Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

109 results about "Network Access Control" patented technology

Network Access Control (NAC) is an approach to computer security that attempts to unify endpoint security technology (such as antivirus, host intrusion prevention, and vulnerability assessment), user or system authentication and network security enforcement.

Dynamic network access control method and system based on zero-trust architecture

The invention discloses a dynamic network access control method and system based on a zero-trust architecture, and the method comprises the steps: integrating equipment health degree evaluation through the triple dynamic binding of biological feature dynamic binding, equipment fingerprint salt value hash verification and environmental state perception, and constructing a real-time trust basis; dynamic risk quantification is realized based on a multi-source heterogeneous data fusion machine learning model, real-time upgrading and degrading self-adaptive adjustment of authority is realized through an AI driving strategy generation module according to a real-time risk score, a zero-trust sandbox limitation sensitive operation is triggered for high-risk access, and a minimum authority channel is started for low-risk access; performing fine-grained access control and intercepting an unauthorized request in real time by adopting an agent-free API gateway technology, and monitoring an operation behavior in combination with a block chain non-tampering storage access log and an anomaly detection algorithm; finally, a continuous self-adaptive evolutionary cycle is formed through a risk assessment-policy execution-abnormal feedback closed loop mechanism, and the static lag problem of traditional network access control is systematically solved.
Owner:TAISHAN UNIV

Network access control system and method and related equipment

The invention relates to a network access control system, a network access control method and related equipment. In the system, a client agent module is used for acquiring process identification information and establishing a binding relationship between a process and a network message; the traffic acquisition and analysis module is used for acquiring network messages at a gateway side, analyzing and aggregating the network messages and generating a structured traffic record; the process association verification module is used for verifying the validity of the binding relationship and establishing and maintaining the association relationship between the process and the structured traffic record; the traffic aggregation and strategy generation module is used for executing traffic aggregation and network behavior analysis based on the structured traffic record and the association relationship, and dynamically generating an access control strategy based on a network behavior analysis result; and the dynamic access control execution module is used for controlling the network access request based on the access control strategy and generating an execution result containing the control result. The system realizes self-adaptive generation of process-level control and access control strategies.
Owner:BEIJING EETRUST TECH CO LTD

Applying security policies based on endpoint and user attributes

An example network access control system includes a memory storing one or more security policies for an enterprise network; and one or more processors coupled to the memory and configured to: receive a request to connect to the enterprise network from a client device of a user, in response to the receipt of the request, determine one or more user attributes associated with the user and one or more endpoint attributes of the client device, identify a security policy of the one or more security policies based on the one or more user attributes and the one or more endpoint attributes, and configure an access control module of a network device of the enterprise network in accordance with the security policy.
Owner:JUNIPER NETWORKS INC

Network access control method and device, equipment and storage medium

The invention discloses a network access control method and device, equipment and a storage medium, and relates to the technical field of network security, and the method comprises the steps: receiving a network resource access request sent by a client, and determining a trust evaluation factor used for carrying out the trust evaluation of the client, and a current trust score; estimating a variation coefficient of a trust evaluation factor based on the number of accesses of the current access request and the current trust score; estimating a conflict coefficient of each trust evaluation factor based on the access frequency and the trust score, and determining an objective weight of each evaluation factor based on the conflict coefficient and the variable coefficient; fusing the subjective weight and the objective weight to obtain a comprehensive weight; and calculating the sum of the products of all the comprehensive weights and the current trust score to obtain a total trust score, if the total trust score exceeds a preset threshold, allowing access, and if the total trust score does not exceed the preset threshold, forbidding access. According to the method, the trust evaluation result can be more accurate, so that accurate network access control is realized.
Owner:CHINA SOUTH-TO-NORTH WATER DIVERSION GROUP WATER NETWORK SMART TECHNOLOGY CO LTD

User device characterization method based on network data traffic information, and network access control method thereof

Provided is a system for network access control. The system includes an authentication server configured to perform a basic authentication procedure for a user by communicating with at least one user terminal, a service server configured to provide a service to at least one user terminal passing through the basic authentication procedure, a collection device configured to acquire traffic data of the at least one user terminal passing through the basic authentication procedure from at least one of the service server and a network interface connected to the service server, acquire a traffic dataset by refining the acquired traffic data in accordance with correlation, and extract time-series feature points of the traffic dataset, and an artificial intelligence (AI) management device configured to train at least one AI model to define a traffic character template of the user on the basis of the time-series feature points.
Owner:AIRCUVE INC

CPE signal adaptive enhancement and link switching method and system

The invention relates to the technical field of wireless communication and terminal network access control, and discloses a CPE (Customer Premise Equipment) signal adaptive enhancement and link switching method and a CPE signal adaptive enhancement and link switching system. According to the method, combined characteristics reflecting short-time quality drop amplitude, error code burst degree, time delay bursting degree and apparent strength level can be included, so that the shielding shadow and multipath illusion can be distinguished in a scene in which the shielding and strong reflection of the steel structure coexist, and the multi-path illusion can be distinguished on the premise of not depending on multi-source data. A small amount of key link observation data is organized into fingerprint representation with scene identification capability, and a basis is provided for subsequent enhancement and switching control. Therefore, the link shadow fingerprint is introduced, so that the link control process has the capability of identifying the special phenomenon that the apparent signal is strong but the actual error code is burst, and the switching decision and the enhanced control form collaborative management, thereby reducing the error switching, reducing the switching jitter and improving the service continuity.
Owner:CHENGDU ZHUOLI COMM SERVICES CO LTD

Network threat systematic protection method

PendingCN121966996ASecuring communicationSecurity operations centerData aggregator
The invention discloses a network threat systematic protection method, and belongs to the technical field of network security. According to the method, a unified policy center is constructed, and three layers of security policies of an overlay network, a terminal and an application are defined and issued in a unified manner; network admission control, terminal security management and API risk monitoring systems are deployed to execute strategies respectively; an intelligent linkage mechanism is established, and cross-system automatic co-processing is realized; centralized monitoring, data aggregation and visual analysis are carried out through the unified safety operation center, and support is provided for optimization; and continuously optimizing the strategy and the rule based on the operation data. According to the invention, the problems of isolation, strategy splitting and response lag of a protection system in the prior art are solved, and an active defense system with cooperative linkage and continuous evolution is constructed.
Owner:GUANGZHOU CHANGBENHENG NETWORK TECHNOLOGY CO LTD +1

Network access control method, apparatus and device, and storage medium

Embodiments of the present disclosure relate to a network access control method, apparatus and device, and a storage medium. The network access control method includes: receiving a certificate verification request sent by a terminal, and returning a certificate verification response to the terminal, wherein the certificate verification response carries a preset server certificate, the certificate verification response is used for instructing the terminal to verify the preset server certificate based on a root certificate installed in the terminal, and identity verification information of the root certificate is partially or fully different from identity verification information of the preset server certificate; and receiving a verification result returned by the terminal for the preset server certificate, and in a case where the verification result indicates that certificate verification succeeds, determining that the terminal has a security risk and interrupting a network access communication link of the terminal. In the embodiments of the present disclosure, when the terminal successfully verifies the preset server certificate, the terminal may be prevented from accessing a network by interrupting the network access communication link with the terminal, thereby improving the security of the network.
Owner:DOUYIN VISION CO LTD

Feature-driven network access control

A First transceiver, especially transceiver of a user equipment, UE, is configured to receive a signal comprising one or more enhanced fields carrying an information for access control based upon feature support and / or feature activation, wherein the transceiver is configured to control its own access to the cell dependent on the one or more enhanced fields.
Owner:FRAUNHOFER GESELLSCHAFT ZUR FORDERUNG DER ANGEWANDTEN FORSCHUNG EV

Network access control method and electronic equipment

The invention discloses a network access control method and electronic equipment, and relates to the technical field of computers, network resources and access strategies thereof are visually presented in a graphical user interface in a node and connecting line mode, logic conflict judgment and strategy optimization recommendation are synchronously completed when a user drags and generates the strategies, and the network access control method and the electronic equipment have the advantages that the user experience is improved, and the user experience is improved. The abstract configuration process originally depending on a command line or a rule form is converted into a visual and interactive operation process, so that the degree of dependence of network access strategy configuration on professional experience is reduced, the probability of occurrence of artificial configuration errors is reduced, potential risks are controlled in the strategy generation stage, and the strategy generation efficiency is improved. And the overall efficiency and security of private cloud network access policy management are improved.
Owner:JINAN INSPUR DATA TECH CO LTD

Dynamic network access control system under zero-trust architecture

The invention discloses a dynamic network access control system under a zero-trust architecture, which relates to the technical field of network security, and comprises a multi-dimensional trust evaluation module, a self-adaptive micro-segmentation engine, a strategy decision execution module and a risk perception feedback module, the multi-dimensional trust evaluation module calculates a comprehensive trust score based on five-dimensional features of identity, equipment, network, application and data; the self-adaptive micro-segmentation engine dynamically generates network micro-segments based on a graph diffusion algorithm; the strategy decision execution module adopts deep reinforcement learning to generate an access decision; the risk perception feedback module identifies abnormity based on the LSTM network and adjusts trust parameters through closed-loop feedback, the four modules are deeply coupled and cooperated, refined dynamic access control is realized, the occurrence rate of security events is reduced by more than 85%, and an innovative solution is provided for enterprise network security.
Owner:INFORMATION CENT OF YELLOW RIVER WATER RESOURCES COMMISSION

Network access control system, method, apparatus and device

This application discloses a network access control system, method, apparatus, and device. The system involves a requesting device sending a network access request to a server; the server authenticating the request; if the authentication is successful, allowing the requesting device to access the target network; acquiring information related to a first network access behavior corresponding to the request and information related to a second network access behavior corresponding to the holder of the network access credential; generating a network access risk assessment prompt based on the first and second network access behavior information; the large language model performing a network access risk assessment based on the prompt; and controlling the requesting device's access to the target network based on the network access risk assessment result. This approach effectively balances a high level of user experience and new risk identification capability with low hardware requirements and low risk assessment data processing requirements.
Owner:ALIBABA (CHINA) CO LTD

Predictive model for handling network configuration failures

A method of operating a server is provided that includes providing, with the server, one or more services relating to network access control and management of a network, predicting a network configuration failure associated with the network with a failure prediction model, and generating a network configuration recommendation based on the predicted network configuration failure to avoid the predicted network configuration failure. The failure prediction model can be a machine-learning based network configuration failure prediction model that is trained on past network configuration failure events. Operated in this way, erroneous network configuration issues can be automatically identified and addressed in a timely fashion.
Owner:ARISTA NETWORKS INC

On-chip network access control methods, devices, equipment, media and products

This disclosure provides a method, apparatus, device, medium, and product for access verification in on-chip networks (NoCs), relating to integrated circuit design and verification and System-on-Chip (SoC) design technologies, particularly in the areas of NoC security verification, access control, and access control isolation verification. The specific implementation scheme is as follows: a routing access permission file is parsed to obtain access permission paths and self-test instances; the self-test instances are executed to obtain self-test results; the self-test results and the routing access permission file are compared and verified to obtain a verification result; if the verification result fails, the access permission paths in the routing access permission file are modified until the verification result passes; routing tests are performed in a UVM environment based on the modified access permission paths to obtain the access verification result. This technical solution can shorten the access verification cycle of on-chip networks.
Owner:KUNWANG (SHANGHAI) TECH CO LTD

Network access control list adjusting method based on flow analysis and optimization

The invention provides a network access control list adjusting method based on flow analysis and optimization, which comprises the following steps of: firstly, acquiring total flow information, and then dynamically constructing a network digital twinborn model based on the total flow information; constructing a causal derivation model based on a simulation result of the network digital twin model; analyzing and processing the real-time traffic by using a causal derivation model, and generating a plurality of network access control list change rules and corresponding deployment strategies; and then simulating the network access control list change rules and the deployment strategy thereof in the network digital twin model, and determining a target network access control list from each network access control list change rule based on a simulation result. According to the invention, a self-learning, dynamic risk quantification and strategy automatic generation and verification ACL tuning system is constructed, and the ACL tuning system is not only an optimization rule, but fundamentally changes the generation and management normal form of the ACL.
Owner:BEIJING ITECHSHARE NETWORK INFORMATION TECH CO LTD

Device-assisted services for protecting network capacity

Device Assisted Services (DAS) for protecting network capacity is provided. In some embodiments, DAS for protecting network capacity includes monitoring a network service usage activity of the communications device in network communication; classifying the network service usage activity for differential network access control for protecting network capacity; and associating the network service usage activity with a network service usage control policy based on a classification of the network service usage activity to facilitate differential network access control for protecting network capacity.
Owner:HEADWATER RESEARCH LLC

Blacklist control method and device for cloud-native kubernetes network

Embodiments of the present disclosure disclose a black list control method and device for cloud-native kubernetes network. The specific implementation of the method comprises: importing a configuration file for interacting with an API service node to obtain a container resource and a network access control custom resource; receiving an event synchronized by the API service node, wherein the event is triggered by the API service node according to a change in the pre-configured container resource and network access control custom resource; obtaining an IP list according to the container resource and the network access control custom resource; generating a black list according to the IP list; and discarding data in response to receiving data meeting the black list. The implementation realizes a black list management and configuration scheme for kubernetes cloud-native.
Owner:JD DIGITS HAIYI INFORMATION TECHNOLOGY CO LTD

Block chain network access control method and device, equipment and storage medium

The invention provides a block chain network access control method and device, equipment and a storage medium, and relates to the technical field of access control. The method comprises the steps of firstly obtaining a user certificate issued by a certificate issuing mechanism in a block chain system; the method comprises the steps of obtaining a TLS certificate issued by a TLS certificate issuing mechanism, carrying out integrity verification on the TLS certificate issued by the TLS certificate issuing mechanism, ensuring communication security between a user and a block chain system, obtaining a data signature certificate issued by a signature issuing mechanism after the integrity verification is passed, and signing target transaction data information and a user certificate by using the data signature certificate. And sending the signed target transaction data information and the user credential to a target institution, and applying for data access, and after the target institution verifies that the data access permission of the user is passed, the user can access the target transaction data. According to the method and the system, the security of the system is enhanced by implementing access permission control on different levels of the block chain system through the multi-level certificate structure.
Owner:CHENGDU PRIME STARK TECH CO LTD

Organization identification of network access server devices into a multi-tenant cloud network access control service

A multi-tenant, cloud-hosted Network Access Control (NAC) system may receive an indicator from a Network Access Server (NAS) device to identify the tenant with which the NAS device is associated. The NAS device may put the identifier in the Transport Layer Security (TLS) / Secure Sockets Layer (SSL) extension Server Name Indication (SNI) field. The NAC system may use the identifier to obtain tenant-specific configuration information for setting up a secure tunnel with the NAS device.
Owner:JUNIPER NETWORKS INC

Network control method, device, equipment, medium and program product

The embodiment of the invention provides a network control method and device, equipment, a medium and a program product, and relates to the technical field of terminal intelligent control. The method comprises the steps of obtaining a unique identifier of a target application program; constructing a network access control list containing the target application program; and configuring a network filtering rule for the target application program based on the network access control list and the unique identifier. Based on the method, the accuracy of network filtering rule configuration can be improved through the uniqueness of the unique identifier of the target application program, and misjudgment caused by factors such as address or port overlapping is avoided. And the network filtering rule is configured for the target application program based on the network access control list and the unique identifier, so that data packet filtering can be forcibly processed, and the forcibility and uniformity of the rule are ensured. Therefore, through the method, the accuracy, uniformity and mandatory of network control can be improved.
Owner:SHENZHEN TAILIWEI INTELLIGENT TECHNOLOGY CO LTD

Risk assessment for network access control through data analytics

Methods and systems of risk assessment for network access control through data analytics. An embodiment of the invention employs well-known machine-learning clustering methods to learn normal entity behavior by looking for patterns in the events that stream in continuously. In an embodiment of the invention, normal entity behaviors are represented as clusters of event vectors. An embodiment of the invention evaluates the risk level for a new event of an entity by comparing the event with the entity's profile represented as clusters of event vectors. In an embodiment of the invention, the risk level is associated with a confidence level. Confidence level indicates how well the system knows about the entity. Embodiments of the invention do not need human administration in the process of building entity profile and assessing risk level of events associated with an entity.
Owner:CYBER ARK SOFTWARE LTD

Network access control method and system for multi-band wireless local area network

The invention discloses a network access control method and system for a multi-band wireless local area network, and belongs to the technical field of wireless communication. The method comprises: on a first frequency band, an access point sends a probe response frame carrying a neighbor report element to a station device, the element comprising target beacon transmission time TBTT offset or target wake-up time TWT offset information of the access point on a second frequency band, and access permission information; and the site equipment calculates accurate scanning starting time based on the offset information, and executes a controlled access process according to the access permission information. According to the invention, by constructing a double-layer architecture of an auxiliary transfer layer and a target service layer and utilizing a cross-band accurate time sequence calibration and authority control mechanism, the problems of low discovery efficiency, high scanning power consumption, serious channel competition conflict, uneven load and the like of a 6GHz band network in the prior art are solved; and the access efficiency, the resource utilization rate and the user experience of the multi-band network are remarkably improved.
Owner:JIANGNAN INFORMATION SECURITY (BEIJING) TECH CO LTD

Cross-platform driver-free network card certificate reading method and device and medium

The application provides a cross-platform driver-free network card certificate reading method and device and a medium, relates to the technical field of network access control, and the method comprises the steps of: constructing a virtual certificate address space in a network card firmware; receiving a target control message; when the network card firmware identifies the preset identification information, importing a certificate reading parameter of the target control message into the virtual certificate address space in the network card firmware, reading a target certificate data segment through mapping to an SPI storage chip; generating a plurality of response messages, writing the response messages into a network card receiving queue, making a network interface receive the plurality of response messages, and splicing the received plurality of response messages by a user state program to obtain complete certificate data. The application solves the technical problem in the prior art that, due to the fact that certificate reading relies on a special driver program, cross-platform reading needs to modify a network card driver program, and builds a virtual certificate address space and maps the virtual certificate address space to an SPI storage, thereby improving cross-platform compatibility.
Owner:SUZHOU HONGCUNXINJIE TECH CO LTD

Database VPC network access method and device, electronic equipment and program product

The invention discloses a database VPC network access method and device, electronic equipment and a program product, and relates to the technical field of cloud computing. According to the method, a network access control assembly comprising a configuration control unit and a cluster control unit is deployed through a container arrangement platform, the cluster control unit judges whether to access a VPC network or not based on annotation information of cloud database custom resources, and a connection agent assembly is deployed during access; and the connection agent component receives and forwards the VPC network request through the first network card and the second network card. The cluster control unit monitors VPC network address change, updates annotation information and binds domain names or elastic public network services, and the configuration control unit achieves configuration hot update of the cluster control unit. According to the technical scheme, non-awareness access of the VPC network of the cloud database is realized, the influence of POD restart on stock connection is avoided, high availability of main and standby switching and real-time hot update of configuration are guaranteed, and the access flexibility, reliability and operation and maintenance efficiency of the VPC network are effectively improved.
Owner:CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1

Network access control method, readable medium, and vehicle-mounted communication terminal

The application relates to the field of Internet of Vehicles, and discloses a network access control method, a readable medium and a vehicle-mounted communication terminal. The network access control method comprises the following steps: a vehicle-mounted communication terminal acquires a domain name resolution request message, wherein the domain name resolution request message comprises a first URL address; the vehicle-mounted communication terminal sends the domain name resolution request message to a domain name resolution server under the condition that the first URL address meets a first preset condition; the vehicle-mounted communication terminal receives a domain name resolution response message generated by the domain name resolution server after the domain name resolution server performs domain name resolution on the first URL address, wherein the domain name resolution response message comprises a first IP address; the vehicle-mounted communication terminal adds the first IP address to an IP address white list under the condition that the domain name resolution response message meets a second preset condition; the vehicle-mounted communication terminal acquires a third IP address generated for a user access request; and the third IP address is allowed to access an external server under the condition that the IP address white list contains the third IP address.
Owner:HUAWEI TECH CO LTD

Cross-border network access control system and method based on service identification

The invention aims to solve the technical problem that an enterprise cannot carry out refined compliance control on the behavior of accessing the overseas Internet service by employees. A traditional firewall is based on an IP management and control mode, specific overseas websites accessed by employees through HTTPS cannot be identified, and a compliance blind area exists. The core method is characterized in that an application layer protocol is analyzed through business identification, and feature information used for identifying target service is extracted, so that specific overseas services or websites to which employees intend to access are accurately identified; the strategy control center matches the identification result with a preset compliance strategy in real time and executes corresponding permission or blocking control; therefore, access to non-compliant overseas services is accurately blocked, normal use of authorized overseas resources is not affected, and key technical means and auditing evidences are provided for an enterprise to perform network content management compliance obligations.
Owner:HUBEI LITTLE UMBRELLA TECHNOLOGY CO LTD

Message processing method and related apparatus

PCT designated stageWO2026036651A1Securing communicationEngineeringMessage processing
A message processing method, which is applied to implementing network access control and preventing the number of policies stored in a network device from expanding. In the message processing method, firstly, a plurality of user identities corresponding to a message are determined on the basis of a sending source identifier in the message; then, a corresponding policy action is searched for each user identity, thereby obtaining a plurality of policy actions; and finally, on the basis of the plurality of policy actions, one target policy action is determined for execution, thereby implementing network access control of the message. In the present solution, after a plurality of user identities corresponding to a message are acquired, the plurality of user identities are respectively used to execute policy matching a plurality of times, and then a policy action that needs to be executed is determined on the basis of a plurality of matched policy actions. Therefore, when a user identity corresponding to a user changes, a controller only adjusts the user identity corresponding to the user without the need for issuing a new policy action to a network device, thereby effectively preventing the number of policies stored in the network device from expanding, and ensuring the normal operation of the network device.
Owner:HUAWEI TECH CO LTD

Multi-modal big data fusion analysis method and system for network security

The invention relates to the technical field of network security-oriented multi-modal big data fusion analysis, and discloses a network security-oriented multi-modal big data fusion analysis method and system. Establishing a communication topology for the firewall, the network access control system, the video switching system and the three-layer switch, and positioning an external injection point; collecting multi-source data to count the packet amount in a fixed window, and converting the packet amount into link / node equivalent resistance; a resistance network and an admittance matrix are assembled, a current vector is constructed in combination with injection flow, and node data potential is solved; generating a dynamic baseline according to historical data and calculating a real-time deviation; normalizing the potential and the current deviation to obtain an abnormal score and judging an abnormal node; and tracing the abnormal nodes by applying a minimum dissipation path algorithm, and outputting a node set and a path.
Owner:泗水县大数据中心(泗水县电子政务中心) +1

Device-Assisted Services for Protecting Network Capacity

Device Assisted Services (DAS) for protecting network capacity is provided. In some embodiments, DAS for protecting network capacity includes monitoring a network service usage activity of the communications device in network communication; classifying the network service usage activity for differential network access control for protecting network capacity; and associating the network service usage activity with a network service usage control policy based on a classification of the network service usage activity to facilitate differential network access control for protecting network capacity.
Owner:HEADWATER RESEARCH LLC

Adaptive Distributed Network Integration System and Method for Virtual-Real UAV Collaboration

ActiveCN120658776BNetwork topologiesSecurity arrangementEngineeringOnline identity
This invention discloses an adaptive distributed network integration system and method for virtual-real drone collaboration, relating to the field of drone control technology. It includes a central control plane and at least one node agent. The central control plane comprises: a global identity manager, configured to assign globally unique network identity information and record and reclaim the network identity information; a network topology and state manager, configured to generate virtual-real network state views, respond to queries, and issue network simulation commands to the node agents; a distributed network coordinator, configured to decide and coordinate the node agents to construct a cross-host logical Layer 2 network domain; and a security policy manager, configured to define and store network access control policies for virtual drones. This adaptive distributed network integration system and method aims to achieve a "physical" representation of virtual drones at the network layer, enabling them to communicate directly and collaborate with real drones within the same network plane.
Owner:ARTIFICIAL INTELLIGENCE RES INST OF HEFEI COMPREHENSIVE NAT SCI CENT (ANHUI ARTIFICIAL INTELLIGENCE LAB)