Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

14 results about "Password policy" patented technology

A password policy is a set of rules designed to enhance computer security by encouraging users to employ strong passwords and use them properly. A password policy is often part of an organization's official regulations and may be taught as part of security awareness training. Either the password policy is merely advisory, or the computer systems force users to comply with it. Some governments have national authentication frameworks that define requirements for user authentication to government services, including requirements for passwords.

AI-driven transport layer security protocol adaptive optimization system

The invention discloses an AI-driven transport layer security protocol adaptive optimization system, which relates to the technical field of traffic data access and comprises a data access module, a state sensing module, a risk assessment module, an optimization transmission module and an adaptive encryption module. The data access module is used for capturing an original data flow from a network and a host in real time; the state sensing module is used for receiving the original data stream and setting a feature engineering state index; the risk assessment module is used for quantitatively assessing the safety score of the current state according to the current traffic environment state; the self-adaptive encryption module is used for constructing a password strategy library and generating an encryption configuration strategy according to a current traffic state; and the optimization transmission module is used for constructing a parameter intelligent optimization model and controlling algorithm interaction to generate performance scheduling optimization actions.
Owner:BEIJING XINDA WANGAN INFORMATION TECH CO LTD

Password security management method applied to industrial security

The invention particularly relates to a password security management method applied to industrial security, which relates to the technical field of industrial control system security, and comprises the following steps of: deploying password strategies in batches in an arranged controlled simulation environment, triggering test case execution according to priorities, and monitoring system response data to obtain a test result; wherein in the test case execution process, whether the obtained execution success rate is correct or not needs to be judged through the verification error coefficient obtained through analysis. According to the invention, an isolation simulation test platform highly consistent with a real production environment is established, an HMI / operator station, a PLC / DCS controller and an industrial network structure are accurately duplicated in combination with a digital twinning technology, and a test process and the production environment are completely isolated; serious consequences, such as automatic process interruption and production line stop, possibly caused by password strategy change testing are avoided from the source.
Owner:TAIRUI (BEIJING) TECH SERVICE CO LTD

Password strategy updating method, device and system, electronic equipment and storage medium

PendingCN121125231AKey distribution for secure communicationPassword policyPassword
The invention discloses a password policy updating method, device and system, electronic equipment and a storage medium, and relates to the technical field of network security, the method comprises the following steps: in response to a received target password policy message, updating a first local password suite library based on a target password policy to obtain an updated first local password suite library; wherein the target password strategy message comprises newly added, modified or forbidden password suite information; starting a new service process based on the updated first local cipher suite library; and sending the update message containing the target password policy to the client, thereby realizing flexible adjustment and instant effectiveness of the target password policy, avoiding terminating an old service process, restarting a system or disconnecting original connection communication, avoiding service data interruption, quickly responding to a security demand, and improving the dynamic instant update capability of the target password policy.
Owner:CHINA MOBILE COMM LTD RES INST +1

Password guessing method based on multi semantic fusion probability context-free grammar

ActiveCN121479754BMathematical modelsSemantic analysisPassword policyPassword
The present application relates to the technical field of information security, and aims at the problems that password guessing based on probabilistic context-free grammar is difficult to identify multi-semantic patterns and the semantic guidance strength is uncontrollable, and proposes a password guessing method based on multi-semantic fusion of probabilistic context-free grammar: enumerating sub-strings in the training password, identifying semantic segments according to simple, date, vocabulary and name patterns and prioritizing disambiguation, dynamically planning segmentation according to the principle of maximum semantic coverage and least semantic segments, setting semantic enhancement parameters β for each semantic pattern during training to weight and normalize the count, and outputting the candidate password dictionary according to the probability priority queue during generation, which is suitable for efficient password guessing in offline password audit, password policy evaluation and penetration testing.
Owner:NANKAI UNIV

Information processing apparatus, information processing method, and information processing system

An information processing apparatus includes a first acquisition unit configured to acquire, from an external apparatus, a state regarding at least one item of a password policy of a password string entered on the external apparatus, and an obfuscated password string, a second acquisition unit configured to acquire a setting, which is made in the information processing apparatus, regarding the at least one item of the password policy, a determination unit configured to determine whether the obfuscated password string satisfies the password policy, based on the acquired state regarding the at least one item of the password policy of the password string, and the acquired setting regarding the at least one item of the password policy, and an update unit configured to update a password based on the obfuscated password string in a case where it is determined that the obfuscated password string satisfies the password policy.
Owner:CANON KK

Method and system for applying cryptography policy

PendingUS20260181021A1Securing communicationPassword policyWorkload
A method for applying a cryptography policy, performed by a computing system. The method may comprise acquiring information on cryptography policies associated with a first workload; determining, using the acquired information, a target cryptography policy to be applied to the first workload, the target cryptography policy including information on a target cryptographic library; and switching an existing cryptographic library applied to the first workload to the target cryptographic library.
Owner:SAMSUNG SDS CO LTD +1

An account security checking system based on RDP protocol

This application relates to the technical field of network and information security, and discloses an account security inspection system based on the RDP protocol. It uses the WinRM protocol as the core remote execution protocol, while also supporting the RDP protocol as an alternative connection method, enabling agentless remote management of Windows hosts. The system employs a multi-dimensional security inspection module covering more than 20 security checks, including password policies, account locking, user permissions, and login auditing. It supports all versions of Windows Server 2008 to 2022 through a cross-distribution compatibility mechanism. It utilizes a dynamic load-aware concurrent inspection engine to process log analysis and embedded account scanning tasks in parallel, and automatically identifies abnormal changes to account information through baseline comparison with integrity protection and a permission change awareness module. This invention requires no software deployment on the target host, is non-intrusive to the production environment, and can efficiently complete account security checks on large-scale Windows assets, significantly improving the account security protection capabilities of enterprise information systems.
Owner:SHANGHAI PEA INFORMATION TECH CO LTD

Cryptographic security management method applied to industrial security

The application is a password security management method applied to industrial safety, and relates to the technical field of industrial control system safety, which comprises: deploying password strategies in batches in a laid controlled simulation environment, triggering test case execution according to priority, monitoring system response data to obtain test results; wherein the execution success rate obtained in the test case execution process needs to be judged whether correct or not by analyzing the verification error coefficient obtained. In the application, an isolated simulation test platform highly consistent with the real production environment is built, the HMI / operator station, PLC / DCS controller and industrial network structure are accurately copied by combining with the digital twin technology, the test process is completely isolated from the production environment, and the serious consequences such as the interruption of the automation process and the shutdown of the production line caused by the password strategy change test are avoided from the root.
Owner:TAIRUI (BEIJING) TECH SERVICE CO LTD

BMC account login management method

PendingCN121887424ASecuring communicationPassword policyPassword
The invention discloses a BMC account login management method. The method comprises the steps of multi-factor authentication integration, password strategy customization, dynamic configuration management and intelligent monitoring and response. According to the invention, by intelligently combining different PAM modules, a multi-level authentication mechanism and enhanced security are realized, centralized management and dynamic update of PAM configuration are realized, management operation is simplified, an intelligent monitoring and response mechanism is introduced, and the automatic security protection capability of the system is improved.
Owner:四川华鲲振宇智能科技有限责任公司

Browser security protection system and method for online banking all-in-one machine equipment

PendingCN121808801AComplete banking machinesDigital data protectionBrowser securityPassword policy
The embodiment of the invention discloses a browser security protection system and method for online banking all-in-one machine equipment. The system comprises a terminal containment layer used for providing a full-screen window, an exclusive instance and hot key shielding; the browser kernel adaptation layer is used for packaging at least two sets of rendering kernels; the network and identity protection layer is used for integrating Wi-Fi vouchers, certificates, dynamic passwords and password strategies and realizing multi-level verification of network access and account management; the system safety hooking layer is used for intercepting unauthorized processes, blocking popup windows and limiting system commands through a process-level hooking and mutual exclusion mechanism; the strategy communication and operation and maintenance layer is used for realizing strategy issuing, state returning and log tracking based on a shared memory and a configuration file; all the parts cooperate with one another, and safety protection of the browser of the online banking all-in-one machine equipment is achieved. The scheme provided by the embodiment of the invention gives consideration to security, service continuity and operation and maintenance efficiency, and has wide popularization and application values.
Owner:SHENZHEN LEAGSOFT TECH

Cryptographic service method, apparatus, device, medium, and product

ActiveCN118631512BKey distribution for secure communicationPassword policyPassword
The application provides a password service method, device, equipment, medium and product, and relates to the technical field of network security. The method comprises the following steps: receiving, by a first security node, an operation request sent by a second security node of a first password service platform; obtaining a sensitive level of first data, a request type of the operation request, at least one security node with access authority of password information, and risk data of the second security node; performing trust evaluation on the second security node according to the risk data to obtain a trust degree; generating a dynamic password policy corresponding to the trust degree, the sensitive level and the request type; in the case that the at least one security node includes the second security node, performing an operation on the first data by using the password information according to the dynamic password policy to obtain second data of the operation; and sending the second data to the second security node by the first security node. The above steps can improve the security of password information in the password service process.
Owner:CHINA CONSTRUCTION BANK +1

Password strategy self-adaptive arrangement method, system, equipment and medium

ActiveCN121750229AMultiple keys/algorithms usagePassword policyPassword
The invention provides a password strategy self-adaptive arrangement method, system and device and a medium, and the method comprises the steps: evaluating a service state according to a collected system architecture, a service interaction path, service interaction information and interaction node information; matching a corresponding baseline password strategy according to the service type; based on a service state and a baseline password strategy, solving an optimal password primitive combination sequence as a final password strategy under the constraint of a planning budget; according to the method, dynamic perception of the composite security target is realized by comprehensively analyzing the service state, and the optimal password primitive combination sequence is solved under the constraint of the planning budget based on the service state and the baseline password strategy to serve as the final password strategy, so that password strategy self-adaptive arrangement is realized; while the encryption protection strength in the business data interaction process is improved, irrelevant resource overhead and related economic investment brought by protection operation are reduced as much as possible, and the method has a good application prospect.
Owner:CHINA ELECTRIC POWER RESEARCH INSTITUTE CO LTD

Password guessing method of probability context-independent grammar based on multi-semantic fusion

ActiveCN121479754AMathematical modelsSemantic analysisPassword policyPassword
The invention relates to the technical field of information security, and provides a password guessing method of a probability context-independent grammar based on multi-semantic fusion aiming at the problems that the password guessing of the probability context-independent grammar is difficult to specifically recognize a multi-semantic mode and the semantic guidance intensity is uncontrollable. Semantic segments are recognized according to simple, date, vocabulary and name modes and subjected to priority disambiguation, segmentation is dynamically planned according to the segmentation principle of maximum semantic coverage and minimum semantic segments, a semantic enhancement parameter beta is set for each semantic mode during training to perform weighted normalization on counting, and a candidate password dictionary is output according to a probability priority queue during generation. The method is suitable for efficient password guessing in offline password auditing, password strategy evaluation and penetration testing.
Owner:NANKAI UNIV

Ai-driven transport layer security protocol adaptive optimization system

This invention discloses an AI-driven adaptive optimization system for transport layer security protocols, relating to the field of traffic data access technology. It includes a data access module, a state awareness module, a risk assessment module, an optimized transmission module, and an adaptive encryption module. The data access module is used to capture raw data streams from the network and hosts in real time. The state awareness module is used to receive the raw data streams and set feature-engineered state indicators. The risk assessment module is used to quantitatively assess the current state security score based on the current traffic environment state. The adaptive encryption module is used to construct a cryptographic policy library and generate encryption configuration policies based on the current traffic state. The optimized transmission module is used to construct a parameter intelligent optimization model and control algorithm interaction to generate performance scheduling optimization actions.
Owner:BEIJING XINDA WANGAN INFORMATION TECH CO LTD