Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

79 results about "Network segmentation" patented technology

Network segmentation in computer networking is the act or practice of splitting a computer network into subnetworks, each being a network segment. Advantages of such splitting are primarily for boosting performance and improving security.

Custom configuration of cloud-based multi-network-segment gateways

In response to a programmatic request, configuration information representing a multi-network-segment gateway established on behalf of a customer is stored at a networking service. In response to another programmatic request, a communication session is established between a route signaling node of the gateway and a routing information source located at a customer premise. In response to additional programmatic input, the networking service stores an indication that the gateway is to be used to transfer packets between a cloud-side virtual network and a customer-side virtual network. The routing information exchanged in the session pertains to the cloud-side and customer-side virtual network, and is used to transfer data packets between the two virtual networks.
Owner:AMAZON TECH INC

Solar panel defect detection method and system, computer equipment and storage medium

The invention belongs to the technical field of intelligent detection of new energy equipment, and particularly relates to a solar panel defect detection method and system, computer equipment and a storage medium, and the method comprises the following steps: a lightweight defect preliminary screening and adaptive shooting step: carrying out the recognition and image collection of a solar panel array through a lightweight model at the edge end of an unmanned aerial vehicle; a defect segmentation and type identification step: performing accurate segmentation on the solar panel and the defects through a neural network model, and judging the types and grades of the defects in combination with a feature extraction and classification model; a defect enhancement optimization step: enhancing the defects through an adversarial network; a detection performance evaluation step: quantitatively evaluating the overall performance of the system through a multi-dimensional index; mSAN-Net network segmentation is adopted, so that the defect detection precision is improved; and in combination with a GAN defect enhancement technology, the omission ratio and the false detection rate of weak defects are reduced, so that the fine operation and maintenance requirements of the solar panel are met.
Owner:SHANGHAI SECOND POLYTECHNIC UNIVERSITY

Zero-trust cybersecurity access control system using continuous identity verification

A system for zero-trust cybersecurity access control using continuous identity verification (100), comprising: a Policy Decision and Enforcement Orchestrator (1) configured to receive an access request from a user device and enforce a session with minimal privileges; an engine for continuous identity verification (2) configured to generate a time-dependent identity trust score by continuously verifying the user identity during an active session; a device state and telemetry collector (3) configured to acquire device state parameters, runtime signals and network telemetry and to generate a state value; a module for detecting behavioral risks and anomalies (4) that is configured to create behavioral profiles and detect anomalies based on user activity patterns, contextual signals and the history of resource access; a cryptographic authentication and secure token module (5) configured to issue and update a short-lived, bound access token associated with at least the identity trust value and the state value; and an adaptive response and microsegmentation module (6) configured to dynamically adjust access permissions, network segmentation and session privileges in real time, based on an aggregated risk assessment derived from modules (2) to (4), where the system (100) continuously reassesses trustworthiness during the session and selectively allows, restricts, requires enhanced authentication or terminates the session based on the aggregated risk assessment.
Owner:SIVASHANMUGAM SATHESH PADMANABAN GLENDALE

Lung CT blood vessel image segmentation and reconstruction system based on multiple interpretable features

PendingCN121304695AImage analysisBiological modelsPulmonary parenchymaFeature extraction
A lung CT blood vessel image segmentation and reconstruction system based on multiple interpretable features performs further fine-grained segmentation on the basis of main airway features through a feature extraction module to obtain a plurality of connected domains, performs multi-stage feature extraction on the connected domains, and outputs multi-scale feature information; the blood vessel segmentation module generates an information matrix according to the indexes and the pulmonary parenchyma mask, generates a blood vessel network segmentation result through an adversarial network and performs post-processing; and the model reconstruction module performs three-dimensional reconstruction on the blood vessel network segmentation result and the pulmonary parenchyma mask to obtain a 3D model. According to the method, on the basis of anatomical priori knowledge of pulmonary vessels and airways, a large amount of multi-scale feature information is utilized, the information loss of the two-stage segmentation network is reduced, and the network adaptability and the learning ability of the relation between pixels under the complex condition are improved. In the aspect of system design, a modular design and management mode is adopted, efficient resource access is achieved, and meanwhile the operability and usability of the system are improved through end-to-end process design.
Owner:SHANGHAI JIAOTONG UNIV

Identity-based distributed cloud firewall for access and network segmentation

According to some embodiments, a method of controlling access to network resources includes: receiving an authentication request from a user device to a core security service; if the user is authenticated, authorizing the user device to connect to a private cloud, and connecting the user device with the private cloud and retrieving user-specific segmented firewall rules stored in the private cloud; routing, through the firewall rules, a request by the user device to access an outer resource; evaluating the request against the firewall rules; if the request meets the firewall rules, routing the request through security measures of the firewall; and if the request does not meet the firewall rules, denying the user device access to the outer resource.
Owner:720 IT UAB

State-based network segmentation in a network device

Methods and systems relate to packet forwarding that includes a network device receiving a message from a second network device and that has a destination address of a third network device. The circuitry of the network device determines that a connection between the second network device and the third network device has been previously opened by the third network device. In response to the determination that the connection is open and in response to receiving the message, the circuitry transmits the message towards the third network device.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

A spinal column segmentation method

The application discloses a kind of spine segmentation methods, comprising the following steps: step 1: data pre-processing, generate spine heat map and windowing to image, the window width and window width of lumbar bone tissue are respectively set to 400 and 1800;Step 2: using U-Net structure roughly locates lumbar vertebra;Step 3: calculate image bounding box, obtain the range of selected lumbar vertebra using 4 neighborhood, and select the voxel with HU value greater than 0.3 times of the maximum HU value of image as possible lumbar vertebra, then the obtained bounding box is extended in each dimension 0.05-0.2 times of the corresponding image size;Step 4: network segmentation based on XUnet network, XUnet uses Inception block to extract features;Through the implementation of the application, while deepening the network width and depth, improving the network expression ability, further reduces the redundant parameters in the network, realizes the deep learning and automatic efficient vertebral automatic segmentation effect, the positioning segmentation effect is good, plays a prominent progress, has certain use value and popularization value.
Owner:杭州邦杰星医疗科技有限公司

Power grid transient fault mode classification method and system based on artificial intelligence

The application provides a power grid transient fault mode classification method and system based on artificial intelligence, relates to the field of power system faults, and comprises the following steps: collecting multi-dimensional physical quantity data, extracting transient response strength and topological connectivity coupling calculation node state values, generating diffusion trajectories and extracting morphological features to determine fault types, source positions and boundaries, calculating time sequence gradient to trace propagation paths, identifying path intersection nodes to calculate cumulative contribution degrees to determine core nodes, configuring isolation trigger conditions for the core nodes to output a network segmentation scheme. The application can quickly and accurately identify faults, reduce power outage ranges, and improve power grid stability.
Owner:ELECTRIC POWER RES INST STATE GRID SHANXI ELECTRIC POWER

Intent-based enterprise security using dynamic learning of network segment prefixes

In an example, systems and methods enable automatic implementation of intent-based security policies in a network system, such as a software-defined wide area network system, in which network segment prefixes for network segments at one or more sites are dynamically learned. A service orchestrator controller translates an intent-based security policy input by a user to a security policy for a first site. The security policy for the first site specifies a segment-specific queryable resource associated with a second site. To implement the security policy, a device associated with the first site queries the segment-specific queryable resource associated with the second site, and updates one or more forwarding tables of the device with the network segment prefixes associated with one or more network segments at the second site received in response to the query. The first site forwards network traffic to the second site based on the updated forwarding tables.
Owner:JUNIPER NETWORKS INC

Network segmentation for secure network tunneling

A request of a VPN client to connect to a second set of one or more networks is received by a first VPN server associated with a first set of one or more networks. The request comprises an identifier of the VPN client, an attestation of an access control server that the VPN client complies with a compliance profile required to access the second set of one or more networks, and a digital signature of the access control server. The digital signature is validated using a public key of the access control server. One or more common networks each included in both the first and second sets of networks are identified. A firewall of the first VPN server is modified to permit the VPN client to connect to the one or more common networks.
Owner:FORTANIX INC

Network anomaly positioning method, device and equipment and readable storage medium

PendingCN122476012AAlgorithmEngineering
The application provides a network anomaly positioning method and device, equipment and a readable storage medium, relates to the technical field of communication, and is applied to an anomaly positioning device. The method comprises the following steps: obtaining a first segment characteristic value, the first segment characteristic value being a value of a transmission characteristic of a first network segment in a network; determining N segment characteristic comparison values, the N segment characteristics comprising transmission characteristics of N network segments in the network, each segment characteristic comparison value in the N segment characteristic comparison values being within a reference value range of the transmission characteristic of the corresponding segment; inputting the N segment characteristic comparison values and the first segment characteristic value into a first prediction model to obtain a first output of the first prediction model, the first prediction model being used for determining whether the network is an abnormal network based on N+1 values corresponding to N+1 segment characteristics; and determining whether the first network segment is an abnormal network segment according to the first output. The application is used for solving the problem of low positioning efficiency when positioning the network anomaly position.
Owner:HUAWEI TECH CO LTD

Network segmentation for secure network tunneling

A request of a VPN client to connect to a second set of one or more networks is received by a first VPN server associated with a first set of one or more networks. The request comprises an identifier of the VPN client, an attestation of an access control server that the VPN client complies with a compliance profile required to access the second set of one or more networks, and a digital signature of the access control server. The digital signature is validated using a public key of the access control server. One or more common networks each included in both the first and second sets of networks are identified. A firewall of the first VPN server is modified to permit the VPN client to connect to the one or more common networks.
Owner:FORTANIX INC

A method for automatically segmenting typical lesions of retinopathy of prematurity

The application discloses a kind of premature infant retinopathy typical lesion automatic segmentation method, comprising the following steps: S1, collect ROP image, exclude unqualified image therein, and after the qualified ROP image is labeled, it is used as ROP lesion segmentation dataset, and dataset is divided into training set, verification set and test set;S2, construct deep neural network model;S3, after the training set is preprocessed, the training set is used to train the deep neural network model, calculate loss, optimize network parameters, and obtain the optimal model after several iterations;S4, the optimal model is tested using test set, and the segmentation performance evaluation index of the model on test set is obtained.Compared with the prior art, the method can better distinguish between background and four lesion structures, reduce the misjudgment rate, achieve automatic pixel-level segmentation of ROP fundus image lesions, and ultimately improve the network segmentation performance.
Owner:GUANGDONG POLYTECHNIC NORMAL UNIV +1

Mapping of ipsec tunnels to sd-wan segmentation

Generally, Software-Defined Wide Area Networks (SD-WAN) generally do not support network segmentation. The concepts disclosed herein connects IPSec SD-WAN fabric to a Virtual Routing and Forwarding (VRF) router and make use of a Software Defined Cloud Interconnect (SDCI) Router to route traffic from IPSec SD-WAN to various cloud services from the SDCI Router in the fabric. The concepts disclosed herein also provides for tunnel multi-plexing that takes incoming and outgoing traffic and maps VPNs to any service VRF associated with the cloud based services.
Owner:CISCO TECHNOLOGY INC

Multi-agent task allocation method based on network coverage dynamic matching control

The invention discloses a multi-agent task allocation method based on network coverage dynamic matching control, which comprises the following steps that: multiple agents self-organize a network and divide the network into N sub-networks, the sub-networks adopt a navigator and follower mode, and the navigator executes sub-network management and decision; each sub-network obtains a current environment state, and selects to explore a task domain or search other sub-networks by using a high-level decision of a hierarchical deep reinforcement learning model; executing agent movement by using a low-level decision of the hierarchical deep reinforcement learning model until a task domain or other sub-networks are found; performing network segmentation or fusion on the sub-networks which find the task domain or other sub-networks through network topology control to form a coverage sub-network or a new sub-network; and the intelligent agent in the coverage sub-network completes task execution by using the task allocation optimization model, and the new sub-network is converted after the task execution is completed. According to the method, task distribution can be explored by using multiple agents with a limited scale in an environment where network infrastructures are lacked and task distribution is unknown, and task distribution is completed, so that task response time is shortened, and the task completion rate is increased.
Owner:JIANGSU VOCATIONAL COLLEGE OF BUSINESS +2

Face reconstruction and occluded region identification method, device and equipment and storage medium

Embodiments of the application disclose a face reconstruction and occlusion region identification method, device and equipment and a storage medium. The method comprises: inputting a face image into a first network structure, outputting a reconstruction parameter vector of the face image when three-dimensional reconstruction is performed through the first network structure; performing three-dimensional reconstruction of the face image based on the reconstruction parameter vector to generate three-dimensional face information; performing rendering and mapping processing on the three-dimensional face information to generate two-dimensional face information containing network segmentation data; obtaining a deep feature map extracted by the first network structure, and constructing graph structure information based on the deep feature map and the two-dimensional face information; inputting the graph structure information into a second network structure, and outputting an occlusion region corresponding to the face image through the second network structure. The scheme optimizes overall resource deployment, can meet application scenarios with many parallel tasks and high real-time requirements, and has higher accuracy in occlusion region determination.
Owner:BIGO TECH PTE LTD

Network security based on vendor network scoring with dynamic network segmentation

Mechanisms are provided for decentralized security orchestration. The mechanisms execute training, for each vendor network in the plurality of vendor networks, on a corresponding vendor network artificial intelligence (AI) computer model. The training is executed with training data collected from a corresponding vendor network over time, where the training data represents transactions occurring within the corresponding vendor network. The trained models are executed on new security information to thereby classify activity in portions of the data processing system as to a security risk level. Fuzzy logic is executed on the classifications to automatically determine if segmentation of the data processing system is to be performed. If segmentation is to be performed, the mechanisms segment / isolate portions having a predetermined security risk level classification.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

A method and system for intelligent centralized monitoring of full-color LED displays

This invention provides an intelligent centralized monitoring method for full-color LED displays, comprising: analyzing inter-node dependencies and communication delays based on a neighboring node association model to identify target areas with network segmentation risks; detecting backup communication paths for risky nodes and selecting paths with communication delays below a preset threshold as priority switching paths; deploying a distributed consistency protocol to compare data differences and generating a synchronization order list based on data update frequency and business priority; using a fragmented transmission mechanism to divide the data to be synchronized into multiple data segments and transmitting them to the target nodes in parallel via multiple paths; initiating an automatic repair mechanism for inconsistent nodes, obtaining backup data from neighboring nodes to perform differential correction; and dynamically optimizing communication path weights and synchronization cycle parameters based on the correction results to complete iterative updates of the system status.
Owner:GUANGDONG ZHENGDIAN OPTOELECTRONICS CO LTD

Teaching method for automatic spot drilling processing based on 3D scanning and spot drilling machine

The invention discloses a teaching method based on 3D scanning automatic spot drilling machining and a spot drilling machine, and belongs to the technical field of 3D scanning automatic spot drilling machine teaching. The teaching method comprises the steps that three-dimensional point cloud data of the surface of a workpiece are collected according to a preset sequence; segmenting workpiece data from the point cloud, registering the workpiece data with a workpiece standard CAD model, and establishing coordinate mapping; analyzing the diamond CAD model to obtain pose and size parameters of the diamond; then, the diamond parameters are converted into equipment control parameters through the coordinate mapping relation and an equipment kinematics model; and finally, generating a final teaching file according to the control parameters. According to the teaching method, full-automatic generation from three-dimensional scanning to machining teaching files is achieved, manual intervention is reduced, the problems that traditional spot drill teaching is low in efficiency and poor in precision are solved, automatic teaching is achieved through 3D scanning, PointNet network segmentation and CAD registration, spot drill machining efficiency and consistency are improved, and labor cost is reduced.
Owner:GUANGZHOU SHANGNA INTELLIGENT TECH CO LTD

A chip image defect segmentation method based on an improved SegFormer

This invention discloses a chip image defect segmentation method based on an improved SegFormer network. It constructs a semantic segmentation dataset of chip surface defect images; improves the SegFormer semantic segmentation network by replacing the self-attention of the Transformer Block in the encoder with Cross-Covariance Attention (CrossCovAttn), changing the decoder to a U-shaped structure, and adding an AFF dynamic feature fusion module; trains an improved SegFormer semantic segmentation model; adjusts the model training parameters to obtain an optimized model; selects the best-performing improved SegFormer semantic segmentation model to perform semantic segmentation on chip surface defect images, obtaining semantic segmentation result images. This invention enhances the ability to handle defects of different types and scales, optimizes the SegFormer network segmentation effect, and improves the segmentation accuracy of defects of different types and scales.
Owner:XIDIAN UNIV

Multi-Network Mode In A Container Orchestration System

Techniques for a container orchestration system are disclosed. A system executes a virtual agent in a cloud network on a virtual node of a container orchestration system. The virtual node hosts multiple container instances within the cloud environment. The system executes a first container instance within the virtual node and connects the first container instance to a first subnet. The system executes a second container instance within the same virtual node and connects the second container instance to a second subnet distinct from the first subnet. The system enables access to the first container instance through the first subnet and enables access to the second container instance via the second subnet. This architecture allows for flexible network configurations within a single virtual node, enhancing resource utilization and network segmentation capabilities in containerized environments.
Owner:ORACLE INT CORP

Multi-factor network segmentation

Implementation(s) for multi-factor network segmentation are described. A plurality of packets at a higher layer of a network stack is processed, where at least one packet of the plurality of packets was previously determined, as part of processing the at least one packet at lower layers of the network stack, to be authorized to be processed by the higher layer. Specifically, responsive to successful authentication of a cryptographic certificate received during the handshake process, a second service is identified from the cryptographic certificate. It is determined, based on a security policy, that the second service is authorized to access the first service. Responsive to the determination, a configuration is caused such that packets sent using the source address are now authorized to be processed by the higher layer.
Owner:SALESFORCE INC

Network segmentation in multi-site computer networks

This disclosure describes techniques for enabling multiple subnets across multiple fabric sites and associated with multiple network segments (e.g., virtual networks (VNs)) to communicate with each other using a shared network infrastructure, such as a service provider network. In some cases, the techniques described herein include using a common transit VN (e.g., a common transit VN with or without a common firewall) in the shared network infrastructure as well as border devices that enable switching traffic between the common transit VNs and segment VNs (e.g., subscriber VNs) for data transmission to and / or from the common transit VN. In some cases, a border device maintains two types of mapping entries (e.g., map-caches): transit mapping entries and local mapping entries. A transit and a local mapping entry may be configured to represent (e.g., installed to program) forwarding information for packets received on a transit VN and on a segment VN, respectively.
Owner:CISCO TECHNOLOGY INC

Network cutover control method and device, electronic equipment and medium

The invention provides a network cutover control method and device, electronic equipment and a medium, and relates to the technical field of network security. The network cutover control method comprises the following steps: in response to a cutover command issued by a network administrator, verifying the cutover command according to a historical cutover command to obtain a first cutover command; based on the context of the first cutover command and a preset command template, generating a target command set through a large language model; and predicting target execution time of the target cutover command in the target command set, and controlling the target cutover command to run at the target execution time. Through the technical scheme provided by the invention, the problems of high security risk, low flexibility and low efficiency of network cutover in related technologies are solved, and the security, flexibility and efficiency of network cutover are improved.
Owner:CHINA MOBILE COMM CORP TIANJIN +1

An image segmentation method introducing spatial information and attention mechanism

The application relates to an image segmentation method introducing spatial information and an attention mechanism and belongs to the image segmentation field. Specifically, the method comprises the following steps: S1, a data preparation stage: preprocessing a brain medical image and cutting out an image block from the preprocessed image; S2, a feature coding stage: extracting image features through pre-activated 3D convolution; and S3, a feature decoding stage: restoring the size of an original image through deconvolution and an attention mechanism with position coding, so that the image segmentation process is completed. The application pays attention to spatial information through the attention mechanism, and the network segmentation performance is improved.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

A high-performance multi-party secure computing training method and system based on GPU

The application relates to a GPU-based high-performance multi-party secure computation training method and system, and particularly relates to the field of multi-party secure computation protocols.The application aims to provide a multi-party secure computation training framework with higher parallelism, so as to realize parallelism between different layers of a neural network in a manner of combining data parallelism and model parallelism, and improve the data throughput speed of a training process.The method is a multi-party secure computation training system based on a pipeline flow training method, as shown in Figure 1, the method is designed according to the characteristics that the bottlenecks of linear computation network layers and nonlinear computation network layers in the MPC model training process are calculation and communication respectively, a pipeline flow training method is designed, parallelism between sub-networks is realized, and an optimal sub-network segmentation algorithm is realized to balance the training load between each sub-network.The application provides a multi-party secure computation training framework with higher parallelism, parallelism between different layers of a neural network is realized in a manner of combining data parallelism and model parallelism, and the data throughput speed of a training process is greatly improved.
Owner:HARBIN INST OF TECH

Bladder tumor image segmentation method and system based on febe-net

This invention discloses a bladder tumor image segmentation method and system based on FEBE-Net, applied in the field of image processing technology. The invention employs a PVTv2 encoder to learn multi-scale feature representations to adapt to variations in bladder tumor size and shape. Secondly, a feature exploration attention module is proposed to fully mine potential local details in the shallow features extracted by the PVTv2 encoder and eliminate noise, supplementing missing fine-grained details for the decoding stage and improving network segmentation performance. Simultaneously, a boundary enhancement and refinement (BER) module is proposed, which uses a boundary detection operator to additionally learn the boundaries of the bladder tumor to enhance the boundary regions in the input features of the decoder and refine the final predicted feature map. Finally, an efficient self-attention calibration decoder module is proposed, which, with the help of boundary cues provided by the BER module, gradually and effectively recovers global contextual information and local detail information from high-level and low-level features.
Owner:ANHUI UNIV

A pipe network segmentation method based on node splitting algorithm

This invention provides a pipeline network segmentation method based on a node explosion algorithm, comprising: constructing an original pipeline network topology; node explosion: breaking the original pipeline network topology at designated segmentation nodes and deleting the designated segmentation nodes to obtain multiple subgraph topologies; node interpolation: in each subgraph topology, constructing edges between the designated segmentation nodes and their neighboring nodes, and re-inserting the designated segmentation nodes into each subgraph topology; and correcting the flow direction of all subgraph topologies after node interpolation. This invention solves the technical problem that the traditional DFS traversal segmentation method suffers from differences in segmentation results due to the different root node input order, and improves the efficiency of topology segmentation and the accuracy of simulation calculations.
Owner:SHANGHAI THREE ZERO FOUR ZERO TECH CO LTD

A point cloud semantic segmentation method based on feature fusion and attention mechanism

The application discloses a point cloud semantic segmentation method based on feature fusion and attention mechanism, wherein a local feature fusion module, a multi-layer attention pool module and a jump connection are stacked together to form a residual module as an encoding module in an encoder-decoder structure; a nearest neighbor interpolation method is used as a feature propagation method in a decoder; and when the number of point clouds is restored to the original number, a semantic label is assigned to each point cloud through a full connection layer. The network of the application can achieve competitive results in the average intersection over union (mIoU), and the network segmentation accuracy is improved by 23% than PoinNet, 5.2% than PointCNN and 4.3% than ELGS in the evaluation of the average intersection over union.
Owner:HEBEI UNIV OF TECH

A multi-scale intestinal polyp segmentation method fusing attention mechanism

The application discloses a multi-scale intestinal polyp segmentation method fusing an attention mechanism. The basic features of the method are as follows: 1. a multi-scale effective semantic fusion module is constructed to extract more abundant and effective multi-scale semantic information; 2. a new encoding-decoding deep network segmentation model is constructed to improve polyp segmentation accuracy; the method extracts sufficient context information and global information under different receptive fields, and filters out as many features useless for the segmentation task as possible, overcomes the defects that semantic information is limited and a large amount of redundancy exists in the traditional encoding-decoding structure, and has excellent segmentation and generalization performance for two-dimensional enteroscopy images with polyp regions of different shapes and different sizes.
Owner:NANJING UNIV OF SCI & TECH