Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

24 results about "Secure Shell" patented technology

Secure Shell (SSH) is a cryptographic network protocol for operating network services securely over an unsecured network. Typical applications include remote command-line, login, and remote command execution, but any network service can be secured with SSH.

Secure shell protocol traffic evidence obtaining and decryption method and system based on key injection

The invention belongs to the technical field of network security and communication, and provides a secure shell protocol flow evidence obtaining decryption method and system based on key injection, and the method comprises the steps: injecting a user-defined dynamic library into a service process, intercepting a key encryption function, and extracting a session key as a shared key when a secure shell protocol server runs; carrying out session identification on the encrypted traffic in the grabbed network, and completing the recombination of the IP fragment and the TCP fragment to obtain the recombined encrypted traffic; carrying out matching and integrity verification on the shared key and the recombined encrypted traffic, and then decrypting to generate a plaintext message; and analyzing the plaintext message into a structured operation record according to a channel type, and classifying and storing the structured operation record in combination with a timestamp, a session ID and a user identifier to form auditing evidence data. According to the method, system files do not need to be modified, complete decryption and behavior restoration of multiple types of sessions such as Shell, SCP and SFTP can be achieved, and the method is suitable for network security audit and judicial evidence obtaining scenes.
Owner:YUANBAO TECH

Containerized service with embedded scripting tools for monitoring health state of hyper-converged infrastructure resources

ActiveCN116668050BSecuring communicationSecure ShellHealth states
The disclosed method deploys a containerized health condition monitoring service that includes an embedded health condition monitoring service script. The containerized service generates a Secure Shell (SSH) key pair, including an SSH public key and an SSH private key. A management account of the containerized service is registered to a centralized account service. An SSH control module of a hyper-converged infrastructure (HCI) manager retrieves the management account of the containerized service from the account service. The control module accesses the containerized service to retrieve the SSH public key and stores the SSH public key to a target resource, such as a host or virtual machine, to enable any instance of the containerized service to remotely execute the health condition monitoring service script on the target resource using SSH commands.
Owner:DELL PROD LP

Conditional ssh tunneling as a policy enforcement point for seamless zero trust integration

Enhanced security for Zero Trust networks is provided by SSH-customized tunnel clients / tunnel servers, a catalog service, and loopback address DNS mechanisms. Systems and methods provide Policy Enforcement Point (PEP) layer enhancements, strategically positioning the PEP between the user and the network resource. It manages network traffic flows and provides moderate control granularity, near-real-time enforcement decisions, low overheads, and broad applicability to TCP / IP traffic through modified tunneling implementations of Secure Shell (SSH). Unique use of SSH tunneling is utilized and adapted to selectively filter tunnel requests based on user entitlements, ensuring secure and authorized access to network resources. This method entails detailed assessment of tunneling requests, DNS manipulation, and the use of loopback address space for traffic redirection, all without requiring modifications to client-side applications. The approach significantly enhances network security by controlling access based on continuous verification of user entitlements, addressing the shortcomings of traditional network security models.
Owner:BANK OF AMERICA CORP

SSH engine(s) for generating user specific SSH configuration files

ActiveUS12647466B2Securing communicationSoftware engineeringSecure Shell
Various embodiments of the present technology generally relate to systems and methods for providing an SSH engine. In an example, a method includes receiving, by an SSH engine, a request for a Secured Shell (SSH) configuration file from a client device. The SSH engine may then determine access privileges associated with the client device and generate rules based on the access privileges. The access privileges may identify resources that the client device has authority to access. The SSH engine may then validate each rule of the rules based on the access privileges and generate the SSH configuration file including the rules for the client device.
Owner:ORACLE INT CORP

A communication method, cloud platform, edge device and client device

PendingCN122160367ASecuring communicationWebSocketSecure Shell
The embodiment of the application provides a communication method, a cloud platform, an edge device and a client device, which can multiplex websocket channels to transmit messages between the cloud platform and the edge device, thereby greatly reducing the number of websocket channels between the cloud platform and the edge device, reducing the network bandwidth resources occupied by the websocket channels, and allowing more client devices to remotely and safely log in on the edge device. The communication method comprises the following steps: after the cloud platform receives a websocket connection request sent by a client device, the cloud platform sends a first websocket message to an edge device through a preset websocket channel; after the edge device establishes a secure shell connection, the cloud platform receives a second websocket message sent by the edge device through the websocket channel; and then the cloud platform sends a websocket connection response to the client device according to a connection identifier in the second websocket message.
Owner:CHENGDU HUAWEI TECH CO LTD

Remote human-computer interface

The invention relates to a system for managing a production line, said production line comprising at least one machine, said system comprising at least: a human-machine interface (20), referred to as HMI, connected to the machines of said production line, referred to as API or industrial programmable automation (19), referred to as PLC according to the English initial abbreviation of "Programmable Logic Controller", and / or a portable terminal (23); the system is characterized in that it comprises at least one remote terminal (21) coupled to the machine or a safety housing (22) of the machine and connected to an industrial programmable automation (API) (19) or a human-machine interface (HMI) (20) of the machine, the remote terminal (21) comprises means for detecting the presence of a portable terminal (23) within a determined perimeter and means for connecting the portable terminal (23) to an industrial programmable automation (API) (19) and / or a human-machine interface (HMI) (20) of the machine, the portable terminal (23) comprising an emergency stop, the emergency stop is automatically connected to an emergency stop management system of an industrial programmable automatic device (API) (19) and / or a human-machine interface (HMI) (20) of the machine when the portable terminal (23) is detected within a determined perimeter and connected to the industrial programmable automatic device (API) (19) and / or the human-machine interface (HMI) (20) of the machine.
Owner:SIDEL PARTICIPATIONS SAS

Code management method and device, medium and program product

The invention relates to the field of distributed technologies, and discloses a code management method and device, a medium and a program product. The method comprises the following steps: acquiring a code downloading request sent by a client through secure shell protocol connection, and acquiring a user identifier, an equipment internet protocol address and a code address according to the code downloading request; if it is detected that the user identifier and the equipment internet protocol address successfully pass verification, obtaining a target code matched with the code address; and sending the target code to the client through the secure shell protocol connection. According to the scheme of the embodiment, after the secure shell protocol connection is established, verification of the internet protocol address of the equipment is newly added, so that the code leakage risk can be reduced, and the security of code management can be improved.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Industrial personal computer performance acquisition method based on third-party control and terminal

The invention discloses an industrial personal computer performance acquisition method and terminal based on a third-party control, and the method comprises the steps: firstly judging whether a to-be-acquired industrial personal computer is a local terminal or not, and then automatically selecting a mode of direct calling or remote calling based on a secure shell protocol to acquire the performance; and a third-party control interface is uniformly called to realize efficient acquisition of hardware performance of the industrial personal computer, so that an optimal calling path is automatically selected in a local scene and a far-end scene. Compared with a traditional mode of directly reading the system file, the method has the advantages that a Linux kernel file structure does not need to be deeply analyzed; a key pair is configured between a local industrial personal computer and a to-be-acquired industrial personal computer in advance, and cross-industrial-personal-computer and cross-network remote acquisition is realized by using a secure shell protocol SSH, so that the safety and reliability of cross-computer performance data acquisition are improved. In conclusion, the method obviously improves the efficiency, accuracy and maintainability of performance acquisition of the industrial personal computer.
Owner:CONTEMPORARY NEBULA TECH ENERGY CO LTD

Specialized computing environment for co-analysis of proprietary data

A specialized computing environment that includes hardware and data security features to enable competitive organizations to co-analyze proprietary data without revealing the underlying proprietary data to unauthorized users. Proprietary data are stored in volatile memory, which may be automatically erased according to pre-stored criteria. The analysis is performed automatically by a processing unit without human intervention. Analytical results are sanitized (e.g., using data masking) to prevent the analytical result from being tracible to any particular data source. Sanitized analytical results are output without outputting the underlying proprietary data (except to users authorized to validate analytical results). The computing environment is enclosed within a secure enclosure (e.g., a steel box with a lock), does not include any peripheral devices outside the secure enclosure, does not communicate wirelessly, and does not have hardware ports accessible from outside the secure enclosure (except, in some embodiments, a wired connection for a web server).
Owner:CHILDRENS HOSPITAL MEDICAL CENT CINCINNATI +1

Terminal access to virtual private servers with automatic protocol fallback

A request to access a Virtual Private Server (VPS) is receive from a client device. An attempt is made to establish a Secure Shell (SSH) connection with the VPS. Responsive to a failure to establish the SSH connection, a serial console connection is automatically established with the VPS. Data communicated via the serial console connection is converted to a format compatible with the request. The converted data is then provided to the client device.
Owner:HOSTINGER OPERATIONS UAB

Database cluster node downtime restarting method and device, equipment and storage medium

The invention relates to the technical field of information processing, in particular to a database cluster node downtime restarting method, device and equipment and a storage medium, by deploying an Nginx reverse proxy service in a StarRocks cluster and configuring the Nginx reverse proxy service to access a plurality of front-end nodes in a polling mode, a high-availability database connection channel is established, a timed detection script is compiled, and the reliability of the database cluster node downtime restarting is improved. And periodically executing a sequential query process for the survival states of all the front-end nodes and the survival states of all the rear-end nodes through a database connection channel, recording a failure node whose survival state is failed according to a first query result, and automatically and remotely executing a remote restart process for the failure node through an SSH (Secure Shell). After the remote restart process is executed, the survival state of the failed node is queried again, and when restart fails, an alarm notification is generated and sent to the management terminal, so that unattended rapid recovery of the cluster node is realized, and the system reliability and the operation and maintenance automation level are improved.
Owner:上海乾臻信息科技有限公司

Remote login identity authentication method and device based on face recognition, equipment and storage medium

The invention discloses a remote login identity authentication method, device and equipment based on face recognition and a storage medium, and relates to the technical field of information safety and identity authentication, the method comprises the steps that a remote login request sent by remote equipment is received and initiated, and the remote login request comprises target account information; detecting authentication configuration corresponding to the target account information through a pluggable authentication module to obtain a detection result; when the detection result is that face authentication needs to be executed, generating an authentication request according to the target account information and the session identifier; the authentication request is sent to a face authentication server, so that the face authentication server authenticates a real-time face image and feeds back an authentication result, and the real-time face image is acquired by the initiating remote device; and processing the remote login request according to the authentication result. According to the invention, on the premise that a secure shell protocol and a client are not modified, it can be ensured that the remote login person and the authorized user are the same person through biological feature verification, and the risk of credential embezzlement is reduced.
Owner:HUNAN KYLIN XINAN TECH CO LTD

Embedded device cross-platform hardware detection method, device and equipment and storage medium

PendingCN121116688AFault responseFault analysisSecure Shell
The invention discloses an embedded device cross-platform hardware detection method, device and equipment and a storage medium, and the method comprises the steps: building communication connection with an operation and maintenance working end through a secure shell protocol channel, and building a file transmission channel and an interaction environment based on the secure shell protocol channel; based on the file transmission channel, a fault analysis program sent by the operation and maintenance working end is obtained, and the fault analysis program is matched with a hardware model and an operating system of the embedded device; obtaining an operation and maintenance instruction sent by an operation and maintenance working end through the interaction environment; executing a fault analysis operation based on the fault analysis instruction and the fault analysis program, or executing operation condition monitoring based on the operation condition monitoring instruction; and when fault analysis or operation condition monitoring is completed, operation and maintenance operation information is generated and fed back to the operation and maintenance working end. A remote interaction environment is constructed through the SSH, cross-platform fault positioning and monitoring are achieved, operation is simplified, an operation and maintenance closed loop can be formed, stable operation of equipment is guaranteed, and the user satisfaction degree is improved.
Owner:CYG CONTRON

Method and system for forensic decryption of secure shell protocol traffic based on key injection

This invention belongs to the field of network security and communication technology, and provides a method and system for forensic decryption of Secure Shell protocol traffic based on key injection. The method includes: injecting a custom dynamic library into the service process during the execution of the Secure Shell protocol server, intercepting key encryption functions and extracting session keys as shared keys; performing session identification on the encrypted traffic captured from the network, completing the reassembly of IP fragments and TCP segments to obtain reconstructed encrypted traffic; performing matching and integrity verification between the shared key and the reconstructed encrypted traffic, and then decrypting to generate plaintext packets; parsing the plaintext packets into structured operation records according to channel type, and storing them in categories based on timestamps, session IDs, and user identifiers to form audit evidence data. The method of this invention does not require modification of system files and can achieve complete decryption and behavior reconstruction of multiple types of sessions such as Shell, SCP, and SFTP, and is suitable for network security auditing and judicial evidence collection scenarios.
Owner:YUANBAO TECH

Test method and device of baseboard management controller, server and storage medium

The invention relates to a substrate management controller test method and device, a server and a storage medium. The method comprises the following steps: aiming at each to-be-tested physical port of a baseboard management controller (BMC), generating a configuration file of the to-be-tested physical port based on test demand data and test data of the to-be-tested physical port; sending the configuration file to a corresponding physical port to be tested, calling a test thread of each physical port to be tested from a secure shell protocol (SSH) connection pool, and concurrently running the configuration file corresponding to each physical port to be tested through each test thread; calling the complex programmable logic device to monitor BMC health state information in the running process of the configuration file, and obtaining a test result of the BMC; the test data is simulation data generated by a data generator in the running process of the BMC. By adopting the method, the BMC can be tested from the bottom layer port, and the influence of the fault of the BMC on an application layer is avoided from the source.
Owner:SHUGUANG INFORMATION IND (SHANGHAI) CO LTD

Apparatus and method for scheming model for detecting secure shell communication

A method for scheming a model for detecting SSH communication according to an embodiment includes collecting a training dataset including a plurality of network session logs from a web proxy, generating a plurality of preprocessed log information based on a plurality of original datasets included in each of the plurality of network session logs, training, in a first algorithm-based first initial model and a second algorithm-based second initial model for detecting a log corresponding to SSH communication from network session logs, the first initial model and the second initial model based on the plurality of preprocessed log information, and using a new dataset as input to the trained first initial model and the trained second initial model and scheming a final model based on a detection result of the trained first initial model and a detection result of the trained second initial model.
Owner:SAMSUNG SDS CO LTD

Systems and methods for using enterprise IDP functionality to authorize user access across servers

The disclosed technology provides for authenticating server access using enterprise credentials. A method can include authenticating, by a client computing device operating within an enterprise environment, a user with an enterprise identity provider (“IdP”) system that authenticates based on user enterprise credentials, receiving, in response to the user being authenticated, a bearer token from the system, transmitting the bearer token to a certificate service for use in obtaining a secure shell (“SSH”) certificate signed by an SSH certificate authority (“CA”) within the enterprise, receiving, at the client computing device, the signed SSH certificate, updating an SSH agent on the client computing device to use the SSH certificate with the enterprise identifier for the user, and remotely accessing any of a group of servers within the enterprise using the SSH certificate and enterprise identifier, where each server authenticates the remote access based on the SSH certificate signed by the SSH CA.
Owner:TARGET BRANDS INC

Remotely accessible secure enclosure

Systems, methods, and apparatuses in accordance with embodiments of the invention can use a variety of computing devices to interact with and / or control a secure enclosure for a key fob. The secure enclosure may enclose the key fob, and includes a computing device, a locking mechanism, and at least one actuator. An actuator may control the locking mechanism. The actuator, when activated, may exert a force on a key fob secured within the secure enclosure, which may cause one of the buttons of the key fob to be depressed. The computing device controls the activation of the actuators. The computing device may have wireless communication capability that allows a user to wirelessly control the actuators of the computing device, for example, to lock or unlock the enclosure, or to depress a button of the key fob secured within the enclosure.
Owner:ALLSTATE INSURANCE COMPANY

Microwave network monitoring system

A system and method for monitoring a multi-vendor microwave network accesses a cell site router (CSR) to obtain IP addresses of radio units, establishes direct Secure Shell (SSH) connections to these units, and retrieves performance data from multiple vendors' equipment. The data is processed to generate unified performance metrics, stored in a cloud-based system, and presented via a web-based graphical user interface. The system compares metrics to predefined thresholds, generates alerts, and presents graphical trends. It detects integrity values of microwave links, identifies high-priority links, and alerts relevant teams. The system provides a vendor-agnostic technique that enables real-time monitoring, automated health checks, and customizable alerts across diverse network equipment.
Owner:DISH WIRELESS LLC

Implementing an infrastructure management service

The present invention extends to methods, systems, and computer program products for implementing an Infrastructure Management Service (IMS). A selected abstract function workflow defines an order for implementing a plurality of different abstract functions for a use case. A bare metal server of a specified configuration is selected to receive the use case. A bare metal profile pack corresponding the specified configuration and use case is accessed. A plurality of different concrete functions within the bare metal profile pack and corresponding to the plurality of different abstract functions are identified. A secure shell protocol daemon acting as a an IMS agent at the bare metal server receives instructions from worker threads executing the plurality of different concrete functions to implement the use case on the bare metal server.
Owner:RAKUTEN SYMPHONY INC

SSH proxy implementation method and device based on peer-to-peer architecture

The invention discloses an SSH (Secure Shell) proxy implementation method and device based on a peer-to-peer architecture, which are characterized in that by constructing a peer-to-peer node network, each node has functions of a proxy server and a client, and distributed deployment and collaboration of an SSH proxy can be realized without relying on a central node. Each distributed node independently runs the SSH service, completes the SSH session negotiation process with the client, and independently processes the service message carried by the SSH session, when a certain node fails, a new offline and online node can be automatically cleaned, and the new node participates in the SSH session negotiation and the service message processing function. According to the method, the SSH sessions can be independently established between the peer-to-peer architecture nodes and the client on the premise that a new device is not added, it is guaranteed that the SSH service of each node can operate independently and is not interfered by other nodes, hot backup of the distributed system is achieved, and therefore the reliability, safety and stability of operation of the distributed system are guaranteed.
Owner:PURPLE MOUNTAIN LAB

Remote human-machine interface

The invention relates to a management system for a production line (100) comprising at least one machine, said system comprising at least a human-machine interface (20), referred to as HMI, connected to an industrial programmable automation (19), referred to as API or PLC, of a machine of said production line (100), and / or a portable terminal (23) and a production control system, referred to as MES, it is notable in that it comprises at least one remote terminal (21) coupled to the machine or a safety housing (22) of the machine and connected to an industrial programmable automation (API) (19) or a human machine interface (HMI) (20) of the machine, the remote terminal (21) comprises means for detecting the presence of the portable terminal (23) within a determined perimeter and means for connecting the portable terminal (23) to a human-machine interface (HMI) (20) and / or to an industrial programmable automatic device (API) (19) of the machine, and wherein the portable terminal (23) comprises connection means for simultaneously connecting to at least two wireless networks, the first wireless network is dedicated to each machine of the production line (100) via the remote terminal (21) and the second wireless network is dedicated to the production control system (MES) such that when the portable terminal (23) is detected within a determined perimeter of the remote terminal (21) and the portable terminal (23) is continuously connected to the production control system (MES) (25), the portable terminal (23) is connected to the remote terminal (21). The portable terminal (23) is connected to the human machine interface (HMI) (20) and / or to an industrial programmable logic controller (API) (19) of the machine.
Owner:SIDEL PARTICIPATIONS SAS