Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

54 results about "Policy decision" patented technology

Policy Decisions is a modern, core platform that supports the full policy lifecycle for highly automated or heavily underwritten products on one platform, serving all user types for all distribution channels. Functionality.

Large model dynamic protection method and system based on zero-trust architecture

The invention provides a large model dynamic protection method and system based on a zero-trust architecture. The method comprises the steps that a security proxy gateway receives an access request; authenticating an initiating main body of the access request, collecting context information and transmitting the context information to a strategy decision point; the strategy decision point calculates a trust score in real time based on a dynamic trust evaluation model and performs real-time evaluation in combination with an access control strategy to generate a dynamic authorization judgment result; if the access is allowed, forwarding the access request to a large language model server, and performing input security filtering; the large language model server generates response content and performs output security filtering; and returning the final response subjected to the output security filtering to the initiating main body through the security proxy gateway. According to the method, a multi-layer protection framework is constructed, a dynamic trust evaluation model is introduced, and a content filtering layer is deployed, so that continuous permission verification, risk adaptive control and full-link content security protection are realized, and the service security of a large model is effectively guaranteed.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

Zero-trust cybersecurity access control system using continuous identity verification

A system for zero-trust cybersecurity access control using continuous identity verification (100), comprising: a Policy Decision and Enforcement Orchestrator (1) configured to receive an access request from a user device and enforce a session with minimal privileges; an engine for continuous identity verification (2) configured to generate a time-dependent identity trust score by continuously verifying the user identity during an active session; a device state and telemetry collector (3) configured to acquire device state parameters, runtime signals and network telemetry and to generate a state value; a module for detecting behavioral risks and anomalies (4) that is configured to create behavioral profiles and detect anomalies based on user activity patterns, contextual signals and the history of resource access; a cryptographic authentication and secure token module (5) configured to issue and update a short-lived, bound access token associated with at least the identity trust value and the state value; and an adaptive response and microsegmentation module (6) configured to dynamically adjust access permissions, network segmentation and session privileges in real time, based on an aggregated risk assessment derived from modules (2) to (4), where the system (100) continuously reassesses trustworthiness during the session and selectively allows, restricts, requires enhanced authentication or terminates the session based on the aggregated risk assessment.
Owner:SIVASHANMUGAM SATHESH PADMANABAN GLENDALE

Method and apparatus for selecting edge application server, and network element device, user equipment and storage medium

The present disclosure relates to method and apparatus for selecting an edge application server, and element network device, user equipment and storage medium. The method includes: a user equipment receiving first indication information, which is sent by an SMF, wherein the first indication information is used for indicating the priority of domain name system (DNS) information; and the user equipment making a DNS policy decision according to the first indication information, and sending a DNS query request to an EASDF, wherein the DNS query request is used by the EASDF to execute the discovery or selection of an edge application server (EAS).
Owner:BEIJING XIAOMI MOBILE SOFTWARE CO LTD

System for secure MCP-mediated tool use by AI agents and generative AI / LLM services in cloud-native distributed applications

A system (100) for the secure MCP-mediated use of tools by AI agents and generative AI / LLM services in cloud-native distributed applications, wherein the system (100) comprises: a KL agent interface (1) configured to receive natural language commands and application events from a variety of client applications and to generate appropriate tool call commands for one or more generative KL or Large Language Model (LLM) services; an MCP mediator service (2) that is configured to: (a) to convert the tool request requests into messages compatible with a model context protocol (MCP); and (b) to maintain the conversation context, including at least one of the following: user identity, tenant identity and application identity; a tool register (3) that stores a plurality of tool descriptions, each tool description defining at least a tool identifier, an input and output scheme, an endpoint location and allowed functions, wherein the tool register (3) is accessible to the MCP mediator service (2); a policy and security manager (4) configured to evaluate each MCP tool call against one or more security and access policies based on the conversation context and the corresponding tool description, and to issue a decision to allow, modify or block the tool call; a tool connector layer (5) comprising a plurality of tool adapters, each tool adapter being configured to communicate securely with a corresponding external tool, service or data source using credentials and permissions restricted according to the decision of the policy and security manager (4); an observation and audit manager (6) configured to record, for each tool call, at least a timestamp, the calling KL agent, the tool identifier, the policy decision, and a summary of the tool response, and to provide audit logs and metrics for monitoring and compliance purposes; and a cloud-native deployment controller (7) configured to provide the MCP mediator service (2), policy and security manager (4), tool connector layer (5) and observation and audit manager (6) as distributed microservices with network isolation between tenants in a cloud-native environment.
Owner:BHANDARWAR NILESH DNYANESHWAR REDMOND

Dynamic network access control system under zero-trust architecture

The invention discloses a dynamic network access control system under a zero-trust architecture, which relates to the technical field of network security, and comprises a multi-dimensional trust evaluation module, a self-adaptive micro-segmentation engine, a strategy decision execution module and a risk perception feedback module, the multi-dimensional trust evaluation module calculates a comprehensive trust score based on five-dimensional features of identity, equipment, network, application and data; the self-adaptive micro-segmentation engine dynamically generates network micro-segments based on a graph diffusion algorithm; the strategy decision execution module adopts deep reinforcement learning to generate an access decision; the risk perception feedback module identifies abnormity based on the LSTM network and adjusts trust parameters through closed-loop feedback, the four modules are deeply coupled and cooperated, refined dynamic access control is realized, the occurrence rate of security events is reduced by more than 85%, and an innovative solution is provided for enterprise network security.
Owner:INFORMATION CENT OF YELLOW RIVER WATER RESOURCES COMMISSION

Communication Method and Communication Apparatus

A communication method includes a first network element that obtains first information and second information, where the first information is from a second network element and includes subscription information and / or policy information of a first service, the second information is from a third network element and indicates that the first service supports being managed by the first network element, and the third network element is a home data storage network element of the terminal device. The first network element determines a policy decision result based on the first information and the second information, where the policy decision result is used by the terminal device to access the first service in a first region. The first network element and the second network element are network elements at a subscription location in which the terminal device subscribes to the first service.
Owner:HUAWEI TECH CO LTD

Blockchain-based pedigree data dynamic permission access control system and method

ActiveCN120074872BData graphData access
The application discloses a kind of based on blockchain's pedigree data dynamic permission access control system and method, rely on attribute-based access control paradigm, and combine pedigree data access constraint to carry out dynamic access control.First, user sends access request to policy decision point;Decision point according to the policy loaded from policy management point, request relevant information to blockchain, and call user historical behavior verification module based on pedigree data, the legality of current access request is verified using dependency relationship and pedigree data graph.System administrator records access request and verification result to blockchain, to support the fast verification of same query, reduce query overhead.In addition, the system passes access information such as query user, time, result, operation content to management node, for subsequent user access tracking and management.The method uses the anonymity and non-tamperability of blockchain, provides strong evidence for user supervision, realizes efficient management and reasoning to source information.
Owner:WUHAN UNIV

Adaptable telemetry orchestration in zero-trust computing environments

Systems and methods provide adaptive collection of telemetry. A telemetry orchestrator of a IHS (Information Handling System) collects telemetry related to a session used by the IHS to access a protected resource of a zero-trust environment, where the telemetry is collected based on a telemetry definition received from a policy decision point of the zero-trust environment. The telemetry orchestrator of the IHS monitors for updates to the telemetry definition, where the updates are generated by the policy decision point of the zero-trust environment. The telemetry orchestrator adjusts measurements by one or more of the sensors of the IHS based on updates to the telemetry definition received from the policy decision point. Telemetry that is generated based on the adjusted measurements is transmitted by the telemetry orchestrator to one or more destinations specified in the update telemetry definition.
Owner:DELL PROD LP

Apparatuses and communication methods using UE information

A communication method using member user equipment (UE) information includes subscribing or unsubscribing, by a first network function (NF), a member UE selection information at a second NF or a third NF, receiving, by the first NF, a notification association with the member UE selection information from the second NF or the third NF, and making, by the first NF, a policy decision based on the notification association with the member UE selection information.
Owner:GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD

Software defined remote access for zero-trust support

ActiveUS12676894B2Policy decisionData access
Various embodiments of the teachings herein include an automated method for data access to a device by an external client, allowing the device to communicate with an internal communication network while the external client communicates with an external communication network. An example method includes: sending a communication access request from the external client for the device to a software implemented application access point; configuring a corresponding software implemented connector using the application access point, so the connector acts as an endpoint for a communication tunnel to the device; configuring a corresponding software implemented policy decision point using the application access point as an interface to the external network for arriving of application data traffic of the external client, so the policy decision point is set up to validate, accept, and forward the access request of the external client to the connector; and accessing the device via the communication tunnel.
Owner:SIEMENS AG

Policy and traffic management in an overlay network

Technique or mechanism in which network security policies are applied close to the source or origin associated with policy decisions. For example. the disclosed technology moves dropped flows from a firewall cluster to a leaf switch based on host location.
Owner:GOOGLE LLC

Updating shader scheduling policy at runtime

Systems, apparatuses, and methods for updating and optimizing task scheduling policies are disclosed. A new policy is obtained and updated at runtime by a client based on a server analyzing a wide spectrum of telemetry data on a relatively long time scale. Instead of only looking at the telemetry data from the client's execution of tasks for the previous frame, the server analyzes the execution times of tasks for multiple previous frames so as to determine a more optimal policy for subsequent frames. This mechanism enables making a more informed task scheduling policy decision as well as customizing the policy per application, game, and user without requiring a driver update. Also, this mechanism facilitates improved load balancing across the various processing engines, each of which has their own task queues. The improved load balancing is achieved by analyzing the telemetry data including resource utilization statistics for the different processing engines.
Owner:ADVANCED MICRO DEVICES INC +1

Adaptable telemetry in zero-trust computing environments

Systems and methods provided adaptive collection of telemetry. A policy decision point of a zero-trust computing environment receives an indication of a change in risk posture within the environment. The policy decision point identifies a telemetry definition specifying telemetry being collected by one or more IHSs that are currently accessing a protected resource of the zero-trust computing environment. The telemetry definition is updated to specify adjusted telemetry to be collected by an IHS that is currently accessing the protected resource and the updated telemetry definition is transmitted to the IHS. Based on the updated telemetry definition received from the policy decision point, the IHS adjust measurements by one or more of the sensors of the IHS. Telemetry generated based on the adjusted measurements is transmitted by the IHS to one or more destinations specified in the updated telemetry definition.
Owner:DELL PROD LP

Information processing method and device based on model transmission state analysis

The application provides an information processing method and device based on model transmission state analysis. The method comprises the following steps: sending a first message to a network data analysis function (NWDAF), wherein the first message is used for requesting to subscribe to analysis information of an artificial intelligence / machine learning (AI / ML) model transmission state in a network; receiving the analysis information sent by the NWDAF; and performing information processing on the AI / ML model transmission according to the analysis information. The information processing based on the AI / ML model transmission can be effectively realized, and then the charging negotiation, charging statistics, policy decision or session management and the like of the AI / ML model transmission can be realized.
Owner:DATANG MOBILE COMM EQUIP CO LTD

Device and method for realizing bare metal console with endogenous safety capability

The invention relates to the technical field of cloud computing security, in particular to a bare metal console implementation device and method with endogenous security capability, and the device comprises a user side agent module which is used for receiving a bare metal VNC console access request initiated by a user and distributing the request to three heterogeneous service agent nodes; operating systems and CPU (Central Processing Unit) frameworks of the three service agent nodes are different from one another, and service agent components corresponding to different bare metal VNC console access modes are respectively deployed on the nodes; the feedback control module is used for collecting running state data of the service agent node, generating judgment parameters and sending the judgment parameters to the strategy judgment module, and is used for executing release or link reset operation according to a judgment result of the strategy judgment module; and the strategy judgment module is used for carrying out consistency judgment on output results of the three service agent nodes based on the judgment parameters and feeding back a judgment result to the feedback control module. According to the invention, high security and high availability of bare metal VNC console access are realized.
Owner:SONGSHAN LAB

Partial policy evaluation

Some embodiments provide a method for evaluating a policy for authorizing an API (Application Programming Interface) call to an application. Based on a first set of parameters available before receiving the API call, the method evaluates only a portion of the policy to produce a partially evaluated policy. The method stores the partially evaluated policy in a cache. The method then receives an API call to authorize, and determines whether the API call should be authorized by fully evaluating the policy, using the partially evaluated policy retrieved from the cache first storage, and a second set of parameters associated with the API call. The method responds to the API call with a policy decision based on the fully evaluated authorization policy.
Owner:APPLE INC

System and method for query management and education

A cloud-based, query management and education system enables provider organizations to query and educate clinicians on how to clarify clinical documentation, resulting in more accurate reimbursement, public reporting, research and policy decisions. Query authors create compliant queries from stored templates which may be supplemented by attaching and / or annotating selected documentation from the patient record. Clinician responses to such queries automatically generate addenda in the relevant patient record. All events around a query are tracked and reportable through a graphical performance scorecards and reporting dashboards.
Owner:ARTIFACT HEALTH INC

System for Blueprinted Platform Engineering using Terraform modules on Kubernetes / Openshift with CI / CD

A system (100) for blueprint-driven platform development that delivers and manages cloud-native application platforms using Infrastructure-as-Code, comprising: a blueprint compiler (1) configured to receive a blueprint describing platform functions as typed, versioned components with parameter contracts and to compile the blueprint into a normalized, acyclic dependency graph of Terraform modules (M); a module registry (2) that stores signed, provenance-tracked versions of the Terraform modules (M) together with compatibility metadata for Kubernetes / OpenShift clusters (K); a policy and compliance engine (3) that enforces pre- and post-processing restrictions defined in the blueprint as machine-verifiable policies, including approval, topology, data sovereignty and cost limits; an Environment Orchestrator (4) that translates the compiled dependency graph into coordinated execution plans for the modules (M), applies the plans to the target clusters (K), and outputs Kubernetes Custom Resources to show deployed functions; a CI / CD pipeline controller (8) integrated into the Environment Orchestrator (4) to create, sign, authenticate and incrementally deploy module and workload artifacts according to staggered promotion rules; a drift detection and adjustment engine (5) that continuously monitors the live cluster status and the terraform status to detect status deviations and generate minimally invasive correction plans taking the dependency graph into account; and a provenance register (7) that immutably records blueprint versions, module digests, attestation statements, policy decisions, execution plans and runtime records, thus enabling the verification and reproducible re-creation of each platform version.
Owner:AHUJA DHARMENDRA KATY

A method for solving a capacitated vehicle routing problem based on time series encoding and attention mechanism

The application discloses a kind of capacity limited vehicle path problem solving method based on timing coding and attention mechanism, first construct the initial feasible solution satisfying constraint condition, and current solution is expressed as containing node level, journey level and solution level hierarchical feature structure;By timing modeling to node sequence in journey and aggregation, journey level feature is obtained, and then the feature set of multiple journeys is modeled by attention, to generate solution embedding vector representing the overall structure of solution;The solution embedding vector is fused with environmental state features and input into the policy decision network, and the selection result of local optimization operator is output, and the solution is iteratively updated according to the selection result until the termination condition is met.The application can enhance the modeling capability of node order change and inter-journey correlation, and improve the stability and generalization performance of the algorithm under different scales.
Owner:NORTHWEST UNIV

Control apparatus and control method

A control apparatus is provided in a vehicle system logically divided into a plurality of partitions. The control apparatus includes: a semantic kernel (SK) that controls, based on a static policy, communication access between two partitions 64 among a plurality of partitions; a policy decision point (PDP) that controls the communication access between the two partitions based on a dynamic policy, and a policy enforcement point (PEP) that controls the communication access between the two partitions based on the control result of the PDP. When a predetermined condition is satisfied, the PEP forces the SK to use the dynamic policy instead of a part of the static policy.
Owner:PANASONIC AUTOMOTIVE SYST CO LTD

Policy decision support device, policy decision support method, and policy decision support program

This invention provides a policy decision support device, a policy decision support method, and a policy decision support program that can identify important factors when deciding on policies. [Solution] The system includes a derivation unit that derives a policy implementation plan based on the future trends of policy parameters predicted by applying preconditions, and an identification unit that identifies factors that satisfy the commonality criterion among multiple different preconditions from which the derivation unit has derived a policy implementation plan that satisfies the same or similar criteria as common factors within the group.
Owner:NEC CORP

Method and system for dynamic user application control service

A method, network device, system, and non-transitory computer-readable storage medium are described in relation to an dynamic user application control service that includes receiving from an application device, a request for access controls associated with a user application and an end device; generating, per the request, policies pertaining to the access controls, wherein the policies include time-based rules, location-based rules, or application type-based rules; obtaining a current location of the end device; comparing, by the network device, a current time with the time-based rules, the current location with the location-based rules, or an application type for the user application with the application-type rules; generating, per the comparing, a policy decision among the policies pertaining to the access controls; and applying, per the policy decision, the time-based rules, the location-based rules, and the application type-based rules for establishment of an application session with the end device.
Owner:VERIZON PATENT & LICENSING INC

Secure telemetry in a zero-trust computing environment

Systems and methods that operate an Information Handling System (IHS) support secure telemetry for use in a zero-trust environment. Upon being initialized, the IHS retrieves a factory-provisioned resource locator of a service that provides the location of a policy decision point of the zero-trust environment. The IHS establishes an encrypted session with the policy decision point that is located using the factory-provisioned resource locator. Via the encrypted session, the IHS receives a symmetric key from the policy decision point, where the key may be fleet-wide key for encryption of a customer's telemetry. Telemetry that is generated by the sensors is identified when ready for transmission and encrypted using the symmetric key received from the policy decision point. The customer's encrypted telemetry can then be securely transmitted.
Owner:DELL PROD LP

Customer-secured telemetry in a zero-trust computing environment

Systems and methods that operate an Information Handling System (IHS) support secure telemetry for use in a zero-trust environment. Upon being initialized, the IHS retrieves a factory-provisioned locator of a service that provides the IHS with a network location of a policy decision point of the zero-trust environment and that provides an encryption key. The IHS identifies telemetry generated by the sensors that is ready for transmission. The IHS transmits the telemetry to a policy information point of the zero-trust environment, where the telemetry includes the factory-provisioned encryption key and also includes the provided network location of the policy decision point. The policy information point uses the network location included in the telemetry and the factory-provisioned encryption key included in the telemetry to establish an encrypted session with the policy decision point. Via the encrypted session, the telemetry is transmitted to the policy decision point.
Owner:DELL PROD LP

Policy optimization method and system, policy control function network element and user equipment

The invention relates to a policy optimization method and system, a policy control function network element and user equipment. The policy optimization method is executed by a policy control function network element, and the policy optimization method comprises the following steps: acquiring event information from a charging function network element, the event information being energy-saving related information; and performing strategy control according to the event information. According to the invention, when the PCF makes the AM / UE / SM policy decision, the energy consumption or energy efficiency information can be used as a consideration factor for making policy adjustment.
Owner:CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1

A method and system for trusted access control compatible with XACML standard

ActiveCN117061163BXACMLPolicy enforcement
The application discloses a kind of compatible XACML standard's trusted access control method and system, belong to access control technical field, the trusted access control method conforms to the XACML standard popular in industry, adopts the policy decision point of decentralization realized by block chain technology, eliminates the mutual distrust between different organizations, guarantee the trusted of access request verification result, to realize the trusted access across organization;With the access control function conforms to the XACML standard popular in industry, the specific implementation can reuse XACML policy decision point, policy enforcement point related open source code, and the deployment access control function is low in cost;Block chain is based on the read-write separation characteristics of XACML policy decision point, with low redundancy parallel execution request verification task, make full use of the computing capacity of block chain node, reduce the request verification overhead, improve the block chain throughput.
Owner:HUAZHONG UNIV OF SCI & TECH