Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

117 results about "Policy decision" patented technology

Policy Decisions is a modern, core platform that supports the full policy lifecycle for highly automated or heavily underwritten products on one platform, serving all user types for all distribution channels. Functionality.

Security-linked telemetry in a zero-trust computing environment

Systems and methods support collection of telemetry by an Information Handling System (IHS). A policy decision point of a zero-trust computing environment controls access to protected resources and receives an indication of attack related to the IHS. A telemetry definition is identified that specifies telemetry being collected by the IHS and it is updated to specify a security delay for telemetry related to the indication of attack. The updated telemetry definition is transmitted to the IHS. Upon identifying telemetry that is ready for transmission, the IHS determines whether the telemetry is subject to a security delay specified in the updated telemetry definition. When the telemetry is subject to a security delay, the telemetry that is ready for transmission is queued and transmitted to one or more destinations specified in the updated telemetry definition upon expiration of the security delay.
Owner:DELL PROD LP

Threat-detection telemetry in a zero-trust computing environment

Systems and methods provide collection of telemetry by an Information Handling System (IHS). A policy decision point (PDP) of a zero-trust computing environment controls access to protected resources and receives an indicator of attack related to the IHS. The PDP identifies a telemetry definition specifying telemetry being collected by the IHS and updates the telemetry definition to specify a subsystem telemetry chain for configuring telemetry by hardware subsystems of the IHS that are related to the indicator of attack. The updated telemetry definition is transmitted to the IHS. Upon identifying the subsystem telemetry chain in the updated telemetry definition, the IHS adjusts telemetry generation by one or more of the hardware subsystems of the IHS based on their position in the subsystem telemetry chain.
Owner:DELL PROD LP

Resource-monitoring telemetry in a zero-trust computing environment

Systems and methods provide collection of telemetry by an Information Handling System (IHS). A policy decision point (PDP), of a zero-trust computing environment that controls access to a plurality of protected resources, receives an indication of resource piracy related to hardware components of the IHS. The PDP identifies a telemetry definition specifying telemetry being collected by the IHS and updates the telemetry definition to specify an updated telemetry chain for configuring telemetry collection by the hardware components of the IHS. The updated telemetry definition is transmitted to the IHS. Upon identifying the updated telemetry chain in the telemetry definition received from the PDP, the IHS adjusts telemetry generation by one or more of the hardware components of the IHS based on their position in the telemetry chain.
Owner:DELL PROD LP

CRM-GIS-oriented multi-dimensional right dynamic adaptation method and system

The invention relates to the technical field of permission adaptation, in particular to a CRM-GIS-oriented multi-protection permission dynamic adaptation method and system. The method comprises the following steps: firstly, defining in a CRM-GIS platform and acquiring a multi-dimensional authority attribute related to an access request in real time; based on a preset permission policy rule in the platform, processing an access request by using a policy decision engine; then, based on the current spatio-temporal information and behavior pattern information of the user, an artificial intelligence risk assessment module is utilized to analyze the real-time risk level of the current operation of the user; thirdly, dynamically judging and adjusting a final permission adaptation decision aiming at the access request by integrating the multi-dimensional permission attribute, the permission strategy rule and the risk level; according to the final permission adaptation decision, the CRM-GIS platform compulsorily executes corresponding access control operation, and limits or allows access to data and functions in the platform; according to the invention, the reliability of multi-dimensional right dynamic adaptation can be improved.
Owner:SHAOXING YIDU INFORMATION TECH CO LTD

GNSS anti-interference receiver system based on radio frequency front end-INS combined assistance

The invention provides a GNSS (Global Navigation Satellite System) anti-interference receiver system based on radio frequency front end-INS (Inertial Navigation System) combined assistance, which adopts a dual-core ARM Cortex-A9 and a programmable logic unit for layered decoupling, and realizes real-time receiving and processing of a high-bandwidth data stream, closed-loop control of an interference suppression link and quick response of a navigation path and a strategy decision. All the modules efficiently cooperate through AXI-Lite register mapping, interrupt signals, a shared state buffer area and a timer synchronization mechanism. By controlling bus and state buffer mapping to keep consistency and supporting a module-level independent debugging and system-level soft reset mechanism under hot start, the expandability of subsystem cascade debugging, fault module positioning and online updating is realized. In the aspects of module architecture, data channels and cooperation mechanisms, the structure order, efficient communication and control closed loop are realized, and an embedded multi-module cooperation anti-interference platform which is suitable for a high-interference environment, multi-channel fusion processing and navigation task real-time response is constructed.
Owner:NANJING UNIV OF SCI & TECH

Customer-secured telemetry in a zero-trust computing environment

Systems and methods that operate an Information Handling System (IHS) support secure telemetry for use in a zero-trust environment. Upon being initialized, the IHS retrieves a factory-provisioned locator of a service that provides the IHS with a network location of a policy decision point of the zero-trust environment and that provides an encryption key. The IHS identifies telemetry generated by the sensors that is ready for transmission. The IHS transmits the telemetry to a policy information point of the zero-trust environment, where the telemetry includes the factory-provisioned encryption key and also includes the provided network location of the policy decision point. The policy information point uses the network location included in the telemetry and the factory-provisioned encryption key included in the telemetry to establish an encrypted session with the policy decision point. Via the encrypted session, the telemetry is transmitted to the policy decision point.
Owner:DELL PROD LP

Secure telemetry in a zero-trust computing environment

Systems and methods that operate an Information Handling System (IHS) support secure telemetry for use in a zero-trust environment. Upon being initialized, the IHS retrieves a factory-provisioned resource locator of a service that provides the location of a policy decision point of the zero-trust environment. The IHS establishes an encrypted session with the policy decision point that is located using the factory-provisioned resource locator. Via the encrypted session, the IHS receives a symmetric key from the policy decision point, where the key may be fleet-wide key for encryption of a customer's telemetry. Telemetry that is generated by the sensors is identified when ready for transmission and encrypted using the symmetric key received from the policy decision point. The customer's encrypted telemetry can then be securely transmitted.
Owner:DELL PROD LP

Adaptable telemetry in zero-trust computing environments

Systems and methods provided adaptive collection of telemetry. A policy decision point of a zero-trust computing environment receives an indication of a change in risk posture within the environment. The policy decision point identifies a telemetry definition specifying telemetry being collected by one or more IHSs that are currently accessing a protected resource of the zero-trust computing environment. The telemetry definition is updated to specify adjusted telemetry to be collected by an IHS that is currently accessing the protected resource and the updated telemetry definition is transmitted to the IHS. Based on the updated telemetry definition received from the policy decision point, the IHS adjust measurements by one or more of the sensors of the IHS. Telemetry generated based on the adjusted measurements is transmitted by the IHS to one or more destinations specified in the updated telemetry definition.
Owner:DELL PROD LP

Adaptable telemetry orchestration in zero-trust computing environments

Systems and methods provide adaptive collection of telemetry. A telemetry orchestrator of a IHS (Information Handling System) collects telemetry related to a session used by the IHS to access a protected resource of a zero-trust environment, where the telemetry is collected based on a telemetry definition received from a policy decision point of the zero-trust environment. The telemetry orchestrator of the IHS monitors for updates to the telemetry definition, where the updates are generated by the policy decision point of the zero-trust environment. The telemetry orchestrator adjusts measurements by one or more of the sensors of the IHS based on updates to the telemetry definition received from the policy decision point. Telemetry that is generated based on the adjusted measurements is transmitted by the telemetry orchestrator to one or more destinations specified in the update telemetry definition.
Owner:DELL PROD LP

Validated telemetry in a zero-trust computing environment

Systems and methods support collection of validated telemetry by an Information Handling System (IHS). A policy decision point (PDP) of a zero-trust computing environment controls access to protected resources The PDP identifies a telemetry stream of the IHS to be validated and identifies a telemetry definition specifying telemetry being collected by the IHS. The PDP updates the telemetry definition to specify adjustments to telemetry streams of the IHS to be authenticated and transmits the updated telemetry definition to the IHS. The IHS identifies telemetry that is ready for transmission and, based on the updated telemetry definition received from the policy decision point, generates a digital signature that authenticates the telemetry that is ready for transmission. The authenticated telemetry is transmitted to one or more destinations specified in the updated telemetry definition.
Owner:DELL PROD LP

Intelligent customer life cycle management SCRM system and method

The invention relates to the technical field of customer relationship management, and discloses an intelligent customer life cycle management SCRM system, which comprises a multi-source data acquisition and fusion engine; a dynamic customer portrait modeling engine; a customer life cycle state evaluation engine; a predictive intervention engine; an intelligent strategy decision engine; a task distribution and execution engine; and a feedback closed loop and learning engine. According to the intelligent customer life cycle management SCRM system and method, by setting a multi-modal decision engine, taking a customer state as input, learning an optimal strategy of maximizing a long term value (LTV) through a DQN / PPO algorithm, when a customer is in a high loss risk state, triggering an exclusive retention scheme for the customer, and generating a strategy according to a comprehensive conversion rate, cost and satisfaction target, so that the customer life cycle management is realized. Moreover, the personalized content template can be automatically generated, the optimal information channel is accurately sent to different clients, personalized matching is carried out for the clients, and the loss rate of the clients is reduced.
Owner:WUXI YIZHI INFORMATION TECHNOLOGY CO LTD

Large model dynamic protection method and system based on zero-trust architecture

The invention provides a large model dynamic protection method and system based on a zero-trust architecture. The method comprises the steps that a security proxy gateway receives an access request; authenticating an initiating main body of the access request, collecting context information and transmitting the context information to a strategy decision point; the strategy decision point calculates a trust score in real time based on a dynamic trust evaluation model and performs real-time evaluation in combination with an access control strategy to generate a dynamic authorization judgment result; if the access is allowed, forwarding the access request to a large language model server, and performing input security filtering; the large language model server generates response content and performs output security filtering; and returning the final response subjected to the output security filtering to the initiating main body through the security proxy gateway. According to the method, a multi-layer protection framework is constructed, a dynamic trust evaluation model is introduced, and a content filtering layer is deployed, so that continuous permission verification, risk adaptive control and full-link content security protection are realized, and the service security of a large model is effectively guaranteed.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

Telemetry-initiated mitigations in a zero-trust computing environment

Information Handling Systems (IHSs) support pre-boot telemetry for use in a zero-trust environment. A pre-boot telemetry orchestrator of the IHS retrieves a factory-provisioned resource locator of a service that provides a location of a policy decision point of the zero-trust environment. The pre-boot telemetry orchestrator establishes an encrypted session with the policy decision point that is located using the factory-provisioned resource locator. Via the encrypted session, the pre-boot telemetry orchestrator receives a telemetry definition specifying pre-boot telemetry to be collected by the IHS. Th telemetry is collected and transmitted during the pre-boot intervals according to the telemetry definition.
Owner:DELL PROD LP

Information security model auxiliary decision-making method and system based on intelligent knowledge graph

The invention relates to the technical field of artificial intelligence, and discloses an information security model auxiliary decision-making method and system based on an intelligent knowledge graph, and the method comprises the steps: constructing a multi-modal security data pool of a to-be-decided scene, training a joint extraction model of the to-be-decided scene, and extracting data examples and example relationships of the multi-modal security data pool; constructing a security knowledge graph of the scene to be decided; constructing an attack tactics-technology-process ontology layer of the scene to be decided to calculate a potential attack path of the scene to be decided, and calculating an attack path occurrence probability and an attack influence range of the potential attack path; marking a strategy decision point of the security knowledge graph, and analyzing a Top-K strategy of the strategy decision point by using a preset PPO algorithm; and constructing an attack chain analysis interface of the Top-K policy in the security knowledge graph to generate a policy optimization parameter of the Top-K policy, and executing the information security model aided decision of the scene to be decided based on the policy optimization parameter. According to the invention, the efficiency of security decision-making of to-be-decided scene information can be improved.
Owner:CHINA CYBER SECURITY REVIEW CERTIFICATION AND MARKET SUPERVISION BIG DATA CENT

Mobile scene-oriented WAPI seamless roaming optimization system and method thereof

The invention discloses a wireless authentication and privacy infrastructure (WAPI) seamless roaming optimization system and method for a mobile scene. Data collaboration and intelligent decision are realized through a three-layer structure of a mobile terminal, a WAPI access point and a switching control center. A mobile terminal collects a motion state and channel information in real time, a WAPI access point monitors a wireless condition in an area while meeting a WAPI security authentication requirement, a switching control center integrates data of all parties, a candidate access point utility value is dynamically calculated through a built-in strategy decision unit by adopting reinforcement learning, cognitive radio and robust control technologies, and the candidate access point utility value is calculated through a wireless network. Therefore, optimal roaming switching is realized. A pre-authentication and certificate caching mechanism is introduced into the system before switching, so that the authentication time delay is greatly reduced, and stable network connection and seamless transition during high-speed movement are ensured. According to the invention, the structure is simple, the adaptability is high, the WAPI security requirement is met, and the network roaming performance in a mobile scene is remarkably improved.
Owner:DALI BUREAU OF ULTRA HIGH VOLTAGE TRANSMISSION CO CHINA SOUTHERN POWER GRID CO LTD

Zero-trust cybersecurity access control system using continuous identity verification

A system for zero-trust cybersecurity access control using continuous identity verification (100), comprising: a Policy Decision and Enforcement Orchestrator (1) configured to receive an access request from a user device and enforce a session with minimal privileges; an engine for continuous identity verification (2) configured to generate a time-dependent identity trust score by continuously verifying the user identity during an active session; a device state and telemetry collector (3) configured to acquire device state parameters, runtime signals and network telemetry and to generate a state value; a module for detecting behavioral risks and anomalies (4) that is configured to create behavioral profiles and detect anomalies based on user activity patterns, contextual signals and the history of resource access; a cryptographic authentication and secure token module (5) configured to issue and update a short-lived, bound access token associated with at least the identity trust value and the state value; and an adaptive response and microsegmentation module (6) configured to dynamically adjust access permissions, network segmentation and session privileges in real time, based on an aggregated risk assessment derived from modules (2) to (4), where the system (100) continuously reassesses trustworthiness during the session and selectively allows, restricts, requires enhanced authentication or terminates the session based on the aggregated risk assessment.
Owner:SIVASHANMUGAM SATHESH PADMANABAN GLENDALE

Quality of trust framework for wireless communication networks

Systems, methods, and devices are disclosed herein to identify and deploy policy changes from a policy source in a wireless communication network to enforcement points in the network based on trends identified by the policy source in KPIs reported by the enforcement points. In an implementation, enforcement points in the network report KPIs to the policy source. The KPIs are related to authorization attempts made by user equipment in the network. The policy source, upon receiving the KPIs, identifies a trend in the KPIs and identifies a policy change based on the KPIs. The policy source then deploys the policy change to the enforcement points. In various implementations, the policy source is a Policy Decision Point (PDP), and the enforcement points are Policy Enforcement Points (PEPs).
Owner:T MOBILE INNOVATIONS LLC

Large and small model collaborative semantic rewriting system based on complexity induction

A big and small model collaborative semantic rewriting system based on complexity sensing comprises a user question receiving module, a context extraction module, a complexity evaluation module, a collaborative strategy module and an output rewriting module, and the user question receiving module is used for receiving questions of a current user and starting a semantic rewriting process. The context extraction module is used for integrating historical dialogue contexts and extracting key entities, the complexity evaluation module is used for evaluating user question semantic complexity and driving strategy decision, the collaborative strategy module is used for dynamically scheduling collaborative modes of small models and large models and optimizing resource allocation, and the output rewriting module is used for generating final rewritten questions. According to the large and small model collaborative semantic rewriting system based on complexity induction, a semantic complexity evaluation algorithm based on machine learning is put forward to evaluate semantic complexity, and a model collaborative strategy algorithm based on a dynamic threshold is put forward to cooperatively process tasks of all levels.
Owner:HANGZHOU TUBU ER TECHNOLOGY CO LTD

Method and apparatus for selecting edge application server, and network element device, user equipment and storage medium

The present disclosure relates to method and apparatus for selecting an edge application server, and element network device, user equipment and storage medium. The method includes: a user equipment receiving first indication information, which is sent by an SMF, wherein the first indication information is used for indicating the priority of domain name system (DNS) information; and the user equipment making a DNS policy decision according to the first indication information, and sending a DNS query request to an EASDF, wherein the DNS query request is used by the EASDF to execute the discovery or selection of an edge application server (EAS).
Owner:BEIJING XIAOMI MOBILE SOFTWARE CO LTD

Vulnerability risk assessment method based on network surveying and mapping

The invention discloses a vulnerability risk assessment method based on network surveying and mapping, and belongs to the technical field of network security, and the assessment method comprises the following specific steps: (1) identifying all devices and services in a network, and drawing a network topological graph to classify and identify risk points and asset distribution in the network; (2) scanning all devices and services in the network, collecting vulnerability data, simulating different attack scenes and vulnerability utilization means, and verifying a scanning result; the method can adapt to different network environments and security requirements, improves the accuracy of vulnerability risk assessment, improves the diversity and refinement degree of vulnerability risk scoring, and enhances the policy decision support of vulnerability repair; transmission of sensitive data is avoided, privacy protection is enhanced, the vulnerability defense capability of the whole system is improved, the requirement for bandwidth and transmission delay are reduced, and the vulnerability response speed and repair efficiency are improved.
Owner:WUZHOU VOCATIONAL COLLEGE

Method and system for dynamic user application control service

A method, network device, system, and non-transitory computer-readable storage medium are described in relation to an dynamic user application control service that includes receiving from an application device, a request for access controls associated with a user application and an end device; generating, per the request, policies pertaining to the access controls, wherein the policies include time-based rules, location-based rules, or application type-based rules; obtaining a current location of the end device; comparing, by the network device, a current time with the time-based rules, the current location with the location-based rules, or an application type for the user application with the application-type rules; generating, per the comparing, a policy decision among the policies pertaining to the access controls; and applying, per the policy decision, the time-based rules, the location-based rules, and the application type-based rules for establishment of an application session with the end device.
Owner:VERIZON PATENT & LICENSING INC

External field equipment trusted access method based on non-addressable stealth gateway

The invention discloses an external field equipment trusted access method based on a non-addressable stealth gateway, which relates to the technical field of network security access, and comprises the following four steps: in a manufacturing period and first access, a certificate authorization machine binds equipment identity and trusted platform module measurement, policy decision point decision, policy execution point implementation and policy subset loading; initiating from the outside of the equipment, establishing an end-to-end trusted channel with the center, and performing inward isolation and transparent bearing on rear-end real services; updating strategies, algorithms and secret keys on line under the control of a unified strategy library; according to the method, the attack surface is reduced, the transformation cost is reduced, non-stop treatment is ensured, the encrypted traffic can be observed and audited, only trusted equipment can reach the center through a trusted channel, and event linkage right descending and certificate state linkage treatment are supported.
Owner:HANGZHOU XENON TECHNOLOGY CO LTD

System for secure MCP-mediated tool use by AI agents and generative AI / LLM services in cloud-native distributed applications

A system (100) for the secure MCP-mediated use of tools by AI agents and generative AI / LLM services in cloud-native distributed applications, wherein the system (100) comprises: a KL agent interface (1) configured to receive natural language commands and application events from a variety of client applications and to generate appropriate tool call commands for one or more generative KL or Large Language Model (LLM) services; an MCP mediator service (2) that is configured to: (a) to convert the tool request requests into messages compatible with a model context protocol (MCP); and (b) to maintain the conversation context, including at least one of the following: user identity, tenant identity and application identity; a tool register (3) that stores a plurality of tool descriptions, each tool description defining at least a tool identifier, an input and output scheme, an endpoint location and allowed functions, wherein the tool register (3) is accessible to the MCP mediator service (2); a policy and security manager (4) configured to evaluate each MCP tool call against one or more security and access policies based on the conversation context and the corresponding tool description, and to issue a decision to allow, modify or block the tool call; a tool connector layer (5) comprising a plurality of tool adapters, each tool adapter being configured to communicate securely with a corresponding external tool, service or data source using credentials and permissions restricted according to the decision of the policy and security manager (4); an observation and audit manager (6) configured to record, for each tool call, at least a timestamp, the calling KL agent, the tool identifier, the policy decision, and a summary of the tool response, and to provide audit logs and metrics for monitoring and compliance purposes; and a cloud-native deployment controller (7) configured to provide the MCP mediator service (2), policy and security manager (4), tool connector layer (5) and observation and audit manager (6) as distributed microservices with network isolation between tenants in a cloud-native environment.
Owner:BHANDARWAR NILESH DNYANESHWAR REDMOND

Distributed cache management method and device, computer equipment and storage medium

The embodiment of the invention discloses a distributed cache management method and device, computer equipment and a storage medium. The method is used for managing a distributed cache system, and comprises the following steps: when a target cache node in a plurality of cache nodes meets a preset data elimination condition, obtaining first index data of a plurality of preset node indexes of the target cache node; inputting the first index data into a strategy decision model corresponding to the target cache node for strategy selection processing, and determining a current elimination strategy of the target cache node; obtaining second index data of a plurality of preset data indexes of each piece of cache data in the target cache node; determining a value density value of each piece of cache data in the target cache node according to each piece of second index data; and performing cache data elimination processing on the target cache node according to the current elimination strategy and the value density value of each piece of cache data in the target cache node. By implementing the method provided by the embodiment of the invention, the cache hit rate and the processing performance of the processing system can be improved.
Owner:SHENZHEN QIANHAI HUANRONG LIANYI INFORMATION TECHNOLOGY SERVICES CO LTD

Dynamic network access control system under zero-trust architecture

The invention discloses a dynamic network access control system under a zero-trust architecture, which relates to the technical field of network security, and comprises a multi-dimensional trust evaluation module, a self-adaptive micro-segmentation engine, a strategy decision execution module and a risk perception feedback module, the multi-dimensional trust evaluation module calculates a comprehensive trust score based on five-dimensional features of identity, equipment, network, application and data; the self-adaptive micro-segmentation engine dynamically generates network micro-segments based on a graph diffusion algorithm; the strategy decision execution module adopts deep reinforcement learning to generate an access decision; the risk perception feedback module identifies abnormity based on the LSTM network and adjusts trust parameters through closed-loop feedback, the four modules are deeply coupled and cooperated, refined dynamic access control is realized, the occurrence rate of security events is reduced by more than 85%, and an innovative solution is provided for enterprise network security.
Owner:INFORMATION CENT OF YELLOW RIVER WATER RESOURCES COMMISSION

Bot prevention velocity framework

The embodiments relate to a system, a computer-implemented method, and a computer program product for performing bot detection using a velocity framework. For example, embodiments include a policy decision engine that can receive requests from a source, wherein each of the requests comprise velocity data including one or more attributes. The policy decision engine can monitor an occurrence of the velocity data in each request, and determine a velocity data rate for the velocity data in each request. Further, the policy decision engine can determine whether the request is a bot request based at least in part on the determined velocity data rate, and transmit a notification to the source of the request based at least in part on the determination of the bot request, wherein the notification indicates whether a bot request has been identified in the request.
Owner:WALMART APOLLO LLC

Communication Method and Communication Apparatus

A communication method includes a first network element that obtains first information and second information, where the first information is from a second network element and includes subscription information and / or policy information of a first service, the second information is from a third network element and indicates that the first service supports being managed by the first network element, and the third network element is a home data storage network element of the terminal device. The first network element determines a policy decision result based on the first information and the second information, where the policy decision result is used by the terminal device to access the first service in a first region. The first network element and the second network element are network elements at a subscription location in which the terminal device subscribes to the first service.
Owner:HUAWEI TECH CO LTD

Terminal access permission analysis method and system based on zero-trust ABAC model

The application discloses a terminal access permission analysis method and system based on a zero-trust ABAC model, and the method comprises the following steps: a user terminal sends a resource access request; a policy enforcement point (PEP) receives the resource access request sent by the user terminal; according to a preset collection requirement, multi-dimensional attributes are extracted from the user request, the user request is converted into an attribute request, and the attribute request is sent to a policy decision point (PDP); the attributes comprise user attributes, environment attributes, operation attributes and object attributes; the PDP performs access permission analysis by using a policy administration point (PAP) based on the attribute request, obtains an access permission analysis result, and feeds back the access permission analysis result to the PEP; the information fed back by the PDP to the PEP comprises permission, rejection, inapplicability and unknown; and the PEP executes the resource access request according to the feedback information received from the PDP. The application is based on a zero-trust technical framework, and fine management of permissions is realized by ABAC, so that the changing business requirements and security challenges can be effectively coped with.
Owner:ELECTRIC POWER RES INST STATE GRID SHANXI ELECTRIC POWER

Telemetry-initiated mitigations in a zero-trust computing environment

Information Handling Systems (IHSs) support pre-boot telemetry for use in a zero-trust environment. A pre-boot telemetry orchestrator of the IHS retrieves a factory-provisioned resource locator of a service that provides a location of a policy decision point of the zero-trust environment. The pre-boot telemetry orchestrator establishes an encrypted session with the policy decision point that is located using the factory-provisioned resource locator. Via the encrypted session, the pre-boot telemetry orchestrator receives a telemetry definition specifying pre-boot telemetry to be collected by the IHS. The telemetry is collected and transmitted during the pre-boot intervals according to the telemetry definition.
Owner:DELL PROD LP

Blockchain-based pedigree data dynamic permission access control system and method

ActiveCN120074872BData graphData access
The application discloses a kind of based on blockchain's pedigree data dynamic permission access control system and method, rely on attribute-based access control paradigm, and combine pedigree data access constraint to carry out dynamic access control.First, user sends access request to policy decision point;Decision point according to the policy loaded from policy management point, request relevant information to blockchain, and call user historical behavior verification module based on pedigree data, the legality of current access request is verified using dependency relationship and pedigree data graph.System administrator records access request and verification result to blockchain, to support the fast verification of same query, reduce query overhead.In addition, the system passes access information such as query user, time, result, operation content to management node, for subsequent user access tracking and management.The method uses the anonymity and non-tamperability of blockchain, provides strong evidence for user supervision, realizes efficient management and reasoning to source information.
Owner:WUHAN UNIV