Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

11 results about "Protection domain" patented technology

RDMA (Remote Direct Memory Access) reliable connection fault-oriented rapid recovery method and system

The invention belongs to the technical field of computer network communication, and provides an RDMA-oriented reliable connection fault rapid recovery method and system, the method is executed by a first communication end, communication is established between the first communication end and a second communication end through a queue pair QP, and the queue pair QP is used for bearing service data transmission. The first communication end reserves resources after the QP enters an error state, and sends a PROBE control frame to the opposite end through the control plane queue pair; the second communication end decides to reuse the original QP or allocate a new QP (reuse an original protection domain, a memory registration area and a completion queue) according to the local QP state, and returns a QP number and a start packet serial number in an RESP frame; and the first communication end updates the local QP context and drives the state machine to switch to a ready sending state. The whole process does not need to destroy the QP and does not depend on CM handshake, the recovery time delay is less than 0.5 millisecond, and the method is transparent to the upper layer application and is suitable for the RoCE v2 network environment.
Owner:XIAN AVIATION COMPUTING TECH RES INST OF AVIATION IND CORP OF CHINA

A power industrial control security protection system and method based on microkernel active defense

PendingCN122179216ASecuring communicationScheduling (computing)Trusted computing base
The application discloses a power industrial control safety protection system and method based on a microkernel active defense, wherein the system takes a microkernel isolation base as a minimum trusted computing base, allocates revocable communication endpoints and controlled mapping permissions to each protection domain, and provides base support for the isolation domain boundary and permission recovery in the active defense; in the method, the system is uniformly formatted by an input module to process field data and service requests and generate a request identifier, a request distribution service distributes the same request to an odd number of online executors for parallel processing, a single decision output available externally is generated, an executor scheduling service selects a candidate executor from a candidate protection domain pool and reconstructs an online user mode service cluster according to a feedback index by adopting a periodic rotation and event triggering strategy, and if the request distribution service, the consistency arbitration service or the executor scheduling service fails, a minimum bottom-up cleaning is performed by an active defense kernel state support module and a reestablishable state is entered.
Owner:NARI INFORMATION & COMM TECH

Method for multi-layer protection and restoration and resource allocation in an optical network

The application discloses a multi-layer protection recovery and resource allocation method of an optical network, and relates to the technical field of network communication.The application comprehensively considers multi-service characteristics and network resource dynamic scheduling, and proposes a hybrid method of multi-routing selection and network service slicing, so that protection based on a WDM optical network in a complex network environment is realized.Meanwhile, a work domain and a protection domain are arranged in a bandwidth allocation period, and a flexible resource allocation scheme is adopted, so that network resource utilization can be improved, and the work route can be protected.
Owner:THE 34TH RES INST OF CHINA ELECTRONICS TECH CORP

Face revocable template protection method based on deep hash

The invention relates to the field of biological feature recognition and information security, in particular to a face revocable template protection method based on deep hash. The method comprises the following steps: detecting and aligning an input face image, and extracting and normalizing features; performing projection and symbol quantization to obtain a binary vector with a fixed length; deriving a dimension permutation and index subset by using a user key, and generating a protected template; registration and identification are completed in a protected domain by a Hamming distance; when the template is leaked or needs to be replaced, a new template is regenerated by updating a secret key or an index rule, and template revocation and non-linkability are achieved. The system side only stores the protected template and necessary verification parameters and does not store plaintext images and unprotected features, so that the method is low in calculation overhead, convenient to deploy and suitable for face identity authentication of end-side equipment and a cloud platform.
Owner:CHONGQING UNIVERSITY OF SCIENCE AND TECHNOLOGY +1

Biological characteristic secret state protection method, verification method, equipment and medium

The invention discloses a biological characteristic secret state protection method, a verification method, equipment and a medium. Dividing the biological characteristics into a plurality of biological characteristic fragments, carrying out homomorphic encryption calculation on each biological characteristic fragment by adopting a randomly generated fragment encryption key to obtain a secret state biological characteristic fragment, randomly generating a fragment index of the secret state biological characteristic fragment, and storing the fragment index of the secret state biological characteristic fragment into a database; storing the secret state biological characteristic fragments into a local biological characteristic secret state protection domain based on the fragment index, dividing the biological characteristic into a plurality of biological characteristic fragments, and performing homomorphic encryption calculation by adopting a randomly generated fragment encryption key to obtain the secret state biological characteristic fragments; then, the secret state biological characteristics are fragmented and stored in random positions in a local biological characteristic secret state protection domain, fragmented secret state protection on the biological characteristics is achieved, biological characteristic data are prevented from being leaked, and safety is improved.
Owner:HUNAN KAIHONG ZHIGU DIGITAL IND DEV CO LTD

Methods for reducing security risks when implementing remote direct storage access through a proxy node

In various embodiments, a memory key service is used for remote access to one or more sections of physical memory contained in a host node. The memory key service generates a first memory key that maps a host address space from a first protection domain assigned to the host node to a second protection domain assigned to a proxy node. The memory key service generates a second memory key based on the first memory key and a first address range assigned to the host node. The memory key service transmits the second memory key to a software component running on the proxy node. The software component causes a shared storage system to access a first section of the physical memory based on the second memory key.
Owner:NVIDIA CORP

Packet Transmission Control Method and Apparatus for a PTN Access Node in an ITS Communication Network

A method for controlling packet transmission at a PTN access node for an ITS communication network and an apparatus for the same are disclosed. A packet transmission control method according to an embodiment of the present invention may include: a step of classifying into a plurality of service classes including control traffic and video traffic based on the header and service identifier of a received frame; a step of receiving traffic event metadata including signal cycles, conflicting traffic events, and priority signal events from a control policy server; a step of generating scheduling parameters including time slot allocation parameters for a control traffic queue and weight adjustment parameters for a video traffic queue based on the metadata; a step of calculating a microburst indicator based on frame inflow characteristics in a short-time observation window, and determining the output order by performing queue management and scheduling control for a queue by service class according to the scheduling parameters and the microburst indicator; a step of transmitting by applying a predetermined transmission encapsulation according to a service identifier; and a step of maintaining an independent protection domain for each service and performing linear or ring protection switching only for the corresponding service when a threshold is exceeded based on an OAM performance indicator for each service.
Owner:SMART VISION

Force feedback method and device for surgical robot master

The application provides a force feedback method and device for a surgical robot master manipulator, and the force feedback method comprises the following steps: acquiring first force feedback data and scene data of the surgical robot master manipulator; generating a virtual protection domain corresponding to the surgical robot master manipulator based on the scene data; generating target force feedback data by using an impedance control algorithm based on the first force feedback data and the virtual protection domain; and sending a first instruction to a force feedback device controller, wherein the first instruction is used to instruct the force feedback device controller to control the surgical robot master manipulator based on the target force feedback data. By using the above method, the design of the virtual protection domain can complete the construction of a repulsion force field or a pulling force field for the surgical robot master manipulator, so that tactile feedback can be provided to the surgical robot master manipulator, and doctors can truly feel the force feedback effect, thereby avoiding damage to human tissues.
Owner:INST OF AUTOMATION CHINESE ACAD OF SCI

History synchronization service and protection extension

Methods and systems for selective presentation of sensitive information are described herein. A computing system may receive, from a cloud computing platform, a history protection extension. The computing system may install the history protection extension, which may cause the computing system to selectively display sensitive information based on whether or not the computing system is connected to a secure network. The computing system may identify, using the history protection extension, that the computing system is currently operating on the secure network. The computing system may intercept a URL access request. The computing system may compare a domain of the URL access request to a protection domain list. Based on identifying that the domain of the URL is included on the protection domain list, the computing system may launch the URL in a secure browser, and display, within the secure browser and based on a history data list, the sensitive information.
Owner:CITRIX SYSTEMS INC

A Zero-Copy Acceleration Method for Virtual Machine Network I / O Based on Pass-Through Drivers of Domestic Operating Systems

This invention relates to a zero-copy acceleration method for virtual machine network I / O based on a passthrough driver of a domestic operating system. The method includes: customizing the kernel of the domestic operating system to introduce a dedicated passthrough driver module; expanding the virtual machine's virtual network device to provide a passthrough mode; receiving passthrough enable requests from virtualization components and performing security authentication and resource pre-checks; upon successful pre-check, creating a virtual machine-specific protection domain based on the IOMMU, locking memory pages used for network transmission and reception and establishing a mapping to the IOVA, recording the mapping relationship to restrict the physical network card to only access the mapped virtual machine memory; configuring the physical network card's passthrough transmission and reception queue and establishing a control channel, sending configuration information to initialize the descriptor ring; and executing a zero-copy transmission and reception process, enabling the physical network card's DMA to directly access the virtual machine's network buffer to complete data transmission. This method reduces host-side data copying and protocol stack processing overhead, lowers latency, and improves throughput.
Owner:SHENGWEI DIGITAL (SHENZHEN) TECHNOLOGY CO LTD

Security isolation method and system applied to power monitoring system

PendingCN121125229ASecuring communicationExecution planProtection domain
The invention provides a security isolation method and system applied to an electric power monitoring system, and belongs to the technical field of electric power system security, and the method comprises the steps: firstly capturing a real-time operation interaction link and an abnormal behavior track of each component in the electric power monitoring system, and then generating an isolation starting instruction including an instruction triggering condition and the like; then, a cross-domain protection linkage framework is constructed based on the isolation starting instruction, and protection strategies of an equipment layer, a communication layer and an application layer are integrated; a hierarchical isolation execution plan is generated by using a cross-domain protection linkage framework, and action sequences of all protection domains and the like are defined; and finally, pushing the hierarchical isolation execution plan to a protection execution component, collecting execution state information, updating framework association logic parameters, and keeping a system global isolation situation, thereby effectively improving the security of the power monitoring system.
Owner:XINYUAN NETWORK TECH CO LTD