Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

448 results about "Proxy server" patented technology

In computer networks, a proxy server is a server (a computer system or an application) that acts as an intermediary for requests from clients seeking resources from other servers. A client connects to the proxy server, requesting some service, such as a file, connection, web page, or other resource available from a different server and the proxy server evaluates the request as a way to simplify and control its complexity. Proxies were invented to add structure and encapsulation to distributed systems.

Systems and methods for generation and control of generative artificial intelligence (AI) applications

Systems and methods for management of generative AI. An example method includes intercepting, via a gateway implemented by the system, a client request associated with a tool invocation via a model context protocol (MCP) server, wherein the gateway operates as a proxy server between a plurality of MCP servers and a plurality of agents or consoles utilized by end-users; accessing policy information associated with MCP, the policy information reflecting, at least, an allowlist and a denylist associated with MCP servers and / or tools; implementing the policy information, wherein implementing includes: adjusting the client request to replace an MCP server included in the client request with a different MCP server, or adjusting the client request to update a schema associated with a tool identified in the client request; and forwarding the client request for receipt by an approved MCP server.
Owner:PARADIGM NETWORKS INC

Methods and Systems for Security Enhancement in Artificial Intelligence Model Interactions via Automated Injection and Proxy Server Implementation

The present technology relates to a computer-implemented method for enhancing enterprise-wide security when using Artificial intelligence (AI) models. Embodiments involve a JavaScript injection process facilitated by a proxy server. This process does not require manual installation as it is automatically injected during operation. The JavaScript injection process operates by intercepting unsecured AI input and output data provided by users interacting with AI websites. The input and output data are sent to a security Application Programming Interface (API) which applies an enterprise security policy to the data in real-time, thereby transforming unsecured input and output into secure data. Embodiments provide a robust framework for safe interaction with Artificial intelligence models while mitigating the risks associated with the transmission of sensitive information over the internet.
Owner:WITNESSAI INC

System and method for URL fetching retry mechanism

A method for overcoming intermittent, temporary, or other fetching failures by using multiple attempts for retrieving a content from a web server to a client device is disclosed. The URL fetching may use direct or non-direct fetching schemes, or a combination thereof. The non-direct fetching method may use intermediate devices, such as proxy server, Data-Center proxy server, tunnel devices, or any combination thereof. Upon sensing a failure of a fetching action, the action is repeated using the same or different parameters or attributes, such as by using different intermediate devices, selected based on different parameters or attributes, such as different countries. The repetitions are limited to a pre-defined maximum number or attempts. The fetching attempts may be performed by the client device, by an intermediate device in a non-direct fetching scheme, or a combination thereof. Various fetching schemes may be used sequentially until the content is retrieved.
Owner:BRIGHT DATA LTD

Proxy servers for managing queries to large language models

Systems, methods, and apparatus, including computer programs encoded on a computer storage medium for managing network traffic to and from a server configured to: (i) receive, from a client device, a query in a natural language, and (ii) generate a response to the query in the natural language. In one aspect, a method includes: receiving, from the client device via a network connection, a network message including a new query for the server; processing the new query, using a text encoder, to generate an embedding vector of the new query; identifying, from amongst multiple entries of a vector database, a particular entry based on a similarity metric between: (i) the embedding vector of the new query, and (ii) an embedding vector of a particular query stored in the particular entry; and determining whether the similarity metric is greater than a threshold similarity value.
Owner:AURADINE INC

Methods and systems for operating a proxy server

Embodiments of a method, a non-transitory computer readable medium, and a proxy server are disclosed. In an embodiment, a method for operating a proxy server involves receiving at least one communication between a client and a web server, wherein the proxy server facilitates a secure tunnel between the client and the web server, determining from the at least one communication that access to the web server has been restricted, and implementing a remedial action in response to the restricted access determination.
Owner:EMEIGH HOLDINGS LLC

Virtual article secure transaction method, device and system, medium and server

The invention relates to the technical field of block chains, and particularly discloses a virtual article secure transaction method, device and system, a medium and a server. The method relates to a mobile terminal, a proxy server and an issuing server, is executed by the proxy server and is used for receiving encrypted ciphertext transaction data sent by the mobile terminal and transmitting the data to the issuing server, so that the issuing server issues a virtual article corresponding to the transaction data obtained by decryption to the mobile terminal, and after the issuing server issues the virtual article, the virtual article is sent to the mobile terminal. And the proxy server and the issuing server carry out account checking. According to the method, the transaction data is encrypted by using the fully homomorphic encryption algorithm in the data transmission process, it is ensured that the proxy server cannot obtain plaintext transaction data, and account checking is performed by the proxy server and the issuing server, so that the problem of non-uniform bills is solved.
Owner:CHINA SOUTHERN AIRLINES CO LTD +1

Network device and processing method for network device for aggregating communications

A network device includes one or more memories and one or more processors. The one or more processors and the one or more memories are configured to obtain proxy information set to the network device, and communicate with a management server via a proxy server using the proxy information in a case where an aggregation mode is enabled and the proxy information is information received from the proxy server or in a case where the aggregation mode is not enabled, and not to communicate with the management server in a case where the aggregation mode is enabled and the proxy information is not the information received from the proxy server.
Owner:CANON KK

Encryption Key Distribution System

Customers of a software platform, such as a unified communications as a service platform, are enabled to control their own encryption keys used to encrypt and decrypt data from various communication services in the software platform. A key connector service is used to coordinate communications with a key management server for generating plaintext keys for data encryption and encrypted keys based on the plain text keys, and with a key broker server for storing and retrieving copies of the encrypted keys. A context identifier may be associated with an encrypted key and used to track which data has been encrypted with an underlying plaintext key. Examples of data encrypted may include conference recordings, webinar recordings, phone call recordings, voicemails, emails, and calendar tokens.
Owner:ZOOM COMMUNICATIONS INC

Caching proxy for a digital object architecture

A digital object architecture infrastructure includes a handle system that stores handle data and a proxy server that caches handle data for rapid access. A client connects to the proxy server to request access to the handle data. When the handle data does not have access restrictions and is currently cached, the proxy server returns the handle data to the client without accessing the handle system. When the handle data does not have access restrictions and is not cached, the proxy server obtains the handle data from the handle system, caches a copy of the handle data for future access, and provides the handle data to the client. The proxy server may cache encrypted handle data that is subject to access restrictions, cannot be decrypted by proxy server, and can be provided to a client determined to be allowed access. The client can then decrypt the encrypted handle data.
Owner:VERISIGN INC

Systems and methods facilitating connection of browsers having different transport layer security versions using a reverse proxy server

Aspects of the subject disclosure may include, for example, deploying a reverse proxy server in front of a first type of web servers and a second type of web servers, where the first type of web servers is compliant with a current version of payment card industry data security standard (PCI DSS) and supports a first version of a transport layer security (TLS) protocol, and where the second type of web servers supports one or more TLS protocols that are older than the first version of TLS protocol, detecting, using the reverse proxy server, a TLS protocol version used in an incoming request, and determining, using the reverse proxy server, routing of the incoming request to one of the first type of web servers and the second type of web servers at least based on the detected TLS protocol version. Other embodiments are disclosed.
Owner:AT&T INTELLECTUAL PROPERTY I L P

Attribute-based access control method for realizing puncture revocation and outsourcing decryption under multiple authorizations

InactiveCN120956419AKey distribution for secure communicationAccess structureEngineering
The invention discloses an attribute-based access control method for realizing puncture revocation and outsourcing decryption under multiple authorizations, which is characterized in that a certificate issuing mechanism is responsible for initialization of a system and registration of an attribute issuing mechanism and a user, and the attribute issuing mechanism manages part of attributes authorized by the attribute issuing mechanism and generates a conversion key of an agency for outsourcing decryption; the data owner encrypts the data by using attribute-based encryption according to the defined access structure and the label structure; and the proxy server converts the access strategy formulated by the data owner into a puncture strategy and then punctures the conversion key so as to cancel the specified user group. According to the method, puncture revocation and outsourcing decryption attribute-based access control under a multi-authorization mechanism can be realized, and a feasible method is provided for lightweight and fine-grained user revocation under the multi-authorization mechanism.
Owner:NANJING UNIV OF POSTS & TELECOMM

Methods and systems of an all purpose broadband network with publish subscribe broker network

A system including a server and a wireless RF access node connected to a communication network is provided. The server provides a first publish-subscribe broker of one or more publish-subscribe brokers forming part of a publish-subscribe broker network. The server connects to the wireless RF access node. A first entity connects via the wireless RF access node to the first publish-subscribe broker using a unicast IP address and thereafter publishes data packets. A second entity connects to the publish-subscribe broker network via any of the one or more publish-subscribe brokers. The server provides packet distribution services via the first publish-subscribe broker for the first entity, the publish-subscribe broker network routes communications from the first entity to the second entity when the second entity is subscribed; and the data packets published by the first entity are routed through the publish-subscribe broker to which the second entity is connected.
Owner:ALL PURPOSE NETWORKS INC

Provisioning a database management platform in a cloud computing environment

Methods and apparatuses for provisioning a database management platform in a cloud computing environment include a server that reserves virtual computing resources in the cloud environment. The server provisions a database management platform using the reserved virtual computing resources. The database management platform includes primary and secondary database instances, a database observer instance, and a platform monitor agent. The server configures a database observer instance to monitor availability of database instances and to route traffic to other database instances. The server integrates the database management platform with an identity authentication service, monitors operational status of the database management platform using a monitoring service, and refreshes the reserved virtual computing resources in the database management platform using a rehydration service.
Owner:FMR CORP

Methods and systems for security enhancement in artificial intelligence model interactions via automated injection and proxy server implementation

The present technology relates to a computer-implemented method for enhancing enterprise-wide security when using Artificial intelligence (AI) models. Embodiments involve a JavaScript injection process facilitated by a proxy server. This process does not require manual installation as it is automatically injected during operation. The JavaScript injection process operates by intercepting unsecured AI input and output data provided by users interacting with AI websites. The input and output data are sent to a security Application Programming Interface (API) which applies an enterprise security policy to the data in real-time, thereby transforming unsecured input and output into secure data. Embodiments provide a robust framework for safe interaction with Artificial intelligence models while mitigating the risks associated with the transmission of sensitive information over the internet.
Owner:WITNESSAI INC

Content fetching by mobile device selected based on battery charge level

A method for fetching a content from a web server to a client device is disclosed, using tunnel devices serving as intermediate devices. The tunnel device is selected based on an attribute, such as IP Geolocation. A tunnel bank server stores a list of available tunnels that may be used, associated with values of various attribute types. The tunnel devices initiate communication with the tunnel bank server, and stays connected to it, for allowing a communication session initiated by the tunnel bank server. Upon receiving a request from a client to a content and for specific attribute types and values, a tunnel is selected by the tunnel bank server, and is used as a tunnel for retrieving the required content from the web server, using standard protocol such as SOCKS, WebSocket or HTTP Proxy. The client only communicates with a super proxy server that manages the content fetching scheme.
Owner:BRIGHT DATA LTD

Model processing method and device, equipment, medium and product

The invention discloses a model processing method and device, equipment, a medium and a product. The method comprises the steps that each data owner trains an initial model based on training data to obtain a local model, and uploads the local model to a proxy server; the proxy server performs aggregation calculation on the local model set to obtain a global model, and sends the global model to the task publisher; if the task publisher detects that the global model does not reach convergence, performing performance test on the global model to obtain a target score corresponding to each data owner, screening the data owners based on the target scores corresponding to the data owners to obtain a data owner set, and storing the data owner set in a database; and sending the initial model to a data owner set, so that each data owner in the data owner set returns to execute the operation of training the initial model based on the training data by each data owner to obtain a local model, uploading the local model to the proxy server until the obtained global model converges, and sending the global model to the cloud service provider.
Owner:HANGZHOU XINYUN SEMICON GRP CO LTD

Video quality detection method and system, electronic device and storage medium

The invention relates to a video quality detection method and system, an electronic device and a storage medium, and is used for a reverse proxy server, the reverse proxy server is deployed at a cloud, and the method comprises the following steps: obtaining camera identification information reported by a proxy client; when a real-time streaming transmission protocol request containing a virtual real-time streaming transmission protocol port initiated by the PC client is received, forwarding the request to a corresponding proxy client according to camera identification information corresponding to the virtual real-time streaming transmission protocol port; the virtual real-time stream transmission protocol port establishes a mapping relationship with the camera identification information in advance; receiving video data uploaded by the proxy client; the video data is locally acquired by the proxy client from the camera according to the forwarding request; and encapsulating the video data into a standard real-time stream transmission protocol response, and returning the real-time stream transmission protocol response to the PC client for video quality detection. A communication link can be established for video transmission, the process is simplified, and the video quality detection efficiency is improved.
Owner:E SURFING VISION TECHNOLOGY CO LTD

MQTT message security protection method and device based on multilayer protection mechanism, and medium

The invention discloses an MQTT message security protection method and device based on a multilayer protection mechanism, and a medium, and relates to the technical field of communication. The method comprises the following steps: establishing MQTT connection between client equipment and a message proxy server, and receiving an MQTT message sent by the message proxy server through the client equipment; the client device reads a pre-configured device key from a secure storage area of the client device and obtains a current time factor so as to generate a local verification code through cryptographic hash operation; and performing consistency comparison verification on the local verification code and a dynamic authentication password extracted from the MQTT message, if verification is consistent, executing a control instruction in the MQTT message through the client device, and if verification is inconsistent, discarding the MQTT message and triggering an exception handling process.
Owner:浪潮智能终端有限公司

Systems and methods for access traffic steering, switching, and splitting with user equipment having multiple identities

A method operable with a first communication network for supporting a user equipment (UE) device having at least a first identity associated with the first communication network and a second identity associated with a second communication network. The method includes (a) exchanging data with the UE device via a first access communication link, the first access communication link being an access communication link of the first communication network, (b) exchanging data with the UE device via a second access communication link and an interface between the first and second communication networks, the second access communication link being an access communication link of the second communication network, (c) performing access traffic steering, switching, and splitting (ATSSS) across at least the first and second communication links, at least partially using a proxy server associated with the first communication network.
Owner:CABLE TELEVISION LAB INC

Safety protection method and system for preventing blasting attack

The invention discloses a safety protection method and system for preventing blasting attacks, and relates to the technical field of data security, and the method comprises the following steps: deploying a bidirectional communication chain between a client and a data rear end through a proxy server; judging a connection request state through a primary verification mechanism, and determining a forward transmission strategy of the two-way communication chain according to the connection request state; judging a response request state through a secondary verification mechanism, and determining a reverse transmission strategy of the two-way communication chain according to the response request state; and executing data security isolation or transmission according to the forward transmission strategy or / and the reverse transmission strategy. The problems of limitation of an account locking mechanism in a high-concurrency scene and conflict with internal security detection in the prior art are solved, and the substantive effects of effectively defending blasting attacks and being compatible with internal security scanning are achieved while stable operation of high-concurrency systems such as middleware and a database is guaranteed.
Owner:ZHEJIANG HONGCHENG COMP SYST

System and method of secure network management using a reverse proxy server

A method and system for securely routing traffic in a computing environment via a firewall, the method including configuring a reverse proxy server via a first configuration file and configuring a DNS server via a second configuration file, and routing traffic via the reverse proxy server by looking up addresses in the DNS server. The first configuration file includes a plurality of target IP addresses, each of the plurality of target IP addresses referencing a DNS record in the DNS server and the second configuration file includes a plurality of DNS records, where each of the DNS records is initially set to point to a default IP address. When it is determined that there is a change to an IP address of a resource in the computing environment, the DNS record associated with the resource in the DNS server is automatically updated via an API call to the DNS server by replacing the default IP address with the updated IP address for the resource. The reverse proxy servers refers to the updated DNS record to route traffic to the resource.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

First class database object server application

A data platform for managing an application as a first-class database object. The data platform includes at least one processor and a memory storing instructions that cause the at least one processor to perform operations including detecting a data request from a browser for a data object located on the data platform, executing a stored procedure, the stored procedure containing instructions that cause the at least one processor to perform additional operations including instantiating a User Defined Function (UDF) server, an application engine, and the application within a security context of the data platform based on a security policy determined by an owner of the data object. The data platform then communicates with the browser using the application engine as a proxy server.
Owner:SNOWFLAKE INC

Cross-network domain HTTP proxy method and device based on message queue and storage medium

The invention discloses a cross-network domain HTTP proxy method and device based on a message queue and a storage medium, and the method comprises the steps: serializing an HTTP request of a client into a request message in a ProtoBuf format through a local proxy server, and transmitting the request message to a message queue system, so that the message queue system forwards the request message to a remote proxy server; the remote proxy server deserializes a request message into an HTTP request and sends the HTTP request to the server, and then serializes an HTTP response returned by the server into a response message in a ProtoBuf format and sends the response message to the message queue system, so that the message queue system forwards the response message to the local proxy server; and deserializing the response message into an HTTP response through the local proxy service and returning the HTTP response to the client. The method improves the efficiency and reliability of cross-network domain communication, and can be widely applied to the technical field of computer networks.
Owner:E SURFING IOT CO LTD

Reliable data transmission method and system based on digital signature and user identity

The invention provides a reliable data transmission method and system based on digital signature and user identity, and the method comprises the steps: obtaining basic parameters of a plurality of proxy server nodes, building a communication network, and generating a multi-proxy workflow system; collecting a network condition, a node load and a security threat level, selecting an encryption algorithm combination, and generating a dynamic encryption strategy containing a digital signature verification rule; generating confused sensitive data; receiving to-be-transmitted data, signing by using a digital signature of a sender, performing fragmentation and encryption processing on the to-be-transmitted data according to a dynamic encryption strategy, adding confused sensitive data as a verification token into data fragments, and transmitting through a multi-agent workflow system; and the receiving end reorganizes and decrypts the encrypted data fragments, and verifies the authenticity of the data by using the digital signature of the receiving party. The problems that a single proxy server is weak in security and a fixed encryption algorithm is easy to crack in the prior art are solved.
Owner:BEIJING AN XIN TIAN XING TECH CO LTD

Selecting proxy device based on hardware resource utilization

A method for fetching a content from a web server to a client device is disclosed, using tunnel devices serving as intermediate devices. The tunnel device is selected based on an attribute, such as IP Geolocation. A tunnel bank server stores a list of available tunnels that may be used, associated with values of various attribute types. The tunnel devices initiate communication with the tunnel bank server, and stays connected to it, for allowing a communication session initiated by the tunnel bank server. Upon receiving a request from a client to a content and for specific attribute types and values, a tunnel is selected by the tunnel bank server, and is used as a tunnel for retrieving the required content from the web server, using standard protocol such as SOCKS, WebSocket or HTTP Proxy. The client only communicates with a super proxy server that manages the content fetching scheme.
Owner:BRIGHT DATA LTD

Intelligent password service platform

The application relates to the technical field of information system security, and particularly discloses an intelligent password service platform, which comprises a service gateway, a synchronization module, a general server, a reverse proxy server and a plurality of password devices; the synchronization module is used for synchronizing key resources of password devices of the same type after the password devices access a network; the general server is provided with a virtual module and a load balancing module; the load balancing module is used for connecting the password devices after the key resources are synchronized; the virtual module is used for virtually changing physical resources of secret devices into resource clouds of different types through a virtualization technology; the service gateway is used for obtaining a calling application of a third-party application service interface; the service gateway is also used for analyzing the calling application and determining service requests facing different resource clouds according to the analyzed results. The technical scheme of the application has high expansibility, can be flexibly networked, is convenient for reusing and does not waste existing resources.
Owner:CHONGQING AEROSPACE INFORMATION CO LTD

Authentication proxy for password rotation

Disclosed is a method, system, and computer program product for rotating a password. According to the method, a proxy server receives a first service ID password from an application server. The proxy server determines whether to use the first service ID password to authenticate the application server at an authentication service based on a query of a database of password changes. Based on the determination of whether to use the first service ID password, the proxy server authenticates the application server at the authentication service using the first service ID password based on the determination or authenticates the application server at the authentication service by replacing the first service ID password with a second service ID password based on the determination.
Owner:VISA INTERNATIONAL SERVICE ASSOCIATION

System and method for intelligent task decomposition and execution proxy based on MCP

The invention belongs to the technical field of artificial intelligence, and discloses an MCP-based intelligent task decomposition and proxy execution system and method.The system comprises a proxy server, an MCP client, a Web service module and a front-end interaction module, and a self-adaptive task decomposition engine, a multi-MCP service dynamic integration framework and other components are arranged in the proxy server; ordered subtasks can be generated according to query complexity, multiple MCP service tools are managed in a unified manner, a flow is pushed in real time, user confirmation is supported, and a backspacing scheme can be triggered when the tools or decomposition fails; according to the method, complex query processing is achieved through the four steps of task decomposition, service connection and tool preparation, task execution and user interaction and result integration and feedback. The system improves the complex task processing accuracy, the user trust degree and the task completion rate when the tool fails, has good expansibility depending on the MCP protocol, and can be applied to scenes such as intelligent customer service and intelligent office assistants.
Owner:RONGZHITONG TECH BEIJING

Platform and method for automated moving target defense

The present invention is a system and method for machine-to-machine communication in a Zero Trust environment. The instant invention describes a platform implementation that disables threat actors and their methods that target workload credentials. The platform is an Automated Moving Target Defense (AMTD) platform that creates sidecars that contain algorithms for creating secure keys from user specified dynamic elements, a machine alias ID (MAID), an encryption library, and an envoy proxy. The sidecars are utilized to control access to, and secure messaging traffic between, entities in a non-trusted environment.
Owner:HOPR CORP

Request forwarding device and method based on traffic hijacking and dynamic routing, and related equipment

The invention discloses a request forwarding device and method based on traffic hijacking and dynamic routing and related equipment, and relates to the field of request forwarding, in the invention, a service request is still sent according to an original address and is automatically forwarded to a lightweight application proxy server for processing by an F5 traffic gateway layer, and a client does not need to modify any configuration or code or restart service. The mechanism thoroughly decouples the strong binding relationship between the calling party and the called party, avoids the problems of long implementation period, high cost, asynchronous configuration and the like caused by coordination of multi-party application upgrading in a traditional scheme, remarkably improves the operability and execution efficiency of system migration, and improves the system migration efficiency. According to the invention, the service request is intercepted at the F5 flow gateway layer and the lightweight application proxy server is introduced to carry out the routing decision, so that the upstream application is completely non-inductive to the switching of the back-end message center.
Owner:NINGBO PORT INFORMATION COMM CO LTD