISE CLOUD TECHNOLOGY (SHANDONG) CO LTD

Terminal auto-discovery method, forwarding device, and readable storage medium

The present application provides a terminal auto-discovery method, a forwarding device, and a readable storage medium. The method comprises: receiving a first message sent by a first terminal, wherein the first terminal is in a first local area network, the first message comprises an identifier of the first local area network and an Internet Protocol (IP) address of the first terminal, and the first terminal needs to be able to support auto-discovery in a second local area network; multicasting a second message in the second local area network, wherein the second message comprises an identifier of the second local area network and the IP address of the first terminal; and receiving a response message sent by a second terminal, wherein the second terminal is in the second local area network, and a destination IP address of the response message is the IP address of the first terminal. The method enables terminal auto-discovery across local area networks, that is, the first terminal in the first local area network can discover the second terminal in the second local area network by using auto-discovery technology.
Owner:HUAWEI TECH CO LTD

Data classification method, system and equipment based on industrial Internet of Things, and medium

The invention belongs to the technical field of industrial Internet of Things, and particularly discloses a data classification method, system and device based on the industrial Internet of Things and a medium, and the method comprises the steps: obtaining the use authority after the system of the industrial Internet of Things is accessed, and then connecting an industrial robot through an Internet protocol; acquiring equipment parameter data and product detection data based on a data interface of the industrial robot; according to the key features of the product detection data, obtaining a product classification result through a MinHash algorithm; and based on the equipment parameter data and the differential privacy federated learning framework, classifying the data of the industrial robot through the classification model. The invention aims to solve the problem that the data classification method of the industrial Internet of Things in the prior art cannot realize the classification of the data of the industrial robot on the premise of protecting the data privacy and security. The problems that robot management devices in the industrial Internet of Things cannot be efficiently cooperated for joint training, and precise classification of industrial robots cannot be achieved are solved.
Owner:CHENGDU QINCHUAN IOT TECH CO LTD

Reflex-reaction server leakage containment system

A segmented local area network with reflex-reaction server leakage containment system includes a segmented local area network (LAN) and a reflex-reaction server leakage containment system. The LAN includes an internal zone with at least one internal server, and a perimeter firewall developing firewall traffic data and being responsive to a block list of internet protocol (IP) addresses. The reflex-reaction server leakage containment system stores a LAN server metadata (LSM) table, is receptive to the firewall traffic data and is operative to automatically update the block list with at least one of an IP address of the at least one internal server and an IP address of an external destination server when a data leakage through the perimeter firewall from the at least one internal server to the external destination server is detected.
Owner:CELERIUM INC