Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

188 results about "Policy enforcement" patented technology

Artificial intelligence driven systems of systems for converged technology stacks

An artificial intelligence driven system of systems may include a layered architecture for providing transaction support to various types of enterprises. A governance layer implements automated governance and policy enforcement through specialized governance modules utilizing generative AI technology. An enterprise layer supports enterprise functions by integrating management and control platforms with digital infrastructure. An offering layer creates and manages system offerings via content generation, personalization, and smart product modules. A transactions layer enables automated transaction orchestration through API integration, execution, and fulfillment modules. An operations layer manages AI systems through generation, training, verification and orchestration modules. A network layer provides adaptive networking capabilities through routing, protocol selection and communication modules. A data layer processes fused data from multiple sources using machine learning and AI systems. A resource layer manages computing, storage, and other resources through specialized resource modules.
Owner:STRONG FORCE TX PORTFOLIO 2018 LLC

Systems and methods for semantically governed specification-driven interoperability in distributed environments

Disclosed herein are systems and methods for enabling decentralized, schema-driven interoperability across distributed computing environments through the use of a Standard Knowledge Language (SKL). An Enterprise Mesh Platform (EMP) interprets and executes SKL specifications—such as capabilities, objects, mappings, policies, and workflows—as composable, machine-interpretable contracts that define data structures, logic, and governance protocols. The system supports dynamic versioning, validation, semantic linking, and recursive execution of SKL-defined components. A mesh-wide analytics server coordinates execution, issue detection, and resolution propagation. Capabilities can be orchestrated, remediated, and adapted in real-time based on SKL-defined relationships, while preserving compliance and traceability. The disclosed architecture facilitates federated development, adaptive system integration, and fine-grained policy enforcement across complex digital ecosystems.
Owner:COMAKE INC

AI-driven financial planning system with real-time market adjustment

An AI-driven financial planning system for real-time market adjustment, consisting of: a neural inference coprocessor configured to execute deep financial forecasting models, including recurrent neural networks and attention-based encoders, on the device, and wherein the processor dynamically updates portfolio parameters in response to market signals exhibiting volatility differences above a statistical threshold calculated using an exponentially weighted moving standard deviation; a financial data acquisition module configured to continuously receive and analyze heterogeneous data streams, including market indices, interest rates, stock and bond price fluctuations, economic indicators, regulatory updates, and financial news sentiment feeds; a behavioral analytics engine configured to create a dynamically evolving user-specific financial behavior profile based on real-time analysis of transaction history, income-expenditure cycles, psychometric test results, and temporal lifestyle patterns using supervised and unsupervised machine learning algorithms; A goal optimization module configured to transform high-level, user-defined financial goals into quantitatively tracked multi-level goals. It uses a reinforcement learning framework that predicts optimal asset allocations across multiple time horizons. a real-time strategy simulation engine configured to perform Monte Carlo simulations and deep Q-learning-based assessments to simulate the resilience of proposed financial strategies under different macroeconomic regimes and trigger redistribution events based on predefined confidence thresholds; a compliance-aware execution interface configured to interact with financial institutions through encrypted API channels, ensuring policy enforcement using a smart contract validator and a hardware-enabled secure transaction signing unit; and a recommendation display unit configured to render dynamic dashboards for visualizing investments, reallocation warnings, confidence intervals, and sensitivity sliders, and where user interaction with the unit flows back into the behavioral model for real-time learning.
Owner:KONATHAM MAHESH REDDY MCKINNEY +2

AI-driven, cloud-based system for real-time biomedical and pharmaceutical compliance and risk management

An AI-driven, cloud-based system (100) for real-time biomedical and pharmaceutical compliance and risk management, including: (a) a compliance knowledge module configured to ingest, interpret and structure regulatory data using natural language processing (NLP) and generate machine-readable compliance rules; (b) a real-time monitoring and event recording module configured to collect and normalise operational data from distributed biomedical and pharmaceutical systems, including laboratory information management systems (LIMS), manufacturing execution systems (MES) and IoT-enabled devices; (c) an intelligent risk assessment and prediction module configured to correlate operational data with compliance rules, calculate dynamic risk scores and predict potential compliance violations using machine learning models; (d) an automated policy and workflow enforcement module configured to initiate remedial actions, assign tasks and log activities based on predefined standard operating procedures (SOPs); (e) an audit readiness and reporting module configured to generate compliance logs, audit trails and standardised regulatory reports in real time; and (f) an adaptive learning and feedback optimization module configured to refine rule sets and predictive models based on feedback, historical data and regulatory updates; g) the modules are integrated into a cloud infrastructure to enable real-time, scalable and predictive compliance and risk management across biomedical and pharmaceutical processes.
Owner:KOGANTI VAMSI KRISHNA CELINA

Cloud deployment automation system with integrated resource orchestration and customizable deployment workflows

A cloud deployment automation system consisting of: a deployment automation device housed in a rack-mountable enclosure, the device comprising: a multi-core orchestration processor configured to execute deployment logic as compiled execution graphs; a storage module operatively coupled to the orchestration processor, the storage storing a set of deployment templates, real-time execution states, telemetry logs, and policy configurations; a secure credential management processing unit embedded in the device, configured to generate, store, and rotate cloud access tokens, API keys, and user-specific credentials, and to provide encrypted access to those credentials during deployment execution; an in-memory workflow execution engine executed by the orchestration processor, configured to analyze a user-defined deployment configuration that includes a declarative specification of infrastructure resources and compile that configuration into a directed acyclic graph (DAG) that represents the resource deployment order, dependency mapping, and rollback relationships, a cloud provider interface subsystem communicatively connected to multiple heterogeneous cloud platforms via appropriate API adapters, the subsystem enabling the orchestration processor to send provisioning requests and receive status events from the platforms; a customizable workflow compiler unit configured to convert graphical workflow definitions or domain-specific language (DSL) scripts into execution sequences that can be used by the workflow execution engine, where the workflow compiler unit supports conditional branching, asynchronous operations, and runtime variable resolution; and A policy enforcement control unit integrated into the deployment automation device, with the policy engine configured to apply organization-specific compliance rules, tagging conventions, security group configurations, and runtime resource limits to all deployment actions in a context-aware manner prior to execution.
Owner:THASON JUSTIN RAJAKUMAR MARIA FAIRFAX

Systems and methods for tag-based policy enforcement for dynamic cloud workloads

Systems and methods for enforcing tag-based policy on dynamic workloads include monitoring, via a cloud-based system, traffic associated with one or more customers of the cloud-based system; receiving a packet from a workload associated with a customer of the one or more customers; performing a tag lookup at one or more nodes of the cloud-based system based on the packet; enforcing one or more policies based on the tag lookup. Based on no tags being found for the workload during the tag lookup at the one or more nodes, the nodes are adapted to drop the packet; query the one or more cloud connectors for workload information; and receive, in a next packet, all tags and a version associated with the workload.
Owner:ZSCALER INC

Systems and methods for network data classification and policy enforcement

This disclosure describes methods, devices and systems for abnormal network data identification and policy enforcement. An example method includes obtaining incoming network data from a network device, the networking data including operating information for the network device and packet metadata. The method also includes classifying the incoming network data using one or more machine learning models, including identifying abnormal network data from the incoming network data. The method further includes causing a policy rule to be generated based on the abnormal network data.
Owner:IP INFUSION INC

Systems and methods for network anomaly detection and policy enforcement

This disclosure describes methods, devices, and systems for network anomaly detection and policy enforcement. An example method includes obtaining metadata for a plurality of network packets. The method also includes detecting an anomaly in the plurality of network packets by analyzing the obtained metadata and the operating information. The method also includes generating, without user input, a policy rule based on the detected anomaly. The method further includes enforcing the policy rule at the one or more network devices.
Owner:IP INFUSION INC

A system for authorizing purchases across multiple channels with dynamic role verification

A system (100) for multi-channel purchase authorization with dynamic role validation, comprising: (a) a multi-channel request capture module configured to receive and standardise purchase requests initiated through a variety of communication channels, including corporate portals, mobile applications, emails and messaging platforms; (b) a role identification and contextual mapping module configured to dynamically retrieve user roles and contextual information based on real-time access management data and organizational hierarchy; c) a policy and rules module configured to evaluate purchase requests based on pre-configured and context-sensitive authorization policies, thresholds and compliance rules; (d) a dynamic role validation and escalation module configured to validate whether the requester has the authority to initiate or authorise a transaction and, if not, to automatically escalate the request to an appropriate authorised role; (e) an authorization workflow orchestration module configured to sequence approval steps, apply business logic, manage parallel or sequential workflows, and interface with external procurement systems; f) and an audit, logging and analytics module configured to record all request, validation and authorization actions in a tamper-proof log and generate real-time insights and compliance metrics, g) where the system enables real-time, role-based purchasing authorization across multiple channels with dynamic policy enforcement and escalation handling.
Owner:DIXIT GAURAV INDIAN LAND

Systems and methods for semantically governed specification-driven interoperability in distribute environments

Disclosed herein are systems and methods for enabling decentralized, schema-driven interoperability across distributed computing environments through the use of a Standard Knowledge Language (SKL). An Enterprise Mesh Platform (EMP) interprets and executes SKL specifications — such as capabilities, objects, mappings, policies, and workflows — as composable, machine-interpretable contracts that define data structures, logic, and governance protocols. The system supports dynamic versioning, validation, semantic linking, and recursive execution of SKL-defined components. A mesh-wide analytics server coordinates execution, issue detection, and resolution propagation. Capabilities can be orchestrated, remediated, and adapted in real-time based on SKL-defined relationships, while preserving compliance and traceability. The disclosed architecture facilitates federated development, adaptive system integration, and fine-grained policy enforcement across complex digital ecosystems.
Owner:COMAKE INC

Intelligent Cognitive AI Based Secure Protocol Channel to Create and Deploy Projects on Demand in Real Time Leveraging Unikernels

ActiveUS20250310352A1Securing communicationConfidentialityUnikernel
This invention introduces a sophisticated system for deploying projects on cloud platforms, combining Unikernels, Cyber Security Mesh Architecture (CSMA), MQTT protocol with SHA256 encryption, an Unikernel Orchestration Rules Engine (UORE), generative AI, and an innovative caching mechanism. Unikernels offer a secure, isolated environment for applications, reducing overhead and boosting performance. CSMA provides extensive security through analytics, identity management, and policy enforcement. The MQTT protocol, secured with SHA256, ensures the integrity and confidentiality of communications. UORE automates deployment, integrating a TLS terminator and data management for streamlined operation. Generative AI proactively resolves deployment challenges, particularly for complex applications, while the caching mechanism enhances performance and efficiency by minimizing latency. This integrated approach automates and secures the deployment process, enabling scalable, efficient, and real-time project creation and deployment in the cloud, thereby addressing the key challenges of cloud application hosting.
Owner:BANK OF AMERICA CORP

Conditional SSH Tunneling as a Policy Enforcement Point for Seamless Zero Trust Integration

Enhanced security for Zero Trust networks is provided by SSH-customized tunnel clients / tunnel servers, a catalog service, and loopback address DNS mechanisms. Systems and methods provide Policy Enforcement Point (PEP) layer enhancements, strategically positioning the PEP between the user and the network resource. It manages network traffic flows and provides moderate control granularity, near-real-time enforcement decisions, low overheads, and broad applicability to TCP / IP traffic through modified tunneling implementations of Secure Shell (SSH). Unique use of SSH tunneling is utilized and adapted to selectively filter tunnel requests based on user entitlements, ensuring secure and authorized access to network resources. This method entails detailed assessment of tunneling requests, DNS manipulation, and the use of loopback address space for traffic redirection, all without requiring modifications to client-side applications. The approach significantly enhances network security by controlling access based on continuous verification of user entitlements, addressing the shortcomings of traditional network security models.
Owner:BANK OF AMERICA CORP

Quality of trust framework for wireless communication networks

Systems, methods, and devices are disclosed herein to identify and deploy policy changes from a policy source in a wireless communication network to enforcement points in the network based on trends identified by the policy source in KPIs reported by the enforcement points. In an implementation, enforcement points in the network report KPIs to the policy source. The KPIs are related to authorization attempts made by user equipment in the network. The policy source, upon receiving the KPIs, identifies a trend in the KPIs and identifies a policy change based on the KPIs. The policy source then deploys the policy change to the enforcement points. In various implementations, the policy source is a Policy Decision Point (PDP), and the enforcement points are Policy Enforcement Points (PEPs).
Owner:T MOBILE INNOVATIONS LLC

Method and apparatus for designing and enforcing a multi-cloud deployment policy for software applications

Provided is an architecture for facilitating creation and enforcement of policy templates. The architecture includes a policy template designer, a script generator, a policy enforcement engine, and a plurality of technology-specific interpreters. The policy template designer records, for creating a policy template, selection of a set of technologies. The script generator generates a policy template script indicative the set of technologies. The policy enforcement engine generates a set of provisioning scripts indicative of a set of resources to be provisioned by the set of technologies. The policy enforcement engine communicates the set of provisioning scripts to a set of technology-specific interpreters of the plurality of technology-specific interpreters. The set of technology-specific interpreters communicate with the set of technologies to provision the set of resources.
Owner:CALIBO LLC

Data processing system and method, and related device

A data processing system and method, and a related device, relating to the technical field of artificial intelligence (AI). The data processing system comprises a general-purpose processor and an AI accelerator card. The general-purpose processor is used for sending an operation request comprising authorization authentication information and requesting to process an AI model deployed in the AI accelerator card. The AI accelerator card is constructed to be provided with a trusted execution environment (TEE), and the AI accelerator card is used for running a policy enforcement point (PEP) component deployed in the TEE, and is further used for receiving the operation request and determining whether the authorization authentication information in the operation request complies with a verification rule in the PEP component, and when the authorization authentication information complies with the verification rule, the first operation request is executed to execute a processing operation on the AI model. In this way, the PEP component is deployed in the TEE of the AI accelerator card, that is, the PEP is deployed in an execution environment closer to the AI model, so that the AI model can be effectively prevented from being illegitimately accessed by the general-purpose processor, thereby ensuring access safety of the AI model in the AI accelerator card.
Owner:HUAWEI TECH CO LTD

Public to Private Mobile Access

This invention provides methods and systems for seamless mobile connectivity between public and private cellular networks. The system dynamically switches user devices between networks based on location, radio signal availability, or preconfigured policies that prioritize private networks when within range. For devices with physical SIM cards, an embedded applet enables switching between operator profiles, while ESIM profiles deploy applets for selecting among multiple identities within a profile. All cellular traffic, whether on public or private networks, is routed through a cloud-based system for centralized security and policy enforcement. Network selection may be influenced by defining the private network as the Home Public Land Mobile Network (HPLMN) or scanning available networks via applet capabilities. The system supports unified subscription, connectivity, and service management via a cloud-based portal, ensuring reliability and security across diverse network environments. This approach enhances mobility, security, and flexibility for enterprise and IoT applications.
Owner:ZSCALER INC

Systems and methods for endpoint process metadata based policy enforcement

Systems and methods for endpoint application metadata based policy enforcement include monitoring traffic via a cloud, the traffic being monitored inline between one or more endpoints and one or more destinations; identifying, within a request from an endpoint, endpoint process metadata associated with an endpoint process used to make the request; processing the endpoint process metadata; and performing one or more actions on the request based on the processing. The endpoint process metadata can be collected by a connector application executing on the one or more endpoints, and forwarded to the cloud in-band therefrom.
Owner:ZSCALER INC

Systems and methods for congestion aware policy enforcement

A device may include a processor configured to detect a Protocol Data Unit (PDU) session associated with a user equipment (UE) device. The processor may be further configured to obtain at least one congestion metric value for a base station associated with the PDU session; determine that the obtained at least one congestion metric value is less than a maximum throughput enforcement threshold; and override a maximum throughput enforcement policy on a User Plane Function (UPF) associated with the UE device, based on determining that the obtained at least one congestion metric value is less than the maximum throughput enforcement threshold.
Owner:VERIZON PATENT & LICENSING INC

System and Method for Policy Enforcement

The technology is generally directed to determining whether candidate digital components violate a policy and using the determination to propagate policy labels. Candidate digital components may be filtered such that only a subset of the candidate digital components is provided to a machine learning model for further policy review. The machine learning model may provide a confidence score associated with the policy violation prediction. The policy violation prediction may be “violates policy” or “does not violate policy.” A label corresponding to the policy violation prediction may be associated with the digital component. The confidence score may be used when determining whether to use the policy violation prediction to propagate labels to other digital components. The labels may be propagated using a seed based enforcement system or a neighborhood based propagation system.
Owner:GOOGLE LLC

Wire-speed routing and policy enforcement without DPI or decryption

A system and computer-implemented method for routing an encrypted packet through a cloud enforcement network based on a metadata tag. The cloud enforcement network applies policy and routing attributions or tags outside of the encrypted packet payload in such a way as to not require an inner packet to first be decrypted. Traffic prioritization, data protection, and per application policies are achieved by using such metadata tags for internode routing without the need for DPI or decryption. Furthermore, the metadata itself can also be signed or encrypted depending on the provenance of the data. As such, applying meta-tagging external to an encrypted packet, the payload would not be needed to be decrypted during transit of the packet to express end-to-end policy and routing decisions.
Owner:CISCO TECHNOLOGY INC

System and method for data compaction utilizing hierarchical behavior codebooks and mismatch probability estimation

Codebook data compaction using hierarchical behavior codebooks to dynamically manage encoding policies and improve entropy encoding methods. A hierarchy of behavior codebooks is maintained, allowing child codebooks to inherit properties from parent codebooks. Behavior codebooks define rules, limitations, and policies for encoding, including sourceblock prioritization and recursive compaction. Conflicts between inherited behaviors are resolved across the hierarchy, and updates to parent codebooks propagate to child codebooks. A behavior codebook manager oversees inheritance validation, policy enforcement, and version control. Data is encoded and decoded using the codebook and the resolved behavior codebooks, ensuring efficient and adaptive data compaction.
Owner:ATOMBEAM TECH INC

Advanced multi-layer access control policy enforcement in a multi-tenant cloud environment

An approach is provided for multi-layer access control policy enforcement in a multi-tenant cloud environment. An advanced policy service is defined in a data container The advanced policy service provides management and validation of an access control policy at multiple levels including an application layer and a low layer, which is at a level lower than the application layer. Using the advanced policy service, a policy definition of the application layer is mapped to an access validation and authorization policy of the low layer. Rules are generated using an analysis of data packets by an eBPF program Using the eBPF program, the policy definition and the rules are applied to a request received from a SaaS application to access a data source. Based on the application of the policy definition and the rules, a data vulnerability is identified and the request is rejected.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Method, apparatus, system and computer program for security processing of multi-agent system

Proposed are a method, an apparatus, a system, and a computer program for security processing of a multi-agent system. More specifically, the present disclosure discloses a method for managing security for a multi-agent system by using a computing apparatus. The method includes establishing an execution plan comprising a plurality of agents to perform a request of a user on the basis of the request, executing one or more agents among the plurality of agents according to the execution plan, and providing a response to the request of the user on the basis of an execution result of the one or more agents among the plurality of agents, wherein access to or input / output of the one or more agents is controlled through a policy enforcement point that enforces a security policy for the one or more agents among the plurality of agents.
Owner:SAMSUNG SDS CO LTD

Virtualized Policy & Charging System

A network system for providing one or more services to one or more end-user devices communicatively coupled to the network system over a wireless access network. The network system includes a policy enforcement function, a policy element, and a network element communicatively coupled to the policy enforcement function and the policy element, and configured to communicate policy information between the policy enforcement function and the policy element, the policy element includes a virtual policy element instance or thread that executes in a policy element cloud system, and the network element includes a load balancer configured to select or assign the virtual policy element instance or thread for communication of the policy information.
Owner:HEADWATER RESEARCH LLC

Off-Chain Gas Management System and Method

An off-chain gas management system allows Web3 developers to cover gas fees for their users. When a user wants to complete a blockchain transaction, the system receives a sponsorship request through an API and checks if the operation qualifies under the developer's gas sponsorship policy. Policies include spending limits, approved addresses, and time restrictions. If approved, the system creates a cryptographic signature that authorizes transfer of the gas fee amount. An on-chain contract validates the signature before covering the gas fees. The system includes a user interface for creating and managing policies with configurable spending controls and address restrictions. Advanced features use machine learning to allocate funds based on user value, detect fraud, classify transaction types, optimize cryptocurrency purchases, and predict when funds will run out. This eliminates the barrier of users needing to own cryptocurrency to pay gas fees while maintaining security through automated policy enforcement and cryptographic validation.
Owner:ALCHEMY INSIGHTS INC

Method for application access in zero trust campus network

Disclosed herein are system, method, and computer program product aspects for providing an agent-based zero trust network access (ZTNA) remote device access to a campus network. Some aspects of this disclosure relate to a universal network access application including a memory and a processor. The processor is configured to receive an authentication request from a client device and in response to receiving the authentication request, retrieve a set of network policies indicating an Internet protocol (IP) address and a port number based on the authentication request. The processor is further configured to transmit the set of network policies to a policy enforcement application in a campus network.
Owner:EXTREME NETWORKS INC

Terminal access permission analysis method and system based on zero-trust ABAC model

The application discloses a terminal access permission analysis method and system based on a zero-trust ABAC model, and the method comprises the following steps: a user terminal sends a resource access request; a policy enforcement point (PEP) receives the resource access request sent by the user terminal; according to a preset collection requirement, multi-dimensional attributes are extracted from the user request, the user request is converted into an attribute request, and the attribute request is sent to a policy decision point (PDP); the attributes comprise user attributes, environment attributes, operation attributes and object attributes; the PDP performs access permission analysis by using a policy administration point (PAP) based on the attribute request, obtains an access permission analysis result, and feeds back the access permission analysis result to the PEP; the information fed back by the PDP to the PEP comprises permission, rejection, inapplicability and unknown; and the PEP executes the resource access request according to the feedback information received from the PDP. The application is based on a zero-trust technical framework, and fine management of permissions is realized by ABAC, so that the changing business requirements and security challenges can be effectively coped with.
Owner:ELECTRIC POWER RES INST STATE GRID SHANXI ELECTRIC POWER