Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

134 results about "Policy enforcement" patented technology

Systems and methods for semantically governed specification-driven interoperability in distributed environments

Disclosed herein are systems and methods for enabling decentralized, schema-driven interoperability across distributed computing environments through the use of a Standard Knowledge Language (SKL). An Enterprise Mesh Platform (EMP) interprets and executes SKL specifications—such as capabilities, objects, mappings, policies, and workflows—as composable, machine-interpretable contracts that define data structures, logic, and governance protocols. The system supports dynamic versioning, validation, semantic linking, and recursive execution of SKL-defined components. A mesh-wide analytics server coordinates execution, issue detection, and resolution propagation. Capabilities can be orchestrated, remediated, and adapted in real-time based on SKL-defined relationships, while preserving compliance and traceability. The disclosed architecture facilitates federated development, adaptive system integration, and fine-grained policy enforcement across complex digital ecosystems.
Owner:COMAKE INC

Cloud deployment automation system with integrated resource orchestration and customizable deployment workflows

ActiveDE202025104332U1Resource allocationResourcesAsynchronous operationExecution control
A cloud deployment automation system consisting of: a deployment automation device housed in a rack-mountable enclosure, the device comprising: a multi-core orchestration processor configured to execute deployment logic as compiled execution graphs; a storage module operatively coupled to the orchestration processor, the storage storing a set of deployment templates, real-time execution states, telemetry logs, and policy configurations; a secure credential management processing unit embedded in the device, configured to generate, store, and rotate cloud access tokens, API keys, and user-specific credentials, and to provide encrypted access to those credentials during deployment execution; an in-memory workflow execution engine executed by the orchestration processor, configured to analyze a user-defined deployment configuration that includes a declarative specification of infrastructure resources and compile that configuration into a directed acyclic graph (DAG) that represents the resource deployment order, dependency mapping, and rollback relationships, a cloud provider interface subsystem communicatively connected to multiple heterogeneous cloud platforms via appropriate API adapters, the subsystem enabling the orchestration processor to send provisioning requests and receive status events from the platforms; a customizable workflow compiler unit configured to convert graphical workflow definitions or domain-specific language (DSL) scripts into execution sequences that can be used by the workflow execution engine, where the workflow compiler unit supports conditional branching, asynchronous operations, and runtime variable resolution; and A policy enforcement control unit integrated into the deployment automation device, with the policy engine configured to apply organization-specific compliance rules, tagging conventions, security group configurations, and runtime resource limits to all deployment actions in a context-aware manner prior to execution.
Owner:THASON JUSTIN RAJAKUMAR MARIA FAIRFAX

Systems and methods for network data classification and policy enforcement

This disclosure describes methods, devices and systems for abnormal network data identification and policy enforcement. An example method includes obtaining incoming network data from a network device, the networking data including operating information for the network device and packet metadata. The method also includes classifying the incoming network data using one or more machine learning models, including identifying abnormal network data from the incoming network data. The method further includes causing a policy rule to be generated based on the abnormal network data.
Owner:IP INFUSION INC

Systems and methods for network anomaly detection and policy enforcement

This disclosure describes methods, devices, and systems for network anomaly detection and policy enforcement. An example method includes obtaining metadata for a plurality of network packets. The method also includes detecting an anomaly in the plurality of network packets by analyzing the obtained metadata and the operating information. The method also includes generating, without user input, a policy rule based on the detected anomaly. The method further includes enforcing the policy rule at the one or more network devices.
Owner:IP INFUSION INC

Systems and methods for semantically governed specification-driven interoperability in distribute environments

Disclosed herein are systems and methods for enabling decentralized, schema-driven interoperability across distributed computing environments through the use of a Standard Knowledge Language (SKL). An Enterprise Mesh Platform (EMP) interprets and executes SKL specifications — such as capabilities, objects, mappings, policies, and workflows — as composable, machine-interpretable contracts that define data structures, logic, and governance protocols. The system supports dynamic versioning, validation, semantic linking, and recursive execution of SKL-defined components. A mesh-wide analytics server coordinates execution, issue detection, and resolution propagation. Capabilities can be orchestrated, remediated, and adapted in real-time based on SKL-defined relationships, while preserving compliance and traceability. The disclosed architecture facilitates federated development, adaptive system integration, and fine-grained policy enforcement across complex digital ecosystems.
Owner:COMAKE INC

Intelligent Cognitive AI Based Secure Protocol Channel to Create and Deploy Projects on Demand in Real Time Leveraging Unikernels

ActiveUS20250310352A1Securing communicationConfidentialityUnikernel
This invention introduces a sophisticated system for deploying projects on cloud platforms, combining Unikernels, Cyber Security Mesh Architecture (CSMA), MQTT protocol with SHA256 encryption, an Unikernel Orchestration Rules Engine (UORE), generative AI, and an innovative caching mechanism. Unikernels offer a secure, isolated environment for applications, reducing overhead and boosting performance. CSMA provides extensive security through analytics, identity management, and policy enforcement. The MQTT protocol, secured with SHA256, ensures the integrity and confidentiality of communications. UORE automates deployment, integrating a TLS terminator and data management for streamlined operation. Generative AI proactively resolves deployment challenges, particularly for complex applications, while the caching mechanism enhances performance and efficiency by minimizing latency. This integrated approach automates and secures the deployment process, enabling scalable, efficient, and real-time project creation and deployment in the cloud, thereby addressing the key challenges of cloud application hosting.
Owner:BANK OF AMERICA CORP

Data processing system and method, and related device

A data processing system and method, and a related device, relating to the technical field of artificial intelligence (AI). The data processing system comprises a general-purpose processor and an AI accelerator card. The general-purpose processor is used for sending an operation request comprising authorization authentication information and requesting to process an AI model deployed in the AI accelerator card. The AI accelerator card is constructed to be provided with a trusted execution environment (TEE), and the AI accelerator card is used for running a policy enforcement point (PEP) component deployed in the TEE, and is further used for receiving the operation request and determining whether the authorization authentication information in the operation request complies with a verification rule in the PEP component, and when the authorization authentication information complies with the verification rule, the first operation request is executed to execute a processing operation on the AI model. In this way, the PEP component is deployed in the TEE of the AI accelerator card, that is, the PEP is deployed in an execution environment closer to the AI model, so that the AI model can be effectively prevented from being illegitimately accessed by the general-purpose processor, thereby ensuring access safety of the AI model in the AI accelerator card.
Owner:HUAWEI TECH CO LTD

Public to Private Mobile Access

This invention provides methods and systems for seamless mobile connectivity between public and private cellular networks. The system dynamically switches user devices between networks based on location, radio signal availability, or preconfigured policies that prioritize private networks when within range. For devices with physical SIM cards, an embedded applet enables switching between operator profiles, while ESIM profiles deploy applets for selecting among multiple identities within a profile. All cellular traffic, whether on public or private networks, is routed through a cloud-based system for centralized security and policy enforcement. Network selection may be influenced by defining the private network as the Home Public Land Mobile Network (HPLMN) or scanning available networks via applet capabilities. The system supports unified subscription, connectivity, and service management via a cloud-based portal, ensuring reliability and security across diverse network environments. This approach enhances mobility, security, and flexibility for enterprise and IoT applications.
Owner:ZSCALER INC

Systems and methods for congestion aware policy enforcement

A device may include a processor configured to detect a Protocol Data Unit (PDU) session associated with a user equipment (UE) device. The processor may be further configured to obtain at least one congestion metric value for a base station associated with the PDU session; determine that the obtained at least one congestion metric value is less than a maximum throughput enforcement threshold; and override a maximum throughput enforcement policy on a User Plane Function (UPF) associated with the UE device, based on determining that the obtained at least one congestion metric value is less than the maximum throughput enforcement threshold.
Owner:VERIZON PATENT & LICENSING INC

Wire-speed routing and policy enforcement without DPI or decryption

A system and computer-implemented method for routing an encrypted packet through a cloud enforcement network based on a metadata tag. The cloud enforcement network applies policy and routing attributions or tags outside of the encrypted packet payload in such a way as to not require an inner packet to first be decrypted. Traffic prioritization, data protection, and per application policies are achieved by using such metadata tags for internode routing without the need for DPI or decryption. Furthermore, the metadata itself can also be signed or encrypted depending on the provenance of the data. As such, applying meta-tagging external to an encrypted packet, the payload would not be needed to be decrypted during transit of the packet to express end-to-end policy and routing decisions.
Owner:CISCO TECHNOLOGY INC

Advanced multi-layer access control policy enforcement in a multi-tenant cloud environment

An approach is provided for multi-layer access control policy enforcement in a multi-tenant cloud environment. An advanced policy service is defined in a data container The advanced policy service provides management and validation of an access control policy at multiple levels including an application layer and a low layer, which is at a level lower than the application layer. Using the advanced policy service, a policy definition of the application layer is mapped to an access validation and authorization policy of the low layer. Rules are generated using an analysis of data packets by an eBPF program Using the eBPF program, the policy definition and the rules are applied to a request received from a SaaS application to access a data source. Based on the application of the policy definition and the rules, a data vulnerability is identified and the request is rejected.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Method, apparatus, system and computer program for security processing of multi-agent system

Proposed are a method, an apparatus, a system, and a computer program for security processing of a multi-agent system. More specifically, the present disclosure discloses a method for managing security for a multi-agent system by using a computing apparatus. The method includes establishing an execution plan comprising a plurality of agents to perform a request of a user on the basis of the request, executing one or more agents among the plurality of agents according to the execution plan, and providing a response to the request of the user on the basis of an execution result of the one or more agents among the plurality of agents, wherein access to or input / output of the one or more agents is controlled through a policy enforcement point that enforces a security policy for the one or more agents among the plurality of agents.
Owner:SAMSUNG SDS CO LTD

Off-Chain Gas Management System and Method

An off-chain gas management system allows Web3 developers to cover gas fees for their users. When a user wants to complete a blockchain transaction, the system receives a sponsorship request through an API and checks if the operation qualifies under the developer's gas sponsorship policy. Policies include spending limits, approved addresses, and time restrictions. If approved, the system creates a cryptographic signature that authorizes transfer of the gas fee amount. An on-chain contract validates the signature before covering the gas fees. The system includes a user interface for creating and managing policies with configurable spending controls and address restrictions. Advanced features use machine learning to allocate funds based on user value, detect fraud, classify transaction types, optimize cryptocurrency purchases, and predict when funds will run out. This eliminates the barrier of users needing to own cryptocurrency to pay gas fees while maintaining security through automated policy enforcement and cryptographic validation.
Owner:ALCHEMY INSIGHTS INC

Method for application access in zero trust campus network

Disclosed herein are system, method, and computer program product aspects for providing an agent-based zero trust network access (ZTNA) remote device access to a campus network. Some aspects of this disclosure relate to a universal network access application including a memory and a processor. The processor is configured to receive an authentication request from a client device and in response to receiving the authentication request, retrieve a set of network policies indicating an Internet protocol (IP) address and a port number based on the authentication request. The processor is further configured to transmit the set of network policies to a policy enforcement application in a campus network.
Owner:EXTREME NETWORKS INC

Terminal access permission analysis method and system based on zero-trust ABAC model

The application discloses a terminal access permission analysis method and system based on a zero-trust ABAC model, and the method comprises the following steps: a user terminal sends a resource access request; a policy enforcement point (PEP) receives the resource access request sent by the user terminal; according to a preset collection requirement, multi-dimensional attributes are extracted from the user request, the user request is converted into an attribute request, and the attribute request is sent to a policy decision point (PDP); the attributes comprise user attributes, environment attributes, operation attributes and object attributes; the PDP performs access permission analysis by using a policy administration point (PAP) based on the attribute request, obtains an access permission analysis result, and feeds back the access permission analysis result to the PEP; the information fed back by the PDP to the PEP comprises permission, rejection, inapplicability and unknown; and the PEP executes the resource access request according to the feedback information received from the PDP. The application is based on a zero-trust technical framework, and fine management of permissions is realized by ABAC, so that the changing business requirements and security challenges can be effectively coped with.
Owner:ELECTRIC POWER RES INST STATE GRID SHANXI ELECTRIC POWER

Method for monitoring and enforcing secure policies in a device

A method for monitoring and enforcing secure policies in a device includes collecting kernel data from a kernel space by a packet filtering module operating in a user space. The kernel data is processed into events that are transmitted to a data bus, where the events are stored and provided to a policy enforcement module. The policy enforcement module evaluates the events with an algorithm to detect potential threat events. When a threat event is identified, one or more secure policies are selected and executed in the device as corresponding actions or commands. The method enables real-time monitoring of kernel activity and enforcement of security policies while maintaining the architecture in user space.
Owner:EXEIN SPA

installing a selected role of a concern source

Embodiments of the present disclosure relate to installing a selected attention source role policy. In some examples, a processing resource converts an attention target role policy to a plurality of attention source role policies and selects a set of attention source role policies from the plurality of attention source role policies based on a source network address and a target network address in a first data packet. The processing resource installs the set of selected attention source role policies in a policy enforcement hardware controller of a policy implemented in an ingress network device for a source computing entity, the policy enforcement hardware controller to enforce an attention source role policy of the set of selected attention source role policies at the ingress network device in response to a second data packet received from the source computing entity.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

System and Method for Authenticating Client Devices Communicating with an Enterprise System

A system and method are provided for authenticating client devices communicating with an enterprise system. The method includes providing a policy enforcement interceptor to intercept API calls and enabling the policy enforcement interceptor to communicate with a policy information point to query the at least one endpoint for entitlements associated with an account. The method also includes intercepting an API call to the application API, communicating with the policy information point to determine entitlements associated with the account by having the policy information point query an entitlements database and, when the entitlements returned to the policy enforcement interceptor are valid, invoking a policy decision point to validate the client device. The method also includes, when the client device is validated, permitting invocation of the API. The method also includes providing an API response to the client device to permit access to the application via the API.
Owner:THE TORONTO DOMINION BANK

Automated escalated policy enforcement

The present disclosure describes a system and method for providing automated policy enforcement. The system and method may be implemented by a service provider to enforce a policy related to copyright infringement activities. According to an example, the policy may define a system of penalty (strike) levels for violations of the policy up to a maximum number of strikes. When a notification of a policy violation is received, the system may operate to determine whether to issue a strike in association with the notification. When a determination is made to issue a strike in association with a received notification a set of enforcement actions to perform in association with the issued strike may be selected and executed. The set of enforcement actions may terminate detected copyright infringement activities and reduce or otherwise limit the service provider's liabilities when such copyright infringement activities may occur.
Owner:LEVEL 3 COMMUNICATIONS LLC

Conditional ssh tunneling as a policy enforcement point for seamless zero trust integration

Enhanced security for Zero Trust networks is provided by SSH-customized tunnel clients / tunnel servers, a catalog service, and loopback address DNS mechanisms. Systems and methods provide Policy Enforcement Point (PEP) layer enhancements, strategically positioning the PEP between the user and the network resource. It manages network traffic flows and provides moderate control granularity, near-real-time enforcement decisions, low overheads, and broad applicability to TCP / IP traffic through modified tunneling implementations of Secure Shell (SSH). Unique use of SSH tunneling is utilized and adapted to selectively filter tunnel requests based on user entitlements, ensuring secure and authorized access to network resources. This method entails detailed assessment of tunneling requests, DNS manipulation, and the use of loopback address space for traffic redirection, all without requiring modifications to client-side applications. The approach significantly enhances network security by controlling access based on continuous verification of user entitlements, addressing the shortcomings of traditional network security models.
Owner:BANK OF AMERICA CORP

Configurable options for device registration in wireless communication networks

Technology is disclosed herein for registering a user device for access to a wireless network. In an implementation, a session manager of a wireless network receives a registration request for access to the network from a user device. The session manager determines a workflow configuration for the access based on parameters relating to the registration request. Prior to sending a request for an access session to a policy enforcement function, the session manager selects a traffic routing function of the wireless network for device access to the network and requests a traffic management session from the traffic routing function. The session manager sends a request for an access session to the policy enforcement function which includes traffic routing information. The session manager sends the user device information by which the user device can access the wireless network.
Owner:T MOBILE INNOVATIONS LLC

Systems and methods for congestion aware policy enforcement

A method includes detecting a communication session in a wireless network and obtaining at least one resource utilization metric associated with the communication session. The method further includes determining, based on the at least one resource utilization metric, that network resources associated with the communication session are underutilized, and relaxing a performance-limiting policy associated with the communication session based on determining that the network resources are underutilized. The method may further include detecting a triggering condition associated with the communication session and initiating an inspection of data associated with the communication session in response to detecting the triggering condition. The method may also include detecting an anomalous condition based on the inspection and generating an alert based on detecting the anomalous condition.
Owner:VERIZON PATENT & LICENSING INC

Cross-System Object Policy Enforcement In Distributed Storage Environments

Systems and methods of maintaining a policy implementation for an object across different storage systems are disclosed. The method includes determining, for an object to be copied from a first storage system, one or more object policies that are applicable to the object; generating metadata that triggers application of the one or more policies at an other storage system that is different from the first storage system; and including the metadata with the object during copying of the object.
Owner:PURE STORAGE INC

Systems and methods for agentic policy enforcement

Systems and methods for policy enforcement within an artificial intelligence (AI) agentic workflow. Each action within the AI agentic workflow is intercepted by a run-time enforcement engine. Utilizing security labels for each component within the AI agentic workflow, the run-time enforcement engine cross-references the security labels against a policy to ensure an action taken by a component within the AI agentic workflow is authorized under the policy.
Owner:BRICKLAYER AI INC

Out-of-band policy enforcement for data processing systems using activity data

Methods and systems for managing operation of a data processing system are disclosed. Activity data for hardware resources of the data processing system may be obtained while the hardware resources are providing computer-implemented services to a user of the data processing system. The activity data may be analyzed to characterize use of the hardware resources by the user with respect to policies for the data processing system. The hardware resources may be adapted to independently enforce the policies when operating nominally; however, when the hardware resources are not operating nominally, a management controller of the data processing system may initiate performance of a policy enforcement process based on the characterized use of the hardware resources to modify provisioning of a portion of the computer-implemented services to the user.
Owner:DELL PROD LP

Device for the safe hybrid execution of context-aware deployments of large language models (LLM)

Device for the secure hybrid execution of context-aware Large Language Model (LLM) deployments, comprising: an edge execution unit (101) configured to execute at least a first part of an LLM inference process on a local device; a cloud inference processing unit (102) configured to execute at least a second part of the LLM inference process on a remote computing infrastructure; a context sensitivity analyzer (103) configured to analyze an input query and associated context data and generate a sensitivity classification for said context data;a hybrid execution orchestration engine (104) that functions with the context sensitivity analyzer (103), the edge execution unit (101), and the cloud inference processing unit (102), wherein the hybrid execution orchestration engine (104) is configured to dynamically split the LLM inference process into an edge-executed part and a cloud-executed part, based on at least the sensitivity classification; a secure communication interface (105) configured to transmit intermediate inference outputs between the edge execution unit (101) and the cloud inference processing unit (102) over an encrypted communication channel; a TEE module (106) integrated into the edge execution unit (101) to perform at least one privacy-relevant inference operation in an isolated, hardware-protected environment;a key management and encryption controller (107) configured to generate, store, distribute, and rotate cryptographic keys and to encrypt and decrypt intermediate inference outputs transmitted between the edge execution unit (101) and the cloud inference processing unit (102); a policy enforcement and access control unit (108) configured to validate user authorization and enforce execution policies that define whether at least some of the context data is restricted to local execution;and an audit logging and threat monitoring module (109) configured to record inference execution events, security decisions, policy enforcement events and communication events and detect anomalous behavior related to the LLM inference process, wherein the device securely generates an output response to the input query by performing context-aware LLM inference while preventing sensitive context data from being disclosed to unauthorized external environments.
Owner:ADEPU GANESH +2

Advanced multi-layer access control policy enforcement in a multi-tenant cloud environment

An approach is provided for multi-layer access control policy enforcement in a multi-tenant cloud environment. An advanced policy service is defined in a data container The advanced policy service provides management and validation of an access control policy at multiple levels including an application layer and a low layer, which is at a level lower than the application layer. Using the advanced policy service, a policy definition of the application layer is mapped to an access validation and authorization policy of the low layer. Rules are generated using an analysis of data packets by an eBPF program Using the eBPF program, the policy definition and the rules are applied to a request received from a SaaS application to access a data source. Based on the application of the policy definition and the rules, a data vulnerability is identified and the request is rejected.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Systems and methods for endpoint process metadata based policy enforcement

Systems and methods for endpoint application metadata based policy enforcement include monitoring traffic via a cloud, the traffic being monitored inline between one or more endpoints and one or more destinations; identifying, within a request from an endpoint, endpoint process metadata associated with an endpoint process used to make the request; processing the endpoint process metadata; and performing one or more actions on the request based on the processing. The endpoint process metadata can be collected by a connector application executing on the one or more endpoints, and forwarded to the cloud in-band therefrom.
Owner:ZSCALER INC

Location-based policy enforcement for data processing systems using out-of-band methods

Methods and systems for managing a data processing system are disclosed. A management controller of the data processing system may obtain location data for the data processing system via an out-of-band communication channel. The management controller may identify policies based on the location data, and make an identification regarding whether the data processing system is operating out of compliance with respect to the policies. If the data processing system is operating out of compliance, then the management controller may perform an action set to update operation of the data processing system in a manner that improves compliance of the data processing system with respect to the policies. The data processing system may provide computer-implemented services based on the updated operation.
Owner:DELL PROD LP