Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

36 results about "Network Endpoint" patented technology

An individual user device on a data communication network.

Large language model (LLM) supply chain security

Disclosed are various approaches for large language model (LLM) supply chain security. In one example, an LLM-extended software bill of materials can be extended to provide LLM specific supply chain information for an LLM application that communicates with an LLM service. The LLM-extended software bill of materials can be attached to the LLM application. An LLM specific security test can be performed on the LLM application. A signed LLM security test attestation can be attached to the LLM-extended software bill of materials based on completion of the automated LLM security test. The LLM application or the LLM-extended software bill of materials can be published or transmitted to a predetermined network endpoint.
Owner:AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC

Flow-level deduplication of network traffic in a network traffic visibility system

A system and method for flow-level deduplication of network traffic are disclosed. A network node receives a first plurality of packets from a first network endpoint. The first plurality of packets represent a flow of data being communicated between the first network endpoint and a second network endpoint. The network node further receives a second plurality of packets from the second network endpoint. The network node identifies a sequence identifier of each packet of the first and second pluralities of packets. The network node determines that the first and second pluralities of packets are all associated with the same flow, based on the sequence identifiers of the first and second pluralities of packets. In response to that determination, the network node deduplicates the flow by discarding the first plurality of packets or the second plurality of packets. The network node may be a traffic visibility node.
Owner:GIGAMON INC

Inference of vulnerable endpoints to a security threat

ActiveUS12641109B2Securing communicationReliability engineeringNetwork Endpoint
Techniques described herein can efficiently detect network endpoints that are vulnerable to individual security threats. New security threats are constantly emerging. Identifying endpoints that are vulnerable to a security threat enables proactive protection of the vulnerable endpoints. Furthermore, detecting endpoints that are vulnerable to a security threat enables tailored protection operations that are limited to protecting vulnerable endpoints without necessarily also expending resources to protect invulnerable endpoints. Historic vulnerability data is used to group endpoints into cohorts that share similar histories of security infections and compromises. When an active security compromise is discovered at an affected endpoint, cohort protection operations can be applied to protect endpoints in the same cohort as the affected endpoint.
Owner:CISCO TECHNOLOGY INC

Probe packet congestion control

ActiveUS20260135819A1TransmissionEngineeringNetwork Endpoint
Apparatuses, systems, computing devices, switches, network endpoints, and methods to handle probe packets. In at least one embodiment, probe packets are handled in a more time-efficient manner as compared to non-probe packets by identifying probe packets and directing probe packets to particular queues.
Owner:MELLANOX TECHNOLOGIES LTD(IL)

An unmanned aerial vehicle inspection video stream communication method based on device state recognition, a gateway and a medium

PendingCN122340321AData packData stream
This invention belongs to the field of inspection data processing technology, specifically involving a drone inspection video stream communication method, gateway, and medium based on device status recognition. The inspection monitoring gateway acquires security configurations, verifies the initial data packets encrypted and forwarded by the drone via the inspection node, and establishes a secure connection. The real-time video stream is identified by device type and its status characteristics are analyzed, classifying the video stream into datasets of different priorities. Adaptive communication channels are constructed for each priority dataset based on device type and network endpoint information. Differentiated upload frequencies and strategies are implemented according to the priority of the datasets through the corresponding channels. The method achieves control from data security access and intelligent analysis to network resource scheduling. The raw video is converted into a priority-based structured data stream. By dynamically matching business priorities with network channels, highly reliable transmission of high-value alarm data is ensured, improving the security and real-time response capability of the inspection system.
Owner:SHANDONG ZHENGCHEN TECH CO LTD

Generating non-redundant physically, logically, and location-specific network endpoint identifiers

The invention relates to generating a non-redundant physical, logical, and location-specific network endpoint identifier. First information identifying a first one of a target circuit or a radio frequency (RF) tag is communicated to a second one of the target circuit or the RF tag. Second information identifying the second one of the target circuit and the RF tag is then derived from the transmitted first information. The second information is then stored. In some cases, the first information is communicated through a wired interface or a wireless interface between the target circuit and the RF tag. The first information identifying the RF tag may be communicated to the target circuit, and may derive second information identifying the target circuit based on the first information identifying the RF tag by making the second information equivalent to the first information or applying a predetermined algorithm to the first information to generate the second information.
Owner:NXP BV

A data encryption method based on WiFi Mesh

This invention relates to the field of Internet of Things (IoT) technology, specifically to a data encryption method based on WiFi Mesh. The WiFi Mesh-based data encryption method includes the following steps: S1, a key exchange phase, where an unconnected node sends a network access request to a connected node, and the connected node generates a public key A and a private key a using an asymmetric encryption algorithm; S2, the connected node sends public key A to the unconnected node, which generates a random key B using a random number, and encrypts the random key B using public key A to obtain ciphertext b; the broadcast key E is initially generated by the WiFi root node using a random number, and all WiFi Mesh network endpoints use the same broadcast key E; the unicast key F is randomly generated by the connected node. Compared with existing technologies, this invention has the following advantages: it solves the problem of sensitive information leakage during the initial key exchange in data transmission using an asymmetric encryption algorithm; it improves the starting point of the entire cycle, ensuring the security of subsequent data communication.
Owner:SHANGHAI HIGH-FLYING ELECTRONICS TECHNOLOGY CO LTD

Endpoint validation security

Examples of the disclosure provide for a scatter network device. In some examples, the scatter network device includes a non-transitory memory, at least one processor, and a key exchange application stored in the non-transitory memory. When executed by the at least one processor, the key exchange application transmits a key exchange request to a first network endpoint, the key exchange request including an identifier of the scatter network device, receives a key exchange response from the first network endpoint, the key exchange response including a set of one-time-use endpoint validation tokens (EVTs) uniquely associated with the identifier of the scatter network device, and transmits an authenticated message to a second network endpoint, the authenticated message including a first of the set of one-time-use EVTs concatenated with an encrypted data portion.
Owner:SCATR CORP

Monitoring tracker activity of applications on an electronic device

ActiveUS12549641B2Hardware monitoringTransmissionActivity trackerEmbedded system
The present disclosure provides systems and methods for monitoring tracker activity for applications on an electronic device. A monitoring process running on an electronic device is configured to monitor network connections of at least a first application running on the electronic device to identify network connections that connect to a network endpoint associated with an activity tracker. Based on the monitoring, tracker monitoring information is generated for at least the first application. The tracker monitoring information identifies activity tracking initiated by the first application. Based on the tracker monitoring information, the monitoring process performs an action.
Owner:APPLE INC

Adaptive routing with endpoint feedback

Systems, switches, network endpoints, and methods are provided. In one example, a system is described that includes a latency measurement circuit to measure traffic on a network from an endpoint sender to an endpoint receiver across multiple paths. The system also includes a packet marking circuit to provide a routing mark for a packet destined for the endpoint receiver according to a network traffic measurement provided by the latency measurement circuit, where the routing mark provides an indication that supports routing for the packet to reach the endpoint receiver via a chosen path or subset of paths among the multiple paths.
Owner:MELLANOX TECHNOLOGIES LTD(IL)

Optimizing tree-based collective communication operations by load-balancing network endpoints

PendingUS20260113274A1TransmissionBalancing networkCollective communication
The present disclosure generally relates to optimizing load-balancing of network endpoints using tree collectives representing a logical network communication topology for the network endpoints. Systems and methods described herein eliminate the previously restrictive conditions imposed on tree-based communication collectives by generating collective trees with any arity and representing any number of physical network endpoints. The resulting collective trees ensure that each represented network endpoint has a number of outgoing flows and a number of incoming flows that are no more than the arity of the collective tree. In this way, the described systems and methods inject significant efficiencies into communication collectives within networked compute nodes by eliminating communication bandwidth latencies and bottlenecks.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Securing endpoints in a heterogenous enterprise network

Endpoints and a corresponding switch within a heterogeneous network work cooperatively to respond to notifications of compromise in order to protect the enterprise network. Endpoints self-isolate when a local security agent detects a compromise, and shun a compromised one of the other endpoints in response to a corresponding notification. The switch forwards a notice of compromise from an endpoint to a threat management facility for the enterprise network and prevents communications from a compromised endpoint through the switch in response to receiving a corresponding request from the threat management facility.
Owner:SOPHOS LTD

Host-level ticket forgery detection and extension to network endpoints

A system and method for detection and prevention of ticket forgery cyberattacks by improving host-level analytics and monitoring and extending the improved host-level analytics and monitoring to endpoints of a network. The methodology described herein comprises the use of a ticket-granting log extension utility which stores every logon session on a network, queries the local ticket cache, and generates additional custom data as a part of an event log stream such as a start time, end time, renew time, and related session data. This comprehensive log extension data can be used to identify certain types of ticket forgery cyberattacks by comparing the user session name with the client name identified in the ticket presented for access to network resources and other means. This host-level ticket forgery detection can be extended to network endpoints for additional security.
Owner:QOMPLX INC

System for detecting anomalous network patterns based on analyzing network traffic data and method thereof

A system for detecting anomalous network patterns based on analyzing network traffic data and method thereof are disclosed. The system comprises a flow aggregator subsystem, a flow feature generation subsystem, an anomaly detection subsystem, a dynamic score subsystem, and a calibration subsystem. The system is configured to receive the network traffic data from one or more network endpoints for aggregating the network traffic data into network flow data. The system is configured to generate one or more flow features for each packet associated with the aggregated network traffic data based on a rolling window-based analysis of the one or more attributes. The system is configured to analyze the one or more flow features by utilizing one or more deep-learning models to detect the one or more anomalous network patterns.
Owner:PRIVAFY INC

System and method for deploying, scaling and managing network endpoint groups in cloud computing environments

Grouping virtualized computing instances in cloud environments can be achieved utilizing groups of network endpoints, such as hardware devices, virtualized computing instances, etc. The network endpoint group (NEG) provides a logical grouping for providers of backend services that may be arranged on the network endpoints, and may be organized based on the backend service to be provided by the computing environments that operate as network endpoints. For example, the NEGs may be implemented for load balancing applications. The network endpoint groups, and the network endpoints included therein, may be managed using a framework of tools, libraries and application programming interfaces.
Owner:GOOGLE LLC

Optimizing tree-based collective communication operations by load-balancing network endpoints

PCT designated stageWO2026089789A1TransmissionBalancing networkCollective communication
The present disclosure generally relates to optimizing load-balancing of network endpoints using tree collectives representing a logical network communication topology for the network endpoints. Systems and methods described herein eliminate the previously restrictive conditions imposed on tree-based communication collectives by generating collective trees with any arity and representing any number of physical network endpoints. The resulting collective trees ensure that each represented network endpoint has a number of outgoing flows and a number of incoming flows that are no more than the arity of the collective tree. In this way, the described systems and methods inject significant efficiencies into communication collectives within networked compute nodes by eliminating communication bandwidth latencies and bottlenecks.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Programmable collective offload engine for performing communication collectives

PendingUS20260148117A1Mathematical modelsProgram controlInstruction memoryComputer architecture
The present disclosure generally relates to offloading the orchestration and control of a communication collective to a specialized collective offload engine. The systems, methods, and specialized computing hardware described herein avoid the latencies and other inefficiencies introduced when software applications control the execution of a communication collective. For example, the described systems, methods, and specialized computing hardware generate a binary representation of one or more direct acyclic graphs of node operations for a communication collective, and load this representation into the instruction memories of specialized collective offload engines residing on network endpoints connected to one or more network switches. During execution of the collective, the collective offload engines initiate node operations based on whether corresponding dependencies are met. By offloading these tasks to the collective offload engines, no additional latencies are introduced and other computing resources are kept free for use by other applications.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Distributed computing power management system, distributed computing power management method and computing device

This application provides a distributed computing power management system, a distributed computing power management method, and a computing device. It includes a registration node and multiple management nodes, including a first management node and at least one second management node. The first management node sends a registration request to the registration node. The registration node returns network endpoint information of currently registered second management nodes to the first management node and notifies the second management node of the network endpoint information of newly registered first management nodes. The first management node also establishes a communication connection with the second management node based on the network endpoint information of the second management node and synchronizes their respective total computing power resources with the established communication connection second management node. By constructing a decentralized distributed architecture, each management node can directly communicate with each other and share the total computing power resources after registration, achieving resource discovery and state synchronization, and improving the availability and robustness of the system.
Owner:XFUSION DIGITAL TECH CO LTD

Dynamically binding network endpoints via key distribution

Systems and methods for dynamically binding network endpoints via key distribution are described. In an illustrative, non-limiting embodiment, an Information Handling System (IHS) may include: a processor; and a memory coupled to the processor, where the memory includes program instructions that cause the IHS to: obtain a network binding map indicating a flat or hierarchical structure of a plurality of endpoints of a network; obtain a respective plurality of cryptographic keys for the plurality of endpoints; and distribute one or more keys of the plurality of cryptographic keys to individual endpoints based, at least in part, on the network binding map. In some embodiments, the program instructions further cause the IHS to: distribute, to individual endpoints, only the one or more keys associated with one or more other endpoints, of plurality of endpoints, to which the respective individual endpoint is bound, according to the network binding map.
Owner:DELL PROD LP

Dynamic endpoint management for heterogeneous machine learning models

PendingCN122295651AEngineeringData mining
Dynamic endpoint management is performed for heterogeneous machine learning models. Placement events for machine learning models associated with managed network endpoints are detected. These managed network endpoints can provide access to machine learning models via requests received from clients of the machine learning service to invoke different specified machine learning models. Computational resources are selected from associated computing resources based on a determination that the computing resources meet the resource requirements of the machine learning model, and the machine learning model is placed on the selected computing resource.
Owner:AMAZON TECH INC

Systems and methods for enhanced network detection

A system for detecting and profiling endpoints of a computer network is provided. The system includes a first computing device including at least one processor in communication with at least one memory device. The first computing device is in communication with a computer network. The at least one memory device stores a plurality of instructions, which when executed by the at least one processor cause the at least one processor to receive a plurality of packets transmitted to the computer network, determine an identity of a first end point device associated with the plurality of packets, determine a behavior pattern for the first end point device based on the plurality of packets, and generate a synthetic profile for the first end point device based on the identity and the behavior pattern.
Owner:CABLE TELEVISION LAB INC

Registration authority

PCT designated stageWO2026084998A1Securing communicationRegistration authorityInternet privacy
A method of updating a certificate at an end-point of a network is disclosed. The method comprises: verifying, by a registration authority, an authenticity of a head-end system in the network; verifying, by the registration authority, an authenticity of at least one end-point communicatively coupled to the head-end system; receiving, by the registration authority and after verification of the authenticity of the head-end system and the at least one end-point, at least one certificate signing request from the at least one end-point, via the head-end system; brokering, by the registration authority, a new certificate from a certificate authority for each at least one end-point based on the respective at least one certificate signing request; and providing, by the registration authority, each new certificate to the head-end system for transmission to the respective at least one end-point.
Owner:LANDIS GYR TECH INC

Grouping endpoints of a network for NAT to organize IP address space for policy applications

Techniques and architecture are described that utilize network address translation (NAT) based on a group tag such that legacy and third-party devices may utilize and apply “subnet” based policies, thereby allowing the subnet based policies to be as effective as “group” based policies. In particular, a subnet may be applied to a group tag where the group tag is not understandable outside an access network such as, for example, a fabric network. Thus, when a packet originates from a fabric network utilizing group tags representing source groups of endpoints and is destined for a legacy or a third-party device-based network that does not utilize and / or understand group tags, then the group is converted into a subnet. Since that subnet is different from the source host within the fabric network, network address translation (NAT) is utilized.
Owner:CISCO TECHNOLOGY INC

Service dependence information determination method and device and electronic equipment

The invention discloses a service dependency information determination method and device and electronic equipment. A target service container corresponding to a service dependency extraction request is determined; matching a to-be-processed file associated with the target service container according to preset keyword information and a preset network endpoint format, and determining a first candidate file and first character string information; according to the first character string information, recognizing a preset number of preorder characters in front of each first character string based on a preorder word classification model, and determining a preorder character recognition result; screening the first character string information according to the preorder character recognition result, and determining second character string information; identifying a second candidate file corresponding to the second character string information according to a file classification model, and determining file attributes; and taking the second candidate file of which the file attribute is consistent with the preset file attribute as the target configuration file, and obtaining the target service dependency information based on the second character string information of the target configuration file, so that the efficiency of extracting the service dependency information is improved.
Owner:CHINA TOBACCO ZHEJIANG IND CO LTD

Subnet coverage by generating network addresses

PendingUS20260039593A1TransmissionNetwork addressingLongest prefix match
Systems and methods for coverage of network addresses in a network enables a network end point to provide communication in the network based in part on a virtual arrangement of the network that includes a root node with a root counter and includes one or more sub-nodes with respective sub-node counters, where the virtual arrangement can be used to provide at least one network address that may be associated with a representative longest prefix match (LPM) having a prefix from the root node to a representative node and using a suffix that is based in part on a node level of the representative node with respect to the root node, and where the representative node can be a lower absent sub-node relative to a subnet node in the virtual arrangement.
Owner:MELLANOX TECHNOLOGIES LTD(IL)

Flow-level deduplication of network traffic in a network traffic visibility system

A system and method for flow-level deduplication of network traffic are disclosed. A network node receives a first plurality of packets from a first network endpoint. The first plurality of packets represent a flow of data being communicated between the first network endpoint and a second network endpoint. The network node further receives a second plurality of packets from the second network endpoint. The network node identifies a sequence identifier of each packet of the first and second pluralities of packets. The network node determines that the first and second pluralities of packets are all associated with the same flow, based on the sequence identifiers of the first and second pluralities of packets. In response to that determination, the network node deduplicates the flow by discarding the first plurality of packets or the second plurality of packets. The network node may be a traffic visibility node.
Owner:GIGAMON INC

Endpoint security groups in private multi-access edge compute networks

ActiveUS12676891B2Device typeEndpoint security
Endpoint security groups include computing device endpoints that are classified according to commonly shared device features and capabilities including device type, function, role, or location. Endpoint security groups are used as an alternative identity mechanism for endpoints for purposes of security and data traffic policy enforcement rather than using conventional IP (Internet Protocol) addressing. Grouping endpoints reduces the scope of network management to enable dynamic policy enforcement for endpoints as they join, leave, and then rejoin computing networks, which is a common behavior, particularly for IoT (Internet-of-Things) devices in manufacturing environments. In an illustrative example, a private multi-access edge compute (MEC) platform supports a scalable policy definition and enforcement framework that provides consistent endpoint handling independent of network access methodology. Endpoint security groups facilitate improvements in security of network access and utilization and segmentation of data traffic on a fine-grained basis.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Band key exchange

Examples of the disclosure provide for a scatter network device. In some examples, the scatter network device includes a non-transitory memory, at least one processor, and a key exchange application stored in the non-transitory memory. When executed by the at least one processor, the key exchange application generates a key exchange request, transmits the key exchange request to a first network endpoint via a first communication band, responsive to transmitting the key exchange request, receives a key exchange response, generates a symmetric encryption key based on the key exchange response, and transmits an authenticated message encrypted via the symmetric encryption key to a second network endpoint via a second communication band.
Owner:SCATR CORP