Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

118 results about "Policy enforcement" patented technology

Systems and methods for semantically governed specification-driven interoperability in distributed environments

Disclosed herein are systems and methods for enabling decentralized, schema-driven interoperability across distributed computing environments through the use of a Standard Knowledge Language (SKL). An Enterprise Mesh Platform (EMP) interprets and executes SKL specifications—such as capabilities, objects, mappings, policies, and workflows—as composable, machine-interpretable contracts that define data structures, logic, and governance protocols. The system supports dynamic versioning, validation, semantic linking, and recursive execution of SKL-defined components. A mesh-wide analytics server coordinates execution, issue detection, and resolution propagation. Capabilities can be orchestrated, remediated, and adapted in real-time based on SKL-defined relationships, while preserving compliance and traceability. The disclosed architecture facilitates federated development, adaptive system integration, and fine-grained policy enforcement across complex digital ecosystems.
Owner:COMAKE INC

Systems and methods for network data classification and policy enforcement

This disclosure describes methods, devices and systems for abnormal network data identification and policy enforcement. An example method includes obtaining incoming network data from a network device, the networking data including operating information for the network device and packet metadata. The method also includes classifying the incoming network data using one or more machine learning models, including identifying abnormal network data from the incoming network data. The method further includes causing a policy rule to be generated based on the abnormal network data.
Owner:IP INFUSION INC

Systems and methods for network anomaly detection and policy enforcement

This disclosure describes methods, devices, and systems for network anomaly detection and policy enforcement. An example method includes obtaining metadata for a plurality of network packets. The method also includes detecting an anomaly in the plurality of network packets by analyzing the obtained metadata and the operating information. The method also includes generating, without user input, a policy rule based on the detected anomaly. The method further includes enforcing the policy rule at the one or more network devices.
Owner:IP INFUSION INC

Systems and methods for semantically governed specification-driven interoperability in distribute environments

Disclosed herein are systems and methods for enabling decentralized, schema-driven interoperability across distributed computing environments through the use of a Standard Knowledge Language (SKL). An Enterprise Mesh Platform (EMP) interprets and executes SKL specifications — such as capabilities, objects, mappings, policies, and workflows — as composable, machine-interpretable contracts that define data structures, logic, and governance protocols. The system supports dynamic versioning, validation, semantic linking, and recursive execution of SKL-defined components. A mesh-wide analytics server coordinates execution, issue detection, and resolution propagation. Capabilities can be orchestrated, remediated, and adapted in real-time based on SKL-defined relationships, while preserving compliance and traceability. The disclosed architecture facilitates federated development, adaptive system integration, and fine-grained policy enforcement across complex digital ecosystems.
Owner:COMAKE INC

Data processing system and method, and related device

A data processing system and method, and a related device, relating to the technical field of artificial intelligence (AI). The data processing system comprises a general-purpose processor and an AI accelerator card. The general-purpose processor is used for sending an operation request comprising authorization authentication information and requesting to process an AI model deployed in the AI accelerator card. The AI accelerator card is constructed to be provided with a trusted execution environment (TEE), and the AI accelerator card is used for running a policy enforcement point (PEP) component deployed in the TEE, and is further used for receiving the operation request and determining whether the authorization authentication information in the operation request complies with a verification rule in the PEP component, and when the authorization authentication information complies with the verification rule, the first operation request is executed to execute a processing operation on the AI model. In this way, the PEP component is deployed in the TEE of the AI accelerator card, that is, the PEP is deployed in an execution environment closer to the AI model, so that the AI model can be effectively prevented from being illegitimately accessed by the general-purpose processor, thereby ensuring access safety of the AI model in the AI accelerator card.
Owner:HUAWEI TECH CO LTD

Public to Private Mobile Access

This invention provides methods and systems for seamless mobile connectivity between public and private cellular networks. The system dynamically switches user devices between networks based on location, radio signal availability, or preconfigured policies that prioritize private networks when within range. For devices with physical SIM cards, an embedded applet enables switching between operator profiles, while ESIM profiles deploy applets for selecting among multiple identities within a profile. All cellular traffic, whether on public or private networks, is routed through a cloud-based system for centralized security and policy enforcement. Network selection may be influenced by defining the private network as the Home Public Land Mobile Network (HPLMN) or scanning available networks via applet capabilities. The system supports unified subscription, connectivity, and service management via a cloud-based portal, ensuring reliability and security across diverse network environments. This approach enhances mobility, security, and flexibility for enterprise and IoT applications.
Owner:ZSCALER INC

Systems and methods for congestion aware policy enforcement

A device may include a processor configured to detect a Protocol Data Unit (PDU) session associated with a user equipment (UE) device. The processor may be further configured to obtain at least one congestion metric value for a base station associated with the PDU session; determine that the obtained at least one congestion metric value is less than a maximum throughput enforcement threshold; and override a maximum throughput enforcement policy on a User Plane Function (UPF) associated with the UE device, based on determining that the obtained at least one congestion metric value is less than the maximum throughput enforcement threshold.
Owner:VERIZON PATENT & LICENSING INC

Wire-speed routing and policy enforcement without DPI or decryption

A system and computer-implemented method for routing an encrypted packet through a cloud enforcement network based on a metadata tag. The cloud enforcement network applies policy and routing attributions or tags outside of the encrypted packet payload in such a way as to not require an inner packet to first be decrypted. Traffic prioritization, data protection, and per application policies are achieved by using such metadata tags for internode routing without the need for DPI or decryption. Furthermore, the metadata itself can also be signed or encrypted depending on the provenance of the data. As such, applying meta-tagging external to an encrypted packet, the payload would not be needed to be decrypted during transit of the packet to express end-to-end policy and routing decisions.
Owner:CISCO TECHNOLOGY INC

Advanced multi-layer access control policy enforcement in a multi-tenant cloud environment

An approach is provided for multi-layer access control policy enforcement in a multi-tenant cloud environment. An advanced policy service is defined in a data container The advanced policy service provides management and validation of an access control policy at multiple levels including an application layer and a low layer, which is at a level lower than the application layer. Using the advanced policy service, a policy definition of the application layer is mapped to an access validation and authorization policy of the low layer. Rules are generated using an analysis of data packets by an eBPF program Using the eBPF program, the policy definition and the rules are applied to a request received from a SaaS application to access a data source. Based on the application of the policy definition and the rules, a data vulnerability is identified and the request is rejected.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Method, apparatus, system and computer program for security processing of multi-agent system

Proposed are a method, an apparatus, a system, and a computer program for security processing of a multi-agent system. More specifically, the present disclosure discloses a method for managing security for a multi-agent system by using a computing apparatus. The method includes establishing an execution plan comprising a plurality of agents to perform a request of a user on the basis of the request, executing one or more agents among the plurality of agents according to the execution plan, and providing a response to the request of the user on the basis of an execution result of the one or more agents among the plurality of agents, wherein access to or input / output of the one or more agents is controlled through a policy enforcement point that enforces a security policy for the one or more agents among the plurality of agents.
Owner:SAMSUNG SDS CO LTD

Off-Chain Gas Management System and Method

An off-chain gas management system allows Web3 developers to cover gas fees for their users. When a user wants to complete a blockchain transaction, the system receives a sponsorship request through an API and checks if the operation qualifies under the developer's gas sponsorship policy. Policies include spending limits, approved addresses, and time restrictions. If approved, the system creates a cryptographic signature that authorizes transfer of the gas fee amount. An on-chain contract validates the signature before covering the gas fees. The system includes a user interface for creating and managing policies with configurable spending controls and address restrictions. Advanced features use machine learning to allocate funds based on user value, detect fraud, classify transaction types, optimize cryptocurrency purchases, and predict when funds will run out. This eliminates the barrier of users needing to own cryptocurrency to pay gas fees while maintaining security through automated policy enforcement and cryptographic validation.
Owner:ALCHEMY INSIGHTS INC

Method for application access in zero trust campus network

PendingUS20260095485A1Securing communicationEngineeringCampus network
Disclosed herein are system, method, and computer program product aspects for providing an agent-based zero trust network access (ZTNA) remote device access to a campus network. Some aspects of this disclosure relate to a universal network access application including a memory and a processor. The processor is configured to receive an authentication request from a client device and in response to receiving the authentication request, retrieve a set of network policies indicating an Internet protocol (IP) address and a port number based on the authentication request. The processor is further configured to transmit the set of network policies to a policy enforcement application in a campus network.
Owner:EXTREME NETWORKS INC

Terminal access permission analysis method and system based on zero-trust ABAC model

The application discloses a terminal access permission analysis method and system based on a zero-trust ABAC model, and the method comprises the following steps: a user terminal sends a resource access request; a policy enforcement point (PEP) receives the resource access request sent by the user terminal; according to a preset collection requirement, multi-dimensional attributes are extracted from the user request, the user request is converted into an attribute request, and the attribute request is sent to a policy decision point (PDP); the attributes comprise user attributes, environment attributes, operation attributes and object attributes; the PDP performs access permission analysis by using a policy administration point (PAP) based on the attribute request, obtains an access permission analysis result, and feeds back the access permission analysis result to the PEP; the information fed back by the PDP to the PEP comprises permission, rejection, inapplicability and unknown; and the PEP executes the resource access request according to the feedback information received from the PDP. The application is based on a zero-trust technical framework, and fine management of permissions is realized by ABAC, so that the changing business requirements and security challenges can be effectively coped with.
Owner:ELECTRIC POWER RES INST STATE GRID SHANXI ELECTRIC POWER

Method for monitoring and enforcing secure policies in a device

A method for monitoring and enforcing secure policies in a device includes collecting kernel data from a kernel space by a packet filtering module operating in a user space. The kernel data is processed into events that are transmitted to a data bus, where the events are stored and provided to a policy enforcement module. The policy enforcement module evaluates the events with an algorithm to detect potential threat events. When a threat event is identified, one or more secure policies are selected and executed in the device as corresponding actions or commands. The method enables real-time monitoring of kernel activity and enforcement of security policies while maintaining the architecture in user space.
Owner:EXEIN SPA

installing a selected role of a concern source

Embodiments of the present disclosure relate to installing a selected attention source role policy. In some examples, a processing resource converts an attention target role policy to a plurality of attention source role policies and selects a set of attention source role policies from the plurality of attention source role policies based on a source network address and a target network address in a first data packet. The processing resource installs the set of selected attention source role policies in a policy enforcement hardware controller of a policy implemented in an ingress network device for a source computing entity, the policy enforcement hardware controller to enforce an attention source role policy of the set of selected attention source role policies at the ingress network device in response to a second data packet received from the source computing entity.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Conditional ssh tunneling as a policy enforcement point for seamless zero trust integration

Enhanced security for Zero Trust networks is provided by SSH-customized tunnel clients / tunnel servers, a catalog service, and loopback address DNS mechanisms. Systems and methods provide Policy Enforcement Point (PEP) layer enhancements, strategically positioning the PEP between the user and the network resource. It manages network traffic flows and provides moderate control granularity, near-real-time enforcement decisions, low overheads, and broad applicability to TCP / IP traffic through modified tunneling implementations of Secure Shell (SSH). Unique use of SSH tunneling is utilized and adapted to selectively filter tunnel requests based on user entitlements, ensuring secure and authorized access to network resources. This method entails detailed assessment of tunneling requests, DNS manipulation, and the use of loopback address space for traffic redirection, all without requiring modifications to client-side applications. The approach significantly enhances network security by controlling access based on continuous verification of user entitlements, addressing the shortcomings of traditional network security models.
Owner:BANK OF AMERICA CORP

Configurable options for device registration in wireless communication networks

Technology is disclosed herein for registering a user device for access to a wireless network. In an implementation, a session manager of a wireless network receives a registration request for access to the network from a user device. The session manager determines a workflow configuration for the access based on parameters relating to the registration request. Prior to sending a request for an access session to a policy enforcement function, the session manager selects a traffic routing function of the wireless network for device access to the network and requests a traffic management session from the traffic routing function. The session manager sends a request for an access session to the policy enforcement function which includes traffic routing information. The session manager sends the user device information by which the user device can access the wireless network.
Owner:T MOBILE INNOVATIONS LLC

Systems and methods for congestion aware policy enforcement

A method includes detecting a communication session in a wireless network and obtaining at least one resource utilization metric associated with the communication session. The method further includes determining, based on the at least one resource utilization metric, that network resources associated with the communication session are underutilized, and relaxing a performance-limiting policy associated with the communication session based on determining that the network resources are underutilized. The method may further include detecting a triggering condition associated with the communication session and initiating an inspection of data associated with the communication session in response to detecting the triggering condition. The method may also include detecting an anomalous condition based on the inspection and generating an alert based on detecting the anomalous condition.
Owner:VERIZON PATENT & LICENSING INC

Cross-System Object Policy Enforcement In Distributed Storage Environments

Systems and methods of maintaining a policy implementation for an object across different storage systems are disclosed. The method includes determining, for an object to be copied from a first storage system, one or more object policies that are applicable to the object; generating metadata that triggers application of the one or more policies at an other storage system that is different from the first storage system; and including the metadata with the object during copying of the object.
Owner:PURE STORAGE INC

Systems and methods for agentic policy enforcement

Systems and methods for policy enforcement within an artificial intelligence (AI) agentic workflow. Each action within the AI agentic workflow is intercepted by a run-time enforcement engine. Utilizing security labels for each component within the AI agentic workflow, the run-time enforcement engine cross-references the security labels against a policy to ensure an action taken by a component within the AI agentic workflow is authorized under the policy.
Owner:BRICKLAYER AI INC

Out-of-band policy enforcement for data processing systems using activity data

Methods and systems for managing operation of a data processing system are disclosed. Activity data for hardware resources of the data processing system may be obtained while the hardware resources are providing computer-implemented services to a user of the data processing system. The activity data may be analyzed to characterize use of the hardware resources by the user with respect to policies for the data processing system. The hardware resources may be adapted to independently enforce the policies when operating nominally; however, when the hardware resources are not operating nominally, a management controller of the data processing system may initiate performance of a policy enforcement process based on the characterized use of the hardware resources to modify provisioning of a portion of the computer-implemented services to the user.
Owner:DELL PROD LP

Device for the safe hybrid execution of context-aware deployments of large language models (LLM)

Device for the secure hybrid execution of context-aware Large Language Model (LLM) deployments, comprising: an edge execution unit (101) configured to execute at least a first part of an LLM inference process on a local device; a cloud inference processing unit (102) configured to execute at least a second part of the LLM inference process on a remote computing infrastructure; a context sensitivity analyzer (103) configured to analyze an input query and associated context data and generate a sensitivity classification for said context data;a hybrid execution orchestration engine (104) that functions with the context sensitivity analyzer (103), the edge execution unit (101), and the cloud inference processing unit (102), wherein the hybrid execution orchestration engine (104) is configured to dynamically split the LLM inference process into an edge-executed part and a cloud-executed part, based on at least the sensitivity classification; a secure communication interface (105) configured to transmit intermediate inference outputs between the edge execution unit (101) and the cloud inference processing unit (102) over an encrypted communication channel; a TEE module (106) integrated into the edge execution unit (101) to perform at least one privacy-relevant inference operation in an isolated, hardware-protected environment;a key management and encryption controller (107) configured to generate, store, distribute, and rotate cryptographic keys and to encrypt and decrypt intermediate inference outputs transmitted between the edge execution unit (101) and the cloud inference processing unit (102); a policy enforcement and access control unit (108) configured to validate user authorization and enforce execution policies that define whether at least some of the context data is restricted to local execution;and an audit logging and threat monitoring module (109) configured to record inference execution events, security decisions, policy enforcement events and communication events and detect anomalous behavior related to the LLM inference process, wherein the device securely generates an output response to the input query by performing context-aware LLM inference while preventing sensitive context data from being disclosed to unauthorized external environments.
Owner:ADEPU GANESH +2

Advanced multi-layer access control policy enforcement in a multi-tenant cloud environment

An approach is provided for multi-layer access control policy enforcement in a multi-tenant cloud environment. An advanced policy service is defined in a data container The advanced policy service provides management and validation of an access control policy at multiple levels including an application layer and a low layer, which is at a level lower than the application layer. Using the advanced policy service, a policy definition of the application layer is mapped to an access validation and authorization policy of the low layer. Rules are generated using an analysis of data packets by an eBPF program Using the eBPF program, the policy definition and the rules are applied to a request received from a SaaS application to access a data source. Based on the application of the policy definition and the rules, a data vulnerability is identified and the request is rejected.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Systems and methods for endpoint process metadata based policy enforcement

Systems and methods for endpoint application metadata based policy enforcement include monitoring traffic via a cloud, the traffic being monitored inline between one or more endpoints and one or more destinations; identifying, within a request from an endpoint, endpoint process metadata associated with an endpoint process used to make the request; processing the endpoint process metadata; and performing one or more actions on the request based on the processing. The endpoint process metadata can be collected by a connector application executing on the one or more endpoints, and forwarded to the cloud in-band therefrom.
Owner:ZSCALER INC

Location-based policy enforcement for data processing systems using out-of-band methods

Methods and systems for managing a data processing system are disclosed. A management controller of the data processing system may obtain location data for the data processing system via an out-of-band communication channel. The management controller may identify policies based on the location data, and make an identification regarding whether the data processing system is operating out of compliance with respect to the policies. If the data processing system is operating out of compliance, then the management controller may perform an action set to update operation of the data processing system in a manner that improves compliance of the data processing system with respect to the policies. The data processing system may provide computer-implemented services based on the updated operation.
Owner:DELL PROD LP

Policy enforcement assistant

PendingUS20260254855A1PathPingNetwork management
A policy enforcement assistant is provided to assist in identifying and implementing configuration changes within a network. The policy enforcement assistant can receive inputs such as administrator inputs, and can determine intent indications based on the inputs, wherein the intent indications indicate configuration change intents affecting the network. The policy enforcement assistant can identify, based on an intent indication, multiple configuration changes under an applicable network policy. The policy enforcement assistant can furthermore identify implementation paths for each of the configuration changes. The implementation paths can use different network management tools to implement the configuration changes. The policy enforcement assistant can either execute the configuration changes via the implementation paths or instruct a user regarding executing the configuration changes.
Owner:CISCO TECHNOLOGY INC

Systems, mobile terminals, servers, methods, and programs

PendingJP2026109509ATerminal serverControl cell
This invention provides a system, mobile terminal, server, method, and program for autonomously and efficiently controlling the operation of various functions in IoT devices in an environment where different laws and safety regulations exist in each country. [Solution] A system comprising a mobile terminal 10 and a server 20, wherein the mobile terminal includes an acquisition unit for acquiring the current location, a determination unit for determining the country, and a control unit for controlling data processing functions. The server includes a storage unit for storing territorial operational policies corresponding to the country. The control unit acquires the territorial operational policy corresponding to the country determined by the determination unit from the server and automatically controls the operation of the data processing functions according to that policy. The territorial operational policy can be configured as a rule set that defines conditions and actions in pairs, and the control unit can function as a policy enforcement engine that interprets, evaluates, and executes the policy, thereby flexibly and reliably responding to complex regulations.
Owner:MIXI INC

Indexing entities and attributes for policy enforcement

Embodiments index entities and attributes for policy enforcement. A plurality of policies and a plurality of entities may be collected for a computing environment. Indexes may be obtained based on features of the plurality of entities such that each entry in the indexes may be associated with a feature of an entity and portions of the plurality of policies. An authorization request may be employed to: collect authorization attributes based on the authorization request; collect index entries from the indexes based on the authorization attributes such that the authorization attributes correspond to entity features associated with the index entries; collecting policies based on the index entries such that each policy may be associated with at least one index entry.
Owner:DELINEA INC