Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

165 results about "Network isolation" patented technology

Isolation network. A network inserted in a circuit or transmission line to prevent interaction between circuits on each side of the insertion point.

Power disaster recovery system-oriented micropatch non-inductive deployment engine and resource scheduling method, system, equipment and medium

The invention relates to the technical field of power monitoring system network security and real-time micropatch hot deployment, and discloses a power disaster recovery system-oriented micropatch non-inductive deployment engine, a resource scheduling method, a system, equipment and a medium, and the method comprises the steps: capturing system events through a kernel eBPF probe, and carrying out feature extraction and model reasoning; generating and transmitting an encrypted scheduling token; loading and verifying a patch fragment by a patch agent, inserting a jump instruction through a kernel interface to redirect an execution stream, and maintaining multi-kernel cache consistency; fusing multi-source telemetry data to carry out fusing judgment, realizing network isolation and calling a key service to cancel a key; and collecting runtime indexes and performing trend prediction, triggering a recovery or rollback operation according to a result, and storing an operation result and data through a block chain. According to the method, through combination of deep fusion of multi-source heterogeneous data, dynamic reasoning of a knowledge graph and strategy optimization of reinforcement learning, efficient perception and defense of a complex attack scene of a digital power grid are realized.
Owner:GUIZHOU POWER GRID CO LTD

Vision-based cross-network interaction method and system

The invention provides a vision-based cross-network interaction method and system, and relates to the technical field of intelligent interaction, and the method comprises the steps: obtaining a visual interaction sequence, constructing multi-modal feature representation, achieving cross-domain semantic alignment, deconstructing visual information into a hierarchical control instruction set, and transmitting the hierarchical control instruction set to a target network environment for execution after security classification. And a bidirectional mapping relation graph is constructed to realize incremental optimization. According to the method, semantic bridging between heterogeneous networks can be established, the cross-domain control precision is improved, and meanwhile safe interaction in a network isolation environment is guaranteed.
Owner:ZHONGTIAN ZHILING (BEIJING) TECH CO LTD

Anode assembly workshop three-dimensional visual management system and method based on digital twinning

The invention discloses a digital twinning-based three-dimensional visual management system and a digital twinning-based three-dimensional visual management method for an anode assembly workshop. The system comprises a triple binding index module, a unified time axis alignment module, a view cone inverse solution positioning module, a safety linkage arrangement module and a resume playback module, and is provided with a process template library and a network isolation / main / standby module. Three-dimensional positioning and PTZ linkage of an AI / threshold event are realized by establishing mapping of a three-dimensional object, a camera and a PLC point location; the batch / bracket / station events, the PLC time sequence and the video slices are indexed in a unified mode; shadow verification, interlocking check, instruction issuing, read-back and video consistency confirmation and trace leaving are executed according to the process, and a safe closed loop from warning to disposal is formed. The method comprises the steps of access and calibration, triple binding, time axis alignment, event positioning and stream taking, linkage processing and resume filing. The positioning and handling efficiency can be improved, the misoperation risk is reduced, and cross-production-line reuse and tracing evidence obtaining are supported.
Owner:QINGTONGXIA ALUMINUM GRP

Multi-tenant API key authentication and resource isolation system in containerized environment

The invention discloses a multi-tenant API key authentication and resource isolation system in a containerized environment, and relates to the field of containerized multi-tenant authentication. Comprising an authentication authorization layer, a resource management and control layer and a security isolation layer. The authentication authorization layer comprises a multi-tenant authentication engine, an API key verification sub-module, a tenant identity recognition sub-module, an authority cascade verification sub-module and a dynamic authority calculation sub-module. And the resource management and control layer comprises a resource quota manager, a dynamic quota allocation sub-module, a real-time use monitoring sub-module, a threshold alarm control sub-module and an elastic capacity expansion and contraction sub-module. The security isolation layer comprises a multi-dimensional isolation engine, a container network isolation sub-module, a storage space isolation sub-module, a process permission isolation sub-module and a system call filtering sub-module; deep fusion of API authentication and container resource control is realized, a dynamic resource quota management mechanism based on tenant identities is established, and fine-grained API authority control and resource use limitation are provided.
Owner:CHINA IND INTERNET RES INST

Multi-level data cleaning method for nuclear power industry

The invention belongs to the technical field of nuclear power data processing, and particularly relates to a multi-level data cleaning method for the nuclear power industry. Comprising a first hierarchy data importing and preprocessing layer, and the first hierarchy is a basic unit for nuclear power multi-hierarchy data cleaning; the second level carries out local processing layer data processing, and the data subjected to secondary cleaning is recompressed, feature codes are extracted, and then the data are transmitted to the third level; or directly forwarding the unprocessed original compressed data; the third hierarchy carries out data processing of the platform layer in the data; and the fourth level performs data processing of the data application layer, and is responsible for performing persistent storage on the data according to a standardized format after the data is subjected to full-process cleaning, compression, feature extraction and desensitization processing. The method has the beneficial effects that the method is specially customized for the nuclear power industry: special requirements of high confidentiality, network isolation, large data volume and the like of data in the nuclear power industry are fully considered, and a special cleaning and desensitization process is designed.
Owner:NUCLEAR POWER OPERATIONS RES INST (NPRI)

Data transmission method and device between security domains, storage medium and electronic equipment

The invention discloses a data transmission method and device between security domains, a storage medium and electronic equipment. Relates to the field of data transmission, and the method comprises: in a front-end application of a first security domain, in response to an interaction request triggered by a user, generating a request message containing a unique identifier, and issuing the request message to a message queue service in the first security domain, the message queue service being used for a large model processing service in a second security domain, consuming the request message according to a pre-configured security access strategy, and writing response data of the large model into a shared cache service of a first security domain; and initiating a query request to the shared cache service to obtain response data corresponding to the interaction request from the shared cache service, and displaying the response data to the user through a user interface of the front-end application. The problem that data transmission efficiency is low when data transmission between security domains in a one-way network isolation environment is realized by depending on a manual or semi-automatic off-line ferry mode in the prior art is solved.
Owner:TRAVELSKY TECHNOLOGY LIMITED

Automatic operation and maintenance method and system suitable for closed system

The invention provides an automatic operation and maintenance method and system suitable for a closed system. The technical problem that a traditional operation and maintenance scheme is difficult to apply due to network isolation and sample scarcity in closed environments such as finance and energy is solved. The method comprises the following steps: generating a unique and traceable migration identifier for all operation and maintenance data, models and reasoning results through a data and migration management module; quantitatively calculating a transferability score between the source domain and the target domain through a transferability evaluation module; an optimal model migration strategy is dynamically selected according to the mobility score, and efficient self-adaption of the model is achieved; closed-loop operation and maintenance are executed through a multi-agent cooperation system comprising detection, diagnosis and repair agents, and self-learning and self-optimization of the system are realized through small sample active learning and a knowledge base evolution mechanism. According to the method, rapid construction, continuous evolution and whole-process traceability of the artificial intelligence operation and maintenance capability in the closed system are realized, and the method has remarkable innovativeness and industrial application value.
Owner:CHINA ACADEMY OF INFORMATION & COMM

System for secure MCP-mediated tool use by AI agents and generative AI / LLM services in cloud-native distributed applications

A system (100) for the secure MCP-mediated use of tools by AI agents and generative AI / LLM services in cloud-native distributed applications, wherein the system (100) comprises: a KL agent interface (1) configured to receive natural language commands and application events from a variety of client applications and to generate appropriate tool call commands for one or more generative KL or Large Language Model (LLM) services; an MCP mediator service (2) that is configured to: (a) to convert the tool request requests into messages compatible with a model context protocol (MCP); and (b) to maintain the conversation context, including at least one of the following: user identity, tenant identity and application identity; a tool register (3) that stores a plurality of tool descriptions, each tool description defining at least a tool identifier, an input and output scheme, an endpoint location and allowed functions, wherein the tool register (3) is accessible to the MCP mediator service (2); a policy and security manager (4) configured to evaluate each MCP tool call against one or more security and access policies based on the conversation context and the corresponding tool description, and to issue a decision to allow, modify or block the tool call; a tool connector layer (5) comprising a plurality of tool adapters, each tool adapter being configured to communicate securely with a corresponding external tool, service or data source using credentials and permissions restricted according to the decision of the policy and security manager (4); an observation and audit manager (6) configured to record, for each tool call, at least a timestamp, the calling KL agent, the tool identifier, the policy decision, and a summary of the tool response, and to provide audit logs and metrics for monitoring and compliance purposes; and a cloud-native deployment controller (7) configured to provide the MCP mediator service (2), policy and security manager (4), tool connector layer (5) and observation and audit manager (6) as distributed microservices with network isolation between tenants in a cloud-native environment.
Owner:BHANDARWAR NILESH DNYANESHWAR REDMOND

Infrastructure and application management system based on cloud native technology

The invention discloses an infrastructure and application management system based on a cloud native technology, and the system comprises a command line tool which is used for carrying out the communication with a server through an MQTT protocol, and executing the cluster management operation; the multi-tenant private cloud cluster module is used for realizing resource isolation and quota management among tenants; the mirror image warehouse module is used for storing and managing application mirror images; the declarative management module is used for defining a resource expectation state through a YAML configuration file; the CI / CD assembly line module is used for automatically constructing, testing and deploying applications; the gateway resource scheduling module is responsible for load balancing and flow control; the user authorization and authentication module is used for realizing authority control based on an RBAC model; the security module comprises data encryption and network isolation; and the asset library management module is used for managing a program component and a platform library. By integrating a cloud native technology stack, a set of efficient, safe and extensible infrastructure and application management system is constructed, and the deployment efficiency and the operation and maintenance capability of enterprise-level applications are remarkably improved.
Owner:HEFEI TANOVO INFORMATION SECURITY TECH CO LTD

Secret transmission security management system for secret-related electronic files

The invention relates to the technical field of secret-related electronic file transmission and management, and discloses a secret-related electronic file secret transmission safety management system which comprises a safety management system. The security management system comprises a hardware security support layer, a distributed security storage layer, a file full life cycle security management layer, a user identity authentication and behavior auditing layer, a security auditing layer and an emergency response layer. The confidential electronic file secret transmission security management system integrates a trusted computing chip, security boot firmware, a physical unclonable function (PUF) and an optical isolation technology through a hardware security support layer, is different from a traditional system which only depends on software protection, constructs a trusted execution environment from a hardware bottom layer, guarantees the operation credibility by using the trusted computing chip, and improves the security of the confidential electronic file. The secure boot firmware blocks illegal program loading, the PUF endows the hardware with a unique uncounterfeited identity, and the optical isolation realizes physical level network isolation, so that threats such as hardware tampering and physical attacks are radically defended.
Owner:BEIJING AEROSPACE NETWORK TECHNOLOGY CO LTD

Power industrial control terminal network isolation method and system based on process security label binding

The application discloses a kind of power industrial control terminal network isolation method and system based on process security label binding;Belong to the technical field of power system network security, its operating steps include: decoupling physical network resources into independent partitions and mapping to independent user-mode network protocol stack instances;Through the bottom flow direction rule, the in-bound traffic is accurately delivered to the corresponding partition;Identify process security label at the application layer, establish the forced mapping of process and specific protocol stack instance and link;Through the controlled shared memory channel, realize the safe data interaction between partitions.The application realizes strong logical isolation on unified hardware, through the forced binding of process identity and network link, reduces the privilege promotion and horizontal penetration risk caused by traditional protocol stack sharing, while limiting the scope of failure impact, without relying on external physical isolation equipment, significantly improves the endogenous security protection capability of industrial control system network boundary.
Owner:NARI INFORMATION & COMM TECH

Storage cluster splitting method and apparatus, electronic device, and storage medium

This application discloses a method, apparatus, electronic device, and storage medium for splitting a storage cluster, relating to the field of computer technology, particularly to artificial intelligence fields such as cloud computing, distributed storage, and big data processing. The specific implementation scheme is as follows: The data path of the target resource in the original storage cluster is adjusted so that requests to access the target resource are sent to the target node in the original storage cluster; the target node is network isolated; the target node is restarted, and in response to the target node's target startup parameter being set to the target value, the target node is split from the original storage cluster as a new storage cluster; wherein, the target startup parameter is a parameter used to force a node to start as a new single-node cluster; the target node is removed from the original storage cluster, and the network isolation of the target node is lifted.
Owner:BEIJING BAIDU NETCOM SCI & TECH CO LTD

Data offline protection method and system, electronic device and storage medium

The invention discloses a data offline protection method and system. The method comprises the steps that a first server backs up target data from a data source end according to a preset first network isolation strategy, and the target data serve as first backup data; at least one second server backs up the first backup data from the first server according to a preset second network isolation strategy to serve as second backup data, and the second server is in a physical isolation state after backup; wherein the first network is configured in a way that the first server only opens the data transmission with the data source end in a first set time period, and closes the data transmission with the data source end after the first backup data is backed up; the second network isolation strategy is configured to enable the second server to only open the data transmission with the first server in a second set time period, and close the data transmission with the first server after the second backup data is backed up. Unified management, calling of services among systems and function integration can be achieved, and the equipment cost is greatly reduced.
Owner:THE PEOPLES BANK OF CHINA DIGITAL CURRENCY INST

Data bidirectional synchronization method based on MongoDB and computer program product

The invention provides a MongoDB-based data bidirectional synchronization method, a computer program product, electronic equipment and a storage medium, and the method comprises the steps: obtaining first incremental data and second incremental data according to copy set service demands corresponding to a first MongoDB database and a second MongoDB database; respectively carrying out data ferrying on the first incremental data and the second incremental data; and respectively carrying out MongoDB database storage operation on the first incremental data after ferrying and the second incremental data after ferrying. By implementing the application, data synchronization can be realized without depending on message middleware, data intrusion is prevented, the primitiveness of the data is not damaged, network isolation is effectively traversed, and the transmission efficiency of the data is improved.
Owner:HUBEI TIANRONGXIN NETWORK SECURITY TECH CO LTD +3

An access method, device, platform, equipment and medium of an intranet and extranet terminal

This invention provides a method, apparatus, platform, device, and medium for accessing internal and external network terminals. The internal and external network access platform is deployed with a software-defined boundary architecture, which includes a zero-trust system. The method includes: receiving communication connection requests from internal and external network terminals through the zero-trust system; responding to the communication connection requests by granting access permissions to the internet ports of the internal and external network terminals based on a door-knocking packet; establishing a communication connection with the internal and external network terminals based on the access permissions and receiving office business access requests from the internal and external network terminals; responding to the office business access requests, acquiring office data, and returning the office data to the workspace domain of the internal and external network terminals. The zero-trust strategy is implemented through the software-defined boundary architecture, utilizing internet port hiding technology to reduce internet exposure; and a zero-trust sandbox is used to provide security assurance by isolating internal and external network terminals in personal and workspaces, achieving internal and external network isolation during office work and maintenance.
Owner:CHINA TELECOM CORP LTD

File transmission device and method under combination of physical and logic isolation networks

PendingCN121940157AMeet the requirements for isolated communicationConvenient and quick deploymentSecuring communicationExchange networkEngineering
The invention discloses a file transmission device and method under the combination of physical and logic isolation networks. The device comprises an all-in-one machine unit, the all-in-one machine unit comprises a gatekeeper front-end processor, an isolation module and a host machine; the host machine comprises a gatekeeper postposition machine, an isolation switching network channel and other logic isolation networks connected with the isolation switching network channel; the gatekeeper front-end processor receives the flow data transmitted by the isolation network; network isolation communication is carried out between the isolation module and the gatekeeper rear-end machine; the gatekeeper postposition machine and the isolation switching network channel internally form a network for TCP communication, the isolation switching network channel and other logic isolation networks directly communicate with the host machine through a shared memory, and the isolation switching network channel and the other logic isolation networks are in network isolation; the all-in-one machine has the beneficial effects that through the all-in-one machine unit provided by the invention, convenient and rapid implementation and deployment are realized, and the implementation cost is reduced; and the requirement of a physical isolation gatekeeper is met, and the requirement of internal network isolation communication is also met.
Owner:SHENZHEN LEAGSOFT TECH

Network knife switch based on physical isolation

A network knife switch based on physical isolation relates to the technical field of communication network maintenance, and comprises a bearing shell, a switching rotary knife switch and an on-off connector, and a rotary center shaft supported by a fixing frame is arranged in the length direction of the bearing shell and located at the center of the interior of the bearing shell. A plurality of groups of switching rotary knife switches are uniformly fixed in the length direction of the rotary middle shaft at intervals, and each group of switching rotary knife switches corresponds to one on-off connector; copper reeds are fixed in the trapezoidal clamping grooves of the on-off connectors, and any group of switching rotary knife switches comprise brake pads which are respectively positioned in the eight trapezoidal clamping grooves in the corresponding on-off connectors; the network switching device is simple in structure, reliable in performance and easy and convenient to operate, switching of different networks is achieved under the condition that the network isolation state is not affected, the risk of cross-network connection of the different networks is reduced, the difficulty of network maintenance is lowered, and the maintenance efficiency of an information system is improved.
Owner:CHINESE PEOPLES LIBERATION ARMY UNIT 96608

An intelligent detection method, device and equipment for electrical line fault and storage medium

This invention provides an intelligent method, apparatus, device, and storage medium for detecting electrical line faults. The method includes: dividing a target electrical line network into sub-networks based on its topology and node distribution; performing an island search based on the current current data, normal operating current reference, and sub-network topology of the target sub-networks to identify target isolated sub-networks that are isolated from the main electrical line network of the power system; synchronously implementing current cutoff operations on each first boundary node of the target isolated sub-networks to obtain the current change characteristics of the first boundary nodes after the current cutoff operations; performing fault area analysis based on the electrical connection relationships of the target sub-networks and the current change characteristics of the first boundary nodes to obtain the faulty line area; and performing fault type analysis based on the line electrical parameters of the faulty line area to obtain the line fault type. This invention improves the recovery efficiency and power supply reliability of the power system.
Owner:JIAN AN CONSTR (GUANGDONG) CO LTD

Multi-tenant network isolation processing method, electronic equipment, storage medium and program product

The embodiment of the invention provides a multi-tenant network isolation processing method, electronic equipment, a storage medium and a program product, and the method comprises the steps: receiving a service data packet sent by a first tenant, the service data packet at least comprising target tenant identification information of the first tenant; according to a preset encryption algorithm, performing encryption processing on the target tenant identification information to obtain target encryption identification information corresponding to the target tenant identification information; target tunnel information corresponding to the target encryption identification information is determined according to a pre-stored tunnel matching rule, the pre-stored tunnel matching rule at least comprises preset encryption identification information and tunnel information corresponding to the preset encryption identification information, and the tunnel is an IPSEC tunnel; according to the target tunnel information, the service data packet is sent, and the tenants are distinguished through the tenant identification information, so that the tenants can be isolated, the problem of false transmission in the data transmission process is avoided, and the accuracy of data transmission is improved.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

Cross-forward isolation data comparison system, method and device, medium and product

PendingCN121966961Areduce risk of exposureAvoid direct connection requirementsSecuring communicationData synchronizationNetwork isolation
The embodiment of the invention provides a cross-forward isolation data comparison system, method and device, a medium and a product, and relates to the field of data synchronization and verification. The system comprises a first agent which is deployed in an intranet and accesses a source end database through a database connection protocol; the second agent is deployed in an external network and establishes one-way communication connection with the first agent; the first agent is also used for transmitting the source end data of the source end database to the second agent through the forward isolation device through the one-way communication connection; and the comparison service is deployed in an external network, pulls the source end data from the interface of the second agent, and performs comparison operation on the source end data and the target end data. According to the method provided by the invention, the technical problem of data comparison in a cross-forward isolation scene is solved through the design of a double-agent architecture and a user-defined protocol, the security and reliability of data comparison are realized, and efficient and secure data comparison in a strict network isolation environment is realized.
Owner:CETC JINCANG (BEIJING) TECH CO LTD

Privacy pocket

A privacy pocket designed to retain at least one mobile computing device to isolate the mobile computing device from all corresponding communication networks. The privacy pocket can be integrated into any clothing garment for use as a normal pocket and to fully isolate the mobile computing device. Alternatively, the privacy pocket can take the form of a separate structure to be carried by the user and / or attach to an external object. The privacy pocket comprises a pocket body, a protection flap, and a pocket fastener. The pocket body comprises a plurality of layers. The internal layers include a conductive fabric layer and a sound-dampening layer to block electromagnetic radiation and sound waves, thereby completely isolating the mobile computing device within the pocket body. The protection flap covers the sealable opening of the pocket body, and the sealable opening is sealed using the pocket fastener.
Owner:PATTE LIRYC +2

Cross-cloud platform virtual private cloud interconnection system based on unified cloud management platform and construction method

The invention provides a cross-cloud platform virtual private cloud interconnection system based on a unified cloud management platform and a construction method, and relates to the technical field of computer networks. The system comprises a unified cloud management platform and at least two independent cloud platforms. Corresponding virtual private clouds run on the independent cloud platform, and the virtual private clouds are in network isolation; the unified cloud management platform is based on the VPN technology, a VPN tunnel network is constructed between a VPN server and a VPN client, and the virtual private cloud client serves as a gateway node to achieve communication between virtual private clouds on different cloud platforms. The configuration information of the VPN server and the virtual private cloud client is issued in a mode of virtual machine data injection and VPN server interface; the problem of data and information islands among cloud platforms in a multi-cloud platform scene can be solved, the resource sharing capability among the cloud platforms is enhanced, and the cross-cloud interconnection of applications and the cross-domain sharing capability of data are realized.
Owner:DIANKEYUN (BEIJING) TECH CO LTD

Network distribution method and device for multi-tenant environment, network system and medium

The invention provides a network distribution method and device for a multi-tenant environment, a network system and a medium, relates to the technical field of network access, and can solve the problem of poor network isolation. The method comprises the following steps: dividing unauthenticated terminal equipment into a preset network, and authenticating the terminal equipment according to the preset network to obtain terminal information and a target network allocated to the terminal equipment; according to the terminal information, configuring the initial PPSK key to obtain a target PPSK key, and binding the terminal device, the target PPSK key and a target network; receiving a real-time access request sent by the terminal equipment, and identifying a target PPSK key corresponding to the real-time access request to obtain a corresponding target network; dividing the terminal equipment into a target network; therefore, the isolation and security of network access are improved.
Owner:CHENGDU SKSPRUCE TECH

X86 SoC array server dual-mode system based on intranet VLAN closed loop

The invention discloses an x86SoC array server dual-mode system based on an intranet VLAN closed loop, and relates to the technical field of cross engineering, and the system comprises a VLAN establishment module which is used for executing a configuration instruction, establishing a VLAN, carrying out MAC port binding and private VLAN function operation at the same time, and generating a secure network closed loop with a trusted SoC as the center; the dual-mode generation module is used for inputting the heterogeneous feature vectors into a small neural network, performing cross-node encryption communication and public VLAN access operation, and generating a high-security intranet-open interconnection dual-mode mode; mAC port binding and private VLAN function operation are executed by establishing the VLAN module, a secure network closed loop with the trusted SoC as the center is generated, synchronous construction of a network isolation strategy and a hardware trusted state is achieved, and the effect of hardware identity trusted verification and dynamic secure network cooperative control is achieved.
Owner:启朔(深圳)科技有限公司

Network distribution method and device for multi-tenant environment, equipment and medium

The invention provides a network distribution method, device and equipment for a multi-tenant environment and a medium, is used for the technical field of network access, and can solve the problem of poor isolation of an existing network. Comprising the following steps: dividing a target terminal into a preset network, and authenticating the target terminal according to the preset network to obtain terminal information and a target network; according to the terminal information, the initial PPSK key is configured to obtain a target PPSK key, and the target terminal, the target PPSK key and the target network are bound; receiving a real-time access request sent by a target terminal, and identifying a target PPSK key corresponding to the real-time access request to obtain a corresponding target network; dividing the target terminal into a target network; therefore, the isolation and security of network access are improved.
Owner:CHENGDU SKSPRUCE TECH

Digital power grid open source software supply chain security management and control method

The invention discloses a digital power grid open source software supply chain security management and control method, relates to the technical field of network security, and solves the problems that in the prior art, single dimensions such as component importance, vulnerability severity and network position are independently used for threshold judgment, and a dynamic aggregation mechanism for coupling calculation of the component importance, the vulnerability severity and the network position is lacked. Therefore, the problem of assessment distortion inevitably occurs in a cross-security region scene is solved. According to the invention, through four-step progressive calculation of dependence propagation quantification, vulnerability reachable correction, network isolation attenuation and time-sensitive aggregation, a dynamic evaluation system which deeply fuses power grid service characteristics and environmental constraints is constructed; according to the method, normal form transformation from static classification to accurate sorting, from isolated judgment to linkage calculation and from universal standards to scene adaptation is realized, so that the safety management and control response can be accurately matched with the real risk level and the service timeliness demand under the complex architecture of the digital power grid.
Owner:GUANGXI POWER GRID CORP

Robot data transmission method, robot and medium

The application relates to the technical field of robots, and discloses a robot data transmission method, a robot and a medium, which comprise the following steps: configuring multiple virtual local area networks, performing robot data transmission network isolation based on the virtual local area networks; obtaining load data of the virtual local area networks, adjusting data transmission priorities of the virtual local area networks based on comparison results of the load data and preset load thresholds, adjusting bandwidths of the virtual local area networks based on the adjusted data transmission priorities and the load data; and performing data transmission based on the adjusted data transmission priorities and the adjusted bandwidths. The application judges network congestion states based on load sensing of each virtual local area network in the robot, improves transmission priorities of virtual local area networks in the congestion states, makes the virtual local area networks in the congestion states transmit preferentially, can effectively avoid delay and packet loss caused by network congestion, and guarantees real-time performance of robot control responses and reliability of action execution.
Owner:UNBOUNDED POWER (BEIJING) TECHNOLOGY R&D CO LTD

Article label anti-counterfeiting authentication method, system and computer device

The application relates to an article label anti-counterfeiting authentication method, system and computer equipment. The method comprises the following steps: reading first label information containing an identification area, a coding area and a password area through an external network base station to realize preliminary data verification and label authentication; and reading second label information containing only the coding area through an internal network base station to perform secondary verification, so that data multiple verification and anti-counterfeiting verification are provided for electronic label data interaction in a network isolation environment, the information comprehensiveness and safety are considered, the accuracy and reliability of target article identification are improved, and data safety is ensured through partition information management.
Owner:CHANGSHA YINGXIN SEMICONDUCTOR TECHNOLOGY CO LTD

Methods, apparatus, software products, and electronic devices for transmitting data across network segments

This application discloses a method, apparatus, program product, and electronic device for cross-network segment data transmission, relating to the field of network security technology. The method includes: first, transmitting target request information from a first network segment to a target queue, where the target queue is a message queue deployed in the first network segment; then, determining the return data corresponding to the target request information in the target queue through a second network segment, wherein the return data is data stored in the second network segment and needs to be transmitted to the first network segment; and finally, transmitting the return data to a target database, where the target database is a memory database deployed in the first network segment. This application solves the technical problem of low data transmission security caused by the prior art requiring manual export and copying of data from different network segments with network isolation when transmitting data between them.
Owner:TRAVELSKY TECHNOLOGY LIMITED

Subway signal system log intelligent analysis method, device, equipment and medium

PendingCN121644207AAlarmsSecuring communicationData aggregatorNetwork Compartment
The invention relates to a subway signal system log intelligent analysis method, device and equipment and a medium. The method is realized by constructing a multi-stage security architecture of an internal security network-network isolation region DMZ-public network, firstly, log data preprocessing and encryption are carried out in the network isolation region DMZ, secondly, reverse communication is blocked through unidirectional transmission hardware, and then, accurate analysis is carried out by utilizing a large model association version demand and log keywords, so that the log data encryption is realized. And finally, establishing a global knowledge base to mine common hidden dangers. Compared with the prior art, the method has the advantages that on the premise that absolute safety of the core production network is ensured, log data aggregation of the whole road network is achieved, and intelligent real-time analysis and early warning are carried out.
Owner:CASCO SIGNAL LTD