Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

70 results about "Network Access Control" patented technology

Network Access Control (NAC) is an approach to computer security that attempts to unify endpoint security technology (such as antivirus, host intrusion prevention, and vulnerability assessment), user or system authentication and network security enforcement.

Dynamic network access control method and system based on zero-trust architecture

The invention discloses a dynamic network access control method and system based on a zero-trust architecture, and the method comprises the steps: integrating equipment health degree evaluation through the triple dynamic binding of biological feature dynamic binding, equipment fingerprint salt value hash verification and environmental state perception, and constructing a real-time trust basis; dynamic risk quantification is realized based on a multi-source heterogeneous data fusion machine learning model, real-time upgrading and degrading self-adaptive adjustment of authority is realized through an AI driving strategy generation module according to a real-time risk score, a zero-trust sandbox limitation sensitive operation is triggered for high-risk access, and a minimum authority channel is started for low-risk access; performing fine-grained access control and intercepting an unauthorized request in real time by adopting an agent-free API gateway technology, and monitoring an operation behavior in combination with a block chain non-tampering storage access log and an anomaly detection algorithm; finally, a continuous self-adaptive evolutionary cycle is formed through a risk assessment-policy execution-abnormal feedback closed loop mechanism, and the static lag problem of traditional network access control is systematically solved.
Owner:TAISHAN UNIV

Network access control system and method and related equipment

The invention relates to a network access control system, a network access control method and related equipment. In the system, a client agent module is used for acquiring process identification information and establishing a binding relationship between a process and a network message; the traffic acquisition and analysis module is used for acquiring network messages at a gateway side, analyzing and aggregating the network messages and generating a structured traffic record; the process association verification module is used for verifying the validity of the binding relationship and establishing and maintaining the association relationship between the process and the structured traffic record; the traffic aggregation and strategy generation module is used for executing traffic aggregation and network behavior analysis based on the structured traffic record and the association relationship, and dynamically generating an access control strategy based on a network behavior analysis result; and the dynamic access control execution module is used for controlling the network access request based on the access control strategy and generating an execution result containing the control result. The system realizes self-adaptive generation of process-level control and access control strategies.
Owner:BEIJING EETRUST TECH CO LTD

Applying security policies based on endpoint and user attributes

An example network access control system includes a memory storing one or more security policies for an enterprise network; and one or more processors coupled to the memory and configured to: receive a request to connect to the enterprise network from a client device of a user, in response to the receipt of the request, determine one or more user attributes associated with the user and one or more endpoint attributes of the client device, identify a security policy of the one or more security policies based on the one or more user attributes and the one or more endpoint attributes, and configure an access control module of a network device of the enterprise network in accordance with the security policy.
Owner:JUNIPER NETWORKS INC

CPE signal adaptive enhancement and link switching method and system

The invention relates to the technical field of wireless communication and terminal network access control, and discloses a CPE (Customer Premise Equipment) signal adaptive enhancement and link switching method and a CPE signal adaptive enhancement and link switching system. According to the method, combined characteristics reflecting short-time quality drop amplitude, error code burst degree, time delay bursting degree and apparent strength level can be included, so that the shielding shadow and multipath illusion can be distinguished in a scene in which the shielding and strong reflection of the steel structure coexist, and the multi-path illusion can be distinguished on the premise of not depending on multi-source data. A small amount of key link observation data is organized into fingerprint representation with scene identification capability, and a basis is provided for subsequent enhancement and switching control. Therefore, the link shadow fingerprint is introduced, so that the link control process has the capability of identifying the special phenomenon that the apparent signal is strong but the actual error code is burst, and the switching decision and the enhanced control form collaborative management, thereby reducing the error switching, reducing the switching jitter and improving the service continuity.
Owner:CHENGDU ZHUOLI COMM SERVICES CO LTD

Network threat systematic protection method

PendingCN121966996ASecuring communicationSecurity operations centerData aggregator
The invention discloses a network threat systematic protection method, and belongs to the technical field of network security. According to the method, a unified policy center is constructed, and three layers of security policies of an overlay network, a terminal and an application are defined and issued in a unified manner; network admission control, terminal security management and API risk monitoring systems are deployed to execute strategies respectively; an intelligent linkage mechanism is established, and cross-system automatic co-processing is realized; centralized monitoring, data aggregation and visual analysis are carried out through the unified safety operation center, and support is provided for optimization; and continuously optimizing the strategy and the rule based on the operation data. According to the invention, the problems of isolation, strategy splitting and response lag of a protection system in the prior art are solved, and an active defense system with cooperative linkage and continuous evolution is constructed.
Owner:GUANGZHOU CHANGBENHENG NETWORK TECHNOLOGY CO LTD +1

Feature-driven network access control

A First transceiver, especially transceiver of a user equipment, UE, is configured to receive a signal comprising one or more enhanced fields carrying an information for access control based upon feature support and / or feature activation, wherein the transceiver is configured to control its own access to the cell dependent on the one or more enhanced fields.
Owner:FRAUNHOFER GESELLSCHAFT ZUR FORDERUNG DER ANGEWANDTEN FORSCHUNG EV

Network access control method and electronic equipment

The invention discloses a network access control method and electronic equipment, and relates to the technical field of computers, network resources and access strategies thereof are visually presented in a graphical user interface in a node and connecting line mode, logic conflict judgment and strategy optimization recommendation are synchronously completed when a user drags and generates the strategies, and the network access control method and the electronic equipment have the advantages that the user experience is improved, and the user experience is improved. The abstract configuration process originally depending on a command line or a rule form is converted into a visual and interactive operation process, so that the degree of dependence of network access strategy configuration on professional experience is reduced, the probability of occurrence of artificial configuration errors is reduced, potential risks are controlled in the strategy generation stage, and the strategy generation efficiency is improved. And the overall efficiency and security of private cloud network access policy management are improved.
Owner:JINAN INSPUR DATA TECH CO LTD

Dynamic network access control system under zero-trust architecture

The invention discloses a dynamic network access control system under a zero-trust architecture, which relates to the technical field of network security, and comprises a multi-dimensional trust evaluation module, a self-adaptive micro-segmentation engine, a strategy decision execution module and a risk perception feedback module, the multi-dimensional trust evaluation module calculates a comprehensive trust score based on five-dimensional features of identity, equipment, network, application and data; the self-adaptive micro-segmentation engine dynamically generates network micro-segments based on a graph diffusion algorithm; the strategy decision execution module adopts deep reinforcement learning to generate an access decision; the risk perception feedback module identifies abnormity based on the LSTM network and adjusts trust parameters through closed-loop feedback, the four modules are deeply coupled and cooperated, refined dynamic access control is realized, the occurrence rate of security events is reduced by more than 85%, and an innovative solution is provided for enterprise network security.
Owner:INFORMATION CENT OF YELLOW RIVER WATER RESOURCES COMMISSION

Network access control system, method, apparatus and device

This application discloses a network access control system, method, apparatus, and device. The system involves a requesting device sending a network access request to a server; the server authenticating the request; if the authentication is successful, allowing the requesting device to access the target network; acquiring information related to a first network access behavior corresponding to the request and information related to a second network access behavior corresponding to the holder of the network access credential; generating a network access risk assessment prompt based on the first and second network access behavior information; the large language model performing a network access risk assessment based on the prompt; and controlling the requesting device's access to the target network based on the network access risk assessment result. This approach effectively balances a high level of user experience and new risk identification capability with low hardware requirements and low risk assessment data processing requirements.
Owner:ALIBABA (CHINA) CO LTD

On-chip network access control methods, devices, equipment, media and products

This disclosure provides a method, apparatus, device, medium, and product for access verification in on-chip networks (NoCs), relating to integrated circuit design and verification and System-on-Chip (SoC) design technologies, particularly in the areas of NoC security verification, access control, and access control isolation verification. The specific implementation scheme is as follows: a routing access permission file is parsed to obtain access permission paths and self-test instances; the self-test instances are executed to obtain self-test results; the self-test results and the routing access permission file are compared and verified to obtain a verification result; if the verification result fails, the access permission paths in the routing access permission file are modified until the verification result passes; routing tests are performed in a UVM environment based on the modified access permission paths to obtain the access verification result. This technical solution can shorten the access verification cycle of on-chip networks.
Owner:KUNWANG (SHANGHAI) TECH CO LTD

Device-assisted services for protecting network capacity

Device Assisted Services (DAS) for protecting network capacity is provided. In some embodiments, DAS for protecting network capacity includes monitoring a network service usage activity of the communications device in network communication; classifying the network service usage activity for differential network access control for protecting network capacity; and associating the network service usage activity with a network service usage control policy based on a classification of the network service usage activity to facilitate differential network access control for protecting network capacity.
Owner:HEADWATER RESEARCH LLC

Block chain network access control method and device, equipment and storage medium

The invention provides a block chain network access control method and device, equipment and a storage medium, and relates to the technical field of access control. The method comprises the steps of firstly obtaining a user certificate issued by a certificate issuing mechanism in a block chain system; the method comprises the steps of obtaining a TLS certificate issued by a TLS certificate issuing mechanism, carrying out integrity verification on the TLS certificate issued by the TLS certificate issuing mechanism, ensuring communication security between a user and a block chain system, obtaining a data signature certificate issued by a signature issuing mechanism after the integrity verification is passed, and signing target transaction data information and a user certificate by using the data signature certificate. And sending the signed target transaction data information and the user credential to a target institution, and applying for data access, and after the target institution verifies that the data access permission of the user is passed, the user can access the target transaction data. According to the method and the system, the security of the system is enhanced by implementing access permission control on different levels of the block chain system through the multi-level certificate structure.
Owner:CHENGDU PRIME STARK TECH CO LTD

Network control method, device, equipment, medium and program product

The embodiment of the invention provides a network control method and device, equipment, a medium and a program product, and relates to the technical field of terminal intelligent control. The method comprises the steps of obtaining a unique identifier of a target application program; constructing a network access control list containing the target application program; and configuring a network filtering rule for the target application program based on the network access control list and the unique identifier. Based on the method, the accuracy of network filtering rule configuration can be improved through the uniqueness of the unique identifier of the target application program, and misjudgment caused by factors such as address or port overlapping is avoided. And the network filtering rule is configured for the target application program based on the network access control list and the unique identifier, so that data packet filtering can be forcibly processed, and the forcibility and uniformity of the rule are ensured. Therefore, through the method, the accuracy, uniformity and mandatory of network control can be improved.
Owner:SHENZHEN TAILIWEI INTELLIGENT TECHNOLOGY CO LTD

Risk assessment for network access control through data analytics

Methods and systems of risk assessment for network access control through data analytics. An embodiment of the invention employs well-known machine-learning clustering methods to learn normal entity behavior by looking for patterns in the events that stream in continuously. In an embodiment of the invention, normal entity behaviors are represented as clusters of event vectors. An embodiment of the invention evaluates the risk level for a new event of an entity by comparing the event with the entity's profile represented as clusters of event vectors. In an embodiment of the invention, the risk level is associated with a confidence level. Confidence level indicates how well the system knows about the entity. Embodiments of the invention do not need human administration in the process of building entity profile and assessing risk level of events associated with an entity.
Owner:CYBER ARK SOFTWARE LTD

Network access control method and system for multi-band wireless local area network

The invention discloses a network access control method and system for a multi-band wireless local area network, and belongs to the technical field of wireless communication. The method comprises: on a first frequency band, an access point sends a probe response frame carrying a neighbor report element to a station device, the element comprising target beacon transmission time TBTT offset or target wake-up time TWT offset information of the access point on a second frequency band, and access permission information; and the site equipment calculates accurate scanning starting time based on the offset information, and executes a controlled access process according to the access permission information. According to the invention, by constructing a double-layer architecture of an auxiliary transfer layer and a target service layer and utilizing a cross-band accurate time sequence calibration and authority control mechanism, the problems of low discovery efficiency, high scanning power consumption, serious channel competition conflict, uneven load and the like of a 6GHz band network in the prior art are solved; and the access efficiency, the resource utilization rate and the user experience of the multi-band network are remarkably improved.
Owner:JIANGNAN INFORMATION SECURITY (BEIJING) TECH CO LTD

Cross-platform driver-free network card certificate reading method and device and medium

The application provides a cross-platform driver-free network card certificate reading method and device and a medium, relates to the technical field of network access control, and the method comprises the steps of: constructing a virtual certificate address space in a network card firmware; receiving a target control message; when the network card firmware identifies the preset identification information, importing a certificate reading parameter of the target control message into the virtual certificate address space in the network card firmware, reading a target certificate data segment through mapping to an SPI storage chip; generating a plurality of response messages, writing the response messages into a network card receiving queue, making a network interface receive the plurality of response messages, and splicing the received plurality of response messages by a user state program to obtain complete certificate data. The application solves the technical problem in the prior art that, due to the fact that certificate reading relies on a special driver program, cross-platform reading needs to modify a network card driver program, and builds a virtual certificate address space and maps the virtual certificate address space to an SPI storage, thereby improving cross-platform compatibility.
Owner:SUZHOU HONGCUNXINJIE TECH CO LTD

Cross-border network access control system and method based on service identification

The invention aims to solve the technical problem that an enterprise cannot carry out refined compliance control on the behavior of accessing the overseas Internet service by employees. A traditional firewall is based on an IP management and control mode, specific overseas websites accessed by employees through HTTPS cannot be identified, and a compliance blind area exists. The core method is characterized in that an application layer protocol is analyzed through business identification, and feature information used for identifying target service is extracted, so that specific overseas services or websites to which employees intend to access are accurately identified; the strategy control center matches the identification result with a preset compliance strategy in real time and executes corresponding permission or blocking control; therefore, access to non-compliant overseas services is accurately blocked, normal use of authorized overseas resources is not affected, and key technical means and auditing evidences are provided for an enterprise to perform network content management compliance obligations.
Owner:HUBEI LITTLE UMBRELLA TECHNOLOGY CO LTD

Message processing method and related apparatus

PCT designated stageWO2026036651A1Securing communicationEngineeringMessage processing
A message processing method, which is applied to implementing network access control and preventing the number of policies stored in a network device from expanding. In the message processing method, firstly, a plurality of user identities corresponding to a message are determined on the basis of a sending source identifier in the message; then, a corresponding policy action is searched for each user identity, thereby obtaining a plurality of policy actions; and finally, on the basis of the plurality of policy actions, one target policy action is determined for execution, thereby implementing network access control of the message. In the present solution, after a plurality of user identities corresponding to a message are acquired, the plurality of user identities are respectively used to execute policy matching a plurality of times, and then a policy action that needs to be executed is determined on the basis of a plurality of matched policy actions. Therefore, when a user identity corresponding to a user changes, a controller only adjusts the user identity corresponding to the user without the need for issuing a new policy action to a network device, thereby effectively preventing the number of policies stored in the network device from expanding, and ensuring the normal operation of the network device.
Owner:HUAWEI TECH CO LTD

Distributed link failure resilient low latency network access control with authentication offloading

A network access server (NAS) device on a wireless network at a site is described, the NAS device comprising a memory comprising a policy cache having entries for one or more client devices, wherein each entry includes a last policy action previously identified by a network access control (NAC) system for a respective client device. The NAS device also includes processing circuitry configured to authenticate a client device upon receiving an access request from the client device for a wireless network. The processing circuitry is configured to determine, after authentication of the client device, whether the client device is included in the policy cache. The processing circuitry is configured to authorize the client device to access the wireless network according to a last policy action for the client device based on the client device being included in the policy cache.
Owner:JUNIPER NETWORKS INC

A method for processing information of a base station and system, and related devices

The present disclosure discloses a method for processing information of a base station and system, and related devices, and relates to the technical field of communication technology. The method of the present disclosure is executed by a network access control function (NACF), including: receiving base station status information sent from each of a plurality of base stations; determining a handover priority for the each of the plurality of base stations based on the base station status information of the each of the plurality of base stations; and sending to the each of the plurality of base stations the handover priority of a relevant base station of the each of the plurality of base stations.
Owner:CHINA TELECOM CORP LTD

Data packet verification method, system and device, electronic equipment and medium

The invention provides a data packet verification method, system and device, electronic equipment and a medium. The method comprises the following steps: receiving a data packet sent by a bare metal server; verifying the data packet by using a multi-level network security rule to obtain a verification result of the data packet; and if the verification result indicates that the data packet is a secure data packet, the data packet is sent to a software defined network, and the multi-level network security rule comprises a security group rule and a network access control list rule. According to the method provided by the invention, the problems of high cost, complex networking, strong coupling and limited functions in the prior art are effectively solved, and an efficient, flexible and reliable bare metal server security access implementation mode is provided.
Owner:CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1

Controller-based system for controlling network access, and method therefor

A node according to an embodiment disclosed in the present document may store instructions for: performing a network access request to an external server through an access control application, the network access request including identification information of a target application and identification information of a destination network; receiving a data flow from the external server through the access control application, the data flow corresponding to identification information of the node and the identification information of the destination network and including information about whether a data packet can be transmitted through a virtual router; and transmitting a data packet of the target application on the basis of the received data flow, through the access control application. The virtual router may be included in a switch to which the node transmits the data packet.
Owner:PRIBIT TECH INC

Security authentication method and system for switch access terminal

The invention provides a switch access terminal security authentication method and system, and the method comprises the steps: detecting a terminal access request through a switch, executing initial authentication based on a terminal hardware fingerprint and a user certificate, and generating and issuing a static key seed corresponding to a session after the authentication is passed; during the terminal access period, according to the track offset degree of the current behavior relative to the historical behavior, calculating the behavior abnormity membership degree; updating the dynamic trust value according to the abnormal behavior membership degree, and generating a security parameter containing a key strength parameter and a micro-isolation strategy identifier; and performing multiple rounds of hash derivation on the static key seed based on the key strength parameter to obtain a dynamic session key, retrieving an access control rule from a policy library in combination with the micro-isolation policy identifier, and issuing the access control rule to a switch to realize communication encryption and dynamic network access control. By adopting the scheme of the invention, adaptive regulation and control of the dynamic key and access control based on terminal behavior perception can be realized, so that the security protection response capability of the switch access environment is improved.
Owner:GUANGZHOU SHENGJIA JIANYE TECH CO LTD

Network and Method for Handling Network Access Control

A network for handling a network access control comprises a memory and a processor. The memory stores instructions and the processor coupled to the memory is configured to execute the instructions of: receiving a registration request from a communication device; determining whether validity information in a UE subscription for a stand-alone non-public network (SNPN) providing access for localized services is met, in response to receiving the registration request; and rejecting the registration request when the validity information is not met, which result in rejecting the communication device with an appropriate cause code to prevent the communication device from selecting or registering the network again in a SNPN selection procedure.
Owner:MEDIATEK INC

Industrial control host interface management and control system based on communication control and flow analysis

The invention relates to an industrial control host interface management and control system based on communication control and flow analysis, and belongs to the field of industrial information security. The system comprises a communication interface control module and a data security detection module, and the communication interface control module comprises a server-side interface group, an equipment-side interface group and a management-side interface group. The data security detection module is divided into seven modules: a communication data forwarding module, a network port data protection module, a serial port data protection module, a communication security encryption and decryption module, a communication mode dynamic configuration module, a configuration management auditing module and an access control module. The system disclosed by the invention is deployed between the industrial control equipment and an external communication end in an industrial control network environment by adopting an external deployment mode, so that security protection such as network access control, communication interface management and control, access control, communication content detection, communication link encryption, maintenance process management and control, USB storage equipment external connection management and control, comprehensive security audit and the like of the industrial control equipment is realized.
Owner:BEIJING INST OF COMP TECH & APPL

A method and system for CPE signal adaptive enhancement and link switching

The present application relates to the technical field of wireless communication and terminal network access control, and discloses a CPE signal adaptive enhancement and link switching method and system, wherein a link shadow fingerprint used for representing the fluctuation form of link quality in a short period is introduced, the combined features reflecting the short-time quality drop range, error code burst degree, time delay spike degree and apparent intensity level can be contained, and then the differentiation between the shielding shadow and the multipath false image in the scenario where the steel structure shielding and strong reflection coexist can be supported, a small amount of key link observation data is organized into a fingerprint type representation with scene recognition ability under the premise of not relying on multi-source data, and the basis for subsequent enhancement and switching control is provided. Thus, the present application introduces the link shadow fingerprint, makes the link control process have the identification ability for the special phenomenon that the apparent strong signal actually has error code burst, and makes the switching decision and the enhancement control form the collaborative management, so as to reduce the error switching, reduce the switching jitter and improve the service continuity.
Owner:CHENGDU ZHUOLI COMM SERVICES CO LTD

Protocol non-inductive dynamic adaptation method and system for government and enterprise data channels

The invention discloses a protocol non-inductive dynamic adaptation method and system for government and enterprise data channels, and the method comprises the steps: collecting network resources, dividing business systems of all departments into security domains according to the institutions to which assets belong, business types and confidentiality levels, and abstracting the security domains into security domain nodes, according to an existing network access control rule, abstracting an allowed access relationship into a directed edge to form a security domain accessibility map; selecting the historical service flow of a stable security domain node in a preset statistical period in the security domain accessibility map, extracting protocol features, processing the protocol features to form credible anchoring sample features corresponding to each protocol category, and storing the credible anchoring sample features in a credible anchoring sample library; performing multi-dimensional credibility scoring according to the protocol characteristics of each piece of service flow collected in real time to obtain a credibility score; whether the traffic has a potential poisoning risk can be more accurately judged, and the poisoning traffic can be eliminated in time.
Owner:HEBEI QINAN SAFETY TECH CO LTD

Network access control intelligent query and authorization method fused with large model

The invention provides a line network access control intelligent query and authorization method fused with a large model, which constructs an independent service access large model on the basis of an existing line network access control system, adds natural language interaction capability, depends on a local semantic resource library, and combines semantic analysis capability of the large model to complete user intention analysis and entity extraction. Information retrieval and employee permission change are intelligently executed; meanwhile, a data desensitization mechanism is established, and the sensitive data leakage risk is reduced. Compared with the prior art, query and authorization driven by natural languages are realized, the interaction efficiency can be remarkably improved, the data security can be ensured, and the method is suitable for intelligent upgrading of the access control system of the urban rail transit network.
Owner:NANJING SAC RAIL TRAFFIC ENG CO LTD

User device characterization method based on network data traffic information, and network access control method thereof

ActiveUS12634271B2
Provided is a system for network access control. The system includes an authentication server configured to perform a basic authentication procedure for a user by communicating with at least one user terminal, a service server configured to provide a service to at least one user terminal passing through the basic authentication procedure, a collection device configured to acquire traffic data of the at least one user terminal passing through the basic authentication procedure from at least one of the service server and a network interface connected to the service server, acquire a traffic dataset by refining the acquired traffic data in accordance with correlation, and extract time-series feature points of the traffic dataset, and an artificial intelligence (AI) management device configured to train at least one AI model to define a traffic character template of the user on the basis of the time-series feature points.
Owner:AIRCUVE INC

Message processing method and related device

A message processing method is applied to realizing network access control and avoiding expansion of the number of policies stored in network equipment. In the message processing method, a plurality of user identities corresponding to a message are determined based on a sending source identifier in the message, and then a corresponding strategy action is searched for each user identity, so that a plurality of strategy actions are obtained. And finally, determining a target policy action to execute based on the plurality of policy actions, thereby realizing network access control of the message. In the scheme, after the plurality of user identities corresponding to the message are obtained, the plurality of user identities are respectively used for executing multiple times of strategy matching, and then the strategy action needing to be executed is determined based on the plurality of matched strategy actions. Therefore, when the user identity corresponding to the user is changed, the controller does not need to issue a new policy action to the network equipment, but only adjusts the user identity corresponding to the user, so that expansion of the number of policies stored in the network equipment can be effectively avoided, and normal operation of the network equipment is ensured.
Owner:HUAWEI TECH CO LTD