Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

49 results about "Secure Shell" patented technology

Secure Shell (SSH) is a cryptographic network protocol for operating network services securely over an unsecured network. Typical applications include remote command-line, login, and remote command execution, but any network service can be secured with SSH.

Conditional SSH Tunneling as a Policy Enforcement Point for Seamless Zero Trust Integration

Enhanced security for Zero Trust networks is provided by SSH-customized tunnel clients / tunnel servers, a catalog service, and loopback address DNS mechanisms. Systems and methods provide Policy Enforcement Point (PEP) layer enhancements, strategically positioning the PEP between the user and the network resource. It manages network traffic flows and provides moderate control granularity, near-real-time enforcement decisions, low overheads, and broad applicability to TCP / IP traffic through modified tunneling implementations of Secure Shell (SSH). Unique use of SSH tunneling is utilized and adapted to selectively filter tunnel requests based on user entitlements, ensuring secure and authorized access to network resources. This method entails detailed assessment of tunneling requests, DNS manipulation, and the use of loopback address space for traffic redirection, all without requiring modifications to client-side applications. The approach significantly enhances network security by controlling access based on continuous verification of user entitlements, addressing the shortcomings of traditional network security models.
Owner:BANK OF AMERICA CORP

Secure shell protocol traffic evidence obtaining and decryption method and system based on key injection

The invention belongs to the technical field of network security and communication, and provides a secure shell protocol flow evidence obtaining decryption method and system based on key injection, and the method comprises the steps: injecting a user-defined dynamic library into a service process, intercepting a key encryption function, and extracting a session key as a shared key when a secure shell protocol server runs; carrying out session identification on the encrypted traffic in the grabbed network, and completing the recombination of the IP fragment and the TCP fragment to obtain the recombined encrypted traffic; carrying out matching and integrity verification on the shared key and the recombined encrypted traffic, and then decrypting to generate a plaintext message; and analyzing the plaintext message into a structured operation record according to a channel type, and classifying and storing the structured operation record in combination with a timestamp, a session ID and a user identifier to form auditing evidence data. According to the method, system files do not need to be modified, complete decryption and behavior restoration of multiple types of sessions such as Shell, SCP and SFTP can be achieved, and the method is suitable for network security audit and judicial evidence obtaining scenes.
Owner:YUANBAO TECH

System And Method For Managing Secure Shell Protocol Access In Cloud Infrastructure Environments

Techniques for creating, managing, and using SSH certificates with one or more target-specific principals are disclosed. A certificate authority receives a certificate signing request that includes both a user identifier and a resource identifier. The user identifier identifies a user, and the resource identifier represents one or more target hosts. The certificate authority forms a target-specific principal for use in creating the certificate. The target-specific principal indicates both the user and the resource identifier representing the resource(s) for which access is requested. The resource identifier may represent a host class associated with more than one host. Once the certificate authority verifies that the user is entitled to access the requested resource(s), it generates the certificate, signs it, and returns it to the requesting device.
Owner:ORACLE INT CORP

Session-centric access control for secure ephemeral shells

Technologies are shown for session centric access control of a remote connection. A request for a remote connection is received from a client. A container is created for the remote connection, and an identifier for each of one or more endpoints authorized for the remote connection are stored in the container. A secure shell is initiated for the remote connection. Access is provided to the first endpoint from the one or more endpoints via the secure shell based on a first identifier for the first endpoint being stored in the container.
Owner:EBAY INC

Containerized service with embedded scripting tools for monitoring health state of hyper-converged infrastructure resources

ActiveCN116668050BSecuring communicationSecure ShellHealth states
The disclosed method deploys a containerized health condition monitoring service that includes an embedded health condition monitoring service script. The containerized service generates a Secure Shell (SSH) key pair, including an SSH public key and an SSH private key. A management account of the containerized service is registered to a centralized account service. An SSH control module of a hyper-converged infrastructure (HCI) manager retrieves the management account of the containerized service from the account service. The control module accesses the containerized service to retrieve the SSH public key and stores the SSH public key to a target resource, such as a host or virtual machine, to enable any instance of the containerized service to remotely execute the health condition monitoring service script on the target resource using SSH commands.
Owner:DELL PROD LP

Conditional ssh tunneling as a policy enforcement point for seamless zero trust integration

Enhanced security for Zero Trust networks is provided by SSH-customized tunnel clients / tunnel servers, a catalog service, and loopback address DNS mechanisms. Systems and methods provide Policy Enforcement Point (PEP) layer enhancements, strategically positioning the PEP between the user and the network resource. It manages network traffic flows and provides moderate control granularity, near-real-time enforcement decisions, low overheads, and broad applicability to TCP / IP traffic through modified tunneling implementations of Secure Shell (SSH). Unique use of SSH tunneling is utilized and adapted to selectively filter tunnel requests based on user entitlements, ensuring secure and authorized access to network resources. This method entails detailed assessment of tunneling requests, DNS manipulation, and the use of loopback address space for traffic redirection, all without requiring modifications to client-side applications. The approach significantly enhances network security by controlling access based on continuous verification of user entitlements, addressing the shortcomings of traditional network security models.
Owner:BANK OF AMERICA CORP

SSH engine(s) for generating user specific SSH configuration files

ActiveUS12647466B2Securing communicationSoftware engineeringSecure Shell
Various embodiments of the present technology generally relate to systems and methods for providing an SSH engine. In an example, a method includes receiving, by an SSH engine, a request for a Secured Shell (SSH) configuration file from a client device. The SSH engine may then determine access privileges associated with the client device and generate rules based on the access privileges. The access privileges may identify resources that the client device has authority to access. The SSH engine may then validate each rule of the rules based on the access privileges and generate the SSH configuration file including the rules for the client device.
Owner:ORACLE INT CORP

A communication method, cloud platform, edge device and client device

PendingCN122160367ASecuring communicationWebSocketSecure Shell
The embodiment of the application provides a communication method, a cloud platform, an edge device and a client device, which can multiplex websocket channels to transmit messages between the cloud platform and the edge device, thereby greatly reducing the number of websocket channels between the cloud platform and the edge device, reducing the network bandwidth resources occupied by the websocket channels, and allowing more client devices to remotely and safely log in on the edge device. The communication method comprises the following steps: after the cloud platform receives a websocket connection request sent by a client device, the cloud platform sends a first websocket message to an edge device through a preset websocket channel; after the edge device establishes a secure shell connection, the cloud platform receives a second websocket message sent by the edge device through the websocket channel; and then the cloud platform sends a websocket connection response to the client device according to a connection identifier in the second websocket message.
Owner:CHENGDU HUAWEI TECH CO LTD

Access Method, Device, Equipment and Storage Medium of Operating System

This application relates to a method, device, equipment, and storage medium for accessing an operating system, specifically in the field of Internet technology. The method is applied to an operating system access platform, which includes a server and a user terminal, and the server includes an operating system. The method includes: proxying the Secure Shell (SSH) service of the operating system to the server; the user terminal sending an SSH access command to the server; and the server responding to the SSH access command through the proxied SSH service of the operating system to assist the user terminal in accessing the operating system. Based on this technical solution, a new way of accessing an operating system is provided. When there is a network failure in direct connection access, the user terminal can still access the operating system automatically through the SSH access method, improving the efficiency of the user terminal accessing the operating system.
Owner:北京自如信息科技有限公司

Techniques for persisting data across instances of cloud shell

To provide a method, computer system and storage medium for persisting data across secure shell instances.SOLUTION: A method includes: causing a computer system to receive a request to reserve a block volume, the request being transmitted from a session manager service; reserving the block volume; identifying a data center identifier of the block volume; returning the data center identifier of the block volume to the session manager service; attaching the block volume to a volume management fleet machine; receiving an instruction from the session manager service to release the block volume; creating a backup of the block volume comprising the data stored in the block volume; and releasing the block volume.SELECTED DRAWING: Figure 7
Owner:ORACLE INT CORP

Remote human-computer interface

The invention relates to a system for managing a production line, said production line comprising at least one machine, said system comprising at least: a human-machine interface (20), referred to as HMI, connected to the machines of said production line, referred to as API or industrial programmable automation (19), referred to as PLC according to the English initial abbreviation of "Programmable Logic Controller", and / or a portable terminal (23); the system is characterized in that it comprises at least one remote terminal (21) coupled to the machine or a safety housing (22) of the machine and connected to an industrial programmable automation (API) (19) or a human-machine interface (HMI) (20) of the machine, the remote terminal (21) comprises means for detecting the presence of a portable terminal (23) within a determined perimeter and means for connecting the portable terminal (23) to an industrial programmable automation (API) (19) and / or a human-machine interface (HMI) (20) of the machine, the portable terminal (23) comprising an emergency stop, the emergency stop is automatically connected to an emergency stop management system of an industrial programmable automatic device (API) (19) and / or a human-machine interface (HMI) (20) of the machine when the portable terminal (23) is detected within a determined perimeter and connected to the industrial programmable automatic device (API) (19) and / or the human-machine interface (HMI) (20) of the machine.
Owner:SIDEL PARTICIPATIONS SAS

Secure shell and role isolation for multi-tenant compute

Embodiments herein describe a SoC with one or more untrusted islands that can host one or more roles or tenants in a data center environment (e.g., a cloud computing environment). In one embodiment, a secure shell encapsulates the untrusted islands with a secure application programming interface (API) to access other hardware resources in the SoC. Hardware resources in the SoC (e.g., HardIP, SoftIP, or both), can either be secure / trusted, or rely on the secure shell to ensure confidentiality.
Owner:XILINX INC

A Security Shell Protocol Traffic Detection Method and Device for Complex Bearings Inside Tunnels

The present invention provides a method and device for detecting Secure Shell (SSH) traffic in a tunnel with complex bearers. The method includes: Step 1, collecting tunnel mixed traffic and extracting three features of the packet length, arrival time interval, and direction of a specified number of packets in each flow; Step 2, constructing packets with the same direction and consecutive ones into the same burst and building a burst feature sequence; Step 3, mapping each packet in the burst to a frequency domain signal to obtain a mixed frequency domain signal of the burst traffic in the frequency domain representation; Step 4, obtaining the statistical features of the mixed frequency domain signal; Step 5, inputting the statistical features of the mixed frequency domain signal into an encoder-decoder architecture based on a recurrent neural network to obtain a prediction label at the burst level and a prediction label at the flow level, and determining whether there is SSH traffic in the mixed traffic and locating the burst where it is located. This method effectively solves the problem of SSH traffic detection under complex bearers in the tunnel and significantly improves the detection accuracy.
Owner:NANJING UNIV OF INFORMATION SCI & TECH

Bare metal server intelligent identification method and device and storage medium

PendingCN120186217ATransmissionBare metalIntelligent Platform Management Interface
The invention discloses a bare metal server intelligent identification method and device and a storage medium, and the method comprises the steps: constructing an intelligent discovery protocol set which comprises an intelligent platform management interface protocol, a simple network management protocol, a secure shell protocol and a hypertext transfer protocol; according to the intelligent discovery protocol set, performing protocol applicability evaluation to obtain an applicability evaluation result; according to the applicability evaluation result and the optimal protocol selection strategy, constructing a protocol intelligent discovery strategy; constructing an intelligent matching strategy; and according to the protocol intelligent discovery strategy and the intelligent matching strategy, intelligent identification of the bare metal server is carried out, and an intelligent identification result of the bare metal server is obtained. According to the invention, the intelligent identification of the bare metal server is realized, the efficiency and compatibility are improved, and the resource consumption is reduced. The method can be widely applied to the technical field of bare metal server operation and maintenance.
Owner:CHINA SOUTHERN POWER GRID DIGITAL GRID GROUP (GUANGDONG) CO LTD

Communication Method, Server, and Client Based on National Cryptography Encryption Network Protocol

The present application discloses a communication method, a server, and a client based on a national cryptographic encryption network protocol, relating to the technical field of communication transmission. The method is applied to the server and includes: in the case of receiving a first national cryptographic secure shell protocol connection request sent by the client, generating confirmation key negotiation completion information that matches the first national cryptographic secure shell protocol connection request, and sending the confirmation key negotiation completion information to the client; in the case of receiving identity authentication challenge information sent by the client, generating identity confirmation information and generating an authentication challenge data packet based on the identity confirmation information; in the case of obtaining an intelligent key and receiving a result data packet, verifying the result data packet and the intelligent key through a preset verification method; and in the case that the result data packet meets a preset threshold and the intelligent key verification meets a preset password, sending a connection request to the client. It can greatly improve the security of the communication channel.
Owner:BEIJING LINX SOFTWARE CORP

Code management method and device, medium and program product

The invention relates to the field of distributed technologies, and discloses a code management method and device, a medium and a program product. The method comprises the following steps: acquiring a code downloading request sent by a client through secure shell protocol connection, and acquiring a user identifier, an equipment internet protocol address and a code address according to the code downloading request; if it is detected that the user identifier and the equipment internet protocol address successfully pass verification, obtaining a target code matched with the code address; and sending the target code to the client through the secure shell protocol connection. According to the scheme of the embodiment, after the secure shell protocol connection is established, verification of the internet protocol address of the equipment is newly added, so that the code leakage risk can be reduced, and the security of code management can be improved.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Industrial personal computer performance acquisition method based on third-party control and terminal

The invention discloses an industrial personal computer performance acquisition method and terminal based on a third-party control, and the method comprises the steps: firstly judging whether a to-be-acquired industrial personal computer is a local terminal or not, and then automatically selecting a mode of direct calling or remote calling based on a secure shell protocol to acquire the performance; and a third-party control interface is uniformly called to realize efficient acquisition of hardware performance of the industrial personal computer, so that an optimal calling path is automatically selected in a local scene and a far-end scene. Compared with a traditional mode of directly reading the system file, the method has the advantages that a Linux kernel file structure does not need to be deeply analyzed; a key pair is configured between a local industrial personal computer and a to-be-acquired industrial personal computer in advance, and cross-industrial-personal-computer and cross-network remote acquisition is realized by using a secure shell protocol SSH, so that the safety and reliability of cross-computer performance data acquisition are improved. In conclusion, the method obviously improves the efficiency, accuracy and maintainability of performance acquisition of the industrial personal computer.
Owner:CONTEMPORARY NEBULA TECH ENERGY CO LTD

Specialized computing environment for co-analysis of proprietary data

A specialized computing environment that includes hardware and data security features to enable competitive organizations to co-analyze proprietary data without revealing the underlying proprietary data to unauthorized users. Proprietary data are stored in volatile memory, which may be automatically erased according to pre-stored criteria. The analysis is performed automatically by a processing unit without human intervention. Analytical results are sanitized (e.g., using data masking) to prevent the analytical result from being tracible to any particular data source. Sanitized analytical results are output without outputting the underlying proprietary data (except to users authorized to validate analytical results). The computing environment is enclosed within a secure enclosure (e.g., a steel box with a lock), does not include any peripheral devices outside the secure enclosure, does not communicate wirelessly, and does not have hardware ports accessible from outside the secure enclosure (except, in some embodiments, a wired connection for a web server).
Owner:CHILDRENS HOSPITAL MEDICAL CENT CINCINNATI +1

Secure shell protocol traffic detection method and device for complex bearing in tunnel

The invention provides a secure shell protocol flow detection method and device for complex bearing in a tunnel, and the method comprises the steps: 1, collecting the mixed flow of the tunnel, and extracting the data packet length, arrival time interval and direction of a specified number of data packets in each flow; 2, constructing continuous data packets in the same direction into the same burst, and constructing a burst feature sequence; step 3, mapping each data packet in the burst into a frequency domain signal to obtain a mixed frequency domain signal of the burst traffic in the frequency domain representation; step 4, obtaining mixed frequency domain signal statistical characteristics; and 5, inputting the mixed frequency domain signal statistical characteristics into an encoder and decoder architecture based on a recurrent neural network to obtain a prediction label of a burst level and a prediction label of a flow level, judging whether the SSH flow exists in the mixed flow or not, and positioning the burst. According to the method, the SSH flow detection problem under the complex bearing of the tunnel is effectively solved, and the detection accuracy is remarkably improved.
Owner:NANJING UNIV OF INFORMATION SCI & TECH

Rebound shell behavior detection method, system, storage medium and terminal

The present application provides a method for detecting rebound shell behavior, including: obtaining a data packet in the reverse transport layer of a secure shell protocol SSH connection; determining the data packet type contained in the data packet; if the data size of each of the data packets satisfies the threshold interval corresponding to the data packet type to which it belongs, determining that a rebound shell behavior exists. The present application does not need to rely on terminal process information, does not need to detect the SSH rebound shell command in the terminal command line, and detects the SSH rebound shell behavior completely through the traffic side. Secondly, the present application does not rely on specific fields of the SSH protocol, does not need to decrypt the SSH encrypted traffic, and can detect the SSH rebound shell behavior only based on the data packet characteristics passing through the reverse transport layer of the SSH session. The present application also provides a rebound shell behavior detection system, storage medium and terminal, which have the above-mentioned beneficial effects.
Owner:SANGFOR TECH INC

Secure shell (SSH) remote connection process management method and computing device

Embodiments of the present application relate to the technical field of server, and specifically provide a secure shell (SSH) remote connection process management method and a computing device, wherein the method comprises: obtaining a login session identifier of a user; determining whether the login session identifier is in a blacklist; in response to the login session identifier being in the blacklist, adding an SSH process of the user into a cgroup resource control group; and in response to the login session identifier not being in the blacklist, monitoring resource usage of the SSH process of the user. Embodiments of the present application can achieve dynamic, real-time and fine resource management for remote connection sessions.
Owner:XFUSION DIGITAL TECH CO LTD

Terminal access to virtual private servers with automatic protocol fallback

A request to access a Virtual Private Server (VPS) is receive from a client device. An attempt is made to establish a Secure Shell (SSH) connection with the VPS. Responsive to a failure to establish the SSH connection, a serial console connection is automatically established with the VPS. Data communicated via the serial console connection is converted to a format compatible with the request. The converted data is then provided to the client device.
Owner:HOSTINGER OPERATIONS UAB

Toggling switch state based on detected behavior associated with component

A point of sale (POS) device includes an output device such as a speaker, a display screen, or a network interface. The POS device also includes a secure enclosure housing a secure processor and tamper detection circuitry for detecting attempts to tamper with the secure enclosure. Use of the output device is shared between the secure processor and a main processor via a switch that is controlled by the secure processor. The secure processor can switch control of the output device from the main processor to itself and can output an output dataset via the output device in a number of scenarios. These scenarios include the secure processor detecting an attempt to tamper with the secure enclosure, the secure processor recognizing that the main processor is behaving suspiciously, or the secure processor wanting to output sensitive information. The output dataset may include visual data, audio data, or network data.
Owner:BLOCK INC

Database cluster node downtime restarting method and device, equipment and storage medium

The invention relates to the technical field of information processing, in particular to a database cluster node downtime restarting method, device and equipment and a storage medium, by deploying an Nginx reverse proxy service in a StarRocks cluster and configuring the Nginx reverse proxy service to access a plurality of front-end nodes in a polling mode, a high-availability database connection channel is established, a timed detection script is compiled, and the reliability of the database cluster node downtime restarting is improved. And periodically executing a sequential query process for the survival states of all the front-end nodes and the survival states of all the rear-end nodes through a database connection channel, recording a failure node whose survival state is failed according to a first query result, and automatically and remotely executing a remote restart process for the failure node through an SSH (Secure Shell). After the remote restart process is executed, the survival state of the failed node is queried again, and when restart fails, an alarm notification is generated and sent to the management terminal, so that unattended rapid recovery of the cluster node is realized, and the system reliability and the operation and maintenance automation level are improved.
Owner:上海乾臻信息科技有限公司

Remote login identity authentication method and device based on face recognition, equipment and storage medium

The invention discloses a remote login identity authentication method, device and equipment based on face recognition and a storage medium, and relates to the technical field of information safety and identity authentication, the method comprises the steps that a remote login request sent by remote equipment is received and initiated, and the remote login request comprises target account information; detecting authentication configuration corresponding to the target account information through a pluggable authentication module to obtain a detection result; when the detection result is that face authentication needs to be executed, generating an authentication request according to the target account information and the session identifier; the authentication request is sent to a face authentication server, so that the face authentication server authenticates a real-time face image and feeds back an authentication result, and the real-time face image is acquired by the initiating remote device; and processing the remote login request according to the authentication result. According to the invention, on the premise that a secure shell protocol and a client are not modified, it can be ensured that the remote login person and the authorized user are the same person through biological feature verification, and the risk of credential embezzlement is reduced.
Owner:HUNAN KYLIN XINAN TECH CO LTD

Embedded device cross-platform hardware detection method, device and equipment and storage medium

PendingCN121116688AFault responseFault analysisSecure Shell
The invention discloses an embedded device cross-platform hardware detection method, device and equipment and a storage medium, and the method comprises the steps: building communication connection with an operation and maintenance working end through a secure shell protocol channel, and building a file transmission channel and an interaction environment based on the secure shell protocol channel; based on the file transmission channel, a fault analysis program sent by the operation and maintenance working end is obtained, and the fault analysis program is matched with a hardware model and an operating system of the embedded device; obtaining an operation and maintenance instruction sent by an operation and maintenance working end through the interaction environment; executing a fault analysis operation based on the fault analysis instruction and the fault analysis program, or executing operation condition monitoring based on the operation condition monitoring instruction; and when fault analysis or operation condition monitoring is completed, operation and maintenance operation information is generated and fed back to the operation and maintenance working end. A remote interaction environment is constructed through the SSH, cross-platform fault positioning and monitoring are achieved, operation is simplified, an operation and maintenance closed loop can be formed, stable operation of equipment is guaranteed, and the user satisfaction degree is improved.
Owner:CYG CONTRON

Provisioning business function on edge

Provisioning business functions is provided. A runtime binary activation code is sent to a nodal edge server that has a needed runtime binary for a set of edge devices to perform a business function. A secure shell protocol connection with root operating system access is established to the nodal edge server that has the needed runtime binary to execute the runtime binary activation code.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Single sign-on for secure shell protocol sessions

One example method includes receiving, at a client computing system, an identification (ID) token from an external identity provider. The ID token authenticates an identity of a user of the client computing system. A first request is provided to a server computing system for the ID token to be exchanged for a first token that is configured to allow the client computing system to establish a first Secure Shell Protocol (SSH) session with the server computing system, the first request including the ID token. The first token is received from the server computing system. The first token is used to establish the first SSH session with the server computing system.
Owner:DELL PROD LP

A cluster expansion method, product, device and medium

The present invention discloses a cluster expansion method, product, device and medium, and relates to the field of cloud technology. Specifically, when a private cloud cluster is expanded and a public cloud host needs to be added to the private cloud cluster, the first virtual network card of the public cloud host and the second virtual network card of the private cloud host are created; based on the public Internet Protocol address of the public cloud host, the first virtual network card of the public cloud host and the second virtual network card of the private cloud host, a secure shell protocol tunnel is established between the public cloud host and the private cloud host, thereby realizing two-way communication between the public cloud host and the private cloud host; finally, the public cloud host is controlled to join the private cloud cluster through the secure shell protocol tunnel, thereby realizing the management of the public cloud host by the private cloud cluster, and the public cloud host can be directly scheduled and resource managed through the management platform of the private cloud cluster, thereby reducing the management cost of the server and improving the development efficiency.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD