Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

82 results about "Isolated environment" patented technology

Secure browser and browsing security

A communications system for providing secure access to a digital resource of a group of digital resources accessible via the internet, the system comprising: a data processing hub accessible via an IP (internet protocol) address; and a plurality of user equipment (UEs) useable to communicate via the internet, each configured to have a cyber secure isolated environment (CISE) isolated from ambient software in the UE, and comprising a secure web browser (SWB); wherein the hub and CISE are configured so that digital resources in motion and at rest in CISE are visible to the hub.
Owner:PALO ALTO NETWORKS INC

Cyber secure communications system

A communications system for providing secure access to a digital resource of a group of digital resources accessible via the internet, the system comprising: a data processing hub accessible via an IP (internet protocol) address; and a plurality of user equipment (UEs) useable to communicate via the internet, each configured to have a cyber secure isolated environment (CISE) isolated from ambient software in the UE, and comprising a secure web browser (SWB); wherein the hub and CISE are configured so that digital resources in motion and at rest in CISE are visible to the hub.
Owner:PALO ALTO NETWORKS INC

Hot update method, system and equipment for automation program of semiconductor equipment and medium

The invention provides a hot updating method, system and equipment for an automation program of semiconductor equipment and a medium. The method comprises the following steps: dynamically loading a new version script code into an isolated runtime environment created by an application domain or a class loader through a reflective API (Application Program Interface) so as to isolate new and old codes. And performing preheating initialization on the new code in an isolated environment, wherein the preheating initialization comprises execution of an initialization function and simulation of a production request test. After preheating is completed, a new request of the production environment is routed to the new version to be processed through atomic switching operation, and meanwhile, the current running version continues to complete existing in-process affairs. According to the method, shutdown is avoided through dynamic loading and isolation, stability is improved through preheating initialization, new requests and in-process transactions are considered in atomic switching, non-shutdown updating of the automatic program of the semiconductor equipment is achieved, production interruption is effectively eliminated, and the equipment utilization rate and operation and maintenance flexibility are improved.
Owner:上海朋熙半导体股份有限公司

Microfluidic device with stable isolation environment

The present application provides a microfluidic device, comprising at least one microfluidic channel unit, each microfluidic channel unit comprising a microfluidic channel configured to contain a fluid and comprising a plurality of independent compartments. Each microfluidic channel unit comprises a first side wall and a second side wall opposite and spaced apart from the first side wall, a plurality of first extensions formed on the first side wall extending toward the second side wall without abutting the second side wall, a plurality of second extensions formed on the second side wall extending toward the first side wall without abutting the first side wall, the plurality of first extensions and the plurality of second extensions being alternately arranged in the microfluidic channel. A compartment is formed in at least one first extension or at least one second extension. The compartment has an opening positioned such that the fluid does not directly flow into each compartment. The microfluidic device of the present application has a stable isolated environment to facilitate various reactions and prevent micro-objects in the compartments from escaping.
Owner:COLORTECH SUZHOU BIOTECHNOLOGY CO LTD

Local isolation in a browser

A communications system for providing secure access to a digital resource of a group of digital resources accessible via the internet, the system comprising: a data processing hub accessible via an IP (internet protocol) address; and a plurality of user equipment (UEs) useable to communicate via the internet, each configured to have a cyber secure isolated environment (CISE) isolated from ambient software in the UE, and comprising a secure web browser (SWB); wherein the hub and CISE are configured so that digital resources in motion and at rest in CISE are visible to the hub.
Owner:PALO ALTO NETWORKS INC

Malware analysis of data / files prior to storage in isolated secure environment

A communications system for providing secure access to a digital resource of a group of digital resources accessible via the internet, the system comprising: a data processing hub accessible via an IP (internet protocol) address; and a plurality of user equipment (UEs) useable to communicate via the internet, each configured to have a cyber secure isolated environment (CISE) isolated from ambient software in the UE, and comprising a secure web browser (SWB); wherein the hub and CISE are configured so that digital resources in motion and at rest in CISE are visible to the hub.
Owner:PALO ALTO NETWORKS INC

System and method for monitoring and mitigating dark web data breaches

Disclosed is a system (100). The system (100) includes a client device (101) and a host device (102). The host device (102) includes processing circuitry (120) that is configured to download files by way of file links, generate an isolated environment by way of a virtual non-transitory computer-readable medium such that the one or more files are received and processed in the isolated environment, generate a first mitigation signal when a data breach associated with the one or more files is detected. Based on the first mitigation signal (i) the virtual non-transitory computer-readable medium is compressed and encrypted and (ii) the generated isolated environment is deleted and generate a second mitigation signal when a data breach associated with the one or more files is not detected. Based on the second mitigation signal (i) the generated isolated environment is deleted and (ii) the virtual non-transitory computer-readable medium is deleted.
Owner:TALENT UNLIMITED ONLINE SERVICES PTE LTD

Data security

A communications system for providing secure access to a digital resource of a group of digital resources accessible via a communications network, the system comprising: a data processing hub accessible via an IP (internet protocol) address; and a plurality of user equipment (UEs) useable to communicate via the communications network, each configured to have a cyber secure isolated environment (CISE) isolated from ambient software in the UE, and comprising a secure web browser (SWB); wherein the hub and CISE are configured so that digital resources in motion and at rest in CISE are visible to the hub.
Owner:PALO ALTO NETWORKS INC

Code execution method and device, electronic equipment and storage medium

The invention provides a code execution method and device, electronic equipment and a storage medium, relates to the technical field of computers, and is used for improving response speed, code transmission safety and concurrency performance and stability of a sandbox system, effectively multiplexing process resources and reducing resource overhead. The method comprises the following steps: in a sandbox system starting stage, creating and initializing a sandbox process pool for operating environments of different programming languages according to predefined process parameters; preheating the process in an initialization stage of the sandbox system; after a code execution request is received each time, distributing a target sandbox process from a corresponding sandbox process pool according to the target programming language type; the code to be executed is encrypted and transmitted to the target sandbox process, decryption is carried out in the isolation environment of the target sandbox process, and code execution and execution result asynchronous return are carried out; and before the target sandbox process is returned, performing health check on the target sandbox process, and determining to destroy or recycle the target sandbox process to the corresponding sandbox process pool for reuse.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD

Table data processing method and related equipment

The invention provides a table data processing method and related equipment. The method comprises the following steps: in response to a first operation on a first table, generating an isolation environment and a second table arranged in the isolation environment; the second table comprises table structure information and / or table data information of the first table; in response to a table configuration operation on the second table, table change information is generated; and in response to a deployment operation in the isolated environment, deploying at least part of the table change information to the first table. According to the table data processing method and the related equipment provided by the invention, modification of the table data in the isolation environment does not influence the table data in the production environment, so that the development and test cost of the table is reduced, and the safety of the table data is guaranteed.
Owner:BEIJING ZITIAO NETWORK TECH CO LTD

Data processing device, data processing method, and data processing program

A data processing device 10 includes a processing logic execution management unit 11 that, by using an isolation function of an operating system in a virtual machine in a node, causes a plurality of processing logics to operate in an isolated environment in the node, and calls the plurality of processing logics in such a manner that the plurality of processing logics are isolated from each other.
Owner:NT T INC

Modular development life cycle management method, system and equipment based on hot update

The invention discloses a modular development life cycle management method, system and device based on hot update, and the method comprises the steps: responding to a detection result that a target module appears in a module warehouse, dynamically loading the target module in a preset isolation environment, and verifying the target module; when the target module passes the verification, registering the target module into a target system; obtaining a target function module corresponding to the target module in the target system according to the target module and the target system; obtaining calling data and / or dependence data of the target function module according to the target function module; obtaining target time based on a preset prediction algorithm according to the calling data and / or dependency data of the target function module; and according to the target time, loading the target module into the target system to replace the original module used by the target function module. The problems that in the prior art, a large amount of manual operation is needed in modular development life cycle management based on hot updating, and the automation degree is low are solved.
Owner:CHENGDU DACHENG JUNTU TECH CO LTD

Passive cloud

Techniques for data management are described. An example method may include processing a first message indicating that an intermediate computing system managed by a first data center has received data from a second data center in a second area. The method may also include transmitting a first control instruction to the intermediate computing system to validate the data based at least in part on the first criteria. The method may also include processing verification results from the intermediate computing system. The method may also include processing a second message indicating that data is released from the first isolated environment of the intermediate computing system. The method may also include processing, by the computing system, a third message indicating that the second message originates from a computing device located in the first area. The method may also include causing the data to be released from the first isolated environment.
Owner:ORACLE INT CORP

An audio task processing method and an audio agent system

The application discloses an audio task processing method and an audio agent system. The audio agent system is composed of an MCP client, an LLM planner, an MCP server and a tool package. After receiving audio and instructions, the MCP client generates a subtask sequence corresponding to instruction text by the LLM planner. The MCP client iterates the subtask sequence to call the MCP server to determine candidate tools from the tool package according to the function description of the subtask. The LLM planner decides the optimal tool and generates an execution command, which is packaged with an audio path to the MCP server. The MCP server calls the tool to execute audio processing in an isolated environment according to the execution command of the optimal tool and the audio path. The audio processing result is forwarded to the LLM planner through the MCP client, and the LLM planner updates the audio path according to the audio processing result. The LLM planner aggregates the audio processing results of all subtasks, generates final reply content and sends it to the MCP client for display. The application can ensure stable execution of complex task processes.
Owner:HUNAN UNIV

Data processing device, data processing system, data processing method, and data processing program

Data processing devices 10A–10C are each a device that processes data in an isolated environment within a node 1–3 and each comprise an encryption proxy unit 11A–11C that uses a common key to encrypt processed data that is processed in the isolated environment and transmits the encrypted data to the other data processing devices and uses the common key to decrypt encrypted data received from the other data processing devices and outputs the decrypted data into the isolated environment and a network setting unit 12A–12C that establishes network settings such that the processed data and the encrypted data transit the proxy unit 11A–11C.
Owner:NT T INC

High-speed plastic nail feeding mechanism

The utility model discloses a high-speed plastic nail feeding mechanism which comprises a round vibration disc and a guide strip installed on the right side of the round vibration disc, a straight vibration strip is arranged on the right side of the guide strip, a material distributing disc is arranged on the right side of the straight vibration strip, and a motor is arranged on the right side of the material distributing disc to drive the material distributing disc to rotate. The motor is electrically connected with an external power source, a plurality of nail blowing air valves are arranged on the left side of the material distribution disc at equal intervals, plastic nail bodies are clamped into the nail blowing air valves, and by installing a sound insulation cover, noise generated in the process that the plastic nail bodies are vibrated through a circular vibration disc is reduced, so that the plastic nail bodies are prevented from being damaged. And noise generated when the rubber nails are vibrated by the circular vibration disc can be effectively reduced through the sound insulation cover. The sound insulation cover can provide an isolated environment, noise transmission is reduced, interference of the surrounding environment is effectively reduced, meanwhile, the storage amount and the working condition of the circular vibration disc can be directly checked through the transparent sound insulation cover, and the storage amount and the working condition can be timely checked and added when the storage amount is insufficient.
Owner:WU HAN FU SHI TE KE JI YOU XIAN GONG SI

Graphical programming software open extension system and method

This invention relates to an open extension system and method for graphical programming software, belonging to the field of computer software technology. The system includes: an extension repository, which uses an independently deployed remote service to store and manage approved third-party extension packages and maintain extension metadata mapping files; a client extension management module, which loads the metadata mapping files when the editor starts and initiates extension loading requests on demand in response to user operations; a dynamic loading and security sandbox module, which retrieves extension packages from the extension repository according to loading requests and loads them into a secure, isolated environment for execution; an application programming interface (API) module, which provides standardized API interfaces for third-party extensions; and an aspect-oriented injection engine, which dynamically weaves the functional logic of third-party extensions during editor runtime. This invention overcomes the limitations and closed nature of block-based extensions, achieving secure, efficient, and flexible extension of graphical programming software.
Owner:CHENGDU LINGDIAN DYNAMIC TECHNOLOGY CO LTD

Software detection method and related device

A software detection method, comprising: acquiring an executable file of software to be subjected to detection; during the process of executing the executable file in an isolated environment, continuously acquiring application programming interface (API) sequences executed in the isolated environment, wherein the API sequences comprise a first API sequence executed in the isolated environment before a first moment; on the basis of the first API sequence executed in the isolated environment before the first moment, analyzing the executable file to obtain an analysis result; when the analysis result indicates that a malicious code is detected in the executable file, releasing resources for executing the executable file in the isolated environment; and when the analysis result indicates that no malicious code is detected in the executable file, analyzing the executable file on the basis of a second API sequence executed in the isolated environment before a second moment. By means of continuously analyzing whether there is maliciousness in a file to be subjected to detection during the dynamic execution of said file and advancing the timing of analysis, API sequence extraction and API sequence analysis can be performed in parallel, thereby improving the efficiency of analysis of a malicious code.
Owner:HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD

A secure isolation and integration method and device for Web application plug-ins

The present invention discloses a method and device for secure isolation and integration of Web application plug-ins. It belongs to the technical field of Web operating systems. In a Web operating system, a third-party plug-in source code is input; the third-party plug-in source code is compiled into a wasm file through the wasm compilation module of the sandbox module, wherein the sandbox module is used to provide an isolated environment; the wasm file is converted into the C source code and header file corresponding to the third-party plug-in source code through the wasm2c conversion module of the sandbox module; the third-party plug-in source code is sandboxed and reconstructed; the plug-in library source code is written, and the C source code and header file corresponding to the third-party plug-in source code are called; the plug-in library source code is compiled into a plug-in library and run. The function of securely accessing the third-party plug-in source code in the form of a plug-in in a Web application is realized, which solves the problem that existing Web applications cannot securely use third-party plug-ins developed in system languages ​​such as C / C++, realizes isolated control of memory access to third-party plug-ins, and avoids security risks such as data leakage and terminal device loss of control caused by third-party plug-in vulnerabilities.
Owner:NAT UNIV OF DEFENSE TECH

Instruction-level program debugging method and device and computer program product

According to the instruction-level program debugging method and device and the computer program product provided by the embodiment of the invention, the tracking log entry is generated by acquiring the execution data information of the machine instruction, and the key register value and the memory access information before and after each instruction is executed are recorded; any instruction execution point can be accurately traced back in the replay process, then the first tracking log entry is preprocessed into a structured instruction tracking log entry, and machine instructions of a target program are executed one by one through a preset instruction level simulator based on an instruction sequence of a uniform format and an analyzable structure, so that the replay efficiency of the target program is improved. The execution of the instruction is accurately simulated, the instruction-level replay operation of the program state is realized, the dependency on the external environment in the debugging process is greatly reduced based on simulator replay, debugging can be performed in a controlled and isolated environment, any execution path of the program can be replayed, the target program does not need to be run again, and the debugging efficiency is improved. And debugging of occasional and difficult-to-reproduce problems is greatly facilitated.
Owner:BEIJING BOXIAOTONG TECH CO LTD

Processing device, processing method, and program

A processing device 10 provides an isolated environment for processing data by processing logic in accordance with a policy. The processing device 10 includes an attestation report generation unit 122 that, following generating the isolated environment, verifies the isolated environment at a verification timing after initialization of the isolated environment and after the execution of processing of the data in the isolated environment, and generates report data including results of the verification. An attestation report includes a hash value of an attestation report from a preceding time.
Owner:NT T INC

Sovereign data center incoming data management

Techniques are described for data management. An example method can include receiving, by a first data center in a first region, a message indicating that an intermediate computing system managed by the first data center has received data from a second data center in a second region, the data stored in an isolated environment of the intermediate computing system. The method can further include determining a criterion for validating the data. The method can further include transmitting to the intermediate computing system, first control instructions to validate the data while stored in the isolated environment based at least in part on the criterion. The method can further include receiving validation results from the intermediate computing system. The method can further include causing the data to be released from the isolated environment based at least in part on the validation results.
Owner:ORACLE INT CORP

Model card example code-oriented automatic program repair method

The invention relates to a model card example code-oriented automatic program repairing method. The method comprises the following steps: performing syntax and semantic joint analysis on a model card document, extracting code snippets and execution clues, and reconstructing the model card document into a runnable document containing preset execution logic; determining a version combination according to clues to generate an environment identifier, constructing or multiplexing an isolation environment and binding a document, executing the document and recording information to form a complete log to locate a failure position, and extracting a context containing an error root cause in combination with execution state association. And converting context and environment information into a determinable condition, retrieving a repair strategy or case, and generating and optimizing a repair patch. And if the patch fails, iteration is carried out until success or an upper limit is reached. And finally, identifying missed conditions, and updating the knowledge base in combination with the optimal scheme to realize dynamic iterative expansion of the repair strategy. By adopting the method, the executable performance and reusability of codes and the stability of platform ecology can be improved.
Owner:NAT UNIV OF DEFENSE TECH

Lightweight function running method and system for server-unaware computing scenarios

The application provides a lightweight function running method and system for a server-unaware computing scene, and the method comprises the following steps: providing a communication primitive for fast cold start of an isolated environment and high-performance intermediate data transmission; for a server-unaware function computing workflow scene, a runtime is provided as a new software stack architecture; the function and the underlying runtime relied by the function are all deployed in the same CPU privilege level and address space for cold start operation; a library operating system with a workflow granularity is used to provide underlying runtime services for the function, and a memory-safe language is used to provide memory isolation and sharing; and an on-demand loading mechanism is implemented for the library operating system. The application solves the technical problems of slow cold start of an isolated environment, poor intermediate data transmission performance, large cold start range and high cost, and poor flexibility of memory isolation and sharing.
Owner:THE ACAD OF TIANJIN UNIV HEFEI

A self-optimizing security testing method, system, and computer-readable storage medium

As various systems evolve towards autonomous self-evolution, self-optimization capability has become a crucial characteristic of modern systems. Systems need to be able to propose improvement suggestions and automatically modify their own code or configuration based on operational data, user feedback, or external instructions. However, existing technologies suffer from deficiencies such as a lack of secure testing mechanisms, data corruption during testing, a stateless branching concept, a lack of conflict handling mechanisms, and insufficient rollback capabilities. This application provides a secure testing method, system, and computer-readable storage medium for system self-optimization, aiming to enable the target system to test improvement suggestions in an isolated environment, independently store state changes generated during testing, intelligently merge them into the main system after successful testing, safely discard them upon test failure, and support precise rollback, ensuring the system maintains stability and data integrity while autonomously evolving.
Owner:亓泽辰

Crib accessory

A pop up cover for a crib is provided for providing a safe, comfortable and isolated environment for a child in a crib. The pop-up cover may be made of breathable fabric panels having an integrated frame, for example a flexible frame, which can be folded (collapsed) on itself, for example when folded in specific ways if appropriate force is applied and which keeps the fabric in a taught, open position when unfolded (preventing the panels form falling inwards onto each other). The pop up cover can be lightweight and compact, quick and easy to set up, dark inside and breathable.
Owner:SLUMBERPOD LLC

Pneumatic isolation environment lift door

The utility model provides a kind of pneumatic isolated environment lift door, it is related to the technical field of isolation door, solve the problem that the transmission efficiency of movable door is low and the space occupied by driving structure is large under the condition of double-layer material conveying of existing rapid roller shutter door.The utility model includes main frame, movable door that is lifted and set in main frame, a group of lifting cylinders for driving movable door lifting symmetrically installed in the left and right sides of the front of main frame, a group of lifting linear guide rails for guiding left and right when movable door lifting symmetrically installed in the left and right sides of the front of main frame, a group of edge sealing symmetrically installed in the left and right inside of the front of main frame, a group of position sensors for positioning lifting stroke are respectively installed in the upper and lower ends of edge sealing.The utility model has the beneficial effects that: the up and down terminal point of lifting is accurately controlled, the overall structure space is simplified;Better ensure the movement track when moving;It can be used together in two sets.
Owner:NINGDE FENGYUE INTELLIGENT EQUIP CO LTD

Dustproof two-side vertical pile cutting machine

The utility model discloses a dustproof two-side vertical pile cutting machine, which relates to the technical field of flannelette cutting, and comprises a rack, a flannelette roller, a driving roller, a support, an expansion piece, a lifting plate, a cutting knife and a dustproof material receiving assembly, the flannelette roller and the driving roller are respectively arranged on the rack, the support is connected to the rack, the expansion piece is arranged on the support and connected with the lifting plate, and the cutting knife is connected with the lifting plate. The lifting plate is provided with a cutting knife, and the dustproof material collecting assembly is installed on the side portion of the machine frame and located on one side of the cutting knife. The dust cover surrounds the material receiving supporting plate, so that lint on the material receiving supporting plate can be placed in an environment relatively isolated from the outside, dust and fluff in a workshop are effectively prevented from easily making contact with each other and staying on the static lint, the lint collected on the material receiving supporting plate is cleaner, the surface is smoother, and the quality of the lint is improved. Long time consumed for cleaning lint by subsequent personnel is saved, and the practicability is improved.
Owner:QUANZHOU MINGQI INTELLIGENT TECH CO LTD

Maternal-imitating constant-temperature feeding device for mink cubs

The invention belongs to the technical field of constant-temperature feeding of mink cubs, and particularly relates to a maternal-imitating constant-temperature feeding device for mink cubs, which comprises a constant-temperature box, an air cushion is fixedly mounted at the bottom of an inner cavity of the constant-temperature box, first mink-imitating plush cloth is fixedly mounted at the top of the air cushion, and second mink-imitating plush cloth is fixedly mounted on the inner wall of the constant-temperature box. A micro vibration motor and a heating plate are fixedly mounted in the air cushion, a heating wire is fixedly mounted in the heating plate, a mounting frame is fixedly mounted on one side of the constant-temperature box, an air pump is fixedly mounted in the mounting frame, an air outlet pipe of the air pump is communicated with the air cushion, a groove is formed in the top of the constant-temperature box, and a sealing gasket is fixedly mounted at the bottom of the groove; according to the invention, through a'temperature-contact-pacifying 'three-in-one mode of bionic contact, bionic stimulation and restoration of female mink feeding, a cub engraving behavior caused by a traditional isolated environment is avoided, so that the survival rate of the mink cubs is improved.
Owner:FERRIS BIOTECHNOLOGY (WUXI) CO LTD

An automated program repair method for model card example code

The application relates to a model card example code-oriented automatic program repair method. The method comprises the following steps: performing joint syntax and semantics analysis on a model card document, extracting a code segment and an execution clue, and reconstructing into a runnable document containing preset execution logic; then determining a version combination generation environment identifier according to the clue, constructing or reusing an isolated environment, binding the document, executing the document, recording information to form a complete log to locate a failure position, and combining an execution state to associate and extract a context containing an error root cause. The context and environment information are converted into a determinable condition, a repair strategy or a case is retrieved, a repair patch is generated and optimized. The patch is verified, and if the verification fails, iteration is performed until success or an upper limit is reached. Finally, a non-hit condition is identified, an optimal scheme is updated in combination with a knowledge base, and repair strategy dynamic iteration and expansion are realized. The method can improve the executability, reusability and stability of a platform ecology of code.
Owner:NAT UNIV OF DEFENSE TECH