Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

74 results about "Network Endpoint" patented technology

An individual user device on a data communication network.

Verifiable credentialling and message content provenance authentication

The technology disclosed allows for leveraging decentralized credentials to achieve bidirectional authentication between two actors leveraging a messaging platform / system, such as email or another text-based system, verifiable credentials (VCs), and secure web endpoints. It empowers one party (“Sender”) to send a message enclosed with a Verifiable Presentation which allows another party (“Recipient”) to authenticate the message's provenance and the identity of the sender. Moreover, the message contains a link to a secure web endpoint, where the recipient can submit a response signed by their own Verifiable Presentation, allowing the Sender to authenticate the identity of the Recipient. In this way, both participants are able to authenticate each other's identities with an additional factor of authentication, with neither participant being required to share a single service.
Owner:LEDGERDOMAIN INC

Adaptive routing with endpoint feedback

Systems, switches, network endpoints, and methods are provided. In one example, a system is described that includes a latency measurement circuit to measure traffic on a network from an endpoint sender to an endpoint receiver across multiple paths. The system also includes a packet marking circuit to provide a routing mark for a packet destined for the endpoint receiver according to a network traffic measurement provided by the latency measurement circuit, where the routing mark provides an indication that supports routing for the packet to reach the endpoint receiver via a chosen path or subset of paths among the multiple paths.
Owner:MELLANOX TECHNOLOGIES LTD(IL)

Autonomous network policy generator

A device, system, and method are provided for generating a network security policy automatically based on network traffic. The network security policy is generated by building a directional graph from the network traffic, with the nodes of the graph representing network end points, and the edges representing communication between two nodes on a communication channel. A feature vector is generated for each of the nodes and a graph neural network is applied to the feature vectors to generate output vectors. The output vectors are clustered using a cost function based on a weighted combination of a distance-based cost function and a network functionality cost function. The clusters generated from the output vectors are used to assign network security rules to each of the clusters.
Owner:CHECK POINT SOFTWARE TECH LTD

Adaptive endpoint-to-endpoint data path selection for data centers

An embodiment selects, using performance data of a plurality of paths, a first path, each path comprising a data communication path from a first network endpoint through a subset of a plurality of network elements in a data communication network to a second network endpoint. An embodiment adjusts a packet header of a data packet, wherein a parameter setting in the adjusted data packet header causes a first network element in the data communication network to forward the adjusted data packet to a next network element in the data communication network along the first path. An embodiment sends the adjusted data packet, wherein the adjusted data packet causes a first subset of the plurality of network elements in the data communication network to forward the adjusted data packet to the second network endpoint along the first path.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Methods, systems, and devices for dynamically modeling and grouping endpoints for edge networking

Various embodiments described herein disclose an endpoint modeling and grouping management system that can collect data from endpoint computer devices in a network. In some embodiments, agents installed on the endpoints can collect real-time information at the kernel level providing the system with deep visibility. In some embodiments, the endpoint modeling and grouping management system can identify similarities in behavior in response to assessing the data collected by the agents. In some embodiments, the endpoint modeling and grouping management system can dynamically model groups such as logical groups, and cluster endpoints based on the similarities and / or differences in behavior of the endpoints. In some embodiments, the endpoint modeling and grouping management system transmits the behavioral models to the agents to allow the agents to identify anomalies and / or security threats autonomously.
Owner:SENTINEL LABS ISRAEL

Network traffic obfuscation

Examples of the disclosure provide for a scatter network device. In some examples, the scatter network device includes a non-transitory memory, at least one processor, and a key exchange application stored in the non-transitory memory. When executed by the at least one processor, the key exchange application generates a key exchange request encrypted according to a public encryption key of a first network endpoint, wherein the encrypted key exchange request is indistinguishable from uniform random noise, and transmits the key exchange request to the first network endpoint via a first communication band, wherein the scatter network device transmits authenticated messages via a second communication band.
Owner:SCATR CORP

Flow-level deduplication of network traffic in a network traffic visibility system

A system and method for flow-level deduplication of network traffic are disclosed. A network node receives a first plurality of packets from a first network endpoint. The first plurality of packets represent a flow of data being communicated between the first network endpoint and a second network endpoint. The network node further receives a second plurality of packets from the second network endpoint. The network node identifies a sequence identifier of each packet of the first and second pluralities of packets. The network node determines that the first and second pluralities of packets are all associated with the same flow, based on the sequence identifiers of the first and second pluralities of packets. In response to that determination, the network node deduplicates the flow by discarding the first plurality of packets or the second plurality of packets. The network node may be a traffic visibility node.
Owner:GIGAMON INC

Dynamically binding network endpoints via key distribution

Systems and methods for dynamically binding network endpoints via key distribution are described. In an illustrative, non-limiting embodiment, an Information Handling System (IHS) may include: a processor; and a memory coupled to the processor, where the memory includes program instructions that cause the IHS to: obtain a network binding map indicating a flat or hierarchical structure of a plurality of endpoints of a network; obtain a respective plurality of cryptographic keys for the plurality of endpoints; and distribute one or more keys of the plurality of cryptographic keys to individual endpoints based, at least in part, on the network binding map. In some embodiments, the program instructions further cause the IHS to: distribute, to individual endpoints, only the one or more keys associated with one or more other endpoints, of plurality of endpoints, to which the respective individual endpoint is bound, according to the network binding map.
Owner:DELL PROD LP

Large language model (LLM) supply chain security

Disclosed are various approaches for large language model (LLM) supply chain security. In one example, an LLM-extended software bill of materials can be extended to provide LLM specific supply chain information for an LLM application that communicates with an LLM service. The LLM-extended software bill of materials can be attached to the LLM application. An LLM specific security test can be performed on the LLM application. A signed LLM security test attestation can be attached to the LLM-extended software bill of materials based on completion of the automated LLM security test. The LLM application or the LLM-extended software bill of materials can be published or transmitted to a predetermined network endpoint.
Owner:AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC

Traffic routing service exposure method and apparatus, electronic device, and storage medium

PendingCN122661109AEngineeringProxy server
The present disclosure provides a traffic routing service exposure method and device, electronic equipment and storage medium, and relates to the technical field of computers. The method comprises: when a target exposure CR occurs creation or update, obtaining service exposure configuration information from the target exposure CR; creating a gateway resource and / or a traffic routing resource according to the service exposure configuration information, wherein the gateway resource is used to define a target network endpoint, and the traffic routing resource is used to define a traffic routing rule; and dynamically configuring a proxy server according to the gateway resource and the traffic routing resource, wherein the proxy server is used to route traffic based on the target network endpoint to a backend according to the traffic routing rule. The present disclosure can realize the definition of the target network endpoint and the traffic routing rule through the target exposure CR, thereby dynamically configuring the proxy server to realize traffic routing, and can reduce the complexity of configuration and management.
Owner:JD DIGITS HAIYI INFORMATION TECHNOLOGY CO LTD

Host-level ticket forgery detection and extension to network endpoints

A system and method for detection and prevention of ticket forgery cyberattacks by improving host-level analytics and monitoring and extending the improved host-level analytics and monitoring to endpoints of a network. The methodology described herein comprises the use of a ticket-granting log extension utility which stores every logon session on a network, queries the local ticket cache, and generates additional custom data as a part of an event log stream such as a start time, end time, renew time, and related session data. This comprehensive log extension data can be used to identify certain types of ticket forgery cyberattacks by comparing the user session name with the client name identified in the ticket presented for access to network resources and other means. This host-level ticket forgery detection can be extended to network endpoints for additional security.
Owner:QOMPLX INC

Inference of Vulnerable Endpoints to a Security Threat

Techniques described herein can efficiently detect network endpoints that are vulnerable to individual security threats. New security threats are constantly emerging. Identifying endpoints that are vulnerable to a security threat enables proactive protection of the vulnerable endpoints. Furthermore, detecting endpoints that are vulnerable to a security threat enables tailored protection operations that are limited to protecting vulnerable endpoints without necessarily also expending resources to protect invulnerable endpoints. Historic vulnerability data is used to group endpoints into cohorts that share similar histories of security infections and compromises. When an active security compromise is discovered at an affected endpoint, cohort protection operations can be applied to protect endpoints in the same cohort as the affected endpoint.
Owner:CISCO TECHNOLOGY INC

Flow-level deduplication of network traffic in a network traffic visibility system

A system and method for flow-level deduplication of network traffic are disclosed. A network node receives a first plurality of packets from a first network endpoint. The first plurality of packets represent a flow of data being communicated between the first network endpoint and a second network endpoint. The network node further receives a second plurality of packets from the second network endpoint. The network node identifies a sequence identifier of each packet of the first and second pluralities of packets. The network node determines that the first and second pluralities of packets are all associated with the same flow, based on the sequence identifiers of the first and second pluralities of packets. In response to that determination, the network node deduplicates the flow by discarding the first plurality of packets or the second plurality of packets. The network node may be a traffic visibility node.
Owner:GIGAMON INC

Cross-domain account management methods, devices, equipment, media and products

This application provides a method, apparatus, device, medium, and product for cross-domain account management. The method includes: upon receiving a centralized authentication request, determining the account information corresponding to the user's currently logged-in first network endpoint, where the centralized authentication request instructs the user to access a second network endpoint from the first network endpoint. Both the first and second network endpoints include any one of a user management system, a data domain, and a business system; matching the account information corresponding to the second network endpoint from an account model based on the account information corresponding to the first network endpoint, where the account model includes the user's primary account information, secondary account information, and secondary account information; and logging into the second network endpoint based on the account information corresponding to the second network endpoint. This solves the technical problem in related technologies where unified account authentication and cross-domain data access cannot be achieved without modifying the interfaces of each data domain.
Owner:CHINA MOBILE GRP GANSU CO LTD +1

Inference of vulnerable endpoints to a security threat

Techniques described herein can efficiently detect network endpoints that are vulnerable to individual security threats. New security threats are constantly emerging. Identifying endpoints that are vulnerable to a security threat enables proactive protection of the vulnerable endpoints. Furthermore, detecting endpoints that are vulnerable to a security threat enables tailored protection operations that are limited to protecting vulnerable endpoints without necessarily also expending resources to protect invulnerable endpoints. Historic vulnerability data is used to group endpoints into cohorts that share similar histories of security infections and compromises. When an active security compromise is discovered at an affected endpoint, cohort protection operations can be applied to protect endpoints in the same cohort as the affected endpoint.
Owner:CISCO TECHNOLOGY INC

Probe packet congestion control

Apparatuses, systems, computing devices, switches, network endpoints, and methods to handle probe packets. In at least one embodiment, probe packets are handled in a more time-efficient manner as compared to non-probe packets by identifying probe packets and directing probe packets to particular queues.
Owner:MELLANOX TECHNOLOGIES LTD(IL)

An unmanned aerial vehicle inspection video stream communication method based on device state recognition, a gateway and a medium

PendingCN122340321AData packData stream
This invention belongs to the field of inspection data processing technology, specifically involving a drone inspection video stream communication method, gateway, and medium based on device status recognition. The inspection monitoring gateway acquires security configurations, verifies the initial data packets encrypted and forwarded by the drone via the inspection node, and establishes a secure connection. The real-time video stream is identified by device type and its status characteristics are analyzed, classifying the video stream into datasets of different priorities. Adaptive communication channels are constructed for each priority dataset based on device type and network endpoint information. Differentiated upload frequencies and strategies are implemented according to the priority of the datasets through the corresponding channels. The method achieves control from data security access and intelligent analysis to network resource scheduling. The raw video is converted into a priority-based structured data stream. By dynamically matching business priorities with network channels, highly reliable transmission of high-value alarm data is ensured, improving the security and real-time response capability of the inspection system.
Owner:SHANDONG ZHENGCHEN TECH CO LTD

Systems and methods for deployment, management and use of dynamic cipher key systems

Dynamic Cipher Key Management (DCKM) of the present invention enables the protection of sensitive electronic data by assigning symmetric or asymmetric cipher keys using a process that delivers the cipher key to a network endpoint device by means of a key installation, delivery, and storage methodology. DCKM may negate the need to physically touch the network device under protection. Further, DCKM's process is based on a set of operating principles that maintains the highest levels of assurance that the cipher key pairs are issued with only devices that have the right and authorization to create a secure communication path. The DCKM process realizes the same level of security confidence that is only achieved today with conventional token based key management services with respect to the paired devices linked via a cipher key public and private relationship.
Owner:ONCLAVE NETWORKS INC

Generating non-redundant physically, logically, and location-specific network endpoint identifiers

The invention relates to generating a non-redundant physical, logical, and location-specific network endpoint identifier. First information identifying a first one of a target circuit or a radio frequency (RF) tag is communicated to a second one of the target circuit or the RF tag. Second information identifying the second one of the target circuit and the RF tag is then derived from the transmitted first information. The second information is then stored. In some cases, the first information is communicated through a wired interface or a wireless interface between the target circuit and the RF tag. The first information identifying the RF tag may be communicated to the target circuit, and may derive second information identifying the target circuit based on the first information identifying the RF tag by making the second information equivalent to the first information or applying a predetermined algorithm to the first information to generate the second information.
Owner:NXP BV

Managed attestation service for compute instances

An attestation service is configured to receive a request to enable attestation for a compute instance according to an attestation policy indicating one or more baseline health measurement values for validating compute instances. The attestation service provides a network endpoint for the compute instance to request attestation. The attestation service receives, via the network endpoint from a compute instance, one or more health measurement values of the compute instance. The attestation service validates the compute instance based at least on a comparison of the one or more current health measurement values and the one or more baseline health measurement values. The attestation service, in response to validating the compute instance, generates an attestation token indicating that the compute instance is authorized to access a secured resource of the provider network.
Owner:AMAZON TECH INC

A data encryption method based on WiFi Mesh

This invention relates to the field of Internet of Things (IoT) technology, specifically to a data encryption method based on WiFi Mesh. The WiFi Mesh-based data encryption method includes the following steps: S1, a key exchange phase, where an unconnected node sends a network access request to a connected node, and the connected node generates a public key A and a private key a using an asymmetric encryption algorithm; S2, the connected node sends public key A to the unconnected node, which generates a random key B using a random number, and encrypts the random key B using public key A to obtain ciphertext b; the broadcast key E is initially generated by the WiFi root node using a random number, and all WiFi Mesh network endpoints use the same broadcast key E; the unicast key F is randomly generated by the connected node. Compared with existing technologies, this invention has the following advantages: it solves the problem of sensitive information leakage during the initial key exchange in data transmission using an asymmetric encryption algorithm; it improves the starting point of the entire cycle, ensuring the security of subsequent data communication.
Owner:SHANGHAI HIGH-FLYING ELECTRONICS TECHNOLOGY CO LTD

Endpoint validation security

Examples of the disclosure provide for a scatter network device. In some examples, the scatter network device includes a non-transitory memory, at least one processor, and a key exchange application stored in the non-transitory memory. When executed by the at least one processor, the key exchange application transmits a key exchange request to a first network endpoint, the key exchange request including an identifier of the scatter network device, receives a key exchange response from the first network endpoint, the key exchange response including a set of one-time-use endpoint validation tokens (EVTs) uniquely associated with the identifier of the scatter network device, and transmits an authenticated message to a second network endpoint, the authenticated message including a first of the set of one-time-use EVTs concatenated with an encrypted data portion.
Owner:SCATR CORP

Systems and methods for enhanced network detection

A system for detecting and profiling endpoints of a computer network is provided. The system includes a first computing device including at least one processor in communication with at least one memory device. The first computing device is in communication with a computer network. The at least one memory device stores a plurality of instructions, which when executed by the at least one processor cause the at least one processor to receive a plurality of packets transmitted to the computer network, determine an identity of a first end point device associated with the plurality of packets, determine a behavior pattern for the first end point device based on the plurality of packets, and generate a synthetic profile for the first end point device based on the identity and the behavior pattern.
Owner:CABLE TELEVISION LAB INC

Monitoring tracker activity of applications on an electronic device

ActiveUS12549641B2Hardware monitoringTransmissionActivity trackerEmbedded system
The present disclosure provides systems and methods for monitoring tracker activity for applications on an electronic device. A monitoring process running on an electronic device is configured to monitor network connections of at least a first application running on the electronic device to identify network connections that connect to a network endpoint associated with an activity tracker. Based on the monitoring, tracker monitoring information is generated for at least the first application. The tracker monitoring information identifies activity tracking initiated by the first application. Based on the tracker monitoring information, the monitoring process performs an action.
Owner:APPLE INC

Intelligent network slicing and policy-based routing engine

One or more aspects of the present disclosure are directed to network optimization solutions provided as software agents (applications) executed on network nodes in a heterogenous multi-vendor environment to provide cross-layer network optimization and ensure availability of network resources to meet associated Quality of Experience (QoE) and Quality of Service (QoS). In one aspect, a network slicing engine is configured to receive at least one request from at least one network endpoint for access to the heterogeneous multi-vendor network for data transmission; receive information on state of operation of a plurality of communication links between the plurality of nodes; determine a set of data transmission routes for the request; assign a network slice for serving the request; determine, from the set of data transmission routes, an end-to-end route for the network slice; and send network traffic associated with the request using the network slice and over the end-to-end route.
Owner:A10 SYST LLC

Adaptive routing with endpoint feedback

Systems, switches, network endpoints, and methods are provided. In one example, a system is described that includes a latency measurement circuit to measure traffic on a network from an endpoint sender to an endpoint receiver across multiple paths. The system also includes a packet marking circuit to provide a routing mark for a packet destined for the endpoint receiver according to a network traffic measurement provided by the latency measurement circuit, where the routing mark provides an indication that supports routing for the packet to reach the endpoint receiver via a chosen path or subset of paths among the multiple paths.
Owner:MELLANOX TECHNOLOGIES LTD(IL)

Optimizing tree-based collective communication operations by load-balancing network endpoints

PendingUS20260113274A1TransmissionBalancing networkCollective communication
The present disclosure generally relates to optimizing load-balancing of network endpoints using tree collectives representing a logical network communication topology for the network endpoints. Systems and methods described herein eliminate the previously restrictive conditions imposed on tree-based communication collectives by generating collective trees with any arity and representing any number of physical network endpoints. The resulting collective trees ensure that each represented network endpoint has a number of outgoing flows and a number of incoming flows that are no more than the arity of the collective tree. In this way, the described systems and methods inject significant efficiencies into communication collectives within networked compute nodes by eliminating communication bandwidth latencies and bottlenecks.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Host-level ticket forgery detection and extension to network endpoints

PCT designated stage expiredWO2025147293A2TransmissionTicketStart time
A system and method for detection and prevention of ticket forgery cyberattacks by improving host-level analytics and monitoring and extending the improved host-level analytics and monitoring to endpoints of a network. The methodology described herein comprises the use of a ticket-granting log extension utility which stores every logon session on a network, queries the local ticket cache, and generates additional custom data as a part of an event log stream such as a start time, end time, renew time, and related session data. This comprehensive log extension data can be used to identify certain types of ticket forgery cyberattacks by comparing the user session name with the client name identified in the ticket presented for access to network resources and other means. This host-level ticket forgery detection can be extended to network endpoints for additional security.
Owner:QOMPLX INC

Securing endpoints in a heterogenous enterprise network

Endpoints and a corresponding switch within a heterogeneous network work cooperatively to respond to notifications of compromise in order to protect the enterprise network. Endpoints self-isolate when a local security agent detects a compromise, and shun a compromised one of the other endpoints in response to a corresponding notification. The switch forwards a notice of compromise from an endpoint to a threat management facility for the enterprise network and prevents communications from a compromised endpoint through the switch in response to receiving a corresponding request from the threat management facility.
Owner:SOPHOS LTD

Host-level ticket forgery detection and extension to network endpoints

A system and method for detection and prevention of ticket forgery cyberattacks by improving host-level analytics and monitoring and extending the improved host-level analytics and monitoring to endpoints of a network. The methodology described herein comprises the use of a ticket-granting log extension utility which stores every logon session on a network, queries the local ticket cache, and generates additional custom data as a part of an event log stream such as a start time, end time, renew time, and related session data. This comprehensive log extension data can be used to identify certain types of ticket forgery cyberattacks by comparing the user session name with the client name identified in the ticket presented for access to network resources and other means. This host-level ticket forgery detection can be extended to network endpoints for additional security.
Owner:QOMPLX INC