Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

82 results about "Policy decision" patented technology

Policy Decisions is a modern, core platform that supports the full policy lifecycle for highly automated or heavily underwritten products on one platform, serving all user types for all distribution channels. Functionality.

Large model dynamic protection method and system based on zero-trust architecture

The invention provides a large model dynamic protection method and system based on a zero-trust architecture. The method comprises the steps that a security proxy gateway receives an access request; authenticating an initiating main body of the access request, collecting context information and transmitting the context information to a strategy decision point; the strategy decision point calculates a trust score in real time based on a dynamic trust evaluation model and performs real-time evaluation in combination with an access control strategy to generate a dynamic authorization judgment result; if the access is allowed, forwarding the access request to a large language model server, and performing input security filtering; the large language model server generates response content and performs output security filtering; and returning the final response subjected to the output security filtering to the initiating main body through the security proxy gateway. According to the method, a multi-layer protection framework is constructed, a dynamic trust evaluation model is introduced, and a content filtering layer is deployed, so that continuous permission verification, risk adaptive control and full-link content security protection are realized, and the service security of a large model is effectively guaranteed.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

Information security model auxiliary decision-making method and system based on intelligent knowledge graph

The invention relates to the technical field of artificial intelligence, and discloses an information security model auxiliary decision-making method and system based on an intelligent knowledge graph, and the method comprises the steps: constructing a multi-modal security data pool of a to-be-decided scene, training a joint extraction model of the to-be-decided scene, and extracting data examples and example relationships of the multi-modal security data pool; constructing a security knowledge graph of the scene to be decided; constructing an attack tactics-technology-process ontology layer of the scene to be decided to calculate a potential attack path of the scene to be decided, and calculating an attack path occurrence probability and an attack influence range of the potential attack path; marking a strategy decision point of the security knowledge graph, and analyzing a Top-K strategy of the strategy decision point by using a preset PPO algorithm; and constructing an attack chain analysis interface of the Top-K policy in the security knowledge graph to generate a policy optimization parameter of the Top-K policy, and executing the information security model aided decision of the scene to be decided based on the policy optimization parameter. According to the invention, the efficiency of security decision-making of to-be-decided scene information can be improved.
Owner:CHINA CYBER SECURITY REVIEW CERTIFICATION AND MARKET SUPERVISION BIG DATA CENT

Zero-trust cybersecurity access control system using continuous identity verification

A system for zero-trust cybersecurity access control using continuous identity verification (100), comprising: a Policy Decision and Enforcement Orchestrator (1) configured to receive an access request from a user device and enforce a session with minimal privileges; an engine for continuous identity verification (2) configured to generate a time-dependent identity trust score by continuously verifying the user identity during an active session; a device state and telemetry collector (3) configured to acquire device state parameters, runtime signals and network telemetry and to generate a state value; a module for detecting behavioral risks and anomalies (4) that is configured to create behavioral profiles and detect anomalies based on user activity patterns, contextual signals and the history of resource access; a cryptographic authentication and secure token module (5) configured to issue and update a short-lived, bound access token associated with at least the identity trust value and the state value; and an adaptive response and microsegmentation module (6) configured to dynamically adjust access permissions, network segmentation and session privileges in real time, based on an aggregated risk assessment derived from modules (2) to (4), where the system (100) continuously reassesses trustworthiness during the session and selectively allows, restricts, requires enhanced authentication or terminates the session based on the aggregated risk assessment.
Owner:SIVASHANMUGAM SATHESH PADMANABAN GLENDALE

Method and apparatus for selecting edge application server, and network element device, user equipment and storage medium

The present disclosure relates to method and apparatus for selecting an edge application server, and element network device, user equipment and storage medium. The method includes: a user equipment receiving first indication information, which is sent by an SMF, wherein the first indication information is used for indicating the priority of domain name system (DNS) information; and the user equipment making a DNS policy decision according to the first indication information, and sending a DNS query request to an EASDF, wherein the DNS query request is used by the EASDF to execute the discovery or selection of an edge application server (EAS).
Owner:BEIJING XIAOMI MOBILE SOFTWARE CO LTD

Vulnerability risk assessment method based on network surveying and mapping

The invention discloses a vulnerability risk assessment method based on network surveying and mapping, and belongs to the technical field of network security, and the assessment method comprises the following specific steps: (1) identifying all devices and services in a network, and drawing a network topological graph to classify and identify risk points and asset distribution in the network; (2) scanning all devices and services in the network, collecting vulnerability data, simulating different attack scenes and vulnerability utilization means, and verifying a scanning result; the method can adapt to different network environments and security requirements, improves the accuracy of vulnerability risk assessment, improves the diversity and refinement degree of vulnerability risk scoring, and enhances the policy decision support of vulnerability repair; transmission of sensitive data is avoided, privacy protection is enhanced, the vulnerability defense capability of the whole system is improved, the requirement for bandwidth and transmission delay are reduced, and the vulnerability response speed and repair efficiency are improved.
Owner:WUZHOU VOCATIONAL COLLEGE

External field equipment trusted access method based on non-addressable stealth gateway

The invention discloses an external field equipment trusted access method based on a non-addressable stealth gateway, which relates to the technical field of network security access, and comprises the following four steps: in a manufacturing period and first access, a certificate authorization machine binds equipment identity and trusted platform module measurement, policy decision point decision, policy execution point implementation and policy subset loading; initiating from the outside of the equipment, establishing an end-to-end trusted channel with the center, and performing inward isolation and transparent bearing on rear-end real services; updating strategies, algorithms and secret keys on line under the control of a unified strategy library; according to the method, the attack surface is reduced, the transformation cost is reduced, non-stop treatment is ensured, the encrypted traffic can be observed and audited, only trusted equipment can reach the center through a trusted channel, and event linkage right descending and certificate state linkage treatment are supported.
Owner:HANGZHOU XENON TECHNOLOGY CO LTD

System for secure MCP-mediated tool use by AI agents and generative AI / LLM services in cloud-native distributed applications

A system (100) for the secure MCP-mediated use of tools by AI agents and generative AI / LLM services in cloud-native distributed applications, wherein the system (100) comprises: a KL agent interface (1) configured to receive natural language commands and application events from a variety of client applications and to generate appropriate tool call commands for one or more generative KL or Large Language Model (LLM) services; an MCP mediator service (2) that is configured to: (a) to convert the tool request requests into messages compatible with a model context protocol (MCP); and (b) to maintain the conversation context, including at least one of the following: user identity, tenant identity and application identity; a tool register (3) that stores a plurality of tool descriptions, each tool description defining at least a tool identifier, an input and output scheme, an endpoint location and allowed functions, wherein the tool register (3) is accessible to the MCP mediator service (2); a policy and security manager (4) configured to evaluate each MCP tool call against one or more security and access policies based on the conversation context and the corresponding tool description, and to issue a decision to allow, modify or block the tool call; a tool connector layer (5) comprising a plurality of tool adapters, each tool adapter being configured to communicate securely with a corresponding external tool, service or data source using credentials and permissions restricted according to the decision of the policy and security manager (4); an observation and audit manager (6) configured to record, for each tool call, at least a timestamp, the calling KL agent, the tool identifier, the policy decision, and a summary of the tool response, and to provide audit logs and metrics for monitoring and compliance purposes; and a cloud-native deployment controller (7) configured to provide the MCP mediator service (2), policy and security manager (4), tool connector layer (5) and observation and audit manager (6) as distributed microservices with network isolation between tenants in a cloud-native environment.
Owner:BHANDARWAR NILESH DNYANESHWAR REDMOND

Dynamic network access control system under zero-trust architecture

The invention discloses a dynamic network access control system under a zero-trust architecture, which relates to the technical field of network security, and comprises a multi-dimensional trust evaluation module, a self-adaptive micro-segmentation engine, a strategy decision execution module and a risk perception feedback module, the multi-dimensional trust evaluation module calculates a comprehensive trust score based on five-dimensional features of identity, equipment, network, application and data; the self-adaptive micro-segmentation engine dynamically generates network micro-segments based on a graph diffusion algorithm; the strategy decision execution module adopts deep reinforcement learning to generate an access decision; the risk perception feedback module identifies abnormity based on the LSTM network and adjusts trust parameters through closed-loop feedback, the four modules are deeply coupled and cooperated, refined dynamic access control is realized, the occurrence rate of security events is reduced by more than 85%, and an innovative solution is provided for enterprise network security.
Owner:INFORMATION CENT OF YELLOW RIVER WATER RESOURCES COMMISSION

Communication Method and Communication Apparatus

A communication method includes a first network element that obtains first information and second information, where the first information is from a second network element and includes subscription information and / or policy information of a first service, the second information is from a third network element and indicates that the first service supports being managed by the first network element, and the third network element is a home data storage network element of the terminal device. The first network element determines a policy decision result based on the first information and the second information, where the policy decision result is used by the terminal device to access the first service in a first region. The first network element and the second network element are network elements at a subscription location in which the terminal device subscribes to the first service.
Owner:HUAWEI TECH CO LTD

Terminal access permission analysis method and system based on zero-trust ABAC model

The application discloses a terminal access permission analysis method and system based on a zero-trust ABAC model, and the method comprises the following steps: a user terminal sends a resource access request; a policy enforcement point (PEP) receives the resource access request sent by the user terminal; according to a preset collection requirement, multi-dimensional attributes are extracted from the user request, the user request is converted into an attribute request, and the attribute request is sent to a policy decision point (PDP); the attributes comprise user attributes, environment attributes, operation attributes and object attributes; the PDP performs access permission analysis by using a policy administration point (PAP) based on the attribute request, obtains an access permission analysis result, and feeds back the access permission analysis result to the PEP; the information fed back by the PDP to the PEP comprises permission, rejection, inapplicability and unknown; and the PEP executes the resource access request according to the feedback information received from the PDP. The application is based on a zero-trust technical framework, and fine management of permissions is realized by ABAC, so that the changing business requirements and security challenges can be effectively coped with.
Owner:ELECTRIC POWER RES INST STATE GRID SHANXI ELECTRIC POWER

Telemetry-initiated mitigations in a zero-trust computing environment

Information Handling Systems (IHSs) support pre-boot telemetry for use in a zero-trust environment. A pre-boot telemetry orchestrator of the IHS retrieves a factory-provisioned resource locator of a service that provides a location of a policy decision point of the zero-trust environment. The pre-boot telemetry orchestrator establishes an encrypted session with the policy decision point that is located using the factory-provisioned resource locator. Via the encrypted session, the pre-boot telemetry orchestrator receives a telemetry definition specifying pre-boot telemetry to be collected by the IHS. The telemetry is collected and transmitted during the pre-boot intervals according to the telemetry definition.
Owner:DELL PROD LP

Blockchain-based pedigree data dynamic permission access control system and method

ActiveCN120074872BData graphData access
The application discloses a kind of based on blockchain's pedigree data dynamic permission access control system and method, rely on attribute-based access control paradigm, and combine pedigree data access constraint to carry out dynamic access control.First, user sends access request to policy decision point;Decision point according to the policy loaded from policy management point, request relevant information to blockchain, and call user historical behavior verification module based on pedigree data, the legality of current access request is verified using dependency relationship and pedigree data graph.System administrator records access request and verification result to blockchain, to support the fast verification of same query, reduce query overhead.In addition, the system passes access information such as query user, time, result, operation content to management node, for subsequent user access tracking and management.The method uses the anonymity and non-tamperability of blockchain, provides strong evidence for user supervision, realizes efficient management and reasoning to source information.
Owner:WUHAN UNIV

System and Method for Authenticating Client Devices Communicating with an Enterprise System

A system and method are provided for authenticating client devices communicating with an enterprise system. The method includes providing a policy enforcement interceptor to intercept API calls and enabling the policy enforcement interceptor to communicate with a policy information point to query the at least one endpoint for entitlements associated with an account. The method also includes intercepting an API call to the application API, communicating with the policy information point to determine entitlements associated with the account by having the policy information point query an entitlements database and, when the entitlements returned to the policy enforcement interceptor are valid, invoking a policy decision point to validate the client device. The method also includes, when the client device is validated, permitting invocation of the API. The method also includes providing an API response to the client device to permit access to the application via the API.
Owner:THE TORONTO DOMINION BANK

Adaptable telemetry orchestration in zero-trust computing environments

Systems and methods provide adaptive collection of telemetry. A telemetry orchestrator of a IHS (Information Handling System) collects telemetry related to a session used by the IHS to access a protected resource of a zero-trust environment, where the telemetry is collected based on a telemetry definition received from a policy decision point of the zero-trust environment. The telemetry orchestrator of the IHS monitors for updates to the telemetry definition, where the updates are generated by the policy decision point of the zero-trust environment. The telemetry orchestrator adjusts measurements by one or more of the sensors of the IHS based on updates to the telemetry definition received from the policy decision point. Telemetry that is generated based on the adjusted measurements is transmitted by the telemetry orchestrator to one or more destinations specified in the update telemetry definition.
Owner:DELL PROD LP

Apparatuses and communication methods using UE information

A communication method using member user equipment (UE) information includes subscribing or unsubscribing, by a first network function (NF), a member UE selection information at a second NF or a third NF, receiving, by the first NF, a notification association with the member UE selection information from the second NF or the third NF, and making, by the first NF, a policy decision based on the notification association with the member UE selection information.
Owner:GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD

Three-side decoupling software-defined wireless ad hoc network and containerization implementation method

The invention discloses a three-side decoupling software-defined wireless ad hoc network and a containerization implementation method, and belongs to the field of wireless ad hoc network communication and network management, and the method comprises the steps: introducing a three-side decoupling hybrid SDN architecture design, and respectively setting a management plane module, a control plane module and a data plane module, the function separation module is used for separating functions of strategy decision, centralized control and data forwarding; a survivability design is introduced, and a main and standby cluster head switching mechanism of a control plane module is set, so that when a main cluster head node is detected to be invalid, a new cluster head node is weighted and elected based on node energy, node position and historical load parameters, and intra-cluster scheduling recovery is completed; according to the method, the link utilization rate and the data transmission performance are improved, and good task adaptability and system toughness are achieved.
Owner:10TH RES INST OF CETC

Software defined remote access for zero-trust support

ActiveUS12676894B2Policy decisionData access
Various embodiments of the teachings herein include an automated method for data access to a device by an external client, allowing the device to communicate with an internal communication network while the external client communicates with an external communication network. An example method includes: sending a communication access request from the external client for the device to a software implemented application access point; configuring a corresponding software implemented connector using the application access point, so the connector acts as an endpoint for a communication tunnel to the device; configuring a corresponding software implemented policy decision point using the application access point as an interface to the external network for arriving of application data traffic of the external client, so the policy decision point is set up to validate, accept, and forward the access request of the external client to the connector; and accessing the device via the communication tunnel.
Owner:SIEMENS AG

Intelligent campus multi-agent zero-trust dynamic access control method and system

PendingCN122661001APolicy decisionEngineering
The application relates to the technical field of information security and access control, and particularly discloses a smart campus multi-agent zero-trust dynamic access control method and system, which comprises the following steps: receiving an access request, collecting identity, terminal, network, resource and behavior information, reconstructing a dynamic access context, generating an identity trust result, a terminal trust result, a behavior deviation state and a resource sensitivity state by multiple agents, forming a comprehensive access risk state by a policy decision agent and outputting an access control result, executing and feeding back execution feedback data by a policy execution node, correcting the risk state according to behavior changes or inconsistent feedback, and triggering a fallback control when an agent outputs an exception. Through context reconstruction, cooperative judgment, feedback correction and fallback control, the application can adjust the access permission according to the changes of the subject, the terminal, the behavior, the resource and the execution state, and reduce the risk of misauthorization of sensitive resources and continuous access of abnormal sessions.
Owner:DONGBEI UNIVERSITY OF FINANCE AND ECONOMICS

Policy and traffic management in an overlay network

Technique or mechanism in which network security policies are applied close to the source or origin associated with policy decisions. For example. the disclosed technology moves dropped flows from a firewall cluster to a leaf switch based on host location.
Owner:GOOGLE LLC

Updating shader scheduling policy at runtime

Systems, apparatuses, and methods for updating and optimizing task scheduling policies are disclosed. A new policy is obtained and updated at runtime by a client based on a server analyzing a wide spectrum of telemetry data on a relatively long time scale. Instead of only looking at the telemetry data from the client's execution of tasks for the previous frame, the server analyzes the execution times of tasks for multiple previous frames so as to determine a more optimal policy for subsequent frames. This mechanism enables making a more informed task scheduling policy decision as well as customizing the policy per application, game, and user without requiring a driver update. Also, this mechanism facilitates improved load balancing across the various processing engines, each of which has their own task queues. The improved load balancing is achieved by analyzing the telemetry data including resource utilization statistics for the different processing engines.
Owner:ADVANCED MICRO DEVICES INC +1

Network energy saving enhancement

Example embodiments of the present disclosure relate to the network energy-saving enhancement. According to example embodiments, a system may include a non-real-time (Non-RT) radio access network intelligent controller (RIC). The Non-RT RIC may be configured to generate an energy-saving policy and provide the energy-saving policy to a near-real-time (Near-RT) RIC. The energy-saving policy is executable by the Near-RT RIC to perform an energy-saving operation, including at least one of: synchronization signal block (SSB) management, system information block 1 (SIB1) management, wake-up signal management, and physical random access channel (PRACH) management. The energy-saving policy may include a parameter associated with an activation criteria, a parameter associated with a user equipment (UE) capability requirement, and a parameter associated with a policy decision.
Owner:RAKUTEN MOBILE INC +1

Adaptable telemetry in zero-trust computing environments

Systems and methods provided adaptive collection of telemetry. A policy decision point of a zero-trust computing environment receives an indication of a change in risk posture within the environment. The policy decision point identifies a telemetry definition specifying telemetry being collected by one or more IHSs that are currently accessing a protected resource of the zero-trust computing environment. The telemetry definition is updated to specify adjusted telemetry to be collected by an IHS that is currently accessing the protected resource and the updated telemetry definition is transmitted to the IHS. Based on the updated telemetry definition received from the policy decision point, the IHS adjust measurements by one or more of the sensors of the IHS. Telemetry generated based on the adjusted measurements is transmitted by the IHS to one or more destinations specified in the updated telemetry definition.
Owner:DELL PROD LP

System and method for risk-aware behavioral policy selection by an autonomous agent

PCT designated stageWO2026024497A1Hand manipulated computer devicesSteering linkagesPolicy decisionControl system
A method for risk-aware policy assessment for an autonomous vehicle can include: collecting information associated with an environment of an ego vehicle; determining a set of policies; determining and assessing a set of risks encounterable (e.g., potentially encountered in the future) by the ego vehicle, and operating the ego vehicle based on the assessed risks. A system implementing the method can include a sensor suite, a computing system, a vehicle control system, and / or any other suitable set of components. In variants, the computing system can implement a multi-policy decision model, a risk model, an element selector, a policy generator, a fallback controller, policies (e.g., made up at least of policy elements, etc.), and / or any other suitable system components.
Owner:MAY MOBILITY INC

Information processing method and device based on model transmission state analysis

The application provides an information processing method and device based on model transmission state analysis. The method comprises the following steps: sending a first message to a network data analysis function (NWDAF), wherein the first message is used for requesting to subscribe to analysis information of an artificial intelligence / machine learning (AI / ML) model transmission state in a network; receiving the analysis information sent by the NWDAF; and performing information processing on the AI / ML model transmission according to the analysis information. The information processing based on the AI / ML model transmission can be effectively realized, and then the charging negotiation, charging statistics, policy decision or session management and the like of the AI / ML model transmission can be realized.
Owner:DATANG MOBILE COMM EQUIP CO LTD

A strategy conflict management method, device and system

The present application relates to the field of communications, and in particular to a policy conflict management method, device, and system. The method is used for a first controller, and includes: receiving first policy information, the first policy information including a first policy configured by the core network for the UE; detecting a policy conflict between the first policy information and the second policy information, the second policy information including a second policy configured by the second controller for the UE, or a first decision result obtained after the first controller makes a policy decision based on the second policy; making a policy decision based on the first policy and the second policy to obtain a second decision result; sending the second decision result to a wireless access network RAN ​​network element, so that the RAN network element executes the second decision result. Therefore, the present application avoids the generation of UE policies with policy conflicts, ensures policy executability, and improves the success rate of policy execution.
Owner:HUAWEI TECH CO LTD

Device and method for realizing bare metal console with endogenous safety capability

The invention relates to the technical field of cloud computing security, in particular to a bare metal console implementation device and method with endogenous security capability, and the device comprises a user side agent module which is used for receiving a bare metal VNC console access request initiated by a user and distributing the request to three heterogeneous service agent nodes; operating systems and CPU (Central Processing Unit) frameworks of the three service agent nodes are different from one another, and service agent components corresponding to different bare metal VNC console access modes are respectively deployed on the nodes; the feedback control module is used for collecting running state data of the service agent node, generating judgment parameters and sending the judgment parameters to the strategy judgment module, and is used for executing release or link reset operation according to a judgment result of the strategy judgment module; and the strategy judgment module is used for carrying out consistency judgment on output results of the three service agent nodes based on the judgment parameters and feeding back a judgment result to the feedback control module. According to the invention, high security and high availability of bare metal VNC console access are realized.
Owner:SONGSHAN LAB

Policy decision-making method and device based on world model

The invention provides a policy decision-making method and device based on a world model. The method comprises the following steps: S10, acquiring situation information in policy interaction; s20, adopting a prediction model network improved based on a Muzero model network to generate implicit vector representation based on the situation information; and S30, determining a decision action based on implicit vector representation selection through a multi-agent tree search algorithm, and outputting the decision action to an agent in strategy interaction. According to the strategy decision-making method and device based on the world model, a multi-agent model algorithm combining a multi-agent reinforcement learning algorithm and MCTS world model planning is adopted for the first time, and compared with the most advanced model-free multi-agent method at present, the search efficiency in a large action space is improved. Experiments prove that compared with an existing multi-agent reinforcement learning algorithm, the method has better sample efficiency on the premise of the same strategy performance.
Owner:INST OF AUTOMATION CHINESE ACAD OF SCI

Partial policy evaluation

Some embodiments provide a method for evaluating a policy for authorizing an API (Application Programming Interface) call to an application. Based on a first set of parameters available before receiving the API call, the method evaluates only a portion of the policy to produce a partially evaluated policy. The method stores the partially evaluated policy in a cache. The method then receives an API call to authorize, and determines whether the API call should be authorized by fully evaluating the policy, using the partially evaluated policy retrieved from the cache first storage, and a second set of parameters associated with the API call. The method responds to the API call with a policy decision based on the fully evaluated authorization policy.
Owner:APPLE INC

Flexible policy decision and quality of service execution

A wireless communication method for policy control functionality is disclosed herein. The method includes determining a flexible quality of service (QoS) profile for a QoS flow and transmitting the flexible QoS profile for the QoS flow to a session management function (SMF), where the flexible QoS profile includes a default set of QoS parameters for the QoS flow and slave QoS information for at least one slave set of QoS parameters for at least one internal flow in the QoS flow.
Owner:ZTE CORP

Communication method and apparatus using UE information

A communication method using member user equipment (UE) information includes: a first network function (NF) subscribes to or unsubscribes to member UE selection information at a second NF or a third NF; the first NF receives a notification associated with the member UE selection information from the second NF or the third NF; and the first NF making a policy decision based on a notification associated with the member UE selection information.
Owner:GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD