Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

73 results about "Policy enforcement" patented technology

Systems and methods for congestion aware policy enforcement

A device may include a processor configured to detect a Protocol Data Unit (PDU) session associated with a user equipment (UE) device. The processor may be further configured to obtain at least one congestion metric value for a base station associated with the PDU session; determine that the obtained at least one congestion metric value is less than a maximum throughput enforcement threshold; and override a maximum throughput enforcement policy on a User Plane Function (UPF) associated with the UE device, based on determining that the obtained at least one congestion metric value is less than the maximum throughput enforcement threshold.
Owner:VERIZON PATENT & LICENSING INC

Method for application access in zero trust campus network

PendingUS20260095485A1Securing communicationEngineeringCampus network
Disclosed herein are system, method, and computer program product aspects for providing an agent-based zero trust network access (ZTNA) remote device access to a campus network. Some aspects of this disclosure relate to a universal network access application including a memory and a processor. The processor is configured to receive an authentication request from a client device and in response to receiving the authentication request, retrieve a set of network policies indicating an Internet protocol (IP) address and a port number based on the authentication request. The processor is further configured to transmit the set of network policies to a policy enforcement application in a campus network.
Owner:EXTREME NETWORKS INC

Method for monitoring and enforcing secure policies in a device

A method for monitoring and enforcing secure policies in a device includes collecting kernel data from a kernel space by a packet filtering module operating in a user space. The kernel data is processed into events that are transmitted to a data bus, where the events are stored and provided to a policy enforcement module. The policy enforcement module evaluates the events with an algorithm to detect potential threat events. When a threat event is identified, one or more secure policies are selected and executed in the device as corresponding actions or commands. The method enables real-time monitoring of kernel activity and enforcement of security policies while maintaining the architecture in user space.
Owner:EXEIN SPA

Conditional ssh tunneling as a policy enforcement point for seamless zero trust integration

Enhanced security for Zero Trust networks is provided by SSH-customized tunnel clients / tunnel servers, a catalog service, and loopback address DNS mechanisms. Systems and methods provide Policy Enforcement Point (PEP) layer enhancements, strategically positioning the PEP between the user and the network resource. It manages network traffic flows and provides moderate control granularity, near-real-time enforcement decisions, low overheads, and broad applicability to TCP / IP traffic through modified tunneling implementations of Secure Shell (SSH). Unique use of SSH tunneling is utilized and adapted to selectively filter tunnel requests based on user entitlements, ensuring secure and authorized access to network resources. This method entails detailed assessment of tunneling requests, DNS manipulation, and the use of loopback address space for traffic redirection, all without requiring modifications to client-side applications. The approach significantly enhances network security by controlling access based on continuous verification of user entitlements, addressing the shortcomings of traditional network security models.
Owner:BANK OF AMERICA CORP

Configurable options for device registration in wireless communication networks

Technology is disclosed herein for registering a user device for access to a wireless network. In an implementation, a session manager of a wireless network receives a registration request for access to the network from a user device. The session manager determines a workflow configuration for the access based on parameters relating to the registration request. Prior to sending a request for an access session to a policy enforcement function, the session manager selects a traffic routing function of the wireless network for device access to the network and requests a traffic management session from the traffic routing function. The session manager sends a request for an access session to the policy enforcement function which includes traffic routing information. The session manager sends the user device information by which the user device can access the wireless network.
Owner:T MOBILE INNOVATIONS LLC

Systems and methods for congestion aware policy enforcement

A method includes detecting a communication session in a wireless network and obtaining at least one resource utilization metric associated with the communication session. The method further includes determining, based on the at least one resource utilization metric, that network resources associated with the communication session are underutilized, and relaxing a performance-limiting policy associated with the communication session based on determining that the network resources are underutilized. The method may further include detecting a triggering condition associated with the communication session and initiating an inspection of data associated with the communication session in response to detecting the triggering condition. The method may also include detecting an anomalous condition based on the inspection and generating an alert based on detecting the anomalous condition.
Owner:VERIZON PATENT & LICENSING INC

Systems and methods for agentic policy enforcement

Systems and methods for policy enforcement within an artificial intelligence (AI) agentic workflow. Each action within the AI agentic workflow is intercepted by a run-time enforcement engine. Utilizing security labels for each component within the AI agentic workflow, the run-time enforcement engine cross-references the security labels against a policy to ensure an action taken by a component within the AI agentic workflow is authorized under the policy.
Owner:BRICKLAYER AI INC

Out-of-band policy enforcement for data processing systems using activity data

Methods and systems for managing operation of a data processing system are disclosed. Activity data for hardware resources of the data processing system may be obtained while the hardware resources are providing computer-implemented services to a user of the data processing system. The activity data may be analyzed to characterize use of the hardware resources by the user with respect to policies for the data processing system. The hardware resources may be adapted to independently enforce the policies when operating nominally; however, when the hardware resources are not operating nominally, a management controller of the data processing system may initiate performance of a policy enforcement process based on the characterized use of the hardware resources to modify provisioning of a portion of the computer-implemented services to the user.
Owner:DELL PROD LP

Device for the safe hybrid execution of context-aware deployments of large language models (LLM)

Device for the secure hybrid execution of context-aware Large Language Model (LLM) deployments, comprising: an edge execution unit (101) configured to execute at least a first part of an LLM inference process on a local device; a cloud inference processing unit (102) configured to execute at least a second part of the LLM inference process on a remote computing infrastructure; a context sensitivity analyzer (103) configured to analyze an input query and associated context data and generate a sensitivity classification for said context data;a hybrid execution orchestration engine (104) that functions with the context sensitivity analyzer (103), the edge execution unit (101), and the cloud inference processing unit (102), wherein the hybrid execution orchestration engine (104) is configured to dynamically split the LLM inference process into an edge-executed part and a cloud-executed part, based on at least the sensitivity classification; a secure communication interface (105) configured to transmit intermediate inference outputs between the edge execution unit (101) and the cloud inference processing unit (102) over an encrypted communication channel; a TEE module (106) integrated into the edge execution unit (101) to perform at least one privacy-relevant inference operation in an isolated, hardware-protected environment;a key management and encryption controller (107) configured to generate, store, distribute, and rotate cryptographic keys and to encrypt and decrypt intermediate inference outputs transmitted between the edge execution unit (101) and the cloud inference processing unit (102); a policy enforcement and access control unit (108) configured to validate user authorization and enforce execution policies that define whether at least some of the context data is restricted to local execution;and an audit logging and threat monitoring module (109) configured to record inference execution events, security decisions, policy enforcement events and communication events and detect anomalous behavior related to the LLM inference process, wherein the device securely generates an output response to the input query by performing context-aware LLM inference while preventing sensitive context data from being disclosed to unauthorized external environments.
Owner:ADEPU GANESH +2

Advanced multi-layer access control policy enforcement in a multi-tenant cloud environment

An approach is provided for multi-layer access control policy enforcement in a multi-tenant cloud environment. An advanced policy service is defined in a data container The advanced policy service provides management and validation of an access control policy at multiple levels including an application layer and a low layer, which is at a level lower than the application layer. Using the advanced policy service, a policy definition of the application layer is mapped to an access validation and authorization policy of the low layer. Rules are generated using an analysis of data packets by an eBPF program Using the eBPF program, the policy definition and the rules are applied to a request received from a SaaS application to access a data source. Based on the application of the policy definition and the rules, a data vulnerability is identified and the request is rejected.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Systems and methods for endpoint process metadata based policy enforcement

Systems and methods for endpoint application metadata based policy enforcement include monitoring traffic via a cloud, the traffic being monitored inline between one or more endpoints and one or more destinations; identifying, within a request from an endpoint, endpoint process metadata associated with an endpoint process used to make the request; processing the endpoint process metadata; and performing one or more actions on the request based on the processing. The endpoint process metadata can be collected by a connector application executing on the one or more endpoints, and forwarded to the cloud in-band therefrom.
Owner:ZSCALER INC

Location-based policy enforcement for data processing systems using out-of-band methods

Methods and systems for managing a data processing system are disclosed. A management controller of the data processing system may obtain location data for the data processing system via an out-of-band communication channel. The management controller may identify policies based on the location data, and make an identification regarding whether the data processing system is operating out of compliance with respect to the policies. If the data processing system is operating out of compliance, then the management controller may perform an action set to update operation of the data processing system in a manner that improves compliance of the data processing system with respect to the policies. The data processing system may provide computer-implemented services based on the updated operation.
Owner:DELL PROD LP

Systems, mobile terminals, servers, methods, and programs

PendingJP2026109509ATerminal serverControl cell
This invention provides a system, mobile terminal, server, method, and program for autonomously and efficiently controlling the operation of various functions in IoT devices in an environment where different laws and safety regulations exist in each country. [Solution] A system comprising a mobile terminal 10 and a server 20, wherein the mobile terminal includes an acquisition unit for acquiring the current location, a determination unit for determining the country, and a control unit for controlling data processing functions. The server includes a storage unit for storing territorial operational policies corresponding to the country. The control unit acquires the territorial operational policy corresponding to the country determined by the determination unit from the server and automatically controls the operation of the data processing functions according to that policy. The territorial operational policy can be configured as a rule set that defines conditions and actions in pairs, and the control unit can function as a policy enforcement engine that interprets, evaluates, and executes the policy, thereby flexibly and reliably responding to complex regulations.
Owner:MIXI INC

Indexing entities and attributes for policy enforcement

Embodiments index entities and attributes for policy enforcement. A plurality of policies and a plurality of entities may be collected for a computing environment. Indexes may be obtained based on features of the plurality of entities such that each entry in the indexes may be associated with a feature of an entity and portions of the plurality of policies. An authorization request may be employed to: collect authorization attributes based on the authorization request; collect index entries from the indexes based on the authorization attributes such that the authorization attributes correspond to entity features associated with the index entries; collecting policies based on the index entries such that each policy may be associated with at least one index entry.
Owner:DELINEA INC

Dynamic policy enforcement for cloud-based applications in an enterprise environment

Provided herein are techniques to facilitate dynamic policy enforcement for cloud-based applications in an enterprise environment. In one example, a method may include obtaining, from a cloud network of a cloud-based application, an authentication request associated with an enterprise user that is seeking to utilize the cloud-based application, wherein the authentication request comprises an application identifier and a vulnerability index associated with the cloud-based application; identifying one or more vulnerabilities of the cloud-based application based on the application identifier and the vulnerability index; determining an access level for which the cloud-based application is allowed to access the enterprise network based, at least in part, on one or more vulnerabilities of the cloud-based application and one or more access rules associated with the cloud-based application; and sending a response to the cloud network indicating the access level for which the cloud-based application is allowed to access the enterprise network.
Owner:CISCO TECHNOLOGY INC

Governance and data protection in use of generative artificial intelligence

A method for governing a generative artificial intelligence (Gen AI) application interaction. Input destined to a Gen AI application via a user interface is received and temporarily stored in a proxy. A policy screening is applied on the input for categorizing the input into one of ‘allow’, ‘ask’ and ‘block’ categories. At least one policy enforcement action is performed depending on the categorization of the input, the policy enforcement action resulting either releasing the input from the proxy to the Gen AI application or blocking the input from being forwarded to the Gen AI application. All interaction with Gen AI is logged.
Owner:NROC SECURITY OY

Method for managing classroom internet surfing of students

PendingCN121968105Aavoid internetMeet the needs of teachingSecurity arrangementSecuring communicationWireless controlTelecommunications
The invention discloses a method for managing classroom internet access of students, which comprises the following steps of: in a training stage, starting a training mode on a teacher terminal, accessing all network resources required to be accessed in teaching once, collecting destination IP addresses accessed by the network resources in a training process through a wireless control point, generating a plurality of ACLs (Access Control Lists), and then issuing the ACLs to a wireless strategy execution point; in the control stage, the network access behavior of the teacher is executed according to an original strategy of a school, the network access behavior of the student is matched with the ACL on a wireless strategy execution point to realize screening, and unmatched network messages are discarded, so that the access of the student to network resources is limited; in the releasing stage, the wireless control point revokes the ACL issued by the class, and the student internet access control recovers to the original state. According to the system and the method, the network access behaviors of the students in the class through the campus Wi-Fi network can be managed, so that the teachers in each class can conveniently formulate the network access management strategy of the class, and the network access management strategy takes effect in real time.
Owner:NANJING AUDIT UNIV

Policy enforcement and visibility by open APIs

The disclosed technology teaches keeping up with the deployment of APIs, so that Secure Access Service Edge (SASE) protection is afforded, parsing an OpenAPI specification for an API family, for identifying overall attributes of the API family. The technology includes parsing an OpenAPI specification to extract usable attributes of API resources, which are useful for building a connector, including extracting attributes of core activities that trigger protective actions, and applying a connection creator that performs actions including accessing a template for creating connector rules and using the extracted attributes with the template to produce the connector rules, thereby automating generation of connectors. Using the connector rules for the SASE protection is also taught.
Owner:NETSKOPE INC

Feature sharing and handoff for power optimization

Described herein are devices, systems, methods, and processes for intelligently managing power consumption in a network by allocating a power budget for packet processing. The power budget can be allocated based on criticality and / or the trust level of the flow. A network device may determine which subsets of features can be executed within the power budget for specific flows. Network devices can signal their capability to run features based on power consumption and adherence to the power budget, allowing for cooperative end-to-end power-based decision-making and policy enforcement. Network devices unable to run all features can select a subset of the features within their power budget and a viable path where other network devices can execute the missing features. Source route information can be added to indicate the path and missing features to be executed by network devices down the segment routing path.
Owner:CISCO TECHNOLOGY INC

Control apparatus and control method

A control apparatus is provided in a vehicle system logically divided into a plurality of partitions. The control apparatus includes: a semantic kernel (SK) that controls, based on a static policy, communication access between two partitions 64 among a plurality of partitions; a policy decision point (PDP) that controls the communication access between the two partitions based on a dynamic policy, and a policy enforcement point (PEP) that controls the communication access between the two partitions based on the control result of the PDP. When a predetermined condition is satisfied, the PEP forces the SK to use the dynamic policy instead of a part of the static policy.
Owner:PANASONIC AUTOMOTIVE SYST CO LTD

System for zero-trust cloud security with AI security analytics and cryptographic identity verification

A system (100) for zero-trust cloud security with AI security analytics and cryptographic identity assurance, wherein the system (100) comprises: a policy enforcement module (1) configured to forward access requests to cloud resources; an identity assurance module (2) configured to establish the cryptographic identity of a user, device and / or workload; a policy decision module (3) configured to make an access decision based on one or more zero trust policies and contextual attributes; a telemetry acquisition module (4) configured to acquire security telemetry data from cloud resources and the policy enforcement module (1); a KL security analysis module (5) configured to analyze the collected telemetry data and generate a risk assessment and / or an anomaly indication; a cryptographic key management module (6) configured to generate, store, rotate, and use cryptographic keys for identity verification and session security; and an adaptive response orchestration module (7) configured to apply one or more risk-based control measures in the policy enforcement module (1), characterized in that the policy decision module (3) continuously updates the access decision during an active session using the risk assessment and / or anomaly indicator generated by the AI ​​security analysis module (5) and the cryptographic identity determined by the identity assurance module (2), thereby enabling continuous review and least privileged access in a cloud environment.
Owner:ELENGOVAN ARUN KUMAR +1

Dynamic attribute based edge-deployed security

Dynamic attribute-based edge-deployed security in an industrial automation environment is described. A policy engine receives a command executable relevant to operational technology of an industrial automation environment via an access account. The policy engine classifies the command as approved or denied based on identifying a security policy based on the access account and operational technology, determining a set of parameter values based on the security policy, determining an intent of the command based on the set of parameter values, and classifying the command by evaluating the intent against the security policy. In response to command approval, the policy engine identifies a first communication channel coupling the operational technology and a policy enforcement point, connects a second communication channel coupling the policy enforcement point and the policy engine, and transmits the command and an indication of the first channel to the policy enforcement point via the second channel.
Owner:ROCKWELL AUTOMATION TECH INC

Systems and methods for tag-based policy enforcement for dynamic cloud workloads

Systems and methods for enforcing tag-based policy on dynamic workloads include monitoring, via a cloud-based system, traffic associated with one or more customers of the cloud-based system; receiving a packet from a workload associated with a customer of the one or more customers; performing a tag lookup at one or more nodes of the cloud-based system based on the packet; enforcing one or more policies based on the tag lookup. Based on no tags being found for the workload during the tag lookup at the one or more nodes, the nodes are adapted to drop the packet; query the one or more cloud connectors for workload information; and receive, in a next packet, all tags and a version associated with the workload.
Owner:ZSCALER INC

Adding roles to network address mapping information

In some examples, a controller obtains an Internet Protocol (IP) address of a compute entity that is to communicate over a network, and determines a role for the compute entity by accessing, using the obtained IP address, a role mapping data structure that maps IP addresses to roles. The controller adds the determined role to network address mapping information in the network, the network address mapping information including entries having respective network addresses, the determined role in the network address mapping information for use by a network device of the network in applying policy enforcement for traffic through the network device.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Alert management for data processing systems using out-of-band methods

Methods and systems for managing operation of a data processing system are disclosed. A management controller of the data processing system may identify an occurrence of an event for the data processing system that triggers a policy for the data processing system. A policy enforcement process may be performed based on the triggered policy. During performance of the policy enforcement process, environment data may be obtained by the management controller using a portion of hardware resources of the data processing system (e.g., a sensing device), and the environment data may be provided by the management controller to a remote system for analysis. To manage an outcome of the occurrence of the event and / or future occurrences of the event, an action set (based on the policy and / or the analysis of the environment data) may be performed.
Owner:DELL PROD LP

Symmetric NAT detection and connectivity support

Techniques described herein can detect sites at which symmetric network address translation (NAT) is employed and can manage network traffic to support data connections to devices at the detected symmetric NAT sites. During a detection stage, multiple network connections can be established with computing devices at a site. IP addresses and port addresses associated with the multiple network connections can be compared in order to detect the use of symmetric NAT. During a policy enforcement stage, sites that employ symmetric NAT can be added to a site list. A control policy can direct traffic for sites on the site list to one or more hubs configured to manage data connections on behalf of devices at symmetric NAT sites.
Owner:CISCO TECHNOLOGY INC

Predictive policy enforcement using encapsulated metadata

Methods are provided for predictive policy enforcement using encapsulated metadata. The methods involve obtaining a packet of an encapsulated traffic flow that is transported in a software-defined wide area network (SD-WAN) or in a cloud network. The packet includes a network virtualization tunneling header with an appended service plane protocol header and a payload. The methods further involve extracting, from the appended service plane protocol header, without performing deep packet inspection, enriched metadata that includes fields for one or more attributes related to a source of the packet or a destination of the packet, determining at least one network policy based on the enriched metadata, and applying, to the packet, the at least one network policy that relates to gathering analytics and / or transporting the encapsulated traffic flow to the destination.
Owner:CISCO TECHNOLOGY INC